1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * tcp_diag.c Module for monitoring TCP transport protocols sockets.
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
6*4882a593Smuzhiyun */
7*4882a593Smuzhiyun
8*4882a593Smuzhiyun #include <linux/module.h>
9*4882a593Smuzhiyun #include <linux/net.h>
10*4882a593Smuzhiyun #include <linux/sock_diag.h>
11*4882a593Smuzhiyun #include <linux/inet_diag.h>
12*4882a593Smuzhiyun
13*4882a593Smuzhiyun #include <linux/tcp.h>
14*4882a593Smuzhiyun
15*4882a593Smuzhiyun #include <net/netlink.h>
16*4882a593Smuzhiyun #include <net/tcp.h>
17*4882a593Smuzhiyun
tcp_diag_get_info(struct sock * sk,struct inet_diag_msg * r,void * _info)18*4882a593Smuzhiyun static void tcp_diag_get_info(struct sock *sk, struct inet_diag_msg *r,
19*4882a593Smuzhiyun void *_info)
20*4882a593Smuzhiyun {
21*4882a593Smuzhiyun struct tcp_info *info = _info;
22*4882a593Smuzhiyun
23*4882a593Smuzhiyun if (inet_sk_state_load(sk) == TCP_LISTEN) {
24*4882a593Smuzhiyun r->idiag_rqueue = READ_ONCE(sk->sk_ack_backlog);
25*4882a593Smuzhiyun r->idiag_wqueue = READ_ONCE(sk->sk_max_ack_backlog);
26*4882a593Smuzhiyun } else if (sk->sk_type == SOCK_STREAM) {
27*4882a593Smuzhiyun const struct tcp_sock *tp = tcp_sk(sk);
28*4882a593Smuzhiyun
29*4882a593Smuzhiyun r->idiag_rqueue = max_t(int, READ_ONCE(tp->rcv_nxt) -
30*4882a593Smuzhiyun READ_ONCE(tp->copied_seq), 0);
31*4882a593Smuzhiyun r->idiag_wqueue = READ_ONCE(tp->write_seq) - tp->snd_una;
32*4882a593Smuzhiyun }
33*4882a593Smuzhiyun if (info)
34*4882a593Smuzhiyun tcp_get_info(sk, info);
35*4882a593Smuzhiyun }
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun #ifdef CONFIG_TCP_MD5SIG
tcp_diag_md5sig_fill(struct tcp_diag_md5sig * info,const struct tcp_md5sig_key * key)38*4882a593Smuzhiyun static void tcp_diag_md5sig_fill(struct tcp_diag_md5sig *info,
39*4882a593Smuzhiyun const struct tcp_md5sig_key *key)
40*4882a593Smuzhiyun {
41*4882a593Smuzhiyun info->tcpm_family = key->family;
42*4882a593Smuzhiyun info->tcpm_prefixlen = key->prefixlen;
43*4882a593Smuzhiyun info->tcpm_keylen = key->keylen;
44*4882a593Smuzhiyun memcpy(info->tcpm_key, key->key, key->keylen);
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun if (key->family == AF_INET)
47*4882a593Smuzhiyun info->tcpm_addr[0] = key->addr.a4.s_addr;
48*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
49*4882a593Smuzhiyun else if (key->family == AF_INET6)
50*4882a593Smuzhiyun memcpy(&info->tcpm_addr, &key->addr.a6,
51*4882a593Smuzhiyun sizeof(info->tcpm_addr));
52*4882a593Smuzhiyun #endif
53*4882a593Smuzhiyun }
54*4882a593Smuzhiyun
tcp_diag_put_md5sig(struct sk_buff * skb,const struct tcp_md5sig_info * md5sig)55*4882a593Smuzhiyun static int tcp_diag_put_md5sig(struct sk_buff *skb,
56*4882a593Smuzhiyun const struct tcp_md5sig_info *md5sig)
