KEYS: add missing permission check for request_key() destination
[linux/fpc-iii.git] / net / core / dev_ioctl.c
blobcf999e09bcd2c23654826b8c7e7b3d3dde2a7a59
1 #include <linux/kmod.h>
2 #include <linux/netdevice.h>
3 #include <linux/etherdevice.h>
4 #include <linux/rtnetlink.h>
5 #include <linux/net_tstamp.h>
6 #include <linux/wireless.h>
7 #include <net/wext.h>
9 /*
10 * Map an interface index to its name (SIOCGIFNAME)
14 * We need this ioctl for efficient implementation of the
15 * if_indextoname() function required by the IPv6 API. Without
16 * it, we would have to search all the interfaces to find a
17 * match. --pb
20 static int dev_ifname(struct net *net, struct ifreq __user *arg)
22 struct ifreq ifr;
23 int error;
26 * Fetch the caller's info block.
29 if (copy_from_user(&ifr, arg, sizeof(struct ifreq)))
30 return -EFAULT;
32 error = netdev_get_name(net, ifr.ifr_name, ifr.ifr_ifindex);
33 if (error)
34 return error;
36 if (copy_to_user(arg, &ifr, sizeof(struct ifreq)))
37 return -EFAULT;
38 return 0;
41 static gifconf_func_t *gifconf_list[NPROTO];
43 /**
44 * register_gifconf - register a SIOCGIF handler
45 * @family: Address family
46 * @gifconf: Function handler
48 * Register protocol dependent address dumping routines. The handler
49 * that is passed must not be freed or reused until it has been replaced
50 * by another handler.
52 int register_gifconf(unsigned int family, gifconf_func_t *gifconf)
54 if (family >= NPROTO)
55 return -EINVAL;
56 gifconf_list[family] = gifconf;
57 return 0;
59 EXPORT_SYMBOL(register_gifconf);
62 * Perform a SIOCGIFCONF call. This structure will change
63 * size eventually, and there is nothing I can do about it.
64 * Thus we will need a 'compatibility mode'.
67 static int dev_ifconf(struct net *net, char __user *arg)
69 struct ifconf ifc;
70 struct net_device *dev;
71 char __user *pos;
72 int len;
73 int total;
74 int i;
77 * Fetch the caller's info block.
80 if (copy_from_user(&ifc, arg, sizeof(struct ifconf)))
81 return -EFAULT;
83 pos = ifc.ifc_buf;
84 len = ifc.ifc_len;
87 * Loop over the interfaces, and write an info block for each.
90 total = 0;
91 for_each_netdev(net, dev) {
92 for (i = 0; i < NPROTO; i++) {
93 if (gifconf_list[i]) {
94 int done;
95 if (!pos)
96 done = gifconf_list[i](dev, NULL, 0);
97 else
98 done = gifconf_list[i](dev, pos + total,
99 len - total);
100 if (done < 0)
101 return -EFAULT;
102 total += done;
108 * All done. Write the updated control block back to the caller.
110 ifc.ifc_len = total;
113 * Both BSD and Solaris return 0 here, so we do too.
115 return copy_to_user(arg, &ifc, sizeof(struct ifconf)) ? -EFAULT : 0;
119 * Perform the SIOCxIFxxx calls, inside rcu_read_lock()
121 static int dev_ifsioc_locked(struct net *net, struct ifreq *ifr, unsigned int cmd)
123 int err;
124 struct net_device *dev = dev_get_by_name_rcu(net, ifr->ifr_name);
126 if (!dev)
127 return -ENODEV;
129 switch (cmd) {
130 case SIOCGIFFLAGS: /* Get interface flags */
131 ifr->ifr_flags = (short) dev_get_flags(dev);
132 return 0;
134 case SIOCGIFMETRIC: /* Get the metric on the interface
135 (currently unused) */
136 ifr->ifr_metric = 0;
137 return 0;
139 case SIOCGIFMTU: /* Get the MTU of a device */
140 ifr->ifr_mtu = dev->mtu;
141 return 0;
143 case SIOCGIFHWADDR:
144 if (!dev->addr_len)
145 memset(ifr->ifr_hwaddr.sa_data, 0, sizeof ifr->ifr_hwaddr.sa_data);
146 else
147 memcpy(ifr->ifr_hwaddr.sa_data, dev->dev_addr,
