xref: /openbmc/linux/net/ipv4/inet_diag.c (revision efe4208f47f907b86f528788da711e8ab9dea44d)
1a8c2190eSArnaldo Carvalho de Melo /*
2a8c2190eSArnaldo Carvalho de Melo  * inet_diag.c	Module for monitoring INET transport protocols sockets.
3a8c2190eSArnaldo Carvalho de Melo  *
4a8c2190eSArnaldo Carvalho de Melo  * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
5a8c2190eSArnaldo Carvalho de Melo  *
6a8c2190eSArnaldo Carvalho de Melo  *	This program is free software; you can redistribute it and/or
7a8c2190eSArnaldo Carvalho de Melo  *      modify it under the terms of the GNU General Public License
8a8c2190eSArnaldo Carvalho de Melo  *      as published by the Free Software Foundation; either version
9a8c2190eSArnaldo Carvalho de Melo  *      2 of the License, or (at your option) any later version.
10a8c2190eSArnaldo Carvalho de Melo  */
11a8c2190eSArnaldo Carvalho de Melo 
12172589ccSIlpo Järvinen #include <linux/kernel.h>
13a8c2190eSArnaldo Carvalho de Melo #include <linux/module.h>
14a8c2190eSArnaldo Carvalho de Melo #include <linux/types.h>
15a8c2190eSArnaldo Carvalho de Melo #include <linux/fcntl.h>
16a8c2190eSArnaldo Carvalho de Melo #include <linux/random.h>
175a0e3ad6STejun Heo #include <linux/slab.h>
18a8c2190eSArnaldo Carvalho de Melo #include <linux/cache.h>
19a8c2190eSArnaldo Carvalho de Melo #include <linux/init.h>
20a8c2190eSArnaldo Carvalho de Melo #include <linux/time.h>
21a8c2190eSArnaldo Carvalho de Melo 
22a8c2190eSArnaldo Carvalho de Melo #include <net/icmp.h>
23a8c2190eSArnaldo Carvalho de Melo #include <net/tcp.h>
24a8c2190eSArnaldo Carvalho de Melo #include <net/ipv6.h>
25a8c2190eSArnaldo Carvalho de Melo #include <net/inet_common.h>
26a8c2190eSArnaldo Carvalho de Melo #include <net/inet_connection_sock.h>
27a8c2190eSArnaldo Carvalho de Melo #include <net/inet_hashtables.h>
28a8c2190eSArnaldo Carvalho de Melo #include <net/inet_timewait_sock.h>
29a8c2190eSArnaldo Carvalho de Melo #include <net/inet6_hashtables.h>
30dc5fc579SArnaldo Carvalho de Melo #include <net/netlink.h>
31a8c2190eSArnaldo Carvalho de Melo 
32a8c2190eSArnaldo Carvalho de Melo #include <linux/inet.h>
33a8c2190eSArnaldo Carvalho de Melo #include <linux/stddef.h>
34a8c2190eSArnaldo Carvalho de Melo 
35a8c2190eSArnaldo Carvalho de Melo #include <linux/inet_diag.h>
36d366477aSPavel Emelyanov #include <linux/sock_diag.h>
37a8c2190eSArnaldo Carvalho de Melo 
38a8c2190eSArnaldo Carvalho de Melo static const struct inet_diag_handler **inet_diag_table;
39a8c2190eSArnaldo Carvalho de Melo 
40a8c2190eSArnaldo Carvalho de Melo struct inet_diag_entry {
419f855299SAl Viro 	__be32 *saddr;
429f855299SAl Viro 	__be32 *daddr;
43a8c2190eSArnaldo Carvalho de Melo 	u16 sport;
44a8c2190eSArnaldo Carvalho de Melo 	u16 dport;
45a8c2190eSArnaldo Carvalho de Melo 	u16 family;
46a8c2190eSArnaldo Carvalho de Melo 	u16 userlocks;
471c95df85SNeal Cardwell #if IS_ENABLED(CONFIG_IPV6)
481c95df85SNeal Cardwell 	struct in6_addr saddr_storage;	/* for IPv4-mapped-IPv6 addresses */
491c95df85SNeal Cardwell 	struct in6_addr daddr_storage;	/* for IPv4-mapped-IPv6 addresses */
501c95df85SNeal Cardwell #endif
51a8c2190eSArnaldo Carvalho de Melo };
52a8c2190eSArnaldo Carvalho de Melo 
53d523a328SHerbert Xu static DEFINE_MUTEX(inet_diag_table_mutex);
54d523a328SHerbert Xu 
55f13c95f0SPavel Emelyanov static const struct inet_diag_handler *inet_diag_lock_handler(int proto)
56d523a328SHerbert Xu {
57f13c95f0SPavel Emelyanov 	if (!inet_diag_table[proto])
58aec8dc62SPavel Emelyanov 		request_module("net-pf-%d-proto-%d-type-%d-%d", PF_NETLINK,
59aec8dc62SPavel Emelyanov 			       NETLINK_SOCK_DIAG, AF_INET, proto);
60d523a328SHerbert Xu 
61d523a328SHerbert Xu 	mutex_lock(&inet_diag_table_mutex);
62f13c95f0SPavel Emelyanov 	if (!inet_diag_table[proto])
63d523a328SHerbert Xu 		return ERR_PTR(-ENOENT);
64d523a328SHerbert Xu 
65f13c95f0SPavel Emelyanov 	return inet_diag_table[proto];
66d523a328SHerbert Xu }
67d523a328SHerbert Xu 
68d523a328SHerbert Xu static inline void inet_diag_unlock_handler(
69d523a328SHerbert Xu 	const struct inet_diag_handler *handler)
70d523a328SHerbert Xu {
71d523a328SHerbert Xu 	mutex_unlock(&inet_diag_table_mutex);
72d523a328SHerbert Xu }
73d523a328SHerbert Xu 
743c4d05c8SPavel Emelyanov int inet_sk_diag_fill(struct sock *sk, struct inet_connection_sock *icsk,
75c8991362SPavel Emelyanov 			      struct sk_buff *skb, struct inet_diag_req_v2 *req,
76d06ca956SEric W. Biederman 			      struct user_namespace *user_ns,
7715e47304SEric W. Biederman 			      u32 portid, u32 seq, u16 nlmsg_flags,
78a8c2190eSArnaldo Carvalho de Melo 			      const struct nlmsghdr *unlh)
79a8c2190eSArnaldo Carvalho de Melo {
80a8c2190eSArnaldo Carvalho de Melo 	const struct inet_sock *inet = inet_sk(sk);
81a8c2190eSArnaldo Carvalho de Melo 	struct inet_diag_msg *r;
82a8c2190eSArnaldo Carvalho de Melo 	struct nlmsghdr  *nlh;
836e277ed5SThomas Graf 	struct nlattr *attr;
84a8c2190eSArnaldo Carvalho de Melo 	void *info = NULL;
85a8c2190eSArnaldo Carvalho de Melo 	const struct inet_diag_handler *handler;
86a029fe26SPavel Emelyanov 	int ext = req->idiag_ext;
87a8c2190eSArnaldo Carvalho de Melo 
88a029fe26SPavel Emelyanov 	handler = inet_diag_table[req->sdiag_protocol];
89a8c2190eSArnaldo Carvalho de Melo 	BUG_ON(handler == NULL);
90a8c2190eSArnaldo Carvalho de Melo 
9115e47304SEric W. Biederman 	nlh = nlmsg_put(skb, portid, seq, unlh->nlmsg_type, sizeof(*r),
926e277ed5SThomas Graf 			nlmsg_flags);
936e277ed5SThomas Graf 	if (!nlh)
94d106352dSDavid S. Miller 		return -EMSGSIZE;
95a8c2190eSArnaldo Carvalho de Melo 
96d106352dSDavid S. Miller 	r = nlmsg_data(nlh);
97c7d58aabSArnaldo Carvalho de Melo 	BUG_ON(sk->sk_state == TCP_TIME_WAIT);
98c7d58aabSArnaldo Carvalho de Melo 
99a8c2190eSArnaldo Carvalho de Melo 	r->idiag_family = sk->sk_family;
100a8c2190eSArnaldo Carvalho de Melo 	r->idiag_state = sk->sk_state;
101a8c2190eSArnaldo Carvalho de Melo 	r->idiag_timer = 0;
102a8c2190eSArnaldo Carvalho de Melo 	r->idiag_retrans = 0;
103a8c2190eSArnaldo Carvalho de Melo 
104a8c2190eSArnaldo Carvalho de Melo 	r->id.idiag_if = sk->sk_bound_dev_if;
105f65c1b53SPavel Emelyanov 	sock_diag_save_cookie(sk, r->id.idiag_cookie);
106a8c2190eSArnaldo Carvalho de Melo 
107c720c7e8SEric Dumazet 	r->id.idiag_sport = inet->inet_sport;
108c720c7e8SEric Dumazet 	r->id.idiag_dport = inet->inet_dport;
109c720c7e8SEric Dumazet 	r->id.idiag_src[0] = inet->inet_rcv_saddr;
110c720c7e8SEric Dumazet 	r->id.idiag_dst[0] = inet->inet_daddr;
111a8c2190eSArnaldo Carvalho de Melo 
112e4e541a8SPavel Emelyanov 	if (nla_put_u8(skb, INET_DIAG_SHUTDOWN, sk->sk_shutdown))
113e4e541a8SPavel Emelyanov 		goto errout;
114e4e541a8SPavel Emelyanov 
115717b6d83SMaciej Żenczykowski 	/* IPv6 dual-stack sockets use inet->tos for IPv4 connections,
116717b6d83SMaciej Żenczykowski 	 * hence this needs to be included regardless of socket family.
