1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * udp_diag.c Module for monitoring UDP transport protocols sockets.
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Authors: Pavel Emelyanov, <xemul@parallels.com>
6*4882a593Smuzhiyun */
7*4882a593Smuzhiyun
8*4882a593Smuzhiyun
9*4882a593Smuzhiyun #include <linux/module.h>
10*4882a593Smuzhiyun #include <linux/inet_diag.h>
11*4882a593Smuzhiyun #include <linux/udp.h>
12*4882a593Smuzhiyun #include <net/udp.h>
13*4882a593Smuzhiyun #include <net/udplite.h>
14*4882a593Smuzhiyun #include <linux/sock_diag.h>
15*4882a593Smuzhiyun
sk_diag_dump(struct sock * sk,struct sk_buff * skb,struct netlink_callback * cb,const struct inet_diag_req_v2 * req,struct nlattr * bc,bool net_admin)16*4882a593Smuzhiyun static int sk_diag_dump(struct sock *sk, struct sk_buff *skb,
17*4882a593Smuzhiyun struct netlink_callback *cb,
18*4882a593Smuzhiyun const struct inet_diag_req_v2 *req,
19*4882a593Smuzhiyun struct nlattr *bc, bool net_admin)
20*4882a593Smuzhiyun {
21*4882a593Smuzhiyun if (!inet_diag_bc_sk(bc, sk))
22*4882a593Smuzhiyun return 0;
23*4882a593Smuzhiyun
24*4882a593Smuzhiyun return inet_sk_diag_fill(sk, NULL, skb, cb, req, NLM_F_MULTI,
25*4882a593Smuzhiyun net_admin);
26*4882a593Smuzhiyun }
27*4882a593Smuzhiyun
udp_dump_one(struct udp_table * tbl,struct netlink_callback * cb,const struct inet_diag_req_v2 * req)28*4882a593Smuzhiyun static int udp_dump_one(struct udp_table *tbl,
29*4882a593Smuzhiyun struct netlink_callback *cb,
30*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
31*4882a593Smuzhiyun {
32*4882a593Smuzhiyun struct sk_buff *in_skb = cb->skb;
33*4882a593Smuzhiyun int err = -EINVAL;
34*4882a593Smuzhiyun struct sock *sk = NULL;
35*4882a593Smuzhiyun struct sk_buff *rep;
36*4882a593Smuzhiyun struct net *net = sock_net(in_skb->sk);
37*4882a593Smuzhiyun
38*4882a593Smuzhiyun rcu_read_lock();
39*4882a593Smuzhiyun if (req->sdiag_family == AF_INET)
40*4882a593Smuzhiyun /* src and dst are swapped for historical reasons */
41*4882a593Smuzhiyun sk = __udp4_lib_lookup(net,
42*4882a593Smuzhiyun req->id.idiag_src[0], req->id.idiag_sport,
43*4882a593Smuzhiyun req->id.idiag_dst[0], req->id.idiag_dport,
44*4882a593Smuzhiyun req->id.idiag_if, 0, tbl, NULL);
45*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
46*4882a593Smuzhiyun else if (req->sdiag_family == AF_INET6)
47*4882a593Smuzhiyun sk = __udp6_lib_lookup(net,
48*4882a593Smuzhiyun (struct in6_addr *)req->id.idiag_src,
49*4882a593Smuzhiyun req->id.idiag_sport,
50*4882a593Smuzhiyun (struct in6_addr *)req->id.idiag_dst,
51*4882a593Smuzhiyun req->id.idiag_dport,
52*4882a593Smuzhiyun req->id.idiag_if, 0, tbl, NULL);
53*4882a593Smuzhiyun #endif
54*4882a593Smuzhiyun if (sk && !refcount_inc_not_zero(&sk->sk_refcnt))
55*4882a593Smuzhiyun sk = NULL;
56*4882a593Smuzhiyun rcu_read_unlock();
57*4882a593Smuzhiyun err = -ENOENT;
58*4882a593Smuzhiyun if (!sk)
59*4882a593Smuzhiyun goto out_nosk;
