1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
5*4882a593Smuzhiyun */
6*4882a593Smuzhiyun
7*4882a593Smuzhiyun #include <linux/capability.h>
8*4882a593Smuzhiyun #include <linux/errno.h>
9*4882a593Smuzhiyun #include <linux/types.h>
10*4882a593Smuzhiyun #include <linux/socket.h>
11*4882a593Smuzhiyun #include <linux/in.h>
12*4882a593Smuzhiyun #include <linux/kernel.h>
13*4882a593Smuzhiyun #include <linux/timer.h>
14*4882a593Smuzhiyun #include <linux/string.h>
15*4882a593Smuzhiyun #include <linux/sockios.h>
16*4882a593Smuzhiyun #include <linux/net.h>
17*4882a593Smuzhiyun #include <linux/spinlock.h>
18*4882a593Smuzhiyun #include <linux/slab.h>
19*4882a593Smuzhiyun #include <net/ax25.h>
20*4882a593Smuzhiyun #include <linux/inet.h>
21*4882a593Smuzhiyun #include <linux/netdevice.h>
22*4882a593Smuzhiyun #include <linux/if_arp.h>
23*4882a593Smuzhiyun #include <linux/skbuff.h>
24*4882a593Smuzhiyun #include <net/sock.h>
25*4882a593Smuzhiyun #include <linux/uaccess.h>
26*4882a593Smuzhiyun #include <linux/fcntl.h>
27*4882a593Smuzhiyun #include <linux/mm.h>
28*4882a593Smuzhiyun #include <linux/interrupt.h>
29*4882a593Smuzhiyun #include <linux/list.h>
30*4882a593Smuzhiyun #include <linux/notifier.h>
31*4882a593Smuzhiyun #include <linux/proc_fs.h>
32*4882a593Smuzhiyun #include <linux/seq_file.h>
33*4882a593Smuzhiyun #include <linux/stat.h>
34*4882a593Smuzhiyun #include <linux/sysctl.h>
35*4882a593Smuzhiyun #include <linux/export.h>
36*4882a593Smuzhiyun #include <net/ip.h>
37*4882a593Smuzhiyun #include <net/arp.h>
38*4882a593Smuzhiyun
39*4882a593Smuzhiyun /*
40*4882a593Smuzhiyun * Callsign/UID mapper. This is in kernel space for security on multi-amateur machines.
41*4882a593Smuzhiyun */
42*4882a593Smuzhiyun
43*4882a593Smuzhiyun static HLIST_HEAD(ax25_uid_list);
44*4882a593Smuzhiyun static DEFINE_RWLOCK(ax25_uid_lock);
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun int ax25_uid_policy;
47*4882a593Smuzhiyun
48*4882a593Smuzhiyun EXPORT_SYMBOL(ax25_uid_policy);
49*4882a593Smuzhiyun
ax25_findbyuid(kuid_t uid)50*4882a593Smuzhiyun ax25_uid_assoc *ax25_findbyuid(kuid_t uid)
51*4882a593Smuzhiyun {
52*4882a593Smuzhiyun ax25_uid_assoc *ax25_uid, *res = NULL;
53*4882a593Smuzhiyun
54*4882a593Smuzhiyun read_lock(&ax25_uid_lock);
55*4882a593Smuzhiyun ax25_uid_for_each(ax25_uid, &ax25_uid_list) {
56*4882a593Smuzhiyun if (uid_eq(ax25_uid->uid, uid)) {
57*4882a593Smuzhiyun ax25_uid_hold(ax25_uid);
58*4882a593Smuzhiyun res = ax25_uid;
59*4882a593Smuzhiyun break;
60*4882a593Smuzhiyun }
61*4882a593Smuzhiyun }
62*4882a593Smuzhiyun read_unlock(&ax25_uid_lock);
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun return res;
65*4882a593Smuzhiyun }
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun EXPORT_SYMBOL(ax25_findbyuid);
68*4882a593Smuzhiyun
ax25_uid_ioctl(int cmd,struct sockaddr_ax25 * sax)69*4882a593Smuzhiyun int ax25_uid_ioctl(int cmd, struct sockaddr_ax25 *sax)
70*4882a593Smuzhiyun {
