xref: /openbmc/linux/fs/proc/fd.c (revision b24413180f5600bcb3bb70fbed5cf186b60864bd)
1*b2441318SGreg Kroah-Hartman // SPDX-License-Identifier: GPL-2.0
23f07c014SIngo Molnar #include <linux/sched/signal.h>
3faf60af1SCyrill Gorcunov #include <linux/errno.h>
4faf60af1SCyrill Gorcunov #include <linux/dcache.h>
5faf60af1SCyrill Gorcunov #include <linux/path.h>
6faf60af1SCyrill Gorcunov #include <linux/fdtable.h>
7faf60af1SCyrill Gorcunov #include <linux/namei.h>
8faf60af1SCyrill Gorcunov #include <linux/pid.h>
9faf60af1SCyrill Gorcunov #include <linux/security.h>
10ddd3e077SCyrill Gorcunov #include <linux/file.h>
11ddd3e077SCyrill Gorcunov #include <linux/seq_file.h>
126c8c9031SAndrey Vagin #include <linux/fs.h>
13faf60af1SCyrill Gorcunov 
14faf60af1SCyrill Gorcunov #include <linux/proc_fs.h>
15faf60af1SCyrill Gorcunov 
1649d063cbSAndrey Vagin #include "../mount.h"
17faf60af1SCyrill Gorcunov #include "internal.h"
18faf60af1SCyrill Gorcunov #include "fd.h"
19faf60af1SCyrill Gorcunov 
20ddd3e077SCyrill Gorcunov static int seq_show(struct seq_file *m, void *v)
21faf60af1SCyrill Gorcunov {
22faf60af1SCyrill Gorcunov 	struct files_struct *files = NULL;
23ddd3e077SCyrill Gorcunov 	int f_flags = 0, ret = -ENOENT;
24ddd3e077SCyrill Gorcunov 	struct file *file = NULL;
25ddd3e077SCyrill Gorcunov 	struct task_struct *task;
26faf60af1SCyrill Gorcunov 
27ddd3e077SCyrill Gorcunov 	task = get_proc_task(m->private);
28ddd3e077SCyrill Gorcunov 	if (!task)
29ddd3e077SCyrill Gorcunov 		return -ENOENT;
30ddd3e077SCyrill Gorcunov 
31faf60af1SCyrill Gorcunov 	files = get_files_struct(task);
32faf60af1SCyrill Gorcunov 	put_task_struct(task);
33ddd3e077SCyrill Gorcunov 
34faf60af1SCyrill Gorcunov 	if (files) {
35771187d6SAlexey Dobriyan 		unsigned int fd = proc_fd(m->private);
36ddd3e077SCyrill Gorcunov 
37faf60af1SCyrill Gorcunov 		spin_lock(&files->file_lock);
38faf60af1SCyrill Gorcunov 		file = fcheck_files(files, fd);
39faf60af1SCyrill Gorcunov 		if (file) {
40ddd3e077SCyrill Gorcunov 			struct fdtable *fdt = files_fdtable(files);
41faf60af1SCyrill Gorcunov 
42c6f3d811SAl Viro 			f_flags = file->f_flags;
43faf60af1SCyrill Gorcunov 			if (close_on_exec(fd, fdt))
44faf60af1SCyrill Gorcunov 				f_flags |= O_CLOEXEC;
45faf60af1SCyrill Gorcunov 
46ddd3e077SCyrill Gorcunov 			get_file(file);
47ddd3e077SCyrill Gorcunov 			ret = 0;
48faf60af1SCyrill Gorcunov 		}
49faf60af1SCyrill Gorcunov 		spin_unlock(&files->file_lock);
50faf60af1SCyrill Gorcunov 		put_files_struct(files);
51faf60af1SCyrill Gorcunov 	}
52ddd3e077SCyrill Gorcunov 
536c8c9031SAndrey Vagin 	if (ret)
546c8c9031SAndrey Vagin 		return ret;
556c8c9031SAndrey Vagin 
5649d063cbSAndrey Vagin 	seq_printf(m, "pos:\t%lli\nflags:\t0%o\nmnt_id:\t%i\n",