60*4882a593Smuzhiyun
61*4882a593Smuzhiyun err = sock_diag_check_cookie(sk, req->id.idiag_cookie);
62*4882a593Smuzhiyun if (err)
63*4882a593Smuzhiyun goto out;
64*4882a593Smuzhiyun
65*4882a593Smuzhiyun err = -ENOMEM;
66*4882a593Smuzhiyun rep = nlmsg_new(nla_total_size(sizeof(struct inet_diag_msg)) +
67*4882a593Smuzhiyun inet_diag_msg_attrs_size() +
68*4882a593Smuzhiyun nla_total_size(sizeof(struct inet_diag_meminfo)) + 64,
69*4882a593Smuzhiyun GFP_KERNEL);
70*4882a593Smuzhiyun if (!rep)
71*4882a593Smuzhiyun goto out;
72*4882a593Smuzhiyun
73*4882a593Smuzhiyun err = inet_sk_diag_fill(sk, NULL, rep, cb, req, 0,
74*4882a593Smuzhiyun netlink_net_capable(in_skb, CAP_NET_ADMIN));
75*4882a593Smuzhiyun if (err < 0) {
76*4882a593Smuzhiyun WARN_ON(err == -EMSGSIZE);
77*4882a593Smuzhiyun kfree_skb(rep);
78*4882a593Smuzhiyun goto out;
79*4882a593Smuzhiyun }
80*4882a593Smuzhiyun err = netlink_unicast(net->diag_nlsk, rep, NETLINK_CB(in_skb).portid,
81*4882a593Smuzhiyun MSG_DONTWAIT);
82*4882a593Smuzhiyun if (err > 0)
83*4882a593Smuzhiyun err = 0;
84*4882a593Smuzhiyun out:
85*4882a593Smuzhiyun if (sk)
86*4882a593Smuzhiyun sock_put(sk);
87*4882a593Smuzhiyun out_nosk:
88*4882a593Smuzhiyun return err;
89*4882a593Smuzhiyun }
90*4882a593Smuzhiyun
udp_dump(struct udp_table * table,struct sk_buff * skb,struct netlink_callback * cb,const struct inet_diag_req_v2 * r)91*4882a593Smuzhiyun static void udp_dump(struct udp_table *table, struct sk_buff *skb,
92*4882a593Smuzhiyun struct netlink_callback *cb,
93*4882a593Smuzhiyun const struct inet_diag_req_v2 *r)
94*4882a593Smuzhiyun {
95*4882a593Smuzhiyun bool net_admin = netlink_net_capable(cb->skb, CAP_NET_ADMIN);
96*4882a593Smuzhiyun struct net *net = sock_net(skb->sk);
97*4882a593Smuzhiyun struct inet_diag_dump_data *cb_data;
98*4882a593Smuzhiyun int num, s_num, slot, s_slot;
99*4882a593Smuzhiyun struct nlattr *bc;
100*4882a593Smuzhiyun
101*4882a593Smuzhiyun cb_data = cb->data;
102*4882a593Smuzhiyun bc = cb_data->inet_diag_nla_bc;
103*4882a593Smuzhiyun s_slot = cb->args[0];
104*4882a593Smuzhiyun num = s_num = cb->args[1];
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun for (slot = s_slot; slot <= table->mask; s_num = 0, slot++) {
107*4882a593Smuzhiyun struct udp_hslot *hslot = &table->hash[slot];
108*4882a593Smuzhiyun struct sock *sk;
109*4882a593Smuzhiyun
110*4882a593Smuzhiyun num = 0;
111*4882a593Smuzhiyun
112*4882a593Smuzhiyun if (hlist_empty(&hslot->head))
113*4882a593Smuzhiyun continue;
114*4882a593Smuzhiyun
115*4882a593Smuzhiyun spin_lock_bh(&hslot->lock);
116*4882a593Smuzhiyun sk_for_each(sk, &hslot->head) {
117*4882a593Smuzhiyun struct inet_sock *inet = inet_sk(sk);
118*4882a593Smuzhiyun
119*4882a593Smuzhiyun if (!net_eq(sock_net(sk), net))
120*4882a593Smuzhiyun continue;
121*4882a593Smuzhiyun if (num < s_num)
122*4882a593Smuzhiyun goto next;
123*4882a593Smuzhiyun if (!(r->idiag_states & (1 << sk->sk_state)))
