Commit | Line | Data |
---|---|---|
f6ebe77f HW |
1 | #include <linux/kernel.h> |
2 | #include <linux/init.h> | |
3 | #include <linux/module.h> | |
4 | #include <linux/proc_fs.h> | |
5 | #include <linux/skbuff.h> | |
6 | #include <linux/netfilter.h> | |
bbd86b9f | 7 | #include <linux/seq_file.h> |
7a11b984 | 8 | #include <linux/rcupdate.h> |
f6ebe77f | 9 | #include <net/protocol.h> |
c01cd429 | 10 | #include <net/netfilter/nf_queue.h> |
f6ebe77f HW |
11 | |
12 | #include "nf_internals.h" | |
13 | ||
601e68e1 | 14 | /* |
f6ebe77f HW |
15 | * A queue handler may be registered for each protocol. Each is protected by |
16 | * long term mutex. The handler must provide an an outfn() to accept packets | |
17 | * for queueing and must reinject all packets it receives, no matter what. | |
18 | */ | |
e3ac5298 | 19 | static const struct nf_queue_handler *queue_handler[NPROTO]; |
f6ebe77f | 20 | |
585426fd | 21 | static DEFINE_MUTEX(queue_handler_mutex); |
f6ebe77f | 22 | |
d72367b6 HW |
23 | /* return EBUSY when somebody else is registered, return EEXIST if the |
24 | * same handler is registered, return 0 in case of success. */ | |
e3ac5298 | 25 | int nf_register_queue_handler(int pf, const struct nf_queue_handler *qh) |
601e68e1 | 26 | { |
f6ebe77f HW |
27 | int ret; |
28 | ||
29 | if (pf >= NPROTO) | |
30 | return -EINVAL; | |
31 | ||
585426fd | 32 | mutex_lock(&queue_handler_mutex); |
d72367b6 HW |
33 | if (queue_handler[pf] == qh) |
34 | ret = -EEXIST; | |
35 | else if (queue_handler[pf]) | |
f6ebe77f HW |
36 | ret = -EBUSY; |
37 | else { | |
585426fd | 38 | rcu_assign_pointer(queue_handler[pf], qh); |
f6ebe77f HW |
39 | ret = 0; |
40 | } | |
585426fd | 41 | mutex_unlock(&queue_handler_mutex); |
f6ebe77f HW |
42 | |
43 | return ret; | |
44 | } | |
45 | EXPORT_SYMBOL(nf_register_queue_handler); | |
46 | ||
47 | /* The caller must flush their queue before this */ | |
e3ac5298 | 48 | int nf_unregister_queue_handler(int pf, const struct nf_queue_handler *qh) |
f6ebe77f HW |
49 | { |
50 | if (pf >= NPROTO) | |
51 | return -EINVAL; | |
52 | ||
585426fd | 53 | mutex_lock(&queue_handler_mutex); |
ce7663d8 | 54 | if (queue_handler[pf] != qh) { |
585426fd | 55 | mutex_unlock(&queue_handler_mutex); |
ce7663d8 YK |
56 | return -EINVAL; |
57 | } | |
58 | ||
585426fd YK |
59 | rcu_assign_pointer(queue_handler[pf], NULL); |
60 | mutex_unlock(&queue_handler_mutex); | |
61 | ||
62 | synchronize_rcu(); | |
601e68e1 | 63 | |
f6ebe77f HW |
64 | return 0; |
65 | } | |
66 | EXPORT_SYMBOL(nf_unregister_queue_handler); | |
67 | ||
e3ac5298 | 68 | void nf_unregister_queue_handlers(const struct nf_queue_handler *qh) |
f6ebe77f HW |
69 | { |
70 | int pf; | |
71 | ||
585426fd | 72 | mutex_lock(&queue_handler_mutex); |
f6ebe77f | 73 | for (pf = 0; pf < NPROTO; pf++) { |
bbd86b9f | 74 | if (queue_handler[pf] == qh) |
585426fd | 75 | rcu_assign_pointer(queue_handler[pf], NULL); |
f6ebe77f | 76 | } |
585426fd YK |
77 | mutex_unlock(&queue_handler_mutex); |
78 | ||
79 | synchronize_rcu(); | |
f6ebe77f HW |
80 | } |
81 | EXPORT_SYMBOL_GPL(nf_unregister_queue_handlers); | |