71*4882a593Smuzhiyun ax25_uid_assoc *ax25_uid;
72*4882a593Smuzhiyun ax25_uid_assoc *user;
73*4882a593Smuzhiyun unsigned long res;
74*4882a593Smuzhiyun
75*4882a593Smuzhiyun switch (cmd) {
76*4882a593Smuzhiyun case SIOCAX25GETUID:
77*4882a593Smuzhiyun res = -ENOENT;
78*4882a593Smuzhiyun read_lock(&ax25_uid_lock);
79*4882a593Smuzhiyun ax25_uid_for_each(ax25_uid, &ax25_uid_list) {
80*4882a593Smuzhiyun if (ax25cmp(&sax->sax25_call, &ax25_uid->call) == 0) {
81*4882a593Smuzhiyun res = from_kuid_munged(current_user_ns(), ax25_uid->uid);
82*4882a593Smuzhiyun break;
83*4882a593Smuzhiyun }
84*4882a593Smuzhiyun }
85*4882a593Smuzhiyun read_unlock(&ax25_uid_lock);
86*4882a593Smuzhiyun
87*4882a593Smuzhiyun return res;
88*4882a593Smuzhiyun
89*4882a593Smuzhiyun case SIOCAX25ADDUID:
90*4882a593Smuzhiyun {
91*4882a593Smuzhiyun kuid_t sax25_kuid;
92*4882a593Smuzhiyun if (!capable(CAP_NET_ADMIN))
93*4882a593Smuzhiyun return -EPERM;
94*4882a593Smuzhiyun sax25_kuid = make_kuid(current_user_ns(), sax->sax25_uid);
95*4882a593Smuzhiyun if (!uid_valid(sax25_kuid))
96*4882a593Smuzhiyun return -EINVAL;
97*4882a593Smuzhiyun user = ax25_findbyuid(sax25_kuid);
98*4882a593Smuzhiyun if (user) {
99*4882a593Smuzhiyun ax25_uid_put(user);
100*4882a593Smuzhiyun return -EEXIST;
101*4882a593Smuzhiyun }
102*4882a593Smuzhiyun if (sax->sax25_uid == 0)
103*4882a593Smuzhiyun return -EINVAL;
104*4882a593Smuzhiyun if ((ax25_uid = kmalloc(sizeof(*ax25_uid), GFP_KERNEL)) == NULL)
105*4882a593Smuzhiyun return -ENOMEM;
106*4882a593Smuzhiyun
107*4882a593Smuzhiyun refcount_set(&ax25_uid->refcount, 1);
108*4882a593Smuzhiyun ax25_uid->uid = sax25_kuid;
109*4882a593Smuzhiyun ax25_uid->call = sax->sax25_call;
110*4882a593Smuzhiyun
111*4882a593Smuzhiyun write_lock(&ax25_uid_lock);
112*4882a593Smuzhiyun hlist_add_head(&ax25_uid->uid_node, &ax25_uid_list);
113*4882a593Smuzhiyun write_unlock(&ax25_uid_lock);
114*4882a593Smuzhiyun
115*4882a593Smuzhiyun return 0;
116*4882a593Smuzhiyun }
117*4882a593Smuzhiyun case SIOCAX25DELUID:
118*4882a593Smuzhiyun if (!capable(CAP_NET_ADMIN))
119*4882a593Smuzhiyun return -EPERM;
120*4882a593Smuzhiyun
121*4882a593Smuzhiyun ax25_uid = NULL;
122*4882a593Smuzhiyun write_lock(&ax25_uid_lock);
123*4882a593Smuzhiyun ax25_uid_for_each(ax25_uid, &ax25_uid_list) {
124*4882a593Smuzhiyun if (ax25cmp(&sax->sax25_call, &ax25_uid->call) == 0)
125*4882a593Smuzhiyun break;
126*4882a593Smuzhiyun }
127*4882a593Smuzhiyun if (ax25_uid == NULL) {
128*4882a593Smuzhiyun write_unlock(&ax25_uid_lock);
129*4882a593Smuzhiyun return -ENOENT;
130*4882a593Smuzhiyun }
131*4882a593Smuzhiyun hlist_del_init(&ax25_uid->uid_node);
132*4882a593Smuzhiyun ax25_uid_put(ax25_uid);
133*4882a593Smuzhiyun write_unlock(&ax25_uid_lock);
134*4882a593Smuzhiyun
135*4882a593Smuzhiyun return 0;
136*4882a593Smuzhiyun
137*4882a593Smuzhiyun default:
138*4882a593Smuzhiyun return -EINVAL;
139*4882a593Smuzhiyun }
140*4882a593Smuzhiyun