57*4882a593Smuzhiyun {
58*4882a593Smuzhiyun const struct tcp_md5sig_key *key;
59*4882a593Smuzhiyun struct tcp_diag_md5sig *info;
60*4882a593Smuzhiyun struct nlattr *attr;
61*4882a593Smuzhiyun int md5sig_count = 0;
62*4882a593Smuzhiyun
63*4882a593Smuzhiyun hlist_for_each_entry_rcu(key, &md5sig->head, node)
64*4882a593Smuzhiyun md5sig_count++;
65*4882a593Smuzhiyun if (md5sig_count == 0)
66*4882a593Smuzhiyun return 0;
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun attr = nla_reserve(skb, INET_DIAG_MD5SIG,
69*4882a593Smuzhiyun md5sig_count * sizeof(struct tcp_diag_md5sig));
70*4882a593Smuzhiyun if (!attr)
71*4882a593Smuzhiyun return -EMSGSIZE;
72*4882a593Smuzhiyun
73*4882a593Smuzhiyun info = nla_data(attr);
74*4882a593Smuzhiyun memset(info, 0, md5sig_count * sizeof(struct tcp_diag_md5sig));
75*4882a593Smuzhiyun hlist_for_each_entry_rcu(key, &md5sig->head, node) {
76*4882a593Smuzhiyun tcp_diag_md5sig_fill(info++, key);
77*4882a593Smuzhiyun if (--md5sig_count == 0)
78*4882a593Smuzhiyun break;
79*4882a593Smuzhiyun }
80*4882a593Smuzhiyun
81*4882a593Smuzhiyun return 0;
82*4882a593Smuzhiyun }
83*4882a593Smuzhiyun #endif
84*4882a593Smuzhiyun
tcp_diag_put_ulp(struct sk_buff * skb,struct sock * sk,const struct tcp_ulp_ops * ulp_ops)85*4882a593Smuzhiyun static int tcp_diag_put_ulp(struct sk_buff *skb, struct sock *sk,
86*4882a593Smuzhiyun const struct tcp_ulp_ops *ulp_ops)
87*4882a593Smuzhiyun {
88*4882a593Smuzhiyun struct nlattr *nest;
89*4882a593Smuzhiyun int err;
90*4882a593Smuzhiyun
91*4882a593Smuzhiyun nest = nla_nest_start_noflag(skb, INET_DIAG_ULP_INFO);
92*4882a593Smuzhiyun if (!nest)
93*4882a593Smuzhiyun return -EMSGSIZE;
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun err = nla_put_string(skb, INET_ULP_INFO_NAME, ulp_ops->name);
96*4882a593Smuzhiyun if (err)
97*4882a593Smuzhiyun goto nla_failure;
98*4882a593Smuzhiyun
99*4882a593Smuzhiyun if (ulp_ops->get_info)
100*4882a593Smuzhiyun err = ulp_ops->get_info(sk, skb);
101*4882a593Smuzhiyun if (err)
102*4882a593Smuzhiyun goto nla_failure;
103*4882a593Smuzhiyun
104*4882a593Smuzhiyun nla_nest_end(skb, nest);
105*4882a593Smuzhiyun return 0;
106*4882a593Smuzhiyun
107*4882a593Smuzhiyun nla_failure:
108*4882a593Smuzhiyun nla_nest_cancel(skb, nest);
109*4882a593Smuzhiyun return err;
110*4882a593Smuzhiyun }
111*4882a593Smuzhiyun
tcp_diag_get_aux(struct sock * sk,bool net_admin,struct sk_buff * skb)112*4882a593Smuzhiyun static int tcp_diag_get_aux(struct sock *sk, bool net_admin,
113*4882a593Smuzhiyun struct sk_buff *skb)
114*4882a593Smuzhiyun {
115*4882a593Smuzhiyun struct inet_connection_sock *icsk = inet_csk(sk);
116*4882a593Smuzhiyun int err = 0;
117*4882a593Smuzhiyun
118*4882a593Smuzhiyun #ifdef CONFIG_TCP_MD5SIG
119*4882a593Smuzhiyun if (net_admin) {