117717b6d83SMaciej Żenczykowski 	 */
118717b6d83SMaciej Żenczykowski 	if (ext & (1 << (INET_DIAG_TOS - 1)))
1196e277ed5SThomas Graf 		if (nla_put_u8(skb, INET_DIAG_TOS, inet->tos) < 0)
1206e277ed5SThomas Graf 			goto errout;
121717b6d83SMaciej Żenczykowski 
122dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
123a8c2190eSArnaldo Carvalho de Melo 	if (r->idiag_family == AF_INET6) {
124a8c2190eSArnaldo Carvalho de Melo 
125*efe4208fSEric Dumazet 		*(struct in6_addr *)r->id.idiag_src = sk->sk_v6_rcv_saddr;
126*efe4208fSEric Dumazet 		*(struct in6_addr *)r->id.idiag_dst = sk->sk_v6_daddr;
1276e277ed5SThomas Graf 
12806236ac3SMaciej Żenczykowski 		if (ext & (1 << (INET_DIAG_TCLASS - 1)))
129*efe4208fSEric Dumazet 			if (nla_put_u8(skb, INET_DIAG_TCLASS,
130*efe4208fSEric Dumazet 				       inet6_sk(sk)->tclass) < 0)
1316e277ed5SThomas Graf 				goto errout;
132a8c2190eSArnaldo Carvalho de Melo 	}
133a8c2190eSArnaldo Carvalho de Melo #endif
134a8c2190eSArnaldo Carvalho de Melo 
135d06ca956SEric W. Biederman 	r->idiag_uid = from_kuid_munged(user_ns, sock_i_uid(sk));
1363c4d05c8SPavel Emelyanov 	r->idiag_inode = sock_i_ino(sk);
1373c4d05c8SPavel Emelyanov 
1386e277ed5SThomas Graf 	if (ext & (1 << (INET_DIAG_MEMINFO - 1))) {
1396e277ed5SThomas Graf 		struct inet_diag_meminfo minfo = {
1406e277ed5SThomas Graf 			.idiag_rmem = sk_rmem_alloc_get(sk),
1416e277ed5SThomas Graf 			.idiag_wmem = sk->sk_wmem_queued,
1426e277ed5SThomas Graf 			.idiag_fmem = sk->sk_forward_alloc,
1436e277ed5SThomas Graf 			.idiag_tmem = sk_wmem_alloc_get(sk),
1446e277ed5SThomas Graf 		};
1456e277ed5SThomas Graf 
1466e277ed5SThomas Graf 		if (nla_put(skb, INET_DIAG_MEMINFO, sizeof(minfo), &minfo) < 0)
1476e277ed5SThomas Graf 			goto errout;
1483c4d05c8SPavel Emelyanov 	}
1493c4d05c8SPavel Emelyanov 
150c0636faaSPavel Emelyanov 	if (ext & (1 << (INET_DIAG_SKMEMINFO - 1)))
151c0636faaSPavel Emelyanov 		if (sock_diag_put_meminfo(sk, skb, INET_DIAG_SKMEMINFO))
1526e277ed5SThomas Graf 			goto errout;
153c0636faaSPavel Emelyanov 
1543c4d05c8SPavel Emelyanov 	if (icsk == NULL) {
15562ad6fcdSShan Wei 		handler->idiag_get_info(sk, r, NULL);
1563c4d05c8SPavel Emelyanov 		goto out;
1573c4d05c8SPavel Emelyanov 	}
1583c4d05c8SPavel Emelyanov 
159172589ccSIlpo Järvinen #define EXPIRES_IN_MS(tmo)  DIV_ROUND_UP((tmo - jiffies) * 1000, HZ)
160a8c2190eSArnaldo Carvalho de Melo 
1616ba8a3b1SNandita Dukkipati 	if (icsk->icsk_pending == ICSK_TIME_RETRANS ||
1626ba8a3b1SNandita Dukkipati 	    icsk->icsk_pending == ICSK_TIME_EARLY_RETRANS ||
1636ba8a3b1SNandita Dukkipati 	    icsk->icsk_pending == ICSK_TIME_LOSS_PROBE) {
164a8c2190eSArnaldo Carvalho de Melo 		r->idiag_timer = 1;
165a8c2190eSArnaldo Carvalho de Melo 		r->idiag_retrans = icsk->icsk_retransmits;
166a8c2190eSArnaldo Carvalho de Melo 		r->idiag_expires = EXPIRES_IN_MS(icsk->icsk_timeout);
167a8c2190eSArnaldo Carvalho de Melo 	} else if (icsk->icsk_pending == ICSK_TIME_PROBE0) {
168a8c2190eSArnaldo Carvalho de Melo 		r->idiag_timer = 4;
169a8c2190eSArnaldo Carvalho de Melo 		r->idiag_retrans = icsk->icsk_probes_out;
170a8c2190eSArnaldo Carvalho de Melo 		r->idiag_expires = EXPIRES_IN_MS(icsk->icsk_timeout);
171a8c2190eSArnaldo Carvalho de Melo 	} else if (timer_pending(&sk->sk_timer)) {
172a8c2190eSArnaldo Carvalho de Melo 		r->idiag_timer = 2;
173a8c2190eSArnaldo Carvalho de Melo 		r->idiag_retrans = icsk->icsk_probes_out;
174a8c2190eSArnaldo Carvalho de Melo 		r->idiag_expires = EXPIRES_IN_MS(sk->sk_timer.expires);
175a8c2190eSArnaldo Carvalho de Melo 	} else {
176a8c2190eSArnaldo Carvalho de Melo 		r->idiag_timer = 0;
177a8c2190eSArnaldo Carvalho de Melo 		r->idiag_expires = 0;
178a8c2190eSArnaldo Carvalho de Melo 	}
179a8c2190eSArnaldo Carvalho de Melo #undef EXPIRES_IN_MS
180a8c2190eSArnaldo Carvalho de Melo 
1816e277ed5SThomas Graf 	if (ext & (1 << (INET_DIAG_INFO - 1))) {
1826e277ed5SThomas Graf 		attr = nla_reserve(skb, INET_DIAG_INFO,
1836e277ed5SThomas Graf 				   sizeof(struct tcp_info));
1846e277ed5SThomas Graf 		if (!attr)
1856e277ed5SThomas Graf 			goto errout;
186a8c2190eSArnaldo Carvalho de Melo 
1876e277ed5SThomas Graf 		info = nla_data(attr);
188a8c2190eSArnaldo Carvalho de Melo 	}
189a8c2190eSArnaldo Carvalho de Melo 
1906e277ed5SThomas Graf 	if ((ext & (1 << (INET_DIAG_CONG - 1))) && icsk->icsk_ca_ops)
1916e277ed5SThomas Graf 		if (nla_put_string(skb, INET_DIAG_CONG,
1926e277ed5SThomas Graf 				   icsk->icsk_ca_ops->name) < 0)
1936e277ed5SThomas Graf 			goto errout;
1946e277ed5SThomas Graf 
195a8c2190eSArnaldo Carvalho de Melo 	handler->idiag_get_info(sk, r, info);
196a8c2190eSArnaldo Carvalho de Melo 
197a8c2190eSArnaldo Carvalho de Melo 	if (sk->sk_state < TCP_TIME_WAIT &&
198a8c2190eSArnaldo Carvalho de Melo 	    icsk->icsk_ca_ops && icsk->icsk_ca_ops->get_info)
199a8c2190eSArnaldo Carvalho de Melo 		icsk->icsk_ca_ops->get_info(sk, ext, skb);
200a8c2190eSArnaldo Carvalho de Melo 
2013c4d05c8SPavel Emelyanov out:
2026e277ed5SThomas Graf 	return nlmsg_end(skb, nlh);
203a8c2190eSArnaldo Carvalho de Melo 
2046e277ed5SThomas Graf errout:
2056e277ed5SThomas Graf 	nlmsg_cancel(skb, nlh);
20626932566SPatrick McHardy 	return -EMSGSIZE;
207a8c2190eSArnaldo Carvalho de Melo }
2083c4d05c8SPavel Emelyanov EXPORT_SYMBOL_GPL(inet_sk_diag_fill);
2093c4d05c8SPavel Emelyanov 
2103c4d05c8SPavel Emelyanov static int inet_csk_diag_fill(struct sock *sk,
211c8991362SPavel Emelyanov 			      struct sk_buff *skb, struct inet_diag_req_v2 *req,
212d06ca956SEric W. Biederman 			      struct user_namespace *user_ns,
21315e47304SEric W. Biederman 			      u32 portid, u32 seq, u16 nlmsg_flags,
2143c4d05c8SPavel Emelyanov 			      const struct nlmsghdr *unlh)
2153c4d05c8SPavel Emelyanov {
2163c4d05c8SPavel Emelyanov 	return inet_sk_diag_fill(sk, inet_csk(sk),
21715e47304SEric W. Biederman 			skb, req, user_ns, portid, seq, nlmsg_flags, unlh);
2183c4d05c8SPavel Emelyanov }
219a8c2190eSArnaldo Carvalho de Melo 
220c7d58aabSArnaldo Carvalho de Melo static int inet_twsk_diag_fill(struct inet_timewait_sock *tw,