5749d063cbSAndrey Vagin 		   (long long)file->f_pos, f_flags,
5849d063cbSAndrey Vagin 		   real_mount(file->f_path.mnt)->mnt_id);
596c8c9031SAndrey Vagin 
606c8c9031SAndrey Vagin 	show_fd_locks(m, file, files);
616c8c9031SAndrey Vagin 	if (seq_has_overflowed(m))
626c8c9031SAndrey Vagin 		goto out;
636c8c9031SAndrey Vagin 
6455985dd7SCyrill Gorcunov 	if (file->f_op->show_fdinfo)
65a3816ab0SJoe Perches 		file->f_op->show_fdinfo(m, file);
66faf60af1SCyrill Gorcunov 
676c8c9031SAndrey Vagin out:
686c8c9031SAndrey Vagin 	fput(file);
696c8c9031SAndrey Vagin 	return 0;
70ddd3e077SCyrill Gorcunov }
71ddd3e077SCyrill Gorcunov 
72ddd3e077SCyrill Gorcunov static int seq_fdinfo_open(struct inode *inode, struct file *file)
73ddd3e077SCyrill Gorcunov {
74ddd3e077SCyrill Gorcunov 	return single_open(file, seq_show, inode);
75ddd3e077SCyrill Gorcunov }
76ddd3e077SCyrill Gorcunov 
77ddd3e077SCyrill Gorcunov static const struct file_operations proc_fdinfo_file_operations = {
78ddd3e077SCyrill Gorcunov 	.open		= seq_fdinfo_open,
79ddd3e077SCyrill Gorcunov 	.read		= seq_read,
80ddd3e077SCyrill Gorcunov 	.llseek		= seq_lseek,
81ddd3e077SCyrill Gorcunov 	.release	= single_release,
82ddd3e077SCyrill Gorcunov };
83ddd3e077SCyrill Gorcunov 
84faf60af1SCyrill Gorcunov static int tid_fd_revalidate(struct dentry *dentry, unsigned int flags)
85faf60af1SCyrill Gorcunov {
86faf60af1SCyrill Gorcunov 	struct files_struct *files;
87faf60af1SCyrill Gorcunov 	struct task_struct *task;
88faf60af1SCyrill Gorcunov 	struct inode *inode;
89771187d6SAlexey Dobriyan 	unsigned int fd;
90faf60af1SCyrill Gorcunov 
91faf60af1SCyrill Gorcunov 	if (flags & LOOKUP_RCU)
92faf60af1SCyrill Gorcunov 		return -ECHILD;
93faf60af1SCyrill Gorcunov 
942b0143b5SDavid Howells 	inode = d_inode(dentry);
95faf60af1SCyrill Gorcunov 	task = get_proc_task(inode);
96faf60af1SCyrill Gorcunov 	fd = proc_fd(inode);
97faf60af1SCyrill Gorcunov 
98faf60af1SCyrill Gorcunov 	if (task) {
99faf60af1SCyrill Gorcunov 		files = get_files_struct(task);
100faf60af1SCyrill Gorcunov 		if (files) {
101faf60af1SCyrill Gorcunov 			struct file *file;
102faf60af1SCyrill Gorcunov 
103faf60af1SCyrill Gorcunov 			rcu_read_lock();
104faf60af1SCyrill Gorcunov 			file = fcheck_files(files, fd);
105faf60af1SCyrill Gorcunov 			if (file) {
106faf60af1SCyrill Gorcunov 				unsigned f_mode = file->f_mode;
107faf60af1SCyrill Gorcunov 
108faf60af1SCyrill Gorcunov 				rcu_read_unlock();
109faf60af1SCyrill Gorcunov 				put_files_struct(files);
110faf60af1SCyrill Gorcunov 
11168eb94f1SEric W. Biederman 				task_dump_owner(task, 0, &inode->i_uid, &inode->i_gid);
112faf60af1SCyrill Gorcunov 
113faf60af1SCyrill Gorcunov 				if (S_ISLNK(inode->i_mode)) {
114faf60af1SCyrill Gorcunov 					unsigned i_mode = S_IFLNK;
