1 /* RxRPC security handling
3 * Copyright (C) 2007 Red Hat, Inc. All Rights Reserved.
4 * Written by David Howells (dhowells@redhat.com)
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License
8 * as published by the Free Software Foundation; either version
9 * 2 of the License, or (at your option) any later version.
12 #include <linux/module.h>
13 #include <linux/net.h>
14 #include <linux/skbuff.h>
15 #include <linux/udp.h>
16 #include <linux/crypto.h>
18 #include <net/af_rxrpc.h>
19 #include "ar-internal.h"
21 static LIST_HEAD(rxrpc_security_methods
);
22 static DECLARE_RWSEM(rxrpc_security_sem
);
25 * get an RxRPC security module
27 static struct rxrpc_security
*rxrpc_security_get(struct rxrpc_security
*sec
)
29 return try_module_get(sec
->owner
) ? sec
: NULL
;
33 * release an RxRPC security module
35 static void rxrpc_security_put(struct rxrpc_security
*sec
)
37 module_put(sec
->owner
);
41 * look up an rxrpc security module
43 static struct rxrpc_security
*rxrpc_security_lookup(u8 security_index
)
45 struct rxrpc_security
*sec
= NULL
;
49 down_read(&rxrpc_security_sem
);
51 list_for_each_entry(sec
, &rxrpc_security_methods
, link
) {
52 if (sec
->security_index
== security_index
) {
53 if (unlikely(!rxrpc_security_get(sec
)))
61 up_read(&rxrpc_security_sem
);
62 _leave(" = %p [%s]", sec
, sec
? sec
->name
: "");
67 * rxrpc_register_security - register an RxRPC security handler
68 * @sec: security module
70 * register an RxRPC security handler for use by RxRPC
72 int rxrpc_register_security(struct rxrpc_security
*sec
)
74 struct rxrpc_security
*psec
;
78 down_write(&rxrpc_security_sem
);
81 list_for_each_entry(psec
, &rxrpc_security_methods
, link
) {
82 if (psec
->security_index
== sec
->security_index
)
86 list_add(&sec
->link
, &rxrpc_security_methods
);
88 printk(KERN_NOTICE
"RxRPC: Registered security type %d '%s'\n",
89 sec
->security_index
, sec
->name
);
93 up_write(&rxrpc_security_sem
);
98 EXPORT_SYMBOL_GPL(rxrpc_register_security
);
101 * rxrpc_unregister_security - unregister an RxRPC security handler
102 * @sec: security module
104 * unregister an RxRPC security handler
106 void rxrpc_unregister_security(struct rxrpc_security
*sec
)
110 down_write(&rxrpc_security_sem
);
111 list_del_init(&sec
->link
);
112 up_write(&rxrpc_security_sem
);
114 printk(KERN_NOTICE
"RxRPC: Unregistered security type %d '%s'\n",
115 sec
->security_index
, sec
->name
);
118 EXPORT_SYMBOL_GPL(rxrpc_unregister_security
);
121 * initialise the security on a client connection
123 int rxrpc_init_client_conn_security(struct rxrpc_connection
*conn
)
125 struct rxrpc_security
*sec
;
126 struct key
*key
= conn
->key
;
129 _enter("{%d},{%x}", conn
->debug_id
, key_serial(key
));
134 ret
= key_validate(key
);
138 sec
= rxrpc_security_lookup(key
->type_data
.x
[0]);
140 return -EKEYREJECTED
;
141 conn
->security
= sec
;
143 ret
= conn
->security
->init_connection_security(conn
);
145 rxrpc_security_put(conn
->security
);
146 conn
->security
= NULL
;
155 * initialise the security on a server connection
157 int rxrpc_init_server_conn_security(struct rxrpc_connection
*conn
)
159 struct rxrpc_security
*sec
;
160 struct rxrpc_local
*local
= conn
->trans
->local
;
161 struct rxrpc_sock
*rx
;
168 sprintf(kdesc
, "%u:%u", ntohs(conn
->service_id
), conn
->security_ix
);
170 sec
= rxrpc_security_lookup(conn
->security_ix
);
172 _leave(" = -ENOKEY [lookup]");
176 /* find the service */
177 read_lock_bh(&local
->services_lock
);
178 list_for_each_entry(rx
, &local
->services
, listen_link
) {
179 if (rx
->service_id
== conn
->service_id
)
183 /* the service appears to have died */
184 read_unlock_bh(&local
->services_lock
);
185 rxrpc_security_put(sec
);
186 _leave(" = -ENOENT");
190 if (!rx
->securities
) {
191 read_unlock_bh(&local
->services_lock
);
192 rxrpc_security_put(sec
);
193 _leave(" = -ENOKEY");
197 /* look through the service's keyring */
198 kref
= keyring_search(make_key_ref(rx
->securities
, 1UL),
199 &key_type_rxrpc_s
, kdesc
);
201 read_unlock_bh(&local
->services_lock
);
202 rxrpc_security_put(sec
);
203 _leave(" = %ld [search]", PTR_ERR(kref
));
204 return PTR_ERR(kref
);
207 key
= key_ref_to_ptr(kref
);
208 read_unlock_bh(&local
->services_lock
);
210 conn
->server_key
= key
;
211 conn
->security
= sec
;
218 * secure a packet prior to transmission
220 int rxrpc_secure_packet(const struct rxrpc_call
*call
,
225 if (call
->conn
->security
)
226 return call
->conn
->security
->secure_packet(
227 call
, skb
, data_size
, sechdr
);
232 * secure a packet prior to transmission
234 int rxrpc_verify_packet(const struct rxrpc_call
*call
, struct sk_buff
*skb
,
237 if (call
->conn
->security
)
238 return call
->conn
->security
->verify_packet(
239 call
, skb
, _abort_code
);
244 * clear connection security
246 void rxrpc_clear_conn_security(struct rxrpc_connection
*conn
)
248 _enter("{%d}", conn
->debug_id
);
250 if (conn
->security
) {
251 conn
->security
->clear(conn
);
252 rxrpc_security_put(conn
->security
);
253 conn
->security
= NULL
;
257 key_put(conn
->server_key
);