221c8991362SPavel Emelyanov 			       struct sk_buff *skb, struct inet_diag_req_v2 *req,
22215e47304SEric W. Biederman 			       u32 portid, u32 seq, u16 nlmsg_flags,
223c7d58aabSArnaldo Carvalho de Melo 			       const struct nlmsghdr *unlh)
224c7d58aabSArnaldo Carvalho de Melo {
22596f817feSEric Dumazet 	s32 tmo;
226c7d58aabSArnaldo Carvalho de Melo 	struct inet_diag_msg *r;
2276e277ed5SThomas Graf 	struct nlmsghdr *nlh;
228c7d58aabSArnaldo Carvalho de Melo 
22915e47304SEric W. Biederman 	nlh = nlmsg_put(skb, portid, seq, unlh->nlmsg_type, sizeof(*r),
2306e277ed5SThomas Graf 			nlmsg_flags);
2316e277ed5SThomas Graf 	if (!nlh)
232d106352dSDavid S. Miller 		return -EMSGSIZE;
233d106352dSDavid S. Miller 
234d106352dSDavid S. Miller 	r = nlmsg_data(nlh);
235c7d58aabSArnaldo Carvalho de Melo 	BUG_ON(tw->tw_state != TCP_TIME_WAIT);
236c7d58aabSArnaldo Carvalho de Melo 
23796f817feSEric Dumazet 	tmo = tw->tw_ttd - inet_tw_time_stamp();
238c7d58aabSArnaldo Carvalho de Melo 	if (tmo < 0)
239c7d58aabSArnaldo Carvalho de Melo 		tmo = 0;
240c7d58aabSArnaldo Carvalho de Melo 
241c7d58aabSArnaldo Carvalho de Melo 	r->idiag_family	      = tw->tw_family;
242c7d58aabSArnaldo Carvalho de Melo 	r->idiag_retrans      = 0;
243c7d58aabSArnaldo Carvalho de Melo 	r->id.idiag_if	      = tw->tw_bound_dev_if;
244f65c1b53SPavel Emelyanov 	sock_diag_save_cookie(tw, r->id.idiag_cookie);
245c7d58aabSArnaldo Carvalho de Melo 	r->id.idiag_sport     = tw->tw_sport;
246c7d58aabSArnaldo Carvalho de Melo 	r->id.idiag_dport     = tw->tw_dport;
247c7d58aabSArnaldo Carvalho de Melo 	r->id.idiag_src[0]    = tw->tw_rcv_saddr;
248c7d58aabSArnaldo Carvalho de Melo 	r->id.idiag_dst[0]    = tw->tw_daddr;
249c7d58aabSArnaldo Carvalho de Melo 	r->idiag_state	      = tw->tw_substate;
250c7d58aabSArnaldo Carvalho de Melo 	r->idiag_timer	      = 3;
25196f817feSEric Dumazet 	r->idiag_expires      = jiffies_to_msecs(tmo);
252c7d58aabSArnaldo Carvalho de Melo 	r->idiag_rqueue	      = 0;
253c7d58aabSArnaldo Carvalho de Melo 	r->idiag_wqueue	      = 0;
254c7d58aabSArnaldo Carvalho de Melo 	r->idiag_uid	      = 0;
255c7d58aabSArnaldo Carvalho de Melo 	r->idiag_inode	      = 0;
256dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
257c7d58aabSArnaldo Carvalho de Melo 	if (tw->tw_family == AF_INET6) {
258*efe4208fSEric Dumazet 		*(struct in6_addr *)r->id.idiag_src = tw->tw_v6_rcv_saddr;
259*efe4208fSEric Dumazet 		*(struct in6_addr *)r->id.idiag_dst = tw->tw_v6_daddr;
260c7d58aabSArnaldo Carvalho de Melo 	}
261c7d58aabSArnaldo Carvalho de Melo #endif
2626e277ed5SThomas Graf 
2636e277ed5SThomas Graf 	return nlmsg_end(skb, nlh);
264c7d58aabSArnaldo Carvalho de Melo }
265c7d58aabSArnaldo Carvalho de Melo 
266dff2c035SArnaldo Carvalho de Melo static int sk_diag_fill(struct sock *sk, struct sk_buff *skb,
267d06ca956SEric W. Biederman 			struct inet_diag_req_v2 *r,
268d06ca956SEric W. Biederman 			struct user_namespace *user_ns,
26915e47304SEric W. Biederman 			u32 portid, u32 seq, u16 nlmsg_flags,
270dff2c035SArnaldo Carvalho de Melo 			const struct nlmsghdr *unlh)
271dff2c035SArnaldo Carvalho de Melo {
272dff2c035SArnaldo Carvalho de Melo 	if (sk->sk_state == TCP_TIME_WAIT)
273*efe4208fSEric Dumazet 		return inet_twsk_diag_fill(inet_twsk(sk), skb, r, portid, seq,
274*efe4208fSEric Dumazet 					   nlmsg_flags, unlh);
275*efe4208fSEric Dumazet 
276*efe4208fSEric Dumazet 	return inet_csk_diag_fill(sk, skb, r, user_ns, portid, seq,
277*efe4208fSEric Dumazet 				  nlmsg_flags, unlh);
278dff2c035SArnaldo Carvalho de Melo }
279dff2c035SArnaldo Carvalho de Melo 
2801942c518SPavel Emelyanov int inet_diag_dump_one_icsk(struct inet_hashinfo *hashinfo, struct sk_buff *in_skb,
281c8991362SPavel Emelyanov 		const struct nlmsghdr *nlh, struct inet_diag_req_v2 *req)
282a8c2190eSArnaldo Carvalho de Melo {
283a8c2190eSArnaldo Carvalho de Melo 	int err;
284a8c2190eSArnaldo Carvalho de Melo 	struct sock *sk;
285a8c2190eSArnaldo Carvalho de Melo 	struct sk_buff *rep;
28651d7cccfSAndrey Vagin 	struct net *net = sock_net(in_skb->sk);
287a8c2190eSArnaldo Carvalho de Melo 
288d523a328SHerbert Xu 	err = -EINVAL;
289fe50ce28SPavel Emelyanov 	if (req->sdiag_family == AF_INET) {
29051d7cccfSAndrey Vagin 		sk = inet_lookup(net, hashinfo, req->id.idiag_dst[0],
291a8c2190eSArnaldo Carvalho de Melo 				 req->id.idiag_dport, req->id.idiag_src[0],
292a8c2190eSArnaldo Carvalho de Melo 				 req->id.idiag_sport, req->id.idiag_if);
293a8c2190eSArnaldo Carvalho de Melo 	}
294dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
295fe50ce28SPavel Emelyanov 	else if (req->sdiag_family == AF_INET6) {
29651d7cccfSAndrey Vagin 		sk = inet6_lookup(net, hashinfo,
297a8c2190eSArnaldo Carvalho de Melo 				  (struct in6_addr *)req->id.idiag_dst,
298a8c2190eSArnaldo Carvalho de Melo 				  req->id.idiag_dport,
299a8c2190eSArnaldo Carvalho de Melo 				  (struct in6_addr *)req->id.idiag_src,
300a8c2190eSArnaldo Carvalho de Melo 				  req->id.idiag_sport,
301a8c2190eSArnaldo Carvalho de Melo 				  req->id.idiag_if);
302a8c2190eSArnaldo Carvalho de Melo 	}
303a8c2190eSArnaldo Carvalho de Melo #endif
304a8c2190eSArnaldo Carvalho de Melo 	else {
305476f7dbfSPavel Emelyanov 		goto out_nosk;
306a8c2190eSArnaldo Carvalho de Melo 	}
307a8c2190eSArnaldo Carvalho de Melo 
308d523a328SHerbert Xu 	err = -ENOENT;
309a8c2190eSArnaldo Carvalho de Melo 	if (sk == NULL)
310476f7dbfSPavel Emelyanov 		goto out_nosk;
311a8c2190eSArnaldo Carvalho de Melo 
312f65c1b53SPavel Emelyanov 	err = sock_diag_check_cookie(sk, req->id.idiag_cookie);
313b005ab4eSPavel Emelyanov 	if (err)
314a8c2190eSArnaldo Carvalho de Melo 		goto out;
315a8c2190eSArnaldo Carvalho de Melo 
3166e277ed5SThomas Graf 	rep = nlmsg_new(sizeof(struct inet_diag_msg) +
317a8c2190eSArnaldo Carvalho de Melo 			sizeof(struct inet_diag_meminfo) +
3186e277ed5SThomas Graf 			sizeof(struct tcp_info) + 64, GFP_KERNEL);
3196e277ed5SThomas Graf 	if (!rep) {
3206e277ed5SThomas Graf 		err = -ENOMEM;
