ipc_sysctl.c 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /*
  3. * Copyright (C) 2007
  4. *
  5. * Author: Eric Biederman <[email protected]>
  6. */
  7. #include <linux/module.h>
  8. #include <linux/ipc.h>
  9. #include <linux/nsproxy.h>
  10. #include <linux/sysctl.h>
  11. #include <linux/uaccess.h>
  12. #include <linux/capability.h>
  13. #include <linux/ipc_namespace.h>
  14. #include <linux/msg.h>
  15. #include <linux/slab.h>
  16. #include "util.h"
  17. static int proc_ipc_dointvec_minmax_orphans(struct ctl_table *table, int write,
  18. void *buffer, size_t *lenp, loff_t *ppos)
  19. {
  20. struct ipc_namespace *ns =
  21. container_of(table->data, struct ipc_namespace, shm_rmid_forced);
  22. int err;
  23. err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
  24. if (err < 0)
  25. return err;
  26. if (ns->shm_rmid_forced)
  27. shm_destroy_orphaned(ns);
  28. return err;
  29. }
  30. static int proc_ipc_auto_msgmni(struct ctl_table *table, int write,
  31. void *buffer, size_t *lenp, loff_t *ppos)
  32. {
  33. struct ctl_table ipc_table;
  34. int dummy = 0;
  35. memcpy(&ipc_table, table, sizeof(ipc_table));
  36. ipc_table.data = &dummy;
  37. if (write)
  38. pr_info_once("writing to auto_msgmni has no effect");
  39. return proc_dointvec_minmax(&ipc_table, write, buffer, lenp, ppos);
  40. }
  41. static int proc_ipc_sem_dointvec(struct ctl_table *table, int write,
  42. void *buffer, size_t *lenp, loff_t *ppos)
  43. {
  44. struct ipc_namespace *ns =
  45. container_of(table->data, struct ipc_namespace, sem_ctls);
  46. int ret, semmni;
  47. semmni = ns->sem_ctls[3];
  48. ret = proc_dointvec(table, write, buffer, lenp, ppos);
  49. if (!ret)
  50. ret = sem_check_semmni(ns);
  51. /*
  52. * Reset the semmni value if an error happens.
  53. */
  54. if (ret)
  55. ns->sem_ctls[3] = semmni;
  56. return ret;
  57. }
  58. int ipc_mni = IPCMNI;
  59. int ipc_mni_shift = IPCMNI_SHIFT;
  60. int ipc_min_cycle = RADIX_TREE_MAP_SIZE;
  61. static struct ctl_table ipc_sysctls[] = {
  62. {
  63. .procname = "shmmax",
  64. .data = &init_ipc_ns.shm_ctlmax,
  65. .maxlen = sizeof(init_ipc_ns.shm_ctlmax),
  66. .mode = 0644,
  67. .proc_handler = proc_doulongvec_minmax,
  68. },
  69. {
  70. .procname = "shmall",
  71. .data = &init_ipc_ns.shm_ctlall,
  72. .maxlen = sizeof(init_ipc_ns.shm_ctlall),
  73. .mode = 0644,
  74. .proc_handler = proc_doulongvec_minmax,
  75. },
  76. {
  77. .procname = "shmmni",
  78. .data = &init_ipc_ns.shm_ctlmni,
  79. .maxlen = sizeof(init_ipc_ns.shm_ctlmni),
  80. .mode = 0644,
  81. .proc_handler = proc_dointvec_minmax,
  82. .extra1 = SYSCTL_ZERO,
  83. .extra2 = &ipc_mni,
  84. },
  85. {
  86. .procname = "shm_rmid_forced",
  87. .data = &init_ipc_ns.shm_rmid_forced,
  88. .maxlen = sizeof(init_ipc_ns.shm_rmid_forced),
  89. .mode = 0644,
  90. .proc_handler = proc_ipc_dointvec_minmax_orphans,
