miscdev.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508
  1. /**
  2. * eCryptfs: Linux filesystem encryption layer
  3. *
  4. * Copyright (C) 2008 International Business Machines Corp.
  5. * Author(s): Michael A. Halcrow <mhalcrow@us.ibm.com>
  6. *
  7. * This program is free software; you can redistribute it and/or
  8. * modify it under the terms of the GNU General Public License version
  9. * 2 as published by the Free Software Foundation.
  10. *
  11. * This program is distributed in the hope that it will be useful, but
  12. * WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU General Public License
  17. * along with this program; if not, write to the Free Software
  18. * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
  19. * 02111-1307, USA.
  20. */
  21. #include <linux/fs.h>
  22. #include <linux/hash.h>
  23. #include <linux/random.h>
  24. #include <linux/miscdevice.h>
  25. #include <linux/poll.h>
  26. #include <linux/slab.h>
  27. #include <linux/wait.h>
  28. #include <linux/module.h>
  29. #include "ecryptfs_kernel.h"
  30. static atomic_t ecryptfs_num_miscdev_opens;
  31. /**
  32. * ecryptfs_miscdev_poll
  33. * @file: dev file
  34. * @pt: dev poll table (ignored)
  35. *
  36. * Returns the poll mask
  37. */
  38. static __poll_t
  39. ecryptfs_miscdev_poll(struct file *file, poll_table *pt)
  40. {
  41. struct ecryptfs_daemon *daemon = file->private_data;
  42. __poll_t mask = 0;
  43. mutex_lock(&daemon->mux);
  44. if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) {
  45. printk(KERN_WARNING "%s: Attempt to poll on zombified "
  46. "daemon\n", __func__);
  47. goto out_unlock_daemon;
  48. }
  49. if (daemon->flags & ECRYPTFS_DAEMON_IN_READ)
  50. goto out_unlock_daemon;
  51. if (daemon->flags & ECRYPTFS_DAEMON_IN_POLL)
  52. goto out_unlock_daemon;
  53. daemon->flags |= ECRYPTFS_DAEMON_IN_POLL;
  54. mutex_unlock(&daemon->mux);
  55. poll_wait(file, &daemon->wait, pt);
  56. mutex_lock(&daemon->mux);
  57. if (!list_empty(&daemon->msg_ctx_out_queue))
  58. mask |= EPOLLIN | EPOLLRDNORM;
  59. out_unlock_daemon:
  60. daemon->flags &= ~ECRYPTFS_DAEMON_IN_POLL;
  61. mutex_unlock(&daemon->mux);
  62. return mask;
  63. }
  64. /**
  65. * ecryptfs_miscdev_open
  66. * @inode: inode of miscdev handle (ignored)
  67. * @file: file for miscdev handle
  68. *
  69. * Returns zero on success; non-zero otherwise
  70. */
  71. static int
  72. ecryptfs_miscdev_open(struct inode *inode, struct file *file)
  73. {
  74. struct ecryptfs_daemon *daemon = NULL;
  75. int rc;
  76. mutex_lock(&ecryptfs_daemon_hash_mux);
  77. rc = ecryptfs_find_daemon_by_euid(&daemon);
  78. if (!rc) {
  79. rc = -EINVAL;
  80. goto out_unlock_daemon_list;
  81. }
  82. rc = ecryptfs_spawn_daemon(&daemon, file);
  83. if (rc) {
  84. printk(KERN_ERR "%s: Error attempting to spawn daemon; "
  85. "rc = [%d]\n", __func__, rc);
  86. goto out_unlock_daemon_list;
  87. }
  88. mutex_lock(&daemon->mux);
  89. if (daemon->flags & ECRYPTFS_DAEMON_MISCDEV_OPEN) {
  90. rc = -EBUSY;
  91. goto out_unlock_daemon;
  92. }
  93. daemon->flags |= ECRYPTFS_DAEMON_MISCDEV_OPEN;
  94. file->private_data = daemon;
  95. atomic_inc(&ecryptfs_num_miscdev_opens);
  96. out_unlock_daemon:
  97. mutex_unlock(&daemon->mux);
  98. out_unlock_daemon_list:
  99. mutex_unlock(&ecryptfs_daemon_hash_mux);
  100. return rc;
  101. }
  102. /**
  103. * ecryptfs_miscdev_release
  104. * @inode: inode of fs/ecryptfs/euid handle (ignored)
  105. * @file: file for fs/ecryptfs/euid handle
  106. *
  107. * This keeps the daemon registered until the daemon sends another
  108. * ioctl to fs/ecryptfs/ctl or until the kernel module unregisters.