321a8c2190eSArnaldo Carvalho de Melo 		goto out;
3226e277ed5SThomas Graf 	}
323a8c2190eSArnaldo Carvalho de Melo 
324a029fe26SPavel Emelyanov 	err = sk_diag_fill(sk, rep, req,
325e32123e5SPatrick McHardy 			   sk_user_ns(NETLINK_CB(in_skb).sk),
32615e47304SEric W. Biederman 			   NETLINK_CB(in_skb).portid,
32726932566SPatrick McHardy 			   nlh->nlmsg_seq, 0, nlh);
32826932566SPatrick McHardy 	if (err < 0) {
32926932566SPatrick McHardy 		WARN_ON(err == -EMSGSIZE);
3306e277ed5SThomas Graf 		nlmsg_free(rep);
33126932566SPatrick McHardy 		goto out;
33226932566SPatrick McHardy 	}
33315e47304SEric W. Biederman 	err = netlink_unicast(net->diag_nlsk, rep, NETLINK_CB(in_skb).portid,
334a8c2190eSArnaldo Carvalho de Melo 			      MSG_DONTWAIT);
335a8c2190eSArnaldo Carvalho de Melo 	if (err > 0)
336a8c2190eSArnaldo Carvalho de Melo 		err = 0;
337a8c2190eSArnaldo Carvalho de Melo 
338a8c2190eSArnaldo Carvalho de Melo out:
339a8c2190eSArnaldo Carvalho de Melo 	if (sk) {
340a8c2190eSArnaldo Carvalho de Melo 		if (sk->sk_state == TCP_TIME_WAIT)
341a8c2190eSArnaldo Carvalho de Melo 			inet_twsk_put((struct inet_timewait_sock *)sk);
342a8c2190eSArnaldo Carvalho de Melo 		else
343a8c2190eSArnaldo Carvalho de Melo 			sock_put(sk);
344a8c2190eSArnaldo Carvalho de Melo 	}
345476f7dbfSPavel Emelyanov out_nosk:
346476f7dbfSPavel Emelyanov 	return err;
347476f7dbfSPavel Emelyanov }
3481942c518SPavel Emelyanov EXPORT_SYMBOL_GPL(inet_diag_dump_one_icsk);
349476f7dbfSPavel Emelyanov 
350476f7dbfSPavel Emelyanov static int inet_diag_get_exact(struct sk_buff *in_skb,
351476f7dbfSPavel Emelyanov 			       const struct nlmsghdr *nlh,
352c8991362SPavel Emelyanov 			       struct inet_diag_req_v2 *req)
353476f7dbfSPavel Emelyanov {
354476f7dbfSPavel Emelyanov 	const struct inet_diag_handler *handler;
355476f7dbfSPavel Emelyanov 	int err;
356476f7dbfSPavel Emelyanov 
357476f7dbfSPavel Emelyanov 	handler = inet_diag_lock_handler(req->sdiag_protocol);
358476f7dbfSPavel Emelyanov 	if (IS_ERR(handler))
359476f7dbfSPavel Emelyanov 		err = PTR_ERR(handler);
360476f7dbfSPavel Emelyanov 	else
3611942c518SPavel Emelyanov 		err = handler->dump_one(in_skb, nlh, req);
362d523a328SHerbert Xu 	inet_diag_unlock_handler(handler);
363476f7dbfSPavel Emelyanov 
364a8c2190eSArnaldo Carvalho de Melo 	return err;
365a8c2190eSArnaldo Carvalho de Melo }
366a8c2190eSArnaldo Carvalho de Melo 
3679f855299SAl Viro static int bitstring_match(const __be32 *a1, const __be32 *a2, int bits)
368a8c2190eSArnaldo Carvalho de Melo {
369a8c2190eSArnaldo Carvalho de Melo 	int words = bits >> 5;
370a8c2190eSArnaldo Carvalho de Melo 
371a8c2190eSArnaldo Carvalho de Melo 	bits &= 0x1f;
372a8c2190eSArnaldo Carvalho de Melo 
373a8c2190eSArnaldo Carvalho de Melo 	if (words) {
374a8c2190eSArnaldo Carvalho de Melo 		if (memcmp(a1, a2, words << 2))
375a8c2190eSArnaldo Carvalho de Melo 			return 0;
376a8c2190eSArnaldo Carvalho de Melo 	}
377a8c2190eSArnaldo Carvalho de Melo 	if (bits) {
3789f855299SAl Viro 		__be32 w1, w2;
3799f855299SAl Viro 		__be32 mask;
380a8c2190eSArnaldo Carvalho de Melo 
381a8c2190eSArnaldo Carvalho de Melo 		w1 = a1[words];
382a8c2190eSArnaldo Carvalho de Melo 		w2 = a2[words];
383a8c2190eSArnaldo Carvalho de Melo 
384a8c2190eSArnaldo Carvalho de Melo 		mask = htonl((0xffffffff) << (32 - bits));
385a8c2190eSArnaldo Carvalho de Melo 
386a8c2190eSArnaldo Carvalho de Melo 		if ((w1 ^ w2) & mask)
387a8c2190eSArnaldo Carvalho de Melo 			return 0;
388a8c2190eSArnaldo Carvalho de Melo 	}
389a8c2190eSArnaldo Carvalho de Melo 
390a8c2190eSArnaldo Carvalho de Melo 	return 1;
391a8c2190eSArnaldo Carvalho de Melo }
392a8c2190eSArnaldo Carvalho de Melo 
393a8c2190eSArnaldo Carvalho de Melo 
39487c22ea5SPavel Emelyanov static int inet_diag_bc_run(const struct nlattr *_bc,
395a8c2190eSArnaldo Carvalho de Melo 		const struct inet_diag_entry *entry)
396a8c2190eSArnaldo Carvalho de Melo {
39787c22ea5SPavel Emelyanov 	const void *bc = nla_data(_bc);
39887c22ea5SPavel Emelyanov 	int len = nla_len(_bc);
39987c22ea5SPavel Emelyanov 
400a8c2190eSArnaldo Carvalho de Melo 	while (len > 0) {
401a8c2190eSArnaldo Carvalho de Melo 		int yes = 1;
402a8c2190eSArnaldo Carvalho de Melo 		const struct inet_diag_bc_op *op = bc;
403a8c2190eSArnaldo Carvalho de Melo 
404a8c2190eSArnaldo Carvalho de Melo 		switch (op->code) {
405a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_NOP:
406a8c2190eSArnaldo Carvalho de Melo 			break;
407a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_JMP:
408a8c2190eSArnaldo Carvalho de Melo 			yes = 0;
409a8c2190eSArnaldo Carvalho de Melo 			break;
410a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_GE:
411a8c2190eSArnaldo Carvalho de Melo 			yes = entry->sport >= op[1].no;
412a8c2190eSArnaldo Carvalho de Melo 			break;
413a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_LE:
414b4ced2b7SRoel Kluin 			yes = entry->sport <= op[1].no;
415a8c2190eSArnaldo Carvalho de Melo 			break;
416a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_GE:
417a8c2190eSArnaldo Carvalho de Melo 			yes = entry->dport >= op[1].no;
418a8c2190eSArnaldo Carvalho de Melo 			break;
419a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_LE:
420a8c2190eSArnaldo Carvalho de Melo 			yes = entry->dport <= op[1].no;
421a8c2190eSArnaldo Carvalho de Melo 			break;
422a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_AUTO:
423a8c2190eSArnaldo Carvalho de Melo 			yes = !(entry->userlocks & SOCK_BINDPORT_LOCK);
424a8c2190eSArnaldo Carvalho de Melo 			break;
425a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_COND:
426a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_COND: {
427a8c2190eSArnaldo Carvalho de Melo 			struct inet_diag_hostcond *cond;
4289f855299SAl Viro 			__be32 *addr;
429a8c2190eSArnaldo Carvalho de Melo 
430a8c2190eSArnaldo Carvalho de Melo 			cond = (struct inet_diag_hostcond *)(op + 1);
431a8c2190eSArnaldo Carvalho de Melo 			if (cond->port != -1 &&
432a8c2190eSArnaldo Carvalho de Melo 			    cond->port != (op->code == INET_DIAG_BC_S_COND ?