124*4882a593Smuzhiyun goto next;
125*4882a593Smuzhiyun if (r->sdiag_family != AF_UNSPEC &&
126*4882a593Smuzhiyun sk->sk_family != r->sdiag_family)
127*4882a593Smuzhiyun goto next;
128*4882a593Smuzhiyun if (r->id.idiag_sport != inet->inet_sport &&
129*4882a593Smuzhiyun r->id.idiag_sport)
130*4882a593Smuzhiyun goto next;
131*4882a593Smuzhiyun if (r->id.idiag_dport != inet->inet_dport &&
132*4882a593Smuzhiyun r->id.idiag_dport)
133*4882a593Smuzhiyun goto next;
134*4882a593Smuzhiyun
135*4882a593Smuzhiyun if (sk_diag_dump(sk, skb, cb, r, bc, net_admin) < 0) {
136*4882a593Smuzhiyun spin_unlock_bh(&hslot->lock);
137*4882a593Smuzhiyun goto done;
138*4882a593Smuzhiyun }
139*4882a593Smuzhiyun next:
140*4882a593Smuzhiyun num++;
141*4882a593Smuzhiyun }
142*4882a593Smuzhiyun spin_unlock_bh(&hslot->lock);
143*4882a593Smuzhiyun }
144*4882a593Smuzhiyun done:
145*4882a593Smuzhiyun cb->args[0] = slot;
146*4882a593Smuzhiyun cb->args[1] = num;
147*4882a593Smuzhiyun }
148*4882a593Smuzhiyun
udp_diag_dump(struct sk_buff * skb,struct netlink_callback * cb,const struct inet_diag_req_v2 * r)149*4882a593Smuzhiyun static void udp_diag_dump(struct sk_buff *skb, struct netlink_callback *cb,
150*4882a593Smuzhiyun const struct inet_diag_req_v2 *r)
151*4882a593Smuzhiyun {
152*4882a593Smuzhiyun udp_dump(&udp_table, skb, cb, r);
153*4882a593Smuzhiyun }
154*4882a593Smuzhiyun
udp_diag_dump_one(struct netlink_callback * cb,const struct inet_diag_req_v2 * req)155*4882a593Smuzhiyun static int udp_diag_dump_one(struct netlink_callback *cb,
156*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
157*4882a593Smuzhiyun {
158*4882a593Smuzhiyun return udp_dump_one(&udp_table, cb, req);
159*4882a593Smuzhiyun }
160*4882a593Smuzhiyun
udp_diag_get_info(struct sock * sk,struct inet_diag_msg * r,void * info)161*4882a593Smuzhiyun static void udp_diag_get_info(struct sock *sk, struct inet_diag_msg *r,
162*4882a593Smuzhiyun void *info)
163*4882a593Smuzhiyun {
164*4882a593Smuzhiyun r->idiag_rqueue = udp_rqueue_get(sk);
165*4882a593Smuzhiyun r->idiag_wqueue = sk_wmem_alloc_get(sk);
166*4882a593Smuzhiyun }
167*4882a593Smuzhiyun
168*4882a593Smuzhiyun #ifdef CONFIG_INET_DIAG_DESTROY
__udp_diag_destroy(struct sk_buff * in_skb,const struct inet_diag_req_v2 * req,struct udp_table * tbl)169*4882a593Smuzhiyun static int __udp_diag_destroy(struct sk_buff *in_skb,
170*4882a593Smuzhiyun const struct inet_diag_req_v2 *req,
171*4882a593Smuzhiyun struct udp_table *tbl)
172*4882a593Smuzhiyun {
173*4882a593Smuzhiyun struct net *net = sock_net(in_skb->sk);
174*4882a593Smuzhiyun struct sock *sk;
175*4882a593Smuzhiyun int err;
176*4882a593Smuzhiyun
177*4882a593Smuzhiyun rcu_read_lock();
178*4882a593Smuzhiyun
179*4882a593Smuzhiyun if (req->sdiag_family == AF_INET)
180*4882a593Smuzhiyun sk = __udp4_lib_lookup(net,
181*4882a593Smuzhiyun req->id.idiag_dst[0], req->id.idiag_dport,
182*4882a593Smuzhiyun req->id.idiag_src[0], req->id.idiag_sport,