115faf60af1SCyrill Gorcunov 					if (f_mode & FMODE_READ)
116faf60af1SCyrill Gorcunov 						i_mode |= S_IRUSR | S_IXUSR;
117faf60af1SCyrill Gorcunov 					if (f_mode & FMODE_WRITE)
118faf60af1SCyrill Gorcunov 						i_mode |= S_IWUSR | S_IXUSR;
119faf60af1SCyrill Gorcunov 					inode->i_mode = i_mode;
120faf60af1SCyrill Gorcunov 				}
121faf60af1SCyrill Gorcunov 
122faf60af1SCyrill Gorcunov 				security_task_to_inode(task, inode);
123faf60af1SCyrill Gorcunov 				put_task_struct(task);
124faf60af1SCyrill Gorcunov 				return 1;
125faf60af1SCyrill Gorcunov 			}
126faf60af1SCyrill Gorcunov 			rcu_read_unlock();
127faf60af1SCyrill Gorcunov 			put_files_struct(files);
128faf60af1SCyrill Gorcunov 		}
129faf60af1SCyrill Gorcunov 		put_task_struct(task);
130faf60af1SCyrill Gorcunov 	}
131faf60af1SCyrill Gorcunov 	return 0;
132faf60af1SCyrill Gorcunov }
133faf60af1SCyrill Gorcunov 
134faf60af1SCyrill Gorcunov static const struct dentry_operations tid_fd_dentry_operations = {
135faf60af1SCyrill Gorcunov 	.d_revalidate	= tid_fd_revalidate,
136faf60af1SCyrill Gorcunov 	.d_delete	= pid_delete_dentry,
137faf60af1SCyrill Gorcunov };
138faf60af1SCyrill Gorcunov 
139faf60af1SCyrill Gorcunov static int proc_fd_link(struct dentry *dentry, struct path *path)
140faf60af1SCyrill Gorcunov {
141ddd3e077SCyrill Gorcunov 	struct files_struct *files = NULL;
142ddd3e077SCyrill Gorcunov 	struct task_struct *task;
143ddd3e077SCyrill Gorcunov 	int ret = -ENOENT;
144ddd3e077SCyrill Gorcunov 
1452b0143b5SDavid Howells 	task = get_proc_task(d_inode(dentry));
146ddd3e077SCyrill Gorcunov 	if (task) {
147ddd3e077SCyrill Gorcunov 		files = get_files_struct(task);
148ddd3e077SCyrill Gorcunov 		put_task_struct(task);
149ddd3e077SCyrill Gorcunov 	}
150ddd3e077SCyrill Gorcunov 
151ddd3e077SCyrill Gorcunov 	if (files) {
152771187d6SAlexey Dobriyan 		unsigned int fd = proc_fd(d_inode(dentry));
153ddd3e077SCyrill Gorcunov 		struct file *fd_file;
154ddd3e077SCyrill Gorcunov 
155ddd3e077SCyrill Gorcunov 		spin_lock(&files->file_lock);
156ddd3e077SCyrill Gorcunov 		fd_file = fcheck_files(files, fd);
157ddd3e077SCyrill Gorcunov 		if (fd_file) {
158ddd3e077SCyrill Gorcunov 			*path = fd_file->f_path;
159ddd3e077SCyrill Gorcunov 			path_get(&fd_file->f_path);
160ddd3e077SCyrill Gorcunov 			ret = 0;
161ddd3e077SCyrill Gorcunov 		}
162ddd3e077SCyrill Gorcunov 		spin_unlock(&files->file_lock);
163ddd3e077SCyrill Gorcunov 		put_files_struct(files);
164ddd3e077SCyrill Gorcunov 	}
165ddd3e077SCyrill Gorcunov 
166ddd3e077SCyrill Gorcunov 	return ret;
167faf60af1SCyrill Gorcunov }
168faf60af1SCyrill Gorcunov 
169c52a47acSAl Viro static int
170faf60af1SCyrill Gorcunov proc_fd_instantiate(struct inode *dir, struct dentry *dentry,