433a8c2190eSArnaldo Carvalho de Melo 					     entry->sport : entry->dport)) {
434a8c2190eSArnaldo Carvalho de Melo 				yes = 0;
435a8c2190eSArnaldo Carvalho de Melo 				break;
436a8c2190eSArnaldo Carvalho de Melo 			}
437a8c2190eSArnaldo Carvalho de Melo 
438a8c2190eSArnaldo Carvalho de Melo 			if (op->code == INET_DIAG_BC_S_COND)
439a8c2190eSArnaldo Carvalho de Melo 				addr = entry->saddr;
440a8c2190eSArnaldo Carvalho de Melo 			else
441a8c2190eSArnaldo Carvalho de Melo 				addr = entry->daddr;
442a8c2190eSArnaldo Carvalho de Melo 
443f67caec9SNeal Cardwell 			if (cond->family != AF_UNSPEC &&
444f67caec9SNeal Cardwell 			    cond->family != entry->family) {
445a8c2190eSArnaldo Carvalho de Melo 				if (entry->family == AF_INET6 &&
446a8c2190eSArnaldo Carvalho de Melo 				    cond->family == AF_INET) {
447a8c2190eSArnaldo Carvalho de Melo 					if (addr[0] == 0 && addr[1] == 0 &&
448a8c2190eSArnaldo Carvalho de Melo 					    addr[2] == htonl(0xffff) &&
449f67caec9SNeal Cardwell 					    bitstring_match(addr + 3,
450f67caec9SNeal Cardwell 							    cond->addr,
451a8c2190eSArnaldo Carvalho de Melo 							    cond->prefix_len))
452a8c2190eSArnaldo Carvalho de Melo 						break;
453a8c2190eSArnaldo Carvalho de Melo 				}
454a8c2190eSArnaldo Carvalho de Melo 				yes = 0;
455a8c2190eSArnaldo Carvalho de Melo 				break;
456a8c2190eSArnaldo Carvalho de Melo 			}
457f67caec9SNeal Cardwell 
458f67caec9SNeal Cardwell 			if (cond->prefix_len == 0)
459f67caec9SNeal Cardwell 				break;
460f67caec9SNeal Cardwell 			if (bitstring_match(addr, cond->addr,
461f67caec9SNeal Cardwell 					    cond->prefix_len))
462f67caec9SNeal Cardwell 				break;
463f67caec9SNeal Cardwell 			yes = 0;
464f67caec9SNeal Cardwell 			break;
465f67caec9SNeal Cardwell 		}
466a8c2190eSArnaldo Carvalho de Melo 		}
467a8c2190eSArnaldo Carvalho de Melo 
468a8c2190eSArnaldo Carvalho de Melo 		if (yes) {
469a8c2190eSArnaldo Carvalho de Melo 			len -= op->yes;
470a8c2190eSArnaldo Carvalho de Melo 			bc += op->yes;
471a8c2190eSArnaldo Carvalho de Melo 		} else {
472a8c2190eSArnaldo Carvalho de Melo 			len -= op->no;
473a8c2190eSArnaldo Carvalho de Melo 			bc += op->no;
474a8c2190eSArnaldo Carvalho de Melo 		}
475a8c2190eSArnaldo Carvalho de Melo 	}
476a02cec21SEric Dumazet 	return len == 0;
477a8c2190eSArnaldo Carvalho de Melo }
478a8c2190eSArnaldo Carvalho de Melo 
4798d07d151SPavel Emelyanov int inet_diag_bc_sk(const struct nlattr *bc, struct sock *sk)
4808d07d151SPavel Emelyanov {
4818d07d151SPavel Emelyanov 	struct inet_diag_entry entry;
4828d07d151SPavel Emelyanov 	struct inet_sock *inet = inet_sk(sk);
4838d07d151SPavel Emelyanov 
4848d07d151SPavel Emelyanov 	if (bc == NULL)
4858d07d151SPavel Emelyanov 		return 1;
4868d07d151SPavel Emelyanov 
4878d07d151SPavel Emelyanov 	entry.family = sk->sk_family;
488dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
4898d07d151SPavel Emelyanov 	if (entry.family == AF_INET6) {
4908d07d151SPavel Emelyanov 
491*efe4208fSEric Dumazet 		entry.saddr = sk->sk_v6_rcv_saddr.s6_addr32;
492*efe4208fSEric Dumazet 		entry.daddr = sk->sk_v6_daddr.s6_addr32;
4938d07d151SPavel Emelyanov 	} else
4948d07d151SPavel Emelyanov #endif
4958d07d151SPavel Emelyanov 	{
4968d07d151SPavel Emelyanov 		entry.saddr = &inet->inet_rcv_saddr;
4978d07d151SPavel Emelyanov 		entry.daddr = &inet->inet_daddr;
4988d07d151SPavel Emelyanov 	}
4998d07d151SPavel Emelyanov 	entry.sport = inet->inet_num;
5008d07d151SPavel Emelyanov 	entry.dport = ntohs(inet->inet_dport);
5018d07d151SPavel Emelyanov 	entry.userlocks = sk->sk_userlocks;
5028d07d151SPavel Emelyanov 
5038d07d151SPavel Emelyanov 	return inet_diag_bc_run(bc, &entry);
5048d07d151SPavel Emelyanov }
5058d07d151SPavel Emelyanov EXPORT_SYMBOL_GPL(inet_diag_bc_sk);
5068d07d151SPavel Emelyanov 
507a8c2190eSArnaldo Carvalho de Melo static int valid_cc(const void *bc, int len, int cc)
508a8c2190eSArnaldo Carvalho de Melo {
509a8c2190eSArnaldo Carvalho de Melo 	while (len >= 0) {
510a8c2190eSArnaldo Carvalho de Melo 		const struct inet_diag_bc_op *op = bc;
511a8c2190eSArnaldo Carvalho de Melo 
512a8c2190eSArnaldo Carvalho de Melo 		if (cc > len)
513a8c2190eSArnaldo Carvalho de Melo 			return 0;
514a8c2190eSArnaldo Carvalho de Melo 		if (cc == len)
515a8c2190eSArnaldo Carvalho de Melo 			return 1;
516eeb14972SEric Dumazet 		if (op->yes < 4 || op->yes & 3)
517a8c2190eSArnaldo Carvalho de Melo 			return 0;
518a8c2190eSArnaldo Carvalho de Melo 		len -= op->yes;
519a8c2190eSArnaldo Carvalho de Melo 		bc  += op->yes;
520a8c2190eSArnaldo Carvalho de Melo 	}
521a8c2190eSArnaldo Carvalho de Melo 	return 0;
522a8c2190eSArnaldo Carvalho de Melo }
523a8c2190eSArnaldo Carvalho de Melo 
524405c0059SNeal Cardwell /* Validate an inet_diag_hostcond. */
525405c0059SNeal Cardwell static bool valid_hostcond(const struct inet_diag_bc_op *op, int len,
526405c0059SNeal Cardwell 			   int *min_len)
527405c0059SNeal Cardwell {
528405c0059SNeal Cardwell 	int addr_len;
529405c0059SNeal Cardwell 	struct inet_diag_hostcond *cond;
530405c0059SNeal Cardwell 
531405c0059SNeal Cardwell 	/* Check hostcond space. */
532405c0059SNeal Cardwell 	*min_len += sizeof(struct inet_diag_hostcond);
533405c0059SNeal Cardwell 	if (len < *min_len)
534405c0059SNeal Cardwell 		return false;
535405c0059SNeal Cardwell 	cond = (struct inet_diag_hostcond *)(op + 1);
536405c0059SNeal Cardwell 
537405c0059SNeal Cardwell 	/* Check address family and address length. */
538405c0059SNeal Cardwell 	switch (cond->family) {
539405c0059SNeal Cardwell 	case AF_UNSPEC:
540405c0059SNeal Cardwell 		addr_len = 0;
541405c0059SNeal Cardwell 		break;
542405c0059SNeal Cardwell 	case AF_INET:
543405c0059SNeal Cardwell 		addr_len = sizeof(struct in_addr);
544405c0059SNeal Cardwell 		break;
545405c0059SNeal Cardwell 	case AF_INET6:
546405c0059SNeal Cardwell 		addr_len = sizeof(struct in6_addr);
547405c0059SNeal Cardwell 		break;
548405c0059SNeal Cardwell 	default:
549405c0059SNeal Cardwell 		return false;
550405c0059SNeal Cardwell 	}
551405c0059SNeal Cardwell 	*min_len += addr_len;
552405c0059SNeal Cardwell 	if (len < *min_len)
553405c0059SNeal Cardwell 		return false;
554405c0059SNeal Cardwell 
555405c0059SNeal Cardwell 	/* Check prefix length (in bits) vs address length (in bytes). */
556405c0059SNeal Cardwell 	if (cond->prefix_len > 8 * addr_len)
557405c0059SNeal Cardwell 		return false;
558405c0059SNeal Cardwell 
559405c0059SNeal Cardwell 	return true;