183*4882a593Smuzhiyun req->id.idiag_if, 0, tbl, NULL);
184*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
185*4882a593Smuzhiyun else if (req->sdiag_family == AF_INET6) {
186*4882a593Smuzhiyun if (ipv6_addr_v4mapped((struct in6_addr *)req->id.idiag_dst) &&
187*4882a593Smuzhiyun ipv6_addr_v4mapped((struct in6_addr *)req->id.idiag_src))
188*4882a593Smuzhiyun sk = __udp4_lib_lookup(net,
189*4882a593Smuzhiyun req->id.idiag_dst[3], req->id.idiag_dport,
190*4882a593Smuzhiyun req->id.idiag_src[3], req->id.idiag_sport,
191*4882a593Smuzhiyun req->id.idiag_if, 0, tbl, NULL);
192*4882a593Smuzhiyun
193*4882a593Smuzhiyun else
194*4882a593Smuzhiyun sk = __udp6_lib_lookup(net,
195*4882a593Smuzhiyun (struct in6_addr *)req->id.idiag_dst,
196*4882a593Smuzhiyun req->id.idiag_dport,
197*4882a593Smuzhiyun (struct in6_addr *)req->id.idiag_src,
198*4882a593Smuzhiyun req->id.idiag_sport,
199*4882a593Smuzhiyun req->id.idiag_if, 0, tbl, NULL);
200*4882a593Smuzhiyun }
201*4882a593Smuzhiyun #endif
202*4882a593Smuzhiyun else {
203*4882a593Smuzhiyun rcu_read_unlock();
204*4882a593Smuzhiyun return -EINVAL;
205*4882a593Smuzhiyun }
206*4882a593Smuzhiyun
207*4882a593Smuzhiyun if (sk && !refcount_inc_not_zero(&sk->sk_refcnt))
208*4882a593Smuzhiyun sk = NULL;
209*4882a593Smuzhiyun
210*4882a593Smuzhiyun rcu_read_unlock();
211*4882a593Smuzhiyun
212*4882a593Smuzhiyun if (!sk)
213*4882a593Smuzhiyun return -ENOENT;
214*4882a593Smuzhiyun
215*4882a593Smuzhiyun if (sock_diag_check_cookie(sk, req->id.idiag_cookie)) {
216*4882a593Smuzhiyun sock_put(sk);
217*4882a593Smuzhiyun return -ENOENT;
218*4882a593Smuzhiyun }
219*4882a593Smuzhiyun
220*4882a593Smuzhiyun err = sock_diag_destroy(sk, ECONNABORTED);
221*4882a593Smuzhiyun
222*4882a593Smuzhiyun sock_put(sk);
223*4882a593Smuzhiyun
224*4882a593Smuzhiyun return err;
225*4882a593Smuzhiyun }
226*4882a593Smuzhiyun
udp_diag_destroy(struct sk_buff * in_skb,const struct inet_diag_req_v2 * req)227*4882a593Smuzhiyun static int udp_diag_destroy(struct sk_buff *in_skb,
228*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
229*4882a593Smuzhiyun {
230*4882a593Smuzhiyun return __udp_diag_destroy(in_skb, req, &udp_table);
231*4882a593Smuzhiyun }
232*4882a593Smuzhiyun
udplite_diag_destroy(struct sk_buff * in_skb,const struct inet_diag_req_v2 * req)233*4882a593Smuzhiyun static int udplite_diag_destroy(struct sk_buff *in_skb,
234*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
235*4882a593Smuzhiyun {
236*4882a593Smuzhiyun return __udp_diag_destroy(in_skb, req, &udplite_table);
237*4882a593Smuzhiyun }
238*4882a593Smuzhiyun
239*4882a593Smuzhiyun #endif
240*4882a593Smuzhiyun
241*4882a593Smuzhiyun static const struct inet_diag_handler udp_diag_handler = {
242*4882a593Smuzhiyun .dump = udp_diag_dump,
243*4882a593Smuzhiyun .dump_one = udp_diag_dump_one,
244*4882a593Smuzhiyun .idiag_get_info = udp_diag_get_info,
245*4882a593Smuzhiyun .idiag_type = IPPROTO_UDP,