  109. *
  110. * Returns zero on success; non-zero otherwise
  111. */
  112. static int
  113. ecryptfs_miscdev_release(struct inode *inode, struct file *file)
  114. {
  115. struct ecryptfs_daemon *daemon = file->private_data;
  116. int rc;
  117. mutex_lock(&daemon->mux);
  118. BUG_ON(!(daemon->flags & ECRYPTFS_DAEMON_MISCDEV_OPEN));
  119. daemon->flags &= ~ECRYPTFS_DAEMON_MISCDEV_OPEN;
  120. atomic_dec(&ecryptfs_num_miscdev_opens);
  121. mutex_unlock(&daemon->mux);
  122. mutex_lock(&ecryptfs_daemon_hash_mux);
  123. rc = ecryptfs_exorcise_daemon(daemon);
  124. mutex_unlock(&ecryptfs_daemon_hash_mux);
  125. if (rc) {
  126. printk(KERN_CRIT "%s: Fatal error whilst attempting to "
  127. "shut down daemon; rc = [%d]. Please report this "
  128. "bug.\n", __func__, rc);
  129. BUG();
  130. }
  131. return rc;
  132. }
  133. /**
  134. * ecryptfs_send_miscdev
  135. * @data: Data to send to daemon; may be NULL
  136. * @data_size: Amount of data to send to daemon
  137. * @msg_ctx: Message context, which is used to handle the reply. If
  138. * this is NULL, then we do not expect a reply.
  139. * @msg_type: Type of message
  140. * @msg_flags: Flags for message
  141. * @daemon: eCryptfs daemon object
  142. *
  143. * Add msg_ctx to queue and then, if it exists, notify the blocked
  144. * miscdevess about the data being available. Must be called with
  145. * ecryptfs_daemon_hash_mux held.
  146. *
  147. * Returns zero on success; non-zero otherwise
  148. */
  149. int ecryptfs_send_miscdev(char *data, size_t data_size,
  150. struct ecryptfs_msg_ctx *msg_ctx, u8 msg_type,
  151. u16 msg_flags, struct ecryptfs_daemon *daemon)
  152. {
  153. struct ecryptfs_message *msg;
  154. msg = kmalloc((sizeof(*msg) + data_size), GFP_KERNEL);
  155. if (!msg)
  156. return -ENOMEM;
  157. mutex_lock(&msg_ctx->mux);
  158. msg_ctx->msg = msg;
  159. msg_ctx->msg->index = msg_ctx->index;
  160. msg_ctx->msg->data_len = data_size;
  161. msg_ctx->type = msg_type;
  162. memcpy(msg_ctx->msg->data, data, data_size);
  163. msg_ctx->msg_size = (sizeof(*msg_ctx->msg) + data_size);
  164. list_add_tail(&msg_ctx->daemon_out_list, &daemon->msg_ctx_out_queue);
  165. mutex_unlock(&msg_ctx->mux);
  166. mutex_lock(&daemon->mux);
  167. daemon->num_queued_msg_ctx++;
  168. wake_up_interruptible(&daemon->wait);
  169. mutex_unlock(&daemon->mux);
  170. return 0;
  171. }
  172. /*
  173. * miscdevfs packet format:
  174. * Octet 0: Type
  175. * Octets 1-4: network byte order msg_ctx->counter
  176. * Octets 5-N0: Size of struct ecryptfs_message to follow
  177. * Octets N0-N1: struct ecryptfs_message (including data)
  178. *
  179. * Octets 5-N1 not written if the packet type does not include a message
  180. */
  181. #define PKT_TYPE_SIZE 1
  182. #define PKT_CTR_SIZE 4
  183. #define MIN_NON_MSG_PKT_SIZE (PKT_TYPE_SIZE + PKT_CTR_SIZE)
  184. #define MIN_MSG_PKT_SIZE (PKT_TYPE_SIZE + PKT_CTR_SIZE \
  185. + ECRYPTFS_MIN_PKT_LEN_SIZE)
  186. /* 4 + ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES comes from tag 65 packet format */
  187. #define MAX_MSG_PKT_SIZE (PKT_TYPE_SIZE + PKT_CTR_SIZE \
  188. + ECRYPTFS_MAX_PKT_LEN_SIZE \
  189. + sizeof(struct ecryptfs_message) \
  190. + 4 + ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES)
  191. #define PKT_TYPE_OFFSET 0
  192. #define PKT_CTR_OFFSET PKT_TYPE_SIZE