560405c0059SNeal Cardwell }
561405c0059SNeal Cardwell 
5625e1f5420SNeal Cardwell /* Validate a port comparison operator. */
5635e1f5420SNeal Cardwell static inline bool valid_port_comparison(const struct inet_diag_bc_op *op,
5645e1f5420SNeal Cardwell 					 int len, int *min_len)
5655e1f5420SNeal Cardwell {
5665e1f5420SNeal Cardwell 	/* Port comparisons put the port in a follow-on inet_diag_bc_op. */
5675e1f5420SNeal Cardwell 	*min_len += sizeof(struct inet_diag_bc_op);
5685e1f5420SNeal Cardwell 	if (len < *min_len)
5695e1f5420SNeal Cardwell 		return false;
5705e1f5420SNeal Cardwell 	return true;
5715e1f5420SNeal Cardwell }
5725e1f5420SNeal Cardwell 
573a8c2190eSArnaldo Carvalho de Melo static int inet_diag_bc_audit(const void *bytecode, int bytecode_len)
574a8c2190eSArnaldo Carvalho de Melo {
575eeb14972SEric Dumazet 	const void *bc = bytecode;
576a8c2190eSArnaldo Carvalho de Melo 	int  len = bytecode_len;
577a8c2190eSArnaldo Carvalho de Melo 
578a8c2190eSArnaldo Carvalho de Melo 	while (len > 0) {
579eeb14972SEric Dumazet 		const struct inet_diag_bc_op *op = bc;
580405c0059SNeal Cardwell 		int min_len = sizeof(struct inet_diag_bc_op);
581a8c2190eSArnaldo Carvalho de Melo 
582a8c2190eSArnaldo Carvalho de Melo //printk("BC: %d %d %d {%d} / %d\n", op->code, op->yes, op->no, op[1].no, len);
583a8c2190eSArnaldo Carvalho de Melo 		switch (op->code) {
584a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_COND:
585a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_COND:
586405c0059SNeal Cardwell 			if (!valid_hostcond(bc, len, &min_len))
587405c0059SNeal Cardwell 				return -EINVAL;
5885e1f5420SNeal Cardwell 			break;
589a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_GE:
590a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_S_LE:
591a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_GE:
592a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_D_LE:
5935e1f5420SNeal Cardwell 			if (!valid_port_comparison(bc, len, &min_len))
594a8c2190eSArnaldo Carvalho de Melo 				return -EINVAL;
595a8c2190eSArnaldo Carvalho de Melo 			break;
5965e1f5420SNeal Cardwell 		case INET_DIAG_BC_AUTO:
5975e1f5420SNeal Cardwell 		case INET_DIAG_BC_JMP:
598a8c2190eSArnaldo Carvalho de Melo 		case INET_DIAG_BC_NOP:
599a8c2190eSArnaldo Carvalho de Melo 			break;
600a8c2190eSArnaldo Carvalho de Melo 		default:
601a8c2190eSArnaldo Carvalho de Melo 			return -EINVAL;
602a8c2190eSArnaldo Carvalho de Melo 		}
6035e1f5420SNeal Cardwell 
6045e1f5420SNeal Cardwell 		if (op->code != INET_DIAG_BC_NOP) {
6055e1f5420SNeal Cardwell 			if (op->no < min_len || op->no > len + 4 || op->no & 3)
6065e1f5420SNeal Cardwell 				return -EINVAL;
6075e1f5420SNeal Cardwell 			if (op->no < len &&
6085e1f5420SNeal Cardwell 			    !valid_cc(bytecode, bytecode_len, len - op->no))
6095e1f5420SNeal Cardwell 				return -EINVAL;
6105e1f5420SNeal Cardwell 		}
6115e1f5420SNeal Cardwell 
612405c0059SNeal Cardwell 		if (op->yes < min_len || op->yes > len + 4 || op->yes & 3)
613eeb14972SEric Dumazet 			return -EINVAL;
614a8c2190eSArnaldo Carvalho de Melo 		bc  += op->yes;
615a8c2190eSArnaldo Carvalho de Melo 		len -= op->yes;
616a8c2190eSArnaldo Carvalho de Melo 	}
617a8c2190eSArnaldo Carvalho de Melo 	return len == 0 ? 0 : -EINVAL;
618a8c2190eSArnaldo Carvalho de Melo }
619a8c2190eSArnaldo Carvalho de Melo 
620dff2c035SArnaldo Carvalho de Melo static int inet_csk_diag_dump(struct sock *sk,
621dff2c035SArnaldo Carvalho de Melo 			      struct sk_buff *skb,
62237f352b5SPavel Emelyanov 			      struct netlink_callback *cb,
623c8991362SPavel Emelyanov 			      struct inet_diag_req_v2 *r,
62437f352b5SPavel Emelyanov 			      const struct nlattr *bc)
625a8c2190eSArnaldo Carvalho de Melo {
6268d07d151SPavel Emelyanov 	if (!inet_diag_bc_sk(bc, sk))
627a8c2190eSArnaldo Carvalho de Melo 		return 0;
628a8c2190eSArnaldo Carvalho de Melo 
629a029fe26SPavel Emelyanov 	return inet_csk_diag_fill(sk, skb, r,
630e32123e5SPatrick McHardy 				  sk_user_ns(NETLINK_CB(cb->skb).sk),
63115e47304SEric W. Biederman 				  NETLINK_CB(cb->skb).portid,
632a8c2190eSArnaldo Carvalho de Melo 				  cb->nlh->nlmsg_seq, NLM_F_MULTI, cb->nlh);
633a8c2190eSArnaldo Carvalho de Melo }
634a8c2190eSArnaldo Carvalho de Melo 
63505dbc7b5SEric Dumazet static int inet_twsk_diag_dump(struct sock *sk,
636c7d58aabSArnaldo Carvalho de Melo 			       struct sk_buff *skb,
63737f352b5SPavel Emelyanov 			       struct netlink_callback *cb,
638c8991362SPavel Emelyanov 			       struct inet_diag_req_v2 *r,
63937f352b5SPavel Emelyanov 			       const struct nlattr *bc)
640c7d58aabSArnaldo Carvalho de Melo {
64105dbc7b5SEric Dumazet 	struct inet_timewait_sock *tw = inet_twsk(sk);
64205dbc7b5SEric Dumazet 
64337f352b5SPavel Emelyanov 	if (bc != NULL) {
644c7d58aabSArnaldo Carvalho de Melo 		struct inet_diag_entry entry;
645c7d58aabSArnaldo Carvalho de Melo 
646c7d58aabSArnaldo Carvalho de Melo 		entry.family = tw->tw_family;
647dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
648c7d58aabSArnaldo Carvalho de Melo 		if (tw->tw_family == AF_INET6) {
649*efe4208fSEric Dumazet 			entry.saddr = tw->tw_v6_rcv_saddr.s6_addr32;
650*efe4208fSEric Dumazet 			entry.daddr = tw->tw_v6_daddr.s6_addr32;
651c7d58aabSArnaldo Carvalho de Melo 		} else
652c7d58aabSArnaldo Carvalho de Melo #endif
653c7d58aabSArnaldo Carvalho de Melo 		{
654c7d58aabSArnaldo Carvalho de Melo 			entry.saddr = &tw->tw_rcv_saddr;
655c7d58aabSArnaldo Carvalho de Melo 			entry.daddr = &tw->tw_daddr;
656c7d58aabSArnaldo Carvalho de Melo 		}
657c7d58aabSArnaldo Carvalho de Melo 		entry.sport = tw->tw_num;
658c7d58aabSArnaldo Carvalho de Melo 		entry.dport = ntohs(tw->tw_dport);
659c7d58aabSArnaldo Carvalho de Melo 		entry.userlocks = 0;
660c7d58aabSArnaldo Carvalho de Melo 
66187c22ea5SPavel Emelyanov 		if (!inet_diag_bc_run(bc, &entry))
662c7d58aabSArnaldo Carvalho de Melo 			return 0;
663c7d58aabSArnaldo Carvalho de Melo 	}
664c7d58aabSArnaldo Carvalho de Melo 
665a029fe26SPavel Emelyanov 	return inet_twsk_diag_fill(tw, skb, r,
66615e47304SEric W. Biederman 				   NETLINK_CB(cb->skb).portid,
667c7d58aabSArnaldo Carvalho de Melo 				   cb->nlh->nlmsg_seq, NLM_F_MULTI, cb->nlh);
668c7d58aabSArnaldo Carvalho de Melo }
669c7d58aabSArnaldo Carvalho de Melo 
6701c95df85SNeal Cardwell /* Get the IPv4, IPv6, or IPv4-mapped-IPv6 local and remote addresses
6711c95df85SNeal Cardwell  * from a request_sock. For IPv4-mapped-IPv6 we must map IPv4 to IPv6.