82 | ||
601e68e1 YH |
83 | /* |
84 | * Any packet that leaves via this function must come back | |
f6ebe77f HW |
85 | * through nf_reinject(). |
86 | */ | |
394f545d PM |
87 | static int __nf_queue(struct sk_buff *skb, |
88 | struct list_head *elem, | |
89 | int pf, unsigned int hook, | |
90 | struct net_device *indev, | |
91 | struct net_device *outdev, | |
92 | int (*okfn)(struct sk_buff *), | |
93 | unsigned int queuenum) | |
f6ebe77f HW |
94 | { |
95 | int status; | |
02f014d8 | 96 | struct nf_queue_entry *entry; |
f6ebe77f HW |
97 | #ifdef CONFIG_BRIDGE_NETFILTER |
98 | struct net_device *physindev = NULL; | |
99 | struct net_device *physoutdev = NULL; | |
100 | #endif | |
bce8032e | 101 | struct nf_afinfo *afinfo; |
e3ac5298 | 102 | const struct nf_queue_handler *qh; |
f6ebe77f HW |
103 | |
104 | /* QUEUE == DROP if noone is waiting, to be safe. */ | |
585426fd YK |
105 | rcu_read_lock(); |
106 | ||
107 | qh = rcu_dereference(queue_handler[pf]); | |
108 | if (!qh) { | |
109 | rcu_read_unlock(); | |
394f545d | 110 | kfree_skb(skb); |
f6ebe77f HW |
111 | return 1; |
112 | } | |
113 | ||
bce8032e PM |
114 | afinfo = nf_get_afinfo(pf); |
115 | if (!afinfo) { | |
585426fd | 116 | rcu_read_unlock(); |
394f545d | 117 | kfree_skb(skb); |
bce8032e PM |
118 | return 1; |
119 | } | |
120 | ||
02f014d8 PM |
121 | entry = kmalloc(sizeof(*entry) + afinfo->route_key_size, GFP_ATOMIC); |
122 | if (!entry) { | |
f6ebe77f HW |
123 | if (net_ratelimit()) |
124 | printk(KERN_ERR "OOM queueing packet %p\n", | |
394f545d | 125 | skb); |
585426fd | 126 | rcu_read_unlock(); |
394f545d | 127 | kfree_skb(skb); |
f6ebe77f HW |
128 | return 1; |
129 | } | |
130 | ||
02f014d8 PM |
131 | *entry = (struct nf_queue_entry) { |
132 | .skb = skb, | |
133 | .elem = list_entry(elem, struct nf_hook_ops, list), | |
134 | .pf = pf, | |
135 | .hook = hook, | |
136 | .indev = indev, | |
137 | .outdev = outdev, | |
138 | .okfn = okfn, | |
139 | }; | |
f6ebe77f HW |
140 | |
141 | /* If it's going away, ignore hook. */ | |
02f014d8 | 142 | if (!try_module_get(entry->elem->owner)) { |
585426fd | 143 | rcu_read_unlock(); |
02f014d8 | 144 | kfree(entry); |
f6ebe77f HW |
145 | return 0; |
146 | } | |
147 | ||
148 | /* Bump dev refs so they don't vanish while packet is out */ | |
8b1cf0db PM |
149 | if (indev) |
150 | dev_hold(indev); | |
151 | if (outdev) | |
152 | dev_hold(outdev); | |
f6ebe77f | 153 | #ifdef CONFIG_BRIDGE_NETFILTER |
394f545d PM |
154 | if (skb->nf_bridge) { |
155 | physindev = skb->nf_bridge->physindev; | |
8b1cf0db PM |
156 | if (physindev) |
157 | dev_hold(physindev); | |
394f545d | 158 | physoutdev = skb->nf_bridge->physoutdev; |
8b1cf0db PM |
159 | if (physoutdev) |
160 | dev_hold(physoutdev); | |
f6ebe77f HW |
161 | } |
162 | #endif | |
02f014d8 PM |
163 | afinfo->saveroute(skb, entry); |
164 | status = qh->outfn(entry, queuenum); | |
f6ebe77f | 165 | |
585426fd | 166 | rcu_read_unlock(); |
f6ebe77f HW |
167 | |
168 | if (status < 0) { | |
169 | /* James M doesn't say fuck enough. */ | |
8b1cf0db PM |
170 | if (indev) |
171 | dev_put(indev); | |