  193. #define PKT_LEN_OFFSET (PKT_TYPE_SIZE + PKT_CTR_SIZE)
  194. /**
  195. * ecryptfs_miscdev_read - format and send message from queue
  196. * @file: miscdevfs handle
  197. * @buf: User buffer into which to copy the next message on the daemon queue
  198. * @count: Amount of space available in @buf
  199. * @ppos: Offset in file (ignored)
  200. *
  201. * Pulls the most recent message from the daemon queue, formats it for
  202. * being sent via a miscdevfs handle, and copies it into @buf
  203. *
  204. * Returns the number of bytes copied into the user buffer
  205. */
  206. static ssize_t
  207. ecryptfs_miscdev_read(struct file *file, char __user *buf, size_t count,
  208. loff_t *ppos)
  209. {
  210. struct ecryptfs_daemon *daemon = file->private_data;
  211. struct ecryptfs_msg_ctx *msg_ctx;
  212. size_t packet_length_size;
  213. char packet_length[ECRYPTFS_MAX_PKT_LEN_SIZE];
  214. size_t i;
  215. size_t total_length;
  216. int rc;
  217. mutex_lock(&daemon->mux);
  218. if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) {
  219. rc = 0;
  220. printk(KERN_WARNING "%s: Attempt to read from zombified "
  221. "daemon\n", __func__);
  222. goto out_unlock_daemon;
  223. }
  224. if (daemon->flags & ECRYPTFS_DAEMON_IN_READ) {
  225. rc = 0;
  226. goto out_unlock_daemon;
  227. }
  228. /* This daemon will not go away so long as this flag is set */
  229. daemon->flags |= ECRYPTFS_DAEMON_IN_READ;
  230. check_list:
  231. if (list_empty(&daemon->msg_ctx_out_queue)) {
  232. mutex_unlock(&daemon->mux);
  233. rc = wait_event_interruptible(
  234. daemon->wait, !list_empty(&daemon->msg_ctx_out_queue));
  235. mutex_lock(&daemon->mux);
  236. if (rc < 0) {
  237. rc = 0;
  238. goto out_unlock_daemon;
  239. }
  240. }
  241. if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) {
  242. rc = 0;
  243. goto out_unlock_daemon;
  244. }
  245. if (list_empty(&daemon->msg_ctx_out_queue)) {
  246. /* Something else jumped in since the
  247. * wait_event_interruptable() and removed the
  248. * message from the queue; try again */
  249. goto check_list;
  250. }
  251. msg_ctx = list_first_entry(&daemon->msg_ctx_out_queue,
  252. struct ecryptfs_msg_ctx, daemon_out_list);
  253. BUG_ON(!msg_ctx);
  254. mutex_lock(&msg_ctx->mux);
  255. if (msg_ctx->msg) {
  256. rc = ecryptfs_write_packet_length(packet_length,
  257. msg_ctx->msg_size,
  258. &packet_length_size);
  259. if (rc) {
  260. rc = 0;
  261. printk(KERN_WARNING "%s: Error writing packet length; "
  262. "rc = [%d]\n", __func__, rc);
  263. goto out_unlock_msg_ctx;
  264. }
  265. } else {
  266. packet_length_size = 0;
  267. msg_ctx->msg_size = 0;
  268. }
  269. total_length = (PKT_TYPE_SIZE + PKT_CTR_SIZE + packet_length_size
  270. + msg_ctx->msg_size);
  271. if (count < total_length) {
  272. rc = 0;
  273. printk(KERN_WARNING "%s: Only given user buffer of "
  274. "size [%zd], but we need [%zd] to read the "
  275. "pending message\n", __func__, count, total_length);
  276. goto out_unlock_msg_ctx;
  277. }
  278. rc = -EFAULT;
  279. if (put_user(msg_ctx->type, buf))
  280. goto out_unlock_msg_ctx;
  281. if (put_user(cpu_to_be32(msg_ctx->counter),
  282. (__be32 __user *)(&buf[PKT_CTR_OFFSET])))
  283. goto out_unlock_msg_ctx;
  284. i = PKT_TYPE_SIZE + PKT_CTR_SIZE;
  285. if (msg_ctx->msg) {