6721c95df85SNeal Cardwell  */
6731c95df85SNeal Cardwell static inline void inet_diag_req_addrs(const struct sock *sk,
6741c95df85SNeal Cardwell 				       const struct request_sock *req,
6751c95df85SNeal Cardwell 				       struct inet_diag_entry *entry)
6761c95df85SNeal Cardwell {
6771c95df85SNeal Cardwell 	struct inet_request_sock *ireq = inet_rsk(req);
6781c95df85SNeal Cardwell 
6791c95df85SNeal Cardwell #if IS_ENABLED(CONFIG_IPV6)
6801c95df85SNeal Cardwell 	if (sk->sk_family == AF_INET6) {
6811c95df85SNeal Cardwell 		if (req->rsk_ops->family == AF_INET6) {
6821c95df85SNeal Cardwell 			entry->saddr = inet6_rsk(req)->loc_addr.s6_addr32;
6831c95df85SNeal Cardwell 			entry->daddr = inet6_rsk(req)->rmt_addr.s6_addr32;
6841c95df85SNeal Cardwell 		} else if (req->rsk_ops->family == AF_INET) {
6851c95df85SNeal Cardwell 			ipv6_addr_set_v4mapped(ireq->loc_addr,
6861c95df85SNeal Cardwell 					       &entry->saddr_storage);
6871c95df85SNeal Cardwell 			ipv6_addr_set_v4mapped(ireq->rmt_addr,
6881c95df85SNeal Cardwell 					       &entry->daddr_storage);
6891c95df85SNeal Cardwell 			entry->saddr = entry->saddr_storage.s6_addr32;
6901c95df85SNeal Cardwell 			entry->daddr = entry->daddr_storage.s6_addr32;
6911c95df85SNeal Cardwell 		}
6921c95df85SNeal Cardwell 	} else
6931c95df85SNeal Cardwell #endif
6941c95df85SNeal Cardwell 	{
6951c95df85SNeal Cardwell 		entry->saddr = &ireq->loc_addr;
6961c95df85SNeal Cardwell 		entry->daddr = &ireq->rmt_addr;
6971c95df85SNeal Cardwell 	}
6981c95df85SNeal Cardwell }
6991c95df85SNeal Cardwell 
700a8c2190eSArnaldo Carvalho de Melo static int inet_diag_fill_req(struct sk_buff *skb, struct sock *sk,
701d06ca956SEric W. Biederman 			      struct request_sock *req,
702d06ca956SEric W. Biederman 			      struct user_namespace *user_ns,
70315e47304SEric W. Biederman 			      u32 portid, u32 seq,
704a8c2190eSArnaldo Carvalho de Melo 			      const struct nlmsghdr *unlh)
705a8c2190eSArnaldo Carvalho de Melo {
706a8c2190eSArnaldo Carvalho de Melo 	const struct inet_request_sock *ireq = inet_rsk(req);
707a8c2190eSArnaldo Carvalho de Melo 	struct inet_sock *inet = inet_sk(sk);
708a8c2190eSArnaldo Carvalho de Melo 	struct inet_diag_msg *r;
709a8c2190eSArnaldo Carvalho de Melo 	struct nlmsghdr *nlh;
710a8c2190eSArnaldo Carvalho de Melo 	long tmo;
711a8c2190eSArnaldo Carvalho de Melo 
71215e47304SEric W. Biederman 	nlh = nlmsg_put(skb, portid, seq, unlh->nlmsg_type, sizeof(*r),
7136e277ed5SThomas Graf 			NLM_F_MULTI);
7146e277ed5SThomas Graf 	if (!nlh)
7156e277ed5SThomas Graf 		return -EMSGSIZE;
716a8c2190eSArnaldo Carvalho de Melo 
7176e277ed5SThomas Graf 	r = nlmsg_data(nlh);
718a8c2190eSArnaldo Carvalho de Melo 	r->idiag_family = sk->sk_family;
719a8c2190eSArnaldo Carvalho de Melo 	r->idiag_state = TCP_SYN_RECV;
720a8c2190eSArnaldo Carvalho de Melo 	r->idiag_timer = 1;
721e6c022a4SEric Dumazet 	r->idiag_retrans = req->num_retrans;
722a8c2190eSArnaldo Carvalho de Melo 
723a8c2190eSArnaldo Carvalho de Melo 	r->id.idiag_if = sk->sk_bound_dev_if;
724f65c1b53SPavel Emelyanov 	sock_diag_save_cookie(req, r->id.idiag_cookie);
725a8c2190eSArnaldo Carvalho de Melo 
726a8c2190eSArnaldo Carvalho de Melo 	tmo = req->expires - jiffies;
727a8c2190eSArnaldo Carvalho de Melo 	if (tmo < 0)
728a8c2190eSArnaldo Carvalho de Melo 		tmo = 0;
729a8c2190eSArnaldo Carvalho de Melo 
730c720c7e8SEric Dumazet 	r->id.idiag_sport = inet->inet_sport;
731a8c2190eSArnaldo Carvalho de Melo 	r->id.idiag_dport = ireq->rmt_port;
732a8c2190eSArnaldo Carvalho de Melo 	r->id.idiag_src[0] = ireq->loc_addr;
733a8c2190eSArnaldo Carvalho de Melo 	r->id.idiag_dst[0] = ireq->rmt_addr;
734a8c2190eSArnaldo Carvalho de Melo 	r->idiag_expires = jiffies_to_msecs(tmo);
735a8c2190eSArnaldo Carvalho de Melo 	r->idiag_rqueue = 0;
736a8c2190eSArnaldo Carvalho de Melo 	r->idiag_wqueue = 0;
737d06ca956SEric W. Biederman 	r->idiag_uid = from_kuid_munged(user_ns, sock_i_uid(sk));
738a8c2190eSArnaldo Carvalho de Melo 	r->idiag_inode = 0;
739dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
740a8c2190eSArnaldo Carvalho de Melo 	if (r->idiag_family == AF_INET6) {
7411c95df85SNeal Cardwell 		struct inet_diag_entry entry;
7421c95df85SNeal Cardwell 		inet_diag_req_addrs(sk, req, &entry);
7431c95df85SNeal Cardwell 		memcpy(r->id.idiag_src, entry.saddr, sizeof(struct in6_addr));
7441c95df85SNeal Cardwell 		memcpy(r->id.idiag_dst, entry.daddr, sizeof(struct in6_addr));
745a8c2190eSArnaldo Carvalho de Melo 	}
746a8c2190eSArnaldo Carvalho de Melo #endif
747a8c2190eSArnaldo Carvalho de Melo 
7486e277ed5SThomas Graf 	return nlmsg_end(skb, nlh);
749a8c2190eSArnaldo Carvalho de Melo }
750a8c2190eSArnaldo Carvalho de Melo 
751a8c2190eSArnaldo Carvalho de Melo static int inet_diag_dump_reqs(struct sk_buff *skb, struct sock *sk,
75237f352b5SPavel Emelyanov 			       struct netlink_callback *cb,
753c8991362SPavel Emelyanov 			       struct inet_diag_req_v2 *r,
75437f352b5SPavel Emelyanov 			       const struct nlattr *bc)
755a8c2190eSArnaldo Carvalho de Melo {
756a8c2190eSArnaldo Carvalho de Melo 	struct inet_diag_entry entry;
757a8c2190eSArnaldo Carvalho de Melo 	struct inet_connection_sock *icsk = inet_csk(sk);
758a8c2190eSArnaldo Carvalho de Melo 	struct listen_sock *lopt;
759a8c2190eSArnaldo Carvalho de Melo 	struct inet_sock *inet = inet_sk(sk);
760a8c2190eSArnaldo Carvalho de Melo 	int j, s_j;
761a8c2190eSArnaldo Carvalho de Melo 	int reqnum, s_reqnum;
762a8c2190eSArnaldo Carvalho de Melo 	int err = 0;
763a8c2190eSArnaldo Carvalho de Melo 
764a8c2190eSArnaldo Carvalho de Melo 	s_j = cb->args[3];
765a8c2190eSArnaldo Carvalho de Melo 	s_reqnum = cb->args[4];
766a8c2190eSArnaldo Carvalho de Melo 
767a8c2190eSArnaldo Carvalho de Melo 	if (s_j > 0)
768a8c2190eSArnaldo Carvalho de Melo 		s_j--;
769a8c2190eSArnaldo Carvalho de Melo 
770a8c2190eSArnaldo Carvalho de Melo 	entry.family = sk->sk_family;
771a8c2190eSArnaldo Carvalho de Melo 
772a8c2190eSArnaldo Carvalho de Melo 	read_lock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
773a8c2190eSArnaldo Carvalho de Melo 
774a8c2190eSArnaldo Carvalho de Melo 	lopt = icsk->icsk_accept_queue.listen_opt;
775a8c2190eSArnaldo Carvalho de Melo 	if (!lopt || !lopt->qlen)
776a8c2190eSArnaldo Carvalho de Melo 		goto out;
777a8c2190eSArnaldo Carvalho de Melo 
77837f352b5SPavel Emelyanov 	if (bc != NULL) {
779c720c7e8SEric Dumazet 		entry.sport = inet->inet_num;
780a8c2190eSArnaldo Carvalho de Melo 		entry.userlocks = sk->sk_userlocks;
781a8c2190eSArnaldo Carvalho de Melo 	}
782a8c2190eSArnaldo Carvalho de Melo 
783a8c2190eSArnaldo Carvalho de Melo 	for (j = s_j; j < lopt->nr_table_entries; j++) {
784a8c2190eSArnaldo Carvalho de Melo 		struct request_sock *req, *head = lopt->syn_table[j];
785a8c2190eSArnaldo Carvalho de Melo 
786a8c2190eSArnaldo Carvalho de Melo 		reqnum = 0;
787a8c2190eSArnaldo Carvalho de Melo 		for (req = head; req; reqnum++, req = req->dl_next) {
788a8c2190eSArnaldo Carvalho de Melo 			struct inet_request_sock *ireq = inet_rsk(req);
789a8c2190eSArnaldo Carvalho de Melo 
790a8c2190eSArnaldo Carvalho de Melo 			if (reqnum < s_reqnum)