120*4882a593Smuzhiyun struct tcp_md5sig_info *md5sig;
121*4882a593Smuzhiyun
122*4882a593Smuzhiyun rcu_read_lock();
123*4882a593Smuzhiyun md5sig = rcu_dereference(tcp_sk(sk)->md5sig_info);
124*4882a593Smuzhiyun if (md5sig)
125*4882a593Smuzhiyun err = tcp_diag_put_md5sig(skb, md5sig);
126*4882a593Smuzhiyun rcu_read_unlock();
127*4882a593Smuzhiyun if (err < 0)
128*4882a593Smuzhiyun return err;
129*4882a593Smuzhiyun }
130*4882a593Smuzhiyun #endif
131*4882a593Smuzhiyun
132*4882a593Smuzhiyun if (net_admin) {
133*4882a593Smuzhiyun const struct tcp_ulp_ops *ulp_ops;
134*4882a593Smuzhiyun
135*4882a593Smuzhiyun ulp_ops = icsk->icsk_ulp_ops;
136*4882a593Smuzhiyun if (ulp_ops)
137*4882a593Smuzhiyun err = tcp_diag_put_ulp(skb, sk, ulp_ops);
138*4882a593Smuzhiyun if (err)
139*4882a593Smuzhiyun return err;
140*4882a593Smuzhiyun }
141*4882a593Smuzhiyun return 0;
142*4882a593Smuzhiyun }
143*4882a593Smuzhiyun
tcp_diag_get_aux_size(struct sock * sk,bool net_admin)144*4882a593Smuzhiyun static size_t tcp_diag_get_aux_size(struct sock *sk, bool net_admin)
145*4882a593Smuzhiyun {
146*4882a593Smuzhiyun struct inet_connection_sock *icsk = inet_csk(sk);
147*4882a593Smuzhiyun size_t size = 0;
148*4882a593Smuzhiyun
149*4882a593Smuzhiyun #ifdef CONFIG_TCP_MD5SIG
150*4882a593Smuzhiyun if (net_admin && sk_fullsock(sk)) {
151*4882a593Smuzhiyun const struct tcp_md5sig_info *md5sig;
152*4882a593Smuzhiyun const struct tcp_md5sig_key *key;
153*4882a593Smuzhiyun size_t md5sig_count = 0;
154*4882a593Smuzhiyun
155*4882a593Smuzhiyun rcu_read_lock();
156*4882a593Smuzhiyun md5sig = rcu_dereference(tcp_sk(sk)->md5sig_info);
157*4882a593Smuzhiyun if (md5sig) {
158*4882a593Smuzhiyun hlist_for_each_entry_rcu(key, &md5sig->head, node)
159*4882a593Smuzhiyun md5sig_count++;
160*4882a593Smuzhiyun }
161*4882a593Smuzhiyun rcu_read_unlock();
162*4882a593Smuzhiyun size += nla_total_size(md5sig_count *
163*4882a593Smuzhiyun sizeof(struct tcp_diag_md5sig));
164*4882a593Smuzhiyun }
165*4882a593Smuzhiyun #endif
166*4882a593Smuzhiyun
167*4882a593Smuzhiyun if (net_admin && sk_fullsock(sk)) {
168*4882a593Smuzhiyun const struct tcp_ulp_ops *ulp_ops;
169*4882a593Smuzhiyun
170*4882a593Smuzhiyun ulp_ops = icsk->icsk_ulp_ops;
171*4882a593Smuzhiyun if (ulp_ops) {
172*4882a593Smuzhiyun size += nla_total_size(0) +
173*4882a593Smuzhiyun nla_total_size(TCP_ULP_NAME_MAX);
174*4882a593Smuzhiyun if (ulp_ops->get_info_size)
175*4882a593Smuzhiyun size += ulp_ops->get_info_size(sk);
176*4882a593Smuzhiyun }
177*4882a593Smuzhiyun }
178*4882a593Smuzhiyun return size;
179*4882a593Smuzhiyun }
180*4882a593Smuzhiyun
tcp_diag_dump(struct sk_buff * skb,struct netlink_callback * cb,const struct inet_diag_req_v2 * r)181*4882a593Smuzhiyun static void tcp_diag_dump(struct sk_buff *skb, struct netlink_callback *cb,