172 | if (outdev) | |
173 | dev_put(outdev); | |
f6ebe77f | 174 | #ifdef CONFIG_BRIDGE_NETFILTER |
8b1cf0db PM |
175 | if (physindev) |
176 | dev_put(physindev); | |
177 | if (physoutdev) | |
178 | dev_put(physoutdev); | |
f6ebe77f | 179 | #endif |
02f014d8 PM |
180 | module_put(entry->elem->owner); |
181 | kfree(entry); | |
394f545d | 182 | kfree_skb(skb); |
f6ebe77f HW |
183 | |
184 | return 1; | |
185 | } | |
186 | ||
187 | return 1; | |
188 | } | |
189 | ||
394f545d PM |
190 | int nf_queue(struct sk_buff *skb, |
191 | struct list_head *elem, | |
192 | int pf, unsigned int hook, | |
193 | struct net_device *indev, | |
194 | struct net_device *outdev, | |
195 | int (*okfn)(struct sk_buff *), | |
196 | unsigned int queuenum) | |
197 | { | |
198 | struct sk_buff *segs; | |
199 | ||
200 | if (!skb_is_gso(skb)) | |
201 | return __nf_queue(skb, elem, pf, hook, indev, outdev, okfn, | |
202 | queuenum); | |
203 | ||
204 | switch (pf) { | |
205 | case AF_INET: | |
206 | skb->protocol = htons(ETH_P_IP); | |
207 | break; | |
208 | case AF_INET6: | |
209 | skb->protocol = htons(ETH_P_IPV6); | |
210 | break; | |
211 | } | |
212 | ||
213 | segs = skb_gso_segment(skb, 0); | |
214 | kfree_skb(skb); | |
215 | if (unlikely(IS_ERR(segs))) | |
216 | return 1; | |
217 | ||
218 | do { | |
219 | struct sk_buff *nskb = segs->next; | |
220 | ||
221 | segs->next = NULL; | |
222 | if (!__nf_queue(segs, elem, pf, hook, indev, outdev, okfn, | |
223 | queuenum)) | |
224 | kfree_skb(segs); | |
225 | segs = nskb; | |
226 | } while (segs); | |
227 | return 1; | |
228 | } | |
229 | ||
02f014d8 | 230 | void nf_reinject(struct nf_queue_entry *entry, unsigned int verdict) |
f6ebe77f | 231 | { |
02f014d8 PM |
232 | struct sk_buff *skb = entry->skb; |
233 | struct list_head *elem = &entry->elem->list; | |
bce8032e | 234 | struct nf_afinfo *afinfo; |
f6ebe77f HW |
235 | |
236 | rcu_read_lock(); | |
237 | ||
238 | /* Release those devices we held, or Alexey will kill me. */ | |
02f014d8 PM |
239 | if (entry->indev) |
240 | dev_put(entry->indev); | |
241 | if (entry->outdev) | |
242 | dev_put(entry->outdev); | |
f6ebe77f HW |
243 | #ifdef CONFIG_BRIDGE_NETFILTER |
244 | if (skb->nf_bridge) { | |
245 | if (skb->nf_bridge->physindev) | |
246 | dev_put(skb->nf_bridge->physindev); | |
247 | if (skb->nf_bridge->physoutdev) | |
248 | dev_put(skb->nf_bridge->physoutdev); | |
249 | } | |
250 | #endif | |
251 | ||
252 | /* Drop reference to owner of hook which queued us. */ | |
02f014d8 | 253 | module_put(entry->elem->owner); |
f6ebe77f | 254 | |
f6ebe77f HW |
255 | /* Continue traversal iff userspace said ok... */ |
256 | if (verdict == NF_REPEAT) { | |
257 | elem = elem->prev; | |
258 | verdict = NF_ACCEPT; | |
259 | } | |
260 | ||
7a11b984 | 261 | if (verdict == NF_ACCEPT) { |
02f014d8 PM |
262 | afinfo = nf_get_afinfo(entry->pf); |
263 | if (!afinfo || afinfo->reroute(skb, entry) < 0) | |
7a11b984 PM |
264 | verdict = NF_DROP; |
265 | } | |
266 | ||
f6ebe77f HW |
267 | if (verdict == NF_ACCEPT) { |
268 | next_hook: | |
02f014d8 PM |
269 | verdict = nf_iterate(&nf_hooks[entry->pf][entry->hook], |