171faf60af1SCyrill Gorcunov 		    struct task_struct *task, const void *ptr)
172faf60af1SCyrill Gorcunov {
173faf60af1SCyrill Gorcunov 	unsigned fd = (unsigned long)ptr;
174faf60af1SCyrill Gorcunov 	struct proc_inode *ei;
175faf60af1SCyrill Gorcunov 	struct inode *inode;
176faf60af1SCyrill Gorcunov 
177db978da8SAndreas Gruenbacher 	inode = proc_pid_make_inode(dir->i_sb, task, S_IFLNK);
178faf60af1SCyrill Gorcunov 	if (!inode)
179faf60af1SCyrill Gorcunov 		goto out;
180faf60af1SCyrill Gorcunov 
181faf60af1SCyrill Gorcunov 	ei = PROC_I(inode);
182faf60af1SCyrill Gorcunov 	ei->fd = fd;
183faf60af1SCyrill Gorcunov 
184faf60af1SCyrill Gorcunov 	inode->i_op = &proc_pid_link_inode_operations;
185faf60af1SCyrill Gorcunov 	inode->i_size = 64;
186faf60af1SCyrill Gorcunov 
187faf60af1SCyrill Gorcunov 	ei->op.proc_get_link = proc_fd_link;
188faf60af1SCyrill Gorcunov 
189faf60af1SCyrill Gorcunov 	d_set_d_op(dentry, &tid_fd_dentry_operations);
190faf60af1SCyrill Gorcunov 	d_add(dentry, inode);
191faf60af1SCyrill Gorcunov 
192faf60af1SCyrill Gorcunov 	/* Close the race of the process dying before we return the dentry */
193faf60af1SCyrill Gorcunov 	if (tid_fd_revalidate(dentry, 0))
194c52a47acSAl Viro 		return 0;
195faf60af1SCyrill Gorcunov  out:
196c52a47acSAl Viro 	return -ENOENT;
197faf60af1SCyrill Gorcunov }
198faf60af1SCyrill Gorcunov 
199faf60af1SCyrill Gorcunov static struct dentry *proc_lookupfd_common(struct inode *dir,
200faf60af1SCyrill Gorcunov 					   struct dentry *dentry,
201faf60af1SCyrill Gorcunov 					   instantiate_t instantiate)
202faf60af1SCyrill Gorcunov {
203faf60af1SCyrill Gorcunov 	struct task_struct *task = get_proc_task(dir);
204c52a47acSAl Viro 	int result = -ENOENT;
205dbcdb504SAlexey Dobriyan 	unsigned fd = name_to_int(&dentry->d_name);
206faf60af1SCyrill Gorcunov 
207faf60af1SCyrill Gorcunov 	if (!task)
208faf60af1SCyrill Gorcunov 		goto out_no_task;
209faf60af1SCyrill Gorcunov 	if (fd == ~0U)
210faf60af1SCyrill Gorcunov 		goto out;
211faf60af1SCyrill Gorcunov 
212faf60af1SCyrill Gorcunov 	result = instantiate(dir, dentry, task, (void *)(unsigned long)fd);
213faf60af1SCyrill Gorcunov out:
214faf60af1SCyrill Gorcunov 	put_task_struct(task);
215faf60af1SCyrill Gorcunov out_no_task:
216c52a47acSAl Viro 	return ERR_PTR(result);
217faf60af1SCyrill Gorcunov }
218faf60af1SCyrill Gorcunov 
219f0c3b509SAl Viro static int proc_readfd_common(struct file *file, struct dir_context *ctx,
220f0c3b509SAl Viro 			      instantiate_t instantiate)
221faf60af1SCyrill Gorcunov {
222f0c3b509SAl Viro 	struct task_struct *p = get_proc_task(file_inode(file));
223faf60af1SCyrill Gorcunov 	struct files_struct *files;
224f0c3b509SAl Viro 	unsigned int fd;
225faf60af1SCyrill Gorcunov 