182*4882a593Smuzhiyun const struct inet_diag_req_v2 *r)
183*4882a593Smuzhiyun {
184*4882a593Smuzhiyun inet_diag_dump_icsk(&tcp_hashinfo, skb, cb, r);
185*4882a593Smuzhiyun }
186*4882a593Smuzhiyun
tcp_diag_dump_one(struct netlink_callback * cb,const struct inet_diag_req_v2 * req)187*4882a593Smuzhiyun static int tcp_diag_dump_one(struct netlink_callback *cb,
188*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
189*4882a593Smuzhiyun {
190*4882a593Smuzhiyun return inet_diag_dump_one_icsk(&tcp_hashinfo, cb, req);
191*4882a593Smuzhiyun }
192*4882a593Smuzhiyun
193*4882a593Smuzhiyun #ifdef CONFIG_INET_DIAG_DESTROY
tcp_diag_destroy(struct sk_buff * in_skb,const struct inet_diag_req_v2 * req)194*4882a593Smuzhiyun static int tcp_diag_destroy(struct sk_buff *in_skb,
195*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
196*4882a593Smuzhiyun {
197*4882a593Smuzhiyun struct net *net = sock_net(in_skb->sk);
198*4882a593Smuzhiyun struct sock *sk = inet_diag_find_one_icsk(net, &tcp_hashinfo, req);
199*4882a593Smuzhiyun int err;
200*4882a593Smuzhiyun
201*4882a593Smuzhiyun if (IS_ERR(sk))
202*4882a593Smuzhiyun return PTR_ERR(sk);
203*4882a593Smuzhiyun
204*4882a593Smuzhiyun err = sock_diag_destroy(sk, ECONNABORTED);
205*4882a593Smuzhiyun
206*4882a593Smuzhiyun sock_gen_put(sk);
207*4882a593Smuzhiyun
208*4882a593Smuzhiyun return err;
209*4882a593Smuzhiyun }
210*4882a593Smuzhiyun #endif
211*4882a593Smuzhiyun
212*4882a593Smuzhiyun static const struct inet_diag_handler tcp_diag_handler = {
213*4882a593Smuzhiyun .dump = tcp_diag_dump,
214*4882a593Smuzhiyun .dump_one = tcp_diag_dump_one,
215*4882a593Smuzhiyun .idiag_get_info = tcp_diag_get_info,
216*4882a593Smuzhiyun .idiag_get_aux = tcp_diag_get_aux,
217*4882a593Smuzhiyun .idiag_get_aux_size = tcp_diag_get_aux_size,
218*4882a593Smuzhiyun .idiag_type = IPPROTO_TCP,
219*4882a593Smuzhiyun .idiag_info_size = sizeof(struct tcp_info),
220*4882a593Smuzhiyun #ifdef CONFIG_INET_DIAG_DESTROY
221*4882a593Smuzhiyun .destroy = tcp_diag_destroy,
222*4882a593Smuzhiyun #endif
223*4882a593Smuzhiyun };
224*4882a593Smuzhiyun
tcp_diag_init(void)225*4882a593Smuzhiyun static int __init tcp_diag_init(void)
226*4882a593Smuzhiyun {
227*4882a593Smuzhiyun return inet_diag_register(&tcp_diag_handler);
228*4882a593Smuzhiyun }
229*4882a593Smuzhiyun
tcp_diag_exit(void)230*4882a593Smuzhiyun static void __exit tcp_diag_exit(void)
231*4882a593Smuzhiyun {
232*4882a593Smuzhiyun inet_diag_unregister(&tcp_diag_handler);
233*4882a593Smuzhiyun }
234*4882a593Smuzhiyun
235*4882a593Smuzhiyun module_init(tcp_diag_init);
236*4882a593Smuzhiyun module_exit(tcp_diag_exit);
237*4882a593Smuzhiyun MODULE_LICENSE("GPL");
238*4882a593Smuzhiyun MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_NETLINK, NETLINK_SOCK_DIAG, 2-6 /* AF_INET - IPPROTO_TCP */);
239