141*4882a593Smuzhiyun return -EINVAL; /*NOTREACHED */
142*4882a593Smuzhiyun }
143*4882a593Smuzhiyun
144*4882a593Smuzhiyun #ifdef CONFIG_PROC_FS
145*4882a593Smuzhiyun
ax25_uid_seq_start(struct seq_file * seq,loff_t * pos)146*4882a593Smuzhiyun static void *ax25_uid_seq_start(struct seq_file *seq, loff_t *pos)
147*4882a593Smuzhiyun __acquires(ax25_uid_lock)
148*4882a593Smuzhiyun {
149*4882a593Smuzhiyun read_lock(&ax25_uid_lock);
150*4882a593Smuzhiyun return seq_hlist_start_head(&ax25_uid_list, *pos);
151*4882a593Smuzhiyun }
152*4882a593Smuzhiyun
ax25_uid_seq_next(struct seq_file * seq,void * v,loff_t * pos)153*4882a593Smuzhiyun static void *ax25_uid_seq_next(struct seq_file *seq, void *v, loff_t *pos)
154*4882a593Smuzhiyun {
155*4882a593Smuzhiyun return seq_hlist_next(v, &ax25_uid_list, pos);
156*4882a593Smuzhiyun }
157*4882a593Smuzhiyun
ax25_uid_seq_stop(struct seq_file * seq,void * v)158*4882a593Smuzhiyun static void ax25_uid_seq_stop(struct seq_file *seq, void *v)
159*4882a593Smuzhiyun __releases(ax25_uid_lock)
160*4882a593Smuzhiyun {
161*4882a593Smuzhiyun read_unlock(&ax25_uid_lock);
162*4882a593Smuzhiyun }
163*4882a593Smuzhiyun
ax25_uid_seq_show(struct seq_file * seq,void * v)164*4882a593Smuzhiyun static int ax25_uid_seq_show(struct seq_file *seq, void *v)
165*4882a593Smuzhiyun {
166*4882a593Smuzhiyun char buf[11];
167*4882a593Smuzhiyun
168*4882a593Smuzhiyun if (v == SEQ_START_TOKEN)
169*4882a593Smuzhiyun seq_printf(seq, "Policy: %d\n", ax25_uid_policy);
170*4882a593Smuzhiyun else {
171*4882a593Smuzhiyun struct ax25_uid_assoc *pt;
172*4882a593Smuzhiyun
173*4882a593Smuzhiyun pt = hlist_entry(v, struct ax25_uid_assoc, uid_node);
174*4882a593Smuzhiyun seq_printf(seq, "%6d %s\n",
175*4882a593Smuzhiyun from_kuid_munged(seq_user_ns(seq), pt->uid),
176*4882a593Smuzhiyun ax2asc(buf, &pt->call));
177*4882a593Smuzhiyun }
178*4882a593Smuzhiyun return 0;
179*4882a593Smuzhiyun }
180*4882a593Smuzhiyun
181*4882a593Smuzhiyun const struct seq_operations ax25_uid_seqops = {
182*4882a593Smuzhiyun .start = ax25_uid_seq_start,
183*4882a593Smuzhiyun .next = ax25_uid_seq_next,
184*4882a593Smuzhiyun .stop = ax25_uid_seq_stop,
185*4882a593Smuzhiyun .show = ax25_uid_seq_show,
186*4882a593Smuzhiyun };
187*4882a593Smuzhiyun #endif
188*4882a593Smuzhiyun
189*4882a593Smuzhiyun /*
190*4882a593Smuzhiyun * Free all memory associated with UID/Callsign structures.
191*4882a593Smuzhiyun */
ax25_uid_free(void)192*4882a593Smuzhiyun void __exit ax25_uid_free(void)
193*4882a593Smuzhiyun {
194*4882a593Smuzhiyun ax25_uid_assoc *ax25_uid;
195*4882a593Smuzhiyun
196*4882a593Smuzhiyun write_lock(&ax25_uid_lock);
197*4882a593Smuzhiyun again:
198*4882a593Smuzhiyun ax25_uid_for_each(ax25_uid, &ax25_uid_list) {
199*4882a593Smuzhiyun hlist_del_init(&ax25_uid->uid_node);
200*4882a593Smuzhiyun ax25_uid_put(ax25_uid);
201*4882a593Smuzhiyun goto again;
202*4882a593Smuzhiyun }
203*4882a593Smuzhiyun write_unlock(&ax25_uid_lock);
204*4882a593Smuzhiyun }
205