  91. .extra1 = SYSCTL_ZERO,
  92. .extra2 = SYSCTL_ONE,
  93. },
  94. {
  95. .procname = "msgmax",
  96. .data = &init_ipc_ns.msg_ctlmax,
  97. .maxlen = sizeof(init_ipc_ns.msg_ctlmax),
  98. .mode = 0644,
  99. .proc_handler = proc_dointvec_minmax,
  100. .extra1 = SYSCTL_ZERO,
  101. .extra2 = SYSCTL_INT_MAX,
  102. },
  103. {
  104. .procname = "msgmni",
  105. .data = &init_ipc_ns.msg_ctlmni,
  106. .maxlen = sizeof(init_ipc_ns.msg_ctlmni),
  107. .mode = 0644,
  108. .proc_handler = proc_dointvec_minmax,
  109. .extra1 = SYSCTL_ZERO,
  110. .extra2 = &ipc_mni,
  111. },
  112. {
  113. .procname = "auto_msgmni",
  114. .data = NULL,
  115. .maxlen = sizeof(int),
  116. .mode = 0644,
  117. .proc_handler = proc_ipc_auto_msgmni,
  118. .extra1 = SYSCTL_ZERO,
  119. .extra2 = SYSCTL_ONE,
  120. },
  121. {
  122. .procname = "msgmnb",
  123. .data = &init_ipc_ns.msg_ctlmnb,
  124. .maxlen = sizeof(init_ipc_ns.msg_ctlmnb),
  125. .mode = 0644,
  126. .proc_handler = proc_dointvec_minmax,
  127. .extra1 = SYSCTL_ZERO,
  128. .extra2 = SYSCTL_INT_MAX,
  129. },
  130. {
  131. .procname = "sem",
  132. .data = &init_ipc_ns.sem_ctls,
  133. .maxlen = 4*sizeof(int),
  134. .mode = 0644,
  135. .proc_handler = proc_ipc_sem_dointvec,
  136. },
  137. #ifdef CONFIG_CHECKPOINT_RESTORE
  138. {
  139. .procname = "sem_next_id",
  140. .data = &init_ipc_ns.ids[IPC_SEM_IDS].next_id,
  141. .maxlen = sizeof(init_ipc_ns.ids[IPC_SEM_IDS].next_id),
  142. .mode = 0444,
  143. .proc_handler = proc_dointvec_minmax,
  144. .extra1 = SYSCTL_ZERO,
  145. .extra2 = SYSCTL_INT_MAX,
  146. },
  147. {
  148. .procname = "msg_next_id",
  149. .data = &init_ipc_ns.ids[IPC_MSG_IDS].next_id,
  150. .maxlen = sizeof(init_ipc_ns.ids[IPC_MSG_IDS].next_id),
  151. .mode = 0444,
  152. .proc_handler = proc_dointvec_minmax,
  153. .extra1 = SYSCTL_ZERO,
  154. .extra2 = SYSCTL_INT_MAX,
  155. },
  156. {
  157. .procname = "shm_next_id",
  158. .data = &init_ipc_ns.ids[IPC_SHM_IDS].next_id,
  159. .maxlen = sizeof(init_ipc_ns.ids[IPC_SHM_IDS].next_id),
  160. .mode = 0444,
  161. .proc_handler = proc_dointvec_minmax,
  162. .extra1 = SYSCTL_ZERO,
  163. .extra2 = SYSCTL_INT_MAX,
  164. },
  165. #endif
  166. {}
  167. };
  168. static struct ctl_table_set *set_lookup(struct ctl_table_root *root)
  169. {
  170. return &current->nsproxy->ipc_ns->ipc_set;
  171. }
  172. static int set_is_seen(struct ctl_table_set *set)
  173. {
  174. return &current->nsproxy->ipc_ns->ipc_set == set;
  175. }
  176. static int ipc_permissions(struct ctl_table_header *head, struct ctl_table *table)
  177. {
  178. int mode = table->mode;
  179. #ifdef CONFIG_CHECKPOINT_RESTORE
  180. struct ipc_namespace *ns = current->nsproxy->ipc_ns;
  181. if (((table->data == &ns->ids[IPC_SEM_IDS].next_id) ||
  182. (table->data == &ns->ids[IPC_MSG_IDS].next_id) ||