148 min(sizeof ifr->ifr_hwaddr.sa_data, (size_t) dev->addr_len));
149 ifr->ifr_hwaddr.sa_family = dev->type;
150 return 0;
152 case SIOCGIFSLAVE:
153 err = -EINVAL;
154 break;
156 case SIOCGIFMAP:
157 ifr->ifr_map.mem_start = dev->mem_start;
158 ifr->ifr_map.mem_end = dev->mem_end;
159 ifr->ifr_map.base_addr = dev->base_addr;
160 ifr->ifr_map.irq = dev->irq;
161 ifr->ifr_map.dma = dev->dma;
162 ifr->ifr_map.port = dev->if_port;
163 return 0;
165 case SIOCGIFINDEX:
166 ifr->ifr_ifindex = dev->ifindex;
167 return 0;
169 case SIOCGIFTXQLEN:
170 ifr->ifr_qlen = dev->tx_queue_len;
171 return 0;
173 default:
174 /* dev_ioctl() should ensure this case
175 * is never reached
177 WARN_ON(1);
178 err = -ENOTTY;
179 break;
182 return err;
185 static int net_hwtstamp_validate(struct ifreq *ifr)
187 struct hwtstamp_config cfg;
188 enum hwtstamp_tx_types tx_type;
189 enum hwtstamp_rx_filters rx_filter;
190 int tx_type_valid = 0;
191 int rx_filter_valid = 0;
193 if (copy_from_user(&cfg, ifr->ifr_data, sizeof(cfg)))
194 return -EFAULT;
196 if (cfg.flags) /* reserved for future extensions */
197 return -EINVAL;
199 tx_type = cfg.tx_type;
200 rx_filter = cfg.rx_filter;
202 switch (tx_type) {
203 case HWTSTAMP_TX_OFF:
204 case HWTSTAMP_TX_ON:
205 case HWTSTAMP_TX_ONESTEP_SYNC:
206 tx_type_valid = 1;
207 break;
210 switch (rx_filter) {
211 case HWTSTAMP_FILTER_NONE:
212 case HWTSTAMP_FILTER_ALL:
213 case HWTSTAMP_FILTER_SOME:
214 case HWTSTAMP_FILTER_PTP_V1_L4_EVENT:
215 case HWTSTAMP_FILTER_PTP_V1_L4_SYNC:
216 case HWTSTAMP_FILTER_PTP_V1_L4_DELAY_REQ:
217 case HWTSTAMP_FILTER_PTP_V2_L4_EVENT:
218 case HWTSTAMP_FILTER_PTP_V2_L4_SYNC:
219 case HWTSTAMP_FILTER_PTP_V2_L4_DELAY_REQ:
220 case HWTSTAMP_FILTER_PTP_V2_L2_EVENT:
221 case HWTSTAMP_FILTER_PTP_V2_L2_SYNC:
222 case HWTSTAMP_FILTER_PTP_V2_L2_DELAY_REQ:
223 case HWTSTAMP_FILTER_PTP_V2_EVENT:
224 case HWTSTAMP_FILTER_PTP_V2_SYNC:
225 case HWTSTAMP_FILTER_PTP_V2_DELAY_REQ:
226 rx_filter_valid = 1;
227 break;
230 if (!tx_type_valid || !rx_filter_valid)
231 return -ERANGE;
233 return 0;
237 * Perform the SIOCxIFxxx calls, inside rtnl_lock()
239 static int dev_ifsioc(struct net *net, struct ifreq *ifr, unsigned int cmd)
241 int err;
242 struct net_device *dev = __dev_get_by_name(net, ifr->ifr_name);
243 const struct net_device_ops *ops;
245 if (!dev)
246 return -ENODEV;
248 ops = dev->netdev_ops;
250 switch (cmd) {
251 case SIOCSIFFLAGS: /* Set interface flags */
252 return dev_change_flags(dev, ifr->ifr_flags);
254 case SIOCSIFMETRIC: /* Set the metric on the interface
255 (currently unused) */
256 return -EOPNOTSUPP;
258 case SIOCSIFMTU: /* Set the MTU of a device */
259 return dev_set_mtu(dev, ifr->ifr_mtu);
261 case SIOCSIFHWADDR:
262 return dev_set_mac_address(dev, &ifr->ifr_hwaddr);
264 case SIOCSIFHWBROADCAST:
265 if (ifr->ifr_hwaddr.sa_family != dev->type)
266 return -EINVAL;
267 memcpy(dev->broadcast, ifr->ifr_hwaddr.sa_data,
268 min(sizeof ifr->ifr_hwaddr.sa_data, (size_t) dev->addr_len));
269 call_netdevice_notifiers(NETDEV_CHANGEADDR, dev);
270 return 0;
272 case SIOCSIFMAP:
273 if (ops->ndo_set_config) {
274 if (!netif_device_present(dev))
275 return -ENODEV;
276 return ops->ndo_set_config(dev, &ifr->ifr_map);
278 return -EOPNOTSUPP;
280 case SIOCADDMULTI:
281 if (!ops->ndo_set_rx_mode ||
282 ifr->ifr_hwaddr.sa_family != AF_UNSPEC)
283 return -EINVAL;
284 if (!netif_device_present(dev))
285 return -ENODEV;
286 return dev_mc_add_global(dev, ifr->ifr_hwaddr.sa_data);
