1 /* krxsecd.c: Rx security daemon
3 * Copyright (C) 2002 Red Hat, Inc. All Rights Reserved.
4 * Written by David Howells (dhowells@redhat.com)
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License
8 * as published by the Free Software Foundation; either version
9 * 2 of the License, or (at your option) any later version.
11 * This daemon deals with:
12 * - consulting the application as to whether inbound peers and calls should be authorised
13 * - generating security challenges for inbound connections
14 * - responding to security challenges on outbound connections
17 #include <linux/module.h>
18 #include <linux/sched.h>
19 #include <linux/completion.h>
20 #include <linux/spinlock.h>
21 #include <linux/init.h>
22 #include <rxrpc/krxsecd.h>
23 #include <rxrpc/transport.h>
24 #include <rxrpc/connection.h>
25 #include <rxrpc/message.h>
26 #include <rxrpc/peer.h>
27 #include <rxrpc/call.h>
28 #include <linux/udp.h>
30 #include <linux/freezer.h>
34 static DECLARE_WAIT_QUEUE_HEAD(rxrpc_krxsecd_sleepq
);
35 static DECLARE_COMPLETION(rxrpc_krxsecd_dead
);
36 static volatile int rxrpc_krxsecd_die
;
38 static atomic_t rxrpc_krxsecd_qcount
;
40 /* queue of unprocessed inbound messages with seqno #1 and
41 * RXRPC_CLIENT_INITIATED flag set */
42 static LIST_HEAD(rxrpc_krxsecd_initmsgq
);
43 static DEFINE_SPINLOCK(rxrpc_krxsecd_initmsgq_lock
);
45 static void rxrpc_krxsecd_process_incoming_call(struct rxrpc_message
*msg
);
47 /*****************************************************************************/
51 static int rxrpc_krxsecd(void *arg
)
53 DECLARE_WAITQUEUE(krxsecd
, current
);
57 printk("Started krxsecd %d\n", current
->pid
);
61 /* loop around waiting for work to do */
63 /* wait for work or to be told to exit */
64 _debug("### Begin Wait");
65 if (!atomic_read(&rxrpc_krxsecd_qcount
)) {
66 set_current_state(TASK_INTERRUPTIBLE
);
68 add_wait_queue(&rxrpc_krxsecd_sleepq
, &krxsecd
);
71 set_current_state(TASK_INTERRUPTIBLE
);
72 if (atomic_read(&rxrpc_krxsecd_qcount
) ||
74 signal_pending(current
))
80 remove_wait_queue(&rxrpc_krxsecd_sleepq
, &krxsecd
);
81 set_current_state(TASK_RUNNING
);
83 die
= rxrpc_krxsecd_die
;
84 _debug("### End Wait");
86 /* see if there're incoming calls in need of authenticating */
87 _debug("### Begin Inbound Calls");
89 if (!list_empty(&rxrpc_krxsecd_initmsgq
)) {
90 struct rxrpc_message
*msg
= NULL
;
92 spin_lock(&rxrpc_krxsecd_initmsgq_lock
);
94 if (!list_empty(&rxrpc_krxsecd_initmsgq
)) {
95 msg
= list_entry(rxrpc_krxsecd_initmsgq
.next
,
96 struct rxrpc_message
, link
);
97 list_del_init(&msg
->link
);
98 atomic_dec(&rxrpc_krxsecd_qcount
);
101 spin_unlock(&rxrpc_krxsecd_initmsgq_lock
);
104 rxrpc_krxsecd_process_incoming_call(msg
);
105 rxrpc_put_message(msg
);
109 _debug("### End Inbound Calls");
113 /* discard pending signals */
114 rxrpc_discard_my_signals();
119 complete_and_exit(&rxrpc_krxsecd_dead
, 0);
121 } /* end rxrpc_krxsecd() */
123 /*****************************************************************************/
125 * start up a krxsecd daemon
127 int __init
rxrpc_krxsecd_init(void)
129 return kernel_thread(rxrpc_krxsecd
, NULL
, 0);
131 } /* end rxrpc_krxsecd_init() */
133 /*****************************************************************************/
135 * kill the krxsecd daemon and wait for it to complete