  183. (table->data == &ns->ids[IPC_SHM_IDS].next_id)) &&
  184. checkpoint_restore_ns_capable(ns->user_ns))
  185. mode = 0666;
  186. #endif
  187. return mode;
  188. }
  189. static struct ctl_table_root set_root = {
  190. .lookup = set_lookup,
  191. .permissions = ipc_permissions,
  192. };
  193. bool setup_ipc_sysctls(struct ipc_namespace *ns)
  194. {
  195. struct ctl_table *tbl;
  196. setup_sysctl_set(&ns->ipc_set, &set_root, set_is_seen);
  197. tbl = kmemdup(ipc_sysctls, sizeof(ipc_sysctls), GFP_KERNEL);
  198. if (tbl) {
  199. int i;
  200. for (i = 0; i < ARRAY_SIZE(ipc_sysctls); i++) {
  201. if (tbl[i].data == &init_ipc_ns.shm_ctlmax)
  202. tbl[i].data = &ns->shm_ctlmax;
  203. else if (tbl[i].data == &init_ipc_ns.shm_ctlall)
  204. tbl[i].data = &ns->shm_ctlall;
  205. else if (tbl[i].data == &init_ipc_ns.shm_ctlmni)
  206. tbl[i].data = &ns->shm_ctlmni;
  207. else if (tbl[i].data == &init_ipc_ns.shm_rmid_forced)
  208. tbl[i].data = &ns->shm_rmid_forced;
  209. else if (tbl[i].data == &init_ipc_ns.msg_ctlmax)
  210. tbl[i].data = &ns->msg_ctlmax;
  211. else if (tbl[i].data == &init_ipc_ns.msg_ctlmni)
  212. tbl[i].data = &ns->msg_ctlmni;
  213. else if (tbl[i].data == &init_ipc_ns.msg_ctlmnb)
  214. tbl[i].data = &ns->msg_ctlmnb;
  215. else if (tbl[i].data == &init_ipc_ns.sem_ctls)
  216. tbl[i].data = &ns->sem_ctls;
  217. #ifdef CONFIG_CHECKPOINT_RESTORE
  218. else if (tbl[i].data == &init_ipc_ns.ids[IPC_SEM_IDS].next_id)
  219. tbl[i].data = &ns->ids[IPC_SEM_IDS].next_id;
  220. else if (tbl[i].data == &init_ipc_ns.ids[IPC_MSG_IDS].next_id)
  221. tbl[i].data = &ns->ids[IPC_MSG_IDS].next_id;
  222. else if (tbl[i].data == &init_ipc_ns.ids[IPC_SHM_IDS].next_id)
  223. tbl[i].data = &ns->ids[IPC_SHM_IDS].next_id;
  224. #endif
  225. else
  226. tbl[i].data = NULL;
  227. }
  228. ns->ipc_sysctls = __register_sysctl_table(&ns->ipc_set, "kernel", tbl);
  229. }
  230. if (!ns->ipc_sysctls) {
  231. kfree(tbl);
  232. retire_sysctl_set(&ns->ipc_set);
  233. return false;
  234. }
  235. return true;
  236. }
  237. void retire_ipc_sysctls(struct ipc_namespace *ns)
  238. {
  239. struct ctl_table *tbl;
  240. tbl = ns->ipc_sysctls->ctl_table_arg;
  241. unregister_sysctl_table(ns->ipc_sysctls);
  242. retire_sysctl_set(&ns->ipc_set);
  243. kfree(tbl);
  244. }
  245. static int __init ipc_sysctl_init(void)
  246. {
  247. if (!setup_ipc_sysctls(&init_ipc_ns)) {
  248. pr_warn("ipc sysctl registration failed\n");
  249. return -ENOMEM;
  250. }
  251. return 0;
  252. }
  253. device_initcall(ipc_sysctl_init);
  254. static int __init ipc_mni_extend(char *str)
  255. {
  256. ipc_mni = IPCMNI_EXTEND;
  257. ipc_mni_shift = IPCMNI_EXTEND_SHIFT;
  258. ipc_min_cycle = IPCMNI_EXTEND_MIN_CYCLE;
  259. pr_info("IPCMNI extended to %d.\n", ipc_mni);
  260. return 0;
  261. }
  262. early_param("ipcmni_extend", ipc_mni_extend);