270 | skb, entry->hook, | |
271 | entry->indev, entry->outdev, &elem, | |
272 | entry->okfn, INT_MIN); | |
f6ebe77f HW |
273 | } |
274 | ||
275 | switch (verdict & NF_VERDICT_MASK) { | |
276 | case NF_ACCEPT: | |
3bc38712 | 277 | case NF_STOP: |
02f014d8 | 278 | entry->okfn(skb); |
3bc38712 | 279 | case NF_STOLEN: |
f6ebe77f | 280 | break; |
f6ebe77f | 281 | case NF_QUEUE: |
02f014d8 PM |
282 | if (!__nf_queue(skb, elem, entry->pf, entry->hook, |
283 | entry->indev, entry->outdev, entry->okfn, | |
394f545d | 284 | verdict >> NF_VERDICT_BITS)) |
f6ebe77f HW |
285 | goto next_hook; |
286 | break; | |
3bc38712 PM |
287 | default: |
288 | kfree_skb(skb); | |
f6ebe77f HW |
289 | } |
290 | rcu_read_unlock(); | |
02f014d8 | 291 | kfree(entry); |
f6ebe77f HW |
292 | return; |
293 | } | |
294 | EXPORT_SYMBOL(nf_reinject); | |
295 | ||
bbd86b9f HW |
296 | #ifdef CONFIG_PROC_FS |
297 | static void *seq_start(struct seq_file *seq, loff_t *pos) | |
298 | { | |
299 | if (*pos >= NPROTO) | |
300 | return NULL; | |
301 | ||
302 | return pos; | |
303 | } | |
304 | ||
305 | static void *seq_next(struct seq_file *s, void *v, loff_t *pos) | |
306 | { | |
307 | (*pos)++; | |
308 | ||
309 | if (*pos >= NPROTO) | |
310 | return NULL; | |
311 | ||
312 | return pos; | |
313 | } | |
314 | ||
315 | static void seq_stop(struct seq_file *s, void *v) | |
316 | { | |
317 | ||
318 | } | |
319 | ||
320 | static int seq_show(struct seq_file *s, void *v) | |
321 | { | |
322 | int ret; | |
323 | loff_t *pos = v; | |
e3ac5298 | 324 | const struct nf_queue_handler *qh; |
bbd86b9f | 325 | |
585426fd YK |
326 | rcu_read_lock(); |
327 | qh = rcu_dereference(queue_handler[*pos]); | |
bbd86b9f HW |
328 | if (!qh) |
329 | ret = seq_printf(s, "%2lld NONE\n", *pos); | |
330 | else | |
331 | ret = seq_printf(s, "%2lld %s\n", *pos, qh->name); | |
585426fd | 332 | rcu_read_unlock(); |
bbd86b9f HW |
333 | |
334 | return ret; | |
335 | } | |
336 | ||
56b3d975 | 337 | static const struct seq_operations nfqueue_seq_ops = { |
bbd86b9f HW |
338 | .start = seq_start, |
339 | .next = seq_next, | |
340 | .stop = seq_stop, | |
341 | .show = seq_show, | |
342 | }; | |
343 | ||
344 | static int nfqueue_open(struct inode *inode, struct file *file) | |
345 | { | |
346 | return seq_open(file, &nfqueue_seq_ops); | |
347 | } | |
348 | ||
da7071d7 | 349 | static const struct file_operations nfqueue_file_ops = { |
bbd86b9f HW |
350 | .owner = THIS_MODULE, |
351 | .open = nfqueue_open, | |
352 | .read = seq_read, | |
353 | .llseek = seq_lseek, | |
354 | .release = seq_release, | |
355 | }; | |
356 | #endif /* PROC_FS */ | |
357 | ||
358 | ||
f6ebe77f HW |
359 | int __init netfilter_queue_init(void) |
360 | { | |
bbd86b9f HW |
361 | #ifdef CONFIG_PROC_FS |
362 | struct proc_dir_entry *pde; | |
f6ebe77f | 363 | |
bbd86b9f | 364 | pde = create_proc_entry("nf_queue", S_IRUGO, proc_net_netfilter); |
e02f7d16 | 365 | if (!pde) |
bbd86b9f | 366 | return -1; |
bbd86b9f HW |
367 | pde->proc_fops = &nfqueue_file_ops; |
368 | #endif | |
f6ebe77f HW |
369 | return 0; |
370 | } | |
371 |