246*4882a593Smuzhiyun .idiag_info_size = 0,
247*4882a593Smuzhiyun #ifdef CONFIG_INET_DIAG_DESTROY
248*4882a593Smuzhiyun .destroy = udp_diag_destroy,
249*4882a593Smuzhiyun #endif
250*4882a593Smuzhiyun };
251*4882a593Smuzhiyun
udplite_diag_dump(struct sk_buff * skb,struct netlink_callback * cb,const struct inet_diag_req_v2 * r)252*4882a593Smuzhiyun static void udplite_diag_dump(struct sk_buff *skb, struct netlink_callback *cb,
253*4882a593Smuzhiyun const struct inet_diag_req_v2 *r)
254*4882a593Smuzhiyun {
255*4882a593Smuzhiyun udp_dump(&udplite_table, skb, cb, r);
256*4882a593Smuzhiyun }
257*4882a593Smuzhiyun
udplite_diag_dump_one(struct netlink_callback * cb,const struct inet_diag_req_v2 * req)258*4882a593Smuzhiyun static int udplite_diag_dump_one(struct netlink_callback *cb,
259*4882a593Smuzhiyun const struct inet_diag_req_v2 *req)
260*4882a593Smuzhiyun {
261*4882a593Smuzhiyun return udp_dump_one(&udplite_table, cb, req);
262*4882a593Smuzhiyun }
263*4882a593Smuzhiyun
264*4882a593Smuzhiyun static const struct inet_diag_handler udplite_diag_handler = {
265*4882a593Smuzhiyun .dump = udplite_diag_dump,
266*4882a593Smuzhiyun .dump_one = udplite_diag_dump_one,
267*4882a593Smuzhiyun .idiag_get_info = udp_diag_get_info,
268*4882a593Smuzhiyun .idiag_type = IPPROTO_UDPLITE,
269*4882a593Smuzhiyun .idiag_info_size = 0,
270*4882a593Smuzhiyun #ifdef CONFIG_INET_DIAG_DESTROY
271*4882a593Smuzhiyun .destroy = udplite_diag_destroy,
272*4882a593Smuzhiyun #endif
273*4882a593Smuzhiyun };
274*4882a593Smuzhiyun
udp_diag_init(void)275*4882a593Smuzhiyun static int __init udp_diag_init(void)
276*4882a593Smuzhiyun {
277*4882a593Smuzhiyun int err;
278*4882a593Smuzhiyun
279*4882a593Smuzhiyun err = inet_diag_register(&udp_diag_handler);
280*4882a593Smuzhiyun if (err)
281*4882a593Smuzhiyun goto out;
282*4882a593Smuzhiyun err = inet_diag_register(&udplite_diag_handler);
283*4882a593Smuzhiyun if (err)
284*4882a593Smuzhiyun goto out_lite;
285*4882a593Smuzhiyun out:
286*4882a593Smuzhiyun return err;
287*4882a593Smuzhiyun out_lite:
288*4882a593Smuzhiyun inet_diag_unregister(&udp_diag_handler);
289*4882a593Smuzhiyun goto out;
290*4882a593Smuzhiyun }
291*4882a593Smuzhiyun
udp_diag_exit(void)292*4882a593Smuzhiyun static void __exit udp_diag_exit(void)
293*4882a593Smuzhiyun {
294*4882a593Smuzhiyun inet_diag_unregister(&udplite_diag_handler);
295*4882a593Smuzhiyun inet_diag_unregister(&udp_diag_handler);
296*4882a593Smuzhiyun }
297*4882a593Smuzhiyun
298*4882a593Smuzhiyun module_init(udp_diag_init);
299*4882a593Smuzhiyun module_exit(udp_diag_exit);
300*4882a593Smuzhiyun MODULE_LICENSE("GPL");
301*4882a593Smuzhiyun MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_NETLINK, NETLINK_SOCK_DIAG, 2-17 /* AF_INET - IPPROTO_UDP */);
302*4882a593Smuzhiyun MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_NETLINK, NETLINK_SOCK_DIAG, 2-136 /* AF_INET - IPPROTO_UDPLITE */);
303