288 case SIOCDELMULTI:
289 if (!ops->ndo_set_rx_mode ||
290 ifr->ifr_hwaddr.sa_family != AF_UNSPEC)
291 return -EINVAL;
292 if (!netif_device_present(dev))
293 return -ENODEV;
294 return dev_mc_del_global(dev, ifr->ifr_hwaddr.sa_data);
296 case SIOCSIFTXQLEN:
297 if (ifr->ifr_qlen < 0)
298 return -EINVAL;
299 dev->tx_queue_len = ifr->ifr_qlen;
300 return 0;
302 case SIOCSIFNAME:
303 ifr->ifr_newname[IFNAMSIZ-1] = '\0';
304 return dev_change_name(dev, ifr->ifr_newname);
306 case SIOCSHWTSTAMP:
307 err = net_hwtstamp_validate(ifr);
308 if (err)
309 return err;
310 /* fall through */
313 * Unknown or private ioctl
315 default:
316 if ((cmd >= SIOCDEVPRIVATE &&
317 cmd <= SIOCDEVPRIVATE + 15) ||
318 cmd == SIOCBONDENSLAVE ||
319 cmd == SIOCBONDRELEASE ||
320 cmd == SIOCBONDSETHWADDR ||
321 cmd == SIOCBONDSLAVEINFOQUERY ||
322 cmd == SIOCBONDINFOQUERY ||
323 cmd == SIOCBONDCHANGEACTIVE ||
324 cmd == SIOCGMIIPHY ||
325 cmd == SIOCGMIIREG ||
326 cmd == SIOCSMIIREG ||
327 cmd == SIOCBRADDIF ||
328 cmd == SIOCBRDELIF ||
329 cmd == SIOCSHWTSTAMP ||
330 cmd == SIOCGHWTSTAMP ||
331 cmd == SIOCWANDEV) {
332 err = -EOPNOTSUPP;
333 if (ops->ndo_do_ioctl) {
334 if (netif_device_present(dev))
335 err = ops->ndo_do_ioctl(dev, ifr, cmd);
336 else
337 err = -ENODEV;
339 } else
340 err = -EINVAL;
343 return err;
347 * dev_load - load a network module
348 * @net: the applicable net namespace
349 * @name: name of interface
351 * If a network interface is not present and the process has suitable
352 * privileges this function loads the module. If module loading is not
353 * available in this kernel then it becomes a nop.
356 void dev_load(struct net *net, const char *name)
358 struct net_device *dev;
359 int no_module;
361 rcu_read_lock();
362 dev = dev_get_by_name_rcu(net, name);
363 rcu_read_unlock();
365 no_module = !dev;
366 if (no_module && capable(CAP_NET_ADMIN))
367 no_module = request_module("netdev-%s", name);
368 if (no_module && capable(CAP_SYS_MODULE)) {
369 if (!request_module("%s", name))
370 pr_warn("Loading kernel module for a network device with CAP_SYS_MODULE (deprecated). Use CAP_NET_ADMIN and alias netdev-%s instead.\n",
371 name);
374 EXPORT_SYMBOL(dev_load);
377 * This function handles all "interface"-type I/O control requests. The actual
378 * 'doing' part of this is dev_ifsioc above.
382 * dev_ioctl - network device ioctl
383 * @net: the applicable net namespace
384 * @cmd: command to issue
385 * @arg: pointer to a struct ifreq in user space
387 * Issue ioctl functions to devices. This is normally called by the
388 * user space syscall interfaces but can sometimes be useful for
389 * other purposes. The return value is the return from the syscall if
390 * positive or a negative errno code on error.
393 int dev_ioctl(struct net *net, unsigned int cmd, void __user *arg)
395 struct ifreq ifr;
396 int ret;
397 char *colon;
399 /* One special case: SIOCGIFCONF takes ifconf argument
400 and requires shared lock, because it sleeps writing
401 to user space.
404 if (cmd == SIOCGIFCONF) {
405 rtnl_lock();
406 ret = dev_ifconf(net, (char __user *) arg);
407 rtnl_unlock();
408 return ret;
410 if (cmd == SIOCGIFNAME)
411 return dev_ifname(net, (struct ifreq __user *)arg);
413 if (copy_from_user(&ifr, arg, sizeof(struct ifreq)))
414 return -EFAULT;
416 ifr.ifr_name[IFNAMSIZ-1] = 0;
418 colon = strchr(ifr.ifr_name, ':');
419 if (colon)
420 *colon = 0;
423 * See which interface the caller is talking about.