226faf60af1SCyrill Gorcunov 	if (!p)
227f0c3b509SAl Viro 		return -ENOENT;
228faf60af1SCyrill Gorcunov 
229f0c3b509SAl Viro 	if (!dir_emit_dots(file, ctx))
230faf60af1SCyrill Gorcunov 		goto out;
231faf60af1SCyrill Gorcunov 	files = get_files_struct(p);
232faf60af1SCyrill Gorcunov 	if (!files)
233faf60af1SCyrill Gorcunov 		goto out;
234f0c3b509SAl Viro 
235faf60af1SCyrill Gorcunov 	rcu_read_lock();
236f0c3b509SAl Viro 	for (fd = ctx->pos - 2;
237faf60af1SCyrill Gorcunov 	     fd < files_fdtable(files)->max_fds;
238f0c3b509SAl Viro 	     fd++, ctx->pos++) {
239faf60af1SCyrill Gorcunov 		char name[PROC_NUMBUF];
240faf60af1SCyrill Gorcunov 		int len;
241faf60af1SCyrill Gorcunov 
242faf60af1SCyrill Gorcunov 		if (!fcheck_files(files, fd))
243faf60af1SCyrill Gorcunov 			continue;
244faf60af1SCyrill Gorcunov 		rcu_read_unlock();
245faf60af1SCyrill Gorcunov 
246771187d6SAlexey Dobriyan 		len = snprintf(name, sizeof(name), "%u", fd);
247f0c3b509SAl Viro 		if (!proc_fill_cache(file, ctx,
248faf60af1SCyrill Gorcunov 				     name, len, instantiate, p,
249f0c3b509SAl Viro 				     (void *)(unsigned long)fd))
250faf60af1SCyrill Gorcunov 			goto out_fd_loop;
2513cc4a84eSEric Dumazet 		cond_resched();
252faf60af1SCyrill Gorcunov 		rcu_read_lock();
253faf60af1SCyrill Gorcunov 	}
254faf60af1SCyrill Gorcunov 	rcu_read_unlock();
255faf60af1SCyrill Gorcunov out_fd_loop:
256faf60af1SCyrill Gorcunov 	put_files_struct(files);
257faf60af1SCyrill Gorcunov out:
258faf60af1SCyrill Gorcunov 	put_task_struct(p);
259f0c3b509SAl Viro 	return 0;
260faf60af1SCyrill Gorcunov }
261faf60af1SCyrill Gorcunov 
262f0c3b509SAl Viro static int proc_readfd(struct file *file, struct dir_context *ctx)
263faf60af1SCyrill Gorcunov {
264f0c3b509SAl Viro 	return proc_readfd_common(file, ctx, proc_fd_instantiate);
265faf60af1SCyrill Gorcunov }
266faf60af1SCyrill Gorcunov 
267faf60af1SCyrill Gorcunov const struct file_operations proc_fd_operations = {
268faf60af1SCyrill Gorcunov 	.read		= generic_read_dir,
269f50752eaSAl Viro 	.iterate_shared	= proc_readfd,
270f50752eaSAl Viro 	.llseek		= generic_file_llseek,
271faf60af1SCyrill Gorcunov };
272faf60af1SCyrill Gorcunov 
273faf60af1SCyrill Gorcunov static struct dentry *proc_lookupfd(struct inode *dir, struct dentry *dentry,
274faf60af1SCyrill Gorcunov 				    unsigned int flags)
275faf60af1SCyrill Gorcunov {
276faf60af1SCyrill Gorcunov 	return proc_lookupfd_common(dir, dentry, proc_fd_instantiate);
277faf60af1SCyrill Gorcunov }
278faf60af1SCyrill Gorcunov 
279faf60af1SCyrill Gorcunov /*
280faf60af1SCyrill Gorcunov  * /proc/pid/fd needs a special permission handler so that a process can still
281faf60af1SCyrill Gorcunov  * access /proc/self/fd after it has executed a setuid().