  286. if (copy_to_user(&buf[i], packet_length, packet_length_size))
  287. goto out_unlock_msg_ctx;
  288. i += packet_length_size;
  289. if (copy_to_user(&buf[i], msg_ctx->msg, msg_ctx->msg_size))
  290. goto out_unlock_msg_ctx;
  291. i += msg_ctx->msg_size;
  292. }
  293. rc = i;
  294. list_del(&msg_ctx->daemon_out_list);
  295. kfree(msg_ctx->msg);
  296. msg_ctx->msg = NULL;
  297. /* We do not expect a reply from the userspace daemon for any
  298. * message type other than ECRYPTFS_MSG_REQUEST */
  299. if (msg_ctx->type != ECRYPTFS_MSG_REQUEST)
  300. ecryptfs_msg_ctx_alloc_to_free(msg_ctx);
  301. out_unlock_msg_ctx:
  302. mutex_unlock(&msg_ctx->mux);
  303. out_unlock_daemon:
  304. daemon->flags &= ~ECRYPTFS_DAEMON_IN_READ;
  305. mutex_unlock(&daemon->mux);
  306. return rc;
  307. }
  308. /**
  309. * ecryptfs_miscdev_response - miscdevess response to message previously sent to daemon
  310. * @data: Bytes comprising struct ecryptfs_message
  311. * @data_size: sizeof(struct ecryptfs_message) + data len
  312. * @seq: Sequence number for miscdev response packet
  313. *
  314. * Returns zero on success; non-zero otherwise
  315. */
  316. static int ecryptfs_miscdev_response(struct ecryptfs_daemon *daemon, char *data,
  317. size_t data_size, u32 seq)
  318. {
  319. struct ecryptfs_message *msg = (struct ecryptfs_message *)data;
  320. int rc;
  321. if ((sizeof(*msg) + msg->data_len) != data_size) {
  322. printk(KERN_WARNING "%s: (sizeof(*msg) + msg->data_len) = "
  323. "[%zd]; data_size = [%zd]. Invalid packet.\n", __func__,
  324. (sizeof(*msg) + msg->data_len), data_size);
  325. rc = -EINVAL;
  326. goto out;
  327. }
  328. rc = ecryptfs_process_response(daemon, msg, seq);
  329. if (rc)
  330. printk(KERN_ERR
  331. "Error processing response message; rc = [%d]\n", rc);
  332. out:
  333. return rc;
  334. }
  335. /**
  336. * ecryptfs_miscdev_write - handle write to daemon miscdev handle
  337. * @file: File for misc dev handle
  338. * @buf: Buffer containing user data
  339. * @count: Amount of data in @buf
  340. * @ppos: Pointer to offset in file (ignored)
  341. *
  342. * Returns the number of bytes read from @buf
  343. */
  344. static ssize_t
  345. ecryptfs_miscdev_write(struct file *file, const char __user *buf,
  346. size_t count, loff_t *ppos)
  347. {
  348. __be32 counter_nbo;
  349. u32 seq;
  350. size_t packet_size, packet_size_length;
  351. char *data;
  352. unsigned char packet_size_peek[ECRYPTFS_MAX_PKT_LEN_SIZE];
  353. ssize_t rc;
  354. if (count == 0) {
  355. return 0;
  356. } else if (count == MIN_NON_MSG_PKT_SIZE) {
  357. /* Likely a harmless MSG_HELO or MSG_QUIT - no packet length */
  358. goto memdup;
  359. } else if (count < MIN_MSG_PKT_SIZE || count > MAX_MSG_PKT_SIZE) {
  360. printk(KERN_WARNING "%s: Acceptable packet size range is "
  361. "[%d-%zu], but amount of data written is [%zu].\n",
  362. __func__, MIN_MSG_PKT_SIZE, MAX_MSG_PKT_SIZE, count);
  363. return -EINVAL;
  364. }
  365. if (copy_from_user(packet_size_peek, &buf[PKT_LEN_OFFSET],
  366. sizeof(packet_size_peek))) {
  367. printk(KERN_WARNING "%s: Error while inspecting packet size\n",
  368. __func__);
  369. return -EFAULT;
  370. }
  371. rc = ecryptfs_parse_packet_length(packet_size_peek, &packet_size,
  372. &packet_size_length);
  373. if (rc) {
  374. printk(KERN_WARNING "%s: Error parsing packet length; "