137 void rxrpc_krxsecd_kill(void)
139 rxrpc_krxsecd_die
= 1;
140 wake_up_all(&rxrpc_krxsecd_sleepq
);
141 wait_for_completion(&rxrpc_krxsecd_dead
);
143 } /* end rxrpc_krxsecd_kill() */
145 /*****************************************************************************/
147 * clear all pending incoming calls for the specified transport
149 void rxrpc_krxsecd_clear_transport(struct rxrpc_transport
*trans
)
153 struct rxrpc_message
*msg
;
154 struct list_head
*_p
, *_n
;
158 /* move all the messages for this transport onto a temp list */
159 spin_lock(&rxrpc_krxsecd_initmsgq_lock
);
161 list_for_each_safe(_p
, _n
, &rxrpc_krxsecd_initmsgq
) {
162 msg
= list_entry(_p
, struct rxrpc_message
, link
);
163 if (msg
->trans
== trans
) {
164 list_move_tail(&msg
->link
, &tmp
);
165 atomic_dec(&rxrpc_krxsecd_qcount
);
169 spin_unlock(&rxrpc_krxsecd_initmsgq_lock
);
171 /* zap all messages on the temp list */
172 while (!list_empty(&tmp
)) {
173 msg
= list_entry(tmp
.next
, struct rxrpc_message
, link
);
174 list_del_init(&msg
->link
);
175 rxrpc_put_message(msg
);
179 } /* end rxrpc_krxsecd_clear_transport() */
181 /*****************************************************************************/
183 * queue a message on the incoming calls list
185 void rxrpc_krxsecd_queue_incoming_call(struct rxrpc_message
*msg
)
189 /* queue for processing by krxsecd */
190 spin_lock(&rxrpc_krxsecd_initmsgq_lock
);
192 if (!rxrpc_krxsecd_die
) {
193 rxrpc_get_message(msg
);
194 list_add_tail(&msg
->link
, &rxrpc_krxsecd_initmsgq
);
195 atomic_inc(&rxrpc_krxsecd_qcount
);
198 spin_unlock(&rxrpc_krxsecd_initmsgq_lock
);
200 wake_up(&rxrpc_krxsecd_sleepq
);
203 } /* end rxrpc_krxsecd_queue_incoming_call() */
205 /*****************************************************************************/
207 * process the initial message of an incoming call
209 void rxrpc_krxsecd_process_incoming_call(struct rxrpc_message
*msg
)
211 struct rxrpc_transport
*trans
= msg
->trans
;
212 struct rxrpc_service
*srv
;
213 struct rxrpc_call
*call
;
214 struct list_head
*_p
;
218 _enter("%p{tr=%p}", msg
, trans
);
220 ret
= rxrpc_incoming_call(msg
->conn
, msg
, &call
);
224 /* find the matching service on the transport */
225 sid
= ntohs(msg
->hdr
.serviceId
);
228 spin_lock(&trans
->lock
);
229 list_for_each(_p
, &trans
->services
) {
230 srv
= list_entry(_p
, struct rxrpc_service
, link
);
231 if (srv
->service_id
== sid
&& try_module_get(srv
->owner
)) {
232 /* found a match (made sure it won't vanish) */
233 _debug("found service '%s'", srv
->name
);
234 call
->owner
= srv
->owner
;
238 spin_unlock(&trans
->lock
);
240 /* report the new connection
241 * - the func must inc the call's usage count to keep it
244 if (_p
!= &trans
->services
) {
245 /* attempt to accept the call */
246 call
->conn
->service
= srv
;
247 call
->app_attn_func
= srv
->attn_func
;
248 call
->app_error_func
= srv
->error_func
;
249 call
->app_aemap_func
= srv
->aemap_func
;
251 ret
= srv
->new_call(call
);
253 /* send an abort if an error occurred */
255 rxrpc_call_abort(call
, ret
);
258 /* formally receive and ACK the new packet */
259 ret
= rxrpc_conn_receive_call_packet(call
->conn
,
264 rxrpc_put_call(call
);
267 rxrpc_trans_immediate_abort(trans
, msg
, ret
);
269 _leave(" (%d)", ret
);
270 } /* end rxrpc_krxsecd_process_incoming_call() */