[ESP]: Ensure IV is in linear part of the skb to avoid BUG() due to OOB access
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / netfilter / nf_log.c
CommitLineData
f6ebe77f
HW
1#include <linux/kernel.h>
2#include <linux/init.h>
3#include <linux/module.h>
4#include <linux/proc_fs.h>
5#include <linux/skbuff.h>
6#include <linux/netfilter.h>
bbd86b9f 7#include <linux/seq_file.h>
f6ebe77f 8#include <net/protocol.h>
f01ffbd6 9#include <net/netfilter/nf_log.h>
f6ebe77f
HW
10
11#include "nf_internals.h"
12
a5d29264 13/* Internal logging interface, which relies on the real
f6ebe77f
HW
14 LOG target modules */
15
16#define NF_LOG_PREFIXLEN 128
17
7b2f9631 18static const struct nf_logger *nf_loggers[NPROTO] __read_mostly;
9b73534d 19static DEFINE_MUTEX(nf_log_mutex);
f6ebe77f 20
d72367b6
HW
21/* return EBUSY if somebody else is registered, EEXIST if the same logger
22 * is registred, 0 on success. */
7b2f9631 23int nf_log_register(int pf, const struct nf_logger *logger)
f6ebe77f 24{
9b73534d 25 int ret;
f6ebe77f 26
8a61fadb
HW
27 if (pf >= NPROTO)
28 return -EINVAL;
29
f6ebe77f
HW
30 /* Any setup of logging members must be done before
31 * substituting pointer. */
9b73534d
PM
32 ret = mutex_lock_interruptible(&nf_log_mutex);
33 if (ret < 0)
34 return ret;
35
e92ad99c
PM
36 if (!nf_loggers[pf])
37 rcu_assign_pointer(nf_loggers[pf], logger);
38 else if (nf_loggers[pf] == logger)
d72367b6 39 ret = -EEXIST;
9b73534d
PM
40 else
41 ret = -EBUSY;
d72367b6 42
9b73534d 43 mutex_unlock(&nf_log_mutex);
f6ebe77f 44 return ret;
601e68e1 45}
f6ebe77f
HW
46EXPORT_SYMBOL(nf_log_register);
47
9dc6aa5f 48void nf_log_unregister_pf(int pf)
f6ebe77f 49{
8a61fadb 50 if (pf >= NPROTO)
9dc6aa5f 51 return;
9b73534d 52 mutex_lock(&nf_log_mutex);
e92ad99c 53 rcu_assign_pointer(nf_loggers[pf], NULL);
9b73534d 54 mutex_unlock(&nf_log_mutex);
f6ebe77f
HW
55
56 /* Give time to concurrent readers. */
a5ea6169 57 synchronize_rcu();
f6ebe77f
HW
58}
59EXPORT_SYMBOL(nf_log_unregister_pf);
60
7b2f9631 61void nf_log_unregister(const struct nf_logger *logger)
f6ebe77f
HW
62{
63 int i;
64
9b73534d 65 mutex_lock(&nf_log_mutex);
f6ebe77f 66 for (i = 0; i < NPROTO; i++) {
e92ad99c
PM
67 if (nf_loggers[i] == logger)
68 rcu_assign_pointer(nf_loggers[i], NULL);
f6ebe77f 69 }
9b73534d 70 mutex_unlock(&nf_log_mutex);
f6ebe77f 71
a5ea6169 72 synchronize_rcu();
f6ebe77f 73}
e92ad99c 74EXPORT_SYMBOL(nf_log_unregister);
f6ebe77f
HW
75
76void nf_log_packet(int pf,
77 unsigned int hooknum,
78 const struct sk_buff *skb,
79 const struct net_device *in,
80 const struct net_device *out,
7b2f9631 81 const struct nf_loginfo *loginfo,
f6ebe77f
HW
82 const char *fmt, ...)
83{
84 va_list args;
85 char prefix[NF_LOG_PREFIXLEN];
7b2f9631 86 const struct nf_logger *logger;
601e68e1 87
f6ebe77f 88 rcu_read_lock();
e92ad99c 89 logger = rcu_dereference(nf_loggers[pf]);
f6ebe77f
HW
90 if (logger) {
91 va_start(args, fmt);
92 vsnprintf(prefix, sizeof(prefix), fmt, args);
93 va_end(args);
f6ebe77f
HW
94 logger->logfn(pf, hooknum, skb, in, out, loginfo, prefix);
95 } else if (net_ratelimit()) {
96 printk(KERN_WARNING "nf_log_packet: can\'t log since "
97 "no backend logging module loaded in! Please either "
98 "load one, or disable logging explicitly\n");
99 }
100 rcu_read_unlock();
101}
102EXPORT_SYMBOL(nf_log_packet);
103
104#ifdef CONFIG_PROC_FS
105static void *seq_start(struct seq_file *seq, loff_t *pos)
ca7c48ca 106 __acquires(RCU)
f6ebe77f
HW
107{
108 rcu_read_lock();
109
110 if (*pos >= NPROTO)
111 return NULL;
112
113 return pos;
114}
115
116static void *seq_next(struct seq_file *s, void *v, loff_t *pos)
117{
118 (*pos)++;
119
120 if (*pos >= NPROTO)
121 return NULL;
122
123 return pos;
124}
125
126static void seq_stop(struct seq_file *s, void *v)
ca7c48ca 127 __releases(RCU)
f6ebe77f
HW
128{
129 rcu_read_unlock();
130}
131
132static int seq_show(struct seq_file *s, void *v)
133{
134 loff_t *pos = v;
135 const struct nf_logger *logger;
136
e92ad99c 137 logger = rcu_dereference(nf_loggers[*pos]);
f6ebe77f
HW
138
139 if (!logger)
140 return seq_printf(s, "%2lld NONE\n", *pos);
601e68e1 141
f6ebe77f
HW
142 return seq_printf(s, "%2lld %s\n", *pos, logger->name);
143}
144
56b3d975 145static const struct seq_operations nflog_seq_ops = {
f6ebe77f
HW
146 .start = seq_start,
147 .next = seq_next,
148 .stop = seq_stop,
149 .show = seq_show,
150};
151
152static int nflog_open(struct inode *inode, struct file *file)
153{
154 return seq_open(file, &nflog_seq_ops);
155}
156
da7071d7 157static const struct file_operations nflog_file_ops = {
f6ebe77f
HW
158 .owner = THIS_MODULE,
159 .open = nflog_open,
160 .read = seq_read,
161 .llseek = seq_lseek,
162 .release = seq_release,
163};
164
165#endif /* PROC_FS */
166
167
168int __init netfilter_log_init(void)
169{
170#ifdef CONFIG_PROC_FS
171 struct proc_dir_entry *pde;
62243927 172
f6ebe77f 173 pde = create_proc_entry("nf_log", S_IRUGO, proc_net_netfilter);
f6ebe77f
HW
174 if (!pde)
175 return -1;
176
177 pde->proc_fops = &nflog_file_ops;
62243927 178#endif
f6ebe77f
HW
179 return 0;
180}