426 switch (cmd) {
428 * These ioctl calls:
429 * - can be done by all.
430 * - atomic and do not require locking.
431 * - return a value
433 case SIOCGIFFLAGS:
434 case SIOCGIFMETRIC:
435 case SIOCGIFMTU:
436 case SIOCGIFHWADDR:
437 case SIOCGIFSLAVE:
438 case SIOCGIFMAP:
439 case SIOCGIFINDEX:
440 case SIOCGIFTXQLEN:
441 dev_load(net, ifr.ifr_name);
442 rcu_read_lock();
443 ret = dev_ifsioc_locked(net, &ifr, cmd);
444 rcu_read_unlock();
445 if (!ret) {
446 if (colon)
447 *colon = ':';
448 if (copy_to_user(arg, &ifr,
449 sizeof(struct ifreq)))
450 ret = -EFAULT;
452 return ret;
454 case SIOCETHTOOL:
455 dev_load(net, ifr.ifr_name);
456 rtnl_lock();
457 ret = dev_ethtool(net, &ifr);
458 rtnl_unlock();
459 if (!ret) {
460 if (colon)
461 *colon = ':';
462 if (copy_to_user(arg, &ifr,
463 sizeof(struct ifreq)))
464 ret = -EFAULT;
466 return ret;
469 * These ioctl calls:
470 * - require superuser power.
471 * - require strict serialization.
472 * - return a value
474 case SIOCGMIIPHY:
475 case SIOCGMIIREG:
476 case SIOCSIFNAME:
477 if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
478 return -EPERM;
479 dev_load(net, ifr.ifr_name);
480 rtnl_lock();
481 ret = dev_ifsioc(net, &ifr, cmd);
482 rtnl_unlock();
483 if (!ret) {
484 if (colon)
485 *colon = ':';
486 if (copy_to_user(arg, &ifr,
487 sizeof(struct ifreq)))
488 ret = -EFAULT;
490 return ret;
493 * These ioctl calls:
494 * - require superuser power.
495 * - require strict serialization.
496 * - do not return a value
498 case SIOCSIFMAP:
499 case SIOCSIFTXQLEN:
500 if (!capable(CAP_NET_ADMIN))
501 return -EPERM;
502 /* fall through */
504 * These ioctl calls:
505 * - require local superuser power.
506 * - require strict serialization.
507 * - do not return a value
509 case SIOCSIFFLAGS:
510 case SIOCSIFMETRIC:
511 case SIOCSIFMTU:
512 case SIOCSIFHWADDR:
513 case SIOCSIFSLAVE:
514 case SIOCADDMULTI:
515 case SIOCDELMULTI:
516 case SIOCSIFHWBROADCAST:
517 case SIOCSMIIREG:
518 case SIOCBONDENSLAVE:
519 case SIOCBONDRELEASE:
520 case SIOCBONDSETHWADDR:
521 case SIOCBONDCHANGEACTIVE:
522 case SIOCBRADDIF:
523 case SIOCBRDELIF:
524 case SIOCSHWTSTAMP:
525 if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
526 return -EPERM;
527 /* fall through */
528 case SIOCBONDSLAVEINFOQUERY:
529 case SIOCBONDINFOQUERY:
530 dev_load(net, ifr.ifr_name);
531 rtnl_lock();
532 ret = dev_ifsioc(net, &ifr, cmd);
533 rtnl_unlock();
534 return ret;
536 case SIOCGIFMEM:
537 /* Get the per device memory space. We can add this but
538 * currently do not support it */
539 case SIOCSIFMEM:
540 /* Set the per device memory buffer space.
541 * Not applicable in our case */
542 case SIOCSIFLINK:
543 return -ENOTTY;
546 * Unknown or private ioctl.
548 default:
549 if (cmd == SIOCWANDEV ||
550 cmd == SIOCGHWTSTAMP ||
551 (cmd >= SIOCDEVPRIVATE &&
552 cmd <= SIOCDEVPRIVATE + 15)) {
553 dev_load(net, ifr.ifr_name);
554 rtnl_lock();
555 ret = dev_ifsioc(net, &ifr, cmd);
556 rtnl_unlock();
557 if (!ret && copy_to_user(arg, &ifr,
558 sizeof(struct ifreq)))
559 ret = -EFAULT;
560 return ret;
562 /* Take care of Wireless Extensions */
563 if (cmd >= SIOCIWFIRST && cmd <= SIOCIWLAST)
564 return wext_handle_ioctl(net, &ifr, cmd, arg);
565 return -ENOTTY;