282faf60af1SCyrill Gorcunov  */
283faf60af1SCyrill Gorcunov int proc_fd_permission(struct inode *inode, int mask)
284faf60af1SCyrill Gorcunov {
28554708d28SOleg Nesterov 	struct task_struct *p;
28654708d28SOleg Nesterov 	int rv;
28754708d28SOleg Nesterov 
28854708d28SOleg Nesterov 	rv = generic_permission(inode, mask);
289faf60af1SCyrill Gorcunov 	if (rv == 0)
29054708d28SOleg Nesterov 		return rv;
29154708d28SOleg Nesterov 
29254708d28SOleg Nesterov 	rcu_read_lock();
29354708d28SOleg Nesterov 	p = pid_task(proc_pid(inode), PIDTYPE_PID);
29454708d28SOleg Nesterov 	if (p && same_thread_group(p, current))
295faf60af1SCyrill Gorcunov 		rv = 0;
29654708d28SOleg Nesterov 	rcu_read_unlock();
29754708d28SOleg Nesterov 
298faf60af1SCyrill Gorcunov 	return rv;
299faf60af1SCyrill Gorcunov }
300faf60af1SCyrill Gorcunov 
301faf60af1SCyrill Gorcunov const struct inode_operations proc_fd_inode_operations = {
302faf60af1SCyrill Gorcunov 	.lookup		= proc_lookupfd,
303faf60af1SCyrill Gorcunov 	.permission	= proc_fd_permission,
304faf60af1SCyrill Gorcunov 	.setattr	= proc_setattr,
305faf60af1SCyrill Gorcunov };
306faf60af1SCyrill Gorcunov 
307c52a47acSAl Viro static int
308faf60af1SCyrill Gorcunov proc_fdinfo_instantiate(struct inode *dir, struct dentry *dentry,
309faf60af1SCyrill Gorcunov 			struct task_struct *task, const void *ptr)
310faf60af1SCyrill Gorcunov {
311faf60af1SCyrill Gorcunov 	unsigned fd = (unsigned long)ptr;
312faf60af1SCyrill Gorcunov 	struct proc_inode *ei;
313faf60af1SCyrill Gorcunov 	struct inode *inode;
314faf60af1SCyrill Gorcunov 
315db978da8SAndreas Gruenbacher 	inode = proc_pid_make_inode(dir->i_sb, task, S_IFREG | S_IRUSR);
316faf60af1SCyrill Gorcunov 	if (!inode)
317faf60af1SCyrill Gorcunov 		goto out;
318faf60af1SCyrill Gorcunov 
319faf60af1SCyrill Gorcunov 	ei = PROC_I(inode);
320faf60af1SCyrill Gorcunov 	ei->fd = fd;
321faf60af1SCyrill Gorcunov 
322faf60af1SCyrill Gorcunov 	inode->i_fop = &proc_fdinfo_file_operations;
323faf60af1SCyrill Gorcunov 
324faf60af1SCyrill Gorcunov 	d_set_d_op(dentry, &tid_fd_dentry_operations);
325faf60af1SCyrill Gorcunov 	d_add(dentry, inode);
326faf60af1SCyrill Gorcunov 
327faf60af1SCyrill Gorcunov 	/* Close the race of the process dying before we return the dentry */
328faf60af1SCyrill Gorcunov 	if (tid_fd_revalidate(dentry, 0))
329c52a47acSAl Viro 		return 0;
330faf60af1SCyrill Gorcunov  out:
331c52a47acSAl Viro 	return -ENOENT;
332faf60af1SCyrill Gorcunov }
333faf60af1SCyrill Gorcunov 
334faf60af1SCyrill Gorcunov static struct dentry *
335faf60af1SCyrill Gorcunov proc_lookupfdinfo(struct inode *dir, struct dentry *dentry, unsigned int flags)
336faf60af1SCyrill Gorcunov {
337faf60af1SCyrill Gorcunov 	return proc_lookupfd_common(dir, dentry, proc_fdinfo_instantiate);
338faf60af1SCyrill Gorcunov }
339faf60af1SCyrill Gorcunov 
340f0c3b509SAl Viro static int proc_readfdinfo(struct file *file, struct dir_context *ctx)
341faf60af1SCyrill Gorcunov {
342f0c3b509SAl Viro 	return proc_readfd_common(file, ctx,
343faf60af1SCyrill Gorcunov 				  proc_fdinfo_instantiate);
344faf60af1SCyrill Gorcunov }
345faf60af1SCyrill Gorcunov 
346faf60af1SCyrill Gorcunov const struct inode_operations proc_fdinfo_inode_operations = {
347faf60af1SCyrill Gorcunov 	.lookup		= proc_lookupfdinfo,
348faf60af1SCyrill Gorcunov 	.setattr	= proc_setattr,
349faf60af1SCyrill Gorcunov };
350faf60af1SCyrill Gorcunov 
351faf60af1SCyrill Gorcunov const struct file_operations proc_fdinfo_operations = {
352faf60af1SCyrill Gorcunov 	.read		= generic_read_dir,
353f50752eaSAl Viro 	.iterate_shared	= proc_readfdinfo,
354f50752eaSAl Viro 	.llseek		= generic_file_llseek,
355faf60af1SCyrill Gorcunov };
356