  375. "rc = [%zd]\n", __func__, rc);
  376. return rc;
  377. }
  378. if ((PKT_TYPE_SIZE + PKT_CTR_SIZE + packet_size_length + packet_size)
  379. != count) {
  380. printk(KERN_WARNING "%s: Invalid packet size [%zu]\n", __func__,
  381. packet_size);
  382. return -EINVAL;
  383. }
  384. memdup:
  385. data = memdup_user(buf, count);
  386. if (IS_ERR(data)) {
  387. printk(KERN_ERR "%s: memdup_user returned error [%ld]\n",
  388. __func__, PTR_ERR(data));
  389. return PTR_ERR(data);
  390. }
  391. switch (data[PKT_TYPE_OFFSET]) {
  392. case ECRYPTFS_MSG_RESPONSE:
  393. if (count < (MIN_MSG_PKT_SIZE
  394. + sizeof(struct ecryptfs_message))) {
  395. printk(KERN_WARNING "%s: Minimum acceptable packet "
  396. "size is [%zd], but amount of data written is "
  397. "only [%zd]. Discarding response packet.\n",
  398. __func__,
  399. (MIN_MSG_PKT_SIZE
  400. + sizeof(struct ecryptfs_message)), count);
  401. rc = -EINVAL;
  402. goto out_free;
  403. }
  404. memcpy(&counter_nbo, &data[PKT_CTR_OFFSET], PKT_CTR_SIZE);
  405. seq = be32_to_cpu(counter_nbo);
  406. rc = ecryptfs_miscdev_response(file->private_data,
  407. &data[PKT_LEN_OFFSET + packet_size_length],
  408. packet_size, seq);
  409. if (rc) {
  410. printk(KERN_WARNING "%s: Failed to deliver miscdev "
  411. "response to requesting operation; rc = [%zd]\n",
  412. __func__, rc);
  413. goto out_free;
  414. }
  415. break;
  416. case ECRYPTFS_MSG_HELO:
  417. case ECRYPTFS_MSG_QUIT:
  418. break;
  419. default:
  420. ecryptfs_printk(KERN_WARNING, "Dropping miscdev "
  421. "message of unrecognized type [%d]\n",
  422. data[0]);
  423. rc = -EINVAL;
  424. goto out_free;
  425. }
  426. rc = count;
  427. out_free:
  428. kfree(data);
  429. return rc;
  430. }
  431. static const struct file_operations ecryptfs_miscdev_fops = {
  432. .owner = THIS_MODULE,
  433. .open = ecryptfs_miscdev_open,
  434. .poll = ecryptfs_miscdev_poll,
  435. .read = ecryptfs_miscdev_read,
  436. .write = ecryptfs_miscdev_write,
  437. .release = ecryptfs_miscdev_release,
  438. .llseek = noop_llseek,
  439. };
  440. static struct miscdevice ecryptfs_miscdev = {
  441. .minor = MISC_DYNAMIC_MINOR,
  442. .name = "ecryptfs",
  443. .fops = &ecryptfs_miscdev_fops
  444. };
  445. /**
  446. * ecryptfs_init_ecryptfs_miscdev
  447. *
  448. * Messages sent to the userspace daemon from the kernel are placed on
  449. * a queue associated with the daemon. The next read against the
  450. * miscdev handle by that daemon will return the oldest message placed
  451. * on the message queue for the daemon.
  452. *
  453. * Returns zero on success; non-zero otherwise
  454. */
  455. int __init ecryptfs_init_ecryptfs_miscdev(void)
  456. {
  457. int rc;
  458. atomic_set(&ecryptfs_num_miscdev_opens, 0);
  459. rc = misc_register(&ecryptfs_miscdev);
  460. if (rc)
  461. printk(KERN_ERR "%s: Failed to register miscellaneous device "
  462. "for communications with userspace daemons; rc = [%d]\n",
  463. __func__, rc);
  464. return rc;
  465. }
  466. /**
  467. * ecryptfs_destroy_ecryptfs_miscdev
  468. *
  469. * All of the daemons must be exorcised prior to calling this
  470. * function.
  471. */
  472. void ecryptfs_destroy_ecryptfs_miscdev(void)
  473. {
  474. BUG_ON(atomic_read(&ecryptfs_num_miscdev_opens) != 0);
  475. misc_deregister(&ecryptfs_miscdev);
  476. }