791a8c2190eSArnaldo Carvalho de Melo 				continue;
792a8c2190eSArnaldo Carvalho de Melo 			if (r->id.idiag_dport != ireq->rmt_port &&
793a8c2190eSArnaldo Carvalho de Melo 			    r->id.idiag_dport)
794a8c2190eSArnaldo Carvalho de Melo 				continue;
795a8c2190eSArnaldo Carvalho de Melo 
796a8c2190eSArnaldo Carvalho de Melo 			if (bc) {
7971c95df85SNeal Cardwell 				inet_diag_req_addrs(sk, req, &entry);
798a8c2190eSArnaldo Carvalho de Melo 				entry.dport = ntohs(ireq->rmt_port);
799a8c2190eSArnaldo Carvalho de Melo 
80087c22ea5SPavel Emelyanov 				if (!inet_diag_bc_run(bc, &entry))
801a8c2190eSArnaldo Carvalho de Melo 					continue;
802a8c2190eSArnaldo Carvalho de Melo 			}
803a8c2190eSArnaldo Carvalho de Melo 
804a8c2190eSArnaldo Carvalho de Melo 			err = inet_diag_fill_req(skb, sk, req,
805e32123e5SPatrick McHardy 					       sk_user_ns(NETLINK_CB(cb->skb).sk),
80615e47304SEric W. Biederman 					       NETLINK_CB(cb->skb).portid,
807a8c2190eSArnaldo Carvalho de Melo 					       cb->nlh->nlmsg_seq, cb->nlh);
808a8c2190eSArnaldo Carvalho de Melo 			if (err < 0) {
809a8c2190eSArnaldo Carvalho de Melo 				cb->args[3] = j + 1;
810a8c2190eSArnaldo Carvalho de Melo 				cb->args[4] = reqnum;
811a8c2190eSArnaldo Carvalho de Melo 				goto out;
812a8c2190eSArnaldo Carvalho de Melo 			}
813a8c2190eSArnaldo Carvalho de Melo 		}
814a8c2190eSArnaldo Carvalho de Melo 
815a8c2190eSArnaldo Carvalho de Melo 		s_reqnum = 0;
816a8c2190eSArnaldo Carvalho de Melo 	}
817a8c2190eSArnaldo Carvalho de Melo 
818a8c2190eSArnaldo Carvalho de Melo out:
819a8c2190eSArnaldo Carvalho de Melo 	read_unlock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
820a8c2190eSArnaldo Carvalho de Melo 
821a8c2190eSArnaldo Carvalho de Melo 	return err;
822a8c2190eSArnaldo Carvalho de Melo }
823a8c2190eSArnaldo Carvalho de Melo 
8241942c518SPavel Emelyanov void inet_diag_dump_icsk(struct inet_hashinfo *hashinfo, struct sk_buff *skb,
825c8991362SPavel Emelyanov 		struct netlink_callback *cb, struct inet_diag_req_v2 *r, struct nlattr *bc)
826a8c2190eSArnaldo Carvalho de Melo {
827a8c2190eSArnaldo Carvalho de Melo 	int i, num;
828a8c2190eSArnaldo Carvalho de Melo 	int s_i, s_num;
82951d7cccfSAndrey Vagin 	struct net *net = sock_net(skb->sk);
830a8c2190eSArnaldo Carvalho de Melo 
831a8c2190eSArnaldo Carvalho de Melo 	s_i = cb->args[1];
832a8c2190eSArnaldo Carvalho de Melo 	s_num = num = cb->args[2];
833a8c2190eSArnaldo Carvalho de Melo 
834a8c2190eSArnaldo Carvalho de Melo 	if (cb->args[0] == 0) {
835a8c2190eSArnaldo Carvalho de Melo 		if (!(r->idiag_states & (TCPF_LISTEN | TCPF_SYN_RECV)))
836a8c2190eSArnaldo Carvalho de Melo 			goto skip_listen_ht;
837a8c2190eSArnaldo Carvalho de Melo 
838a8c2190eSArnaldo Carvalho de Melo 		for (i = s_i; i < INET_LHTABLE_SIZE; i++) {
839a8c2190eSArnaldo Carvalho de Melo 			struct sock *sk;
840c25eb3bfSEric Dumazet 			struct hlist_nulls_node *node;
8415caea4eaSEric Dumazet 			struct inet_listen_hashbucket *ilb;
842a8c2190eSArnaldo Carvalho de Melo 
843a8c2190eSArnaldo Carvalho de Melo 			num = 0;
8445caea4eaSEric Dumazet 			ilb = &hashinfo->listening_hash[i];
8455caea4eaSEric Dumazet 			spin_lock_bh(&ilb->lock);
846c25eb3bfSEric Dumazet 			sk_nulls_for_each(sk, node, &ilb->head) {
847a8c2190eSArnaldo Carvalho de Melo 				struct inet_sock *inet = inet_sk(sk);
848a8c2190eSArnaldo Carvalho de Melo 
84951d7cccfSAndrey Vagin 				if (!net_eq(sock_net(sk), net))
85051d7cccfSAndrey Vagin 					continue;
85151d7cccfSAndrey Vagin 
852a8c2190eSArnaldo Carvalho de Melo 				if (num < s_num) {
853a8c2190eSArnaldo Carvalho de Melo 					num++;
854a8c2190eSArnaldo Carvalho de Melo 					continue;
855a8c2190eSArnaldo Carvalho de Melo 				}
856a8c2190eSArnaldo Carvalho de Melo 
857d23deaa0SPavel Emelyanov 				if (r->sdiag_family != AF_UNSPEC &&
858d23deaa0SPavel Emelyanov 						sk->sk_family != r->sdiag_family)
859d23deaa0SPavel Emelyanov 					goto next_listen;
860d23deaa0SPavel Emelyanov 
861c720c7e8SEric Dumazet 				if (r->id.idiag_sport != inet->inet_sport &&
862a8c2190eSArnaldo Carvalho de Melo 				    r->id.idiag_sport)
863a8c2190eSArnaldo Carvalho de Melo 					goto next_listen;
864a8c2190eSArnaldo Carvalho de Melo 
865a8c2190eSArnaldo Carvalho de Melo 				if (!(r->idiag_states & TCPF_LISTEN) ||
866a8c2190eSArnaldo Carvalho de Melo 				    r->id.idiag_dport ||
867a8c2190eSArnaldo Carvalho de Melo 				    cb->args[3] > 0)
868a8c2190eSArnaldo Carvalho de Melo 					goto syn_recv;
869a8c2190eSArnaldo Carvalho de Melo 
87025c4cd2bSPavel Emelyanov 				if (inet_csk_diag_dump(sk, skb, cb, r, bc) < 0) {
8715caea4eaSEric Dumazet 					spin_unlock_bh(&ilb->lock);
872a8c2190eSArnaldo Carvalho de Melo 					goto done;
873a8c2190eSArnaldo Carvalho de Melo 				}
874a8c2190eSArnaldo Carvalho de Melo 
875a8c2190eSArnaldo Carvalho de Melo syn_recv:
876a8c2190eSArnaldo Carvalho de Melo 				if (!(r->idiag_states & TCPF_SYN_RECV))
877a8c2190eSArnaldo Carvalho de Melo 					goto next_listen;
878a8c2190eSArnaldo Carvalho de Melo 
87925c4cd2bSPavel Emelyanov 				if (inet_diag_dump_reqs(skb, sk, cb, r, bc) < 0) {
8805caea4eaSEric Dumazet 					spin_unlock_bh(&ilb->lock);
881a8c2190eSArnaldo Carvalho de Melo 					goto done;
882a8c2190eSArnaldo Carvalho de Melo 				}
883a8c2190eSArnaldo Carvalho de Melo 
884a8c2190eSArnaldo Carvalho de Melo next_listen:
885a8c2190eSArnaldo Carvalho de Melo 				cb->args[3] = 0;
886a8c2190eSArnaldo Carvalho de Melo 				cb->args[4] = 0;
887a8c2190eSArnaldo Carvalho de Melo 				++num;
888a8c2190eSArnaldo Carvalho de Melo 			}
8895caea4eaSEric Dumazet 			spin_unlock_bh(&ilb->lock);
890a8c2190eSArnaldo Carvalho de Melo 
891a8c2190eSArnaldo Carvalho de Melo 			s_num = 0;
892a8c2190eSArnaldo Carvalho de Melo 			cb->args[3] = 0;
893a8c2190eSArnaldo Carvalho de Melo 			cb->args[4] = 0;
894a8c2190eSArnaldo Carvalho de Melo 		}
895a8c2190eSArnaldo Carvalho de Melo skip_listen_ht:
896a8c2190eSArnaldo Carvalho de Melo 		cb->args[0] = 1;
897a8c2190eSArnaldo Carvalho de Melo 		s_i = num = s_num = 0;
898a8c2190eSArnaldo Carvalho de Melo 	}
899a8c2190eSArnaldo Carvalho de Melo 
900a8c2190eSArnaldo Carvalho de Melo 	if (!(r->idiag_states & ~(TCPF_LISTEN | TCPF_SYN_RECV)))
901efb3cb42SPavel Emelyanov 		goto out;
902a8c2190eSArnaldo Carvalho de Melo 
903f373b53bSEric Dumazet 	for (i = s_i; i <= hashinfo->ehash_mask; i++) {
904a8c2190eSArnaldo Carvalho de Melo 		struct inet_ehash_bucket *head = &hashinfo->ehash[i];
9057e3aab4aSDavid S. Miller 		spinlock_t *lock = inet_ehash_lockp(hashinfo, i);
906a8c2190eSArnaldo Carvalho de Melo 		struct sock *sk;
9073ab5aee7SEric Dumazet 		struct hlist_nulls_node *node;
908a8c2190eSArnaldo Carvalho de Melo 
9096be547a6SAndi Kleen 		num = 0;
9106be547a6SAndi Kleen 
91105dbc7b5SEric Dumazet 		if (hlist_nulls_empty(&head->chain))
9126be547a6SAndi Kleen 			continue;
9136be547a6SAndi Kleen 
914a8c2190eSArnaldo Carvalho de Melo 		if (i > s_i)
915a8c2190eSArnaldo Carvalho de Melo 			s_num = 0;
916a8c2190eSArnaldo Carvalho de Melo 
9177e3aab4aSDavid S. Miller 		spin_lock_bh(lock);
9183ab5aee7SEric Dumazet 		sk_nulls_for_each(sk, node, &head->chain) {
91905dbc7b5SEric Dumazet 			int res;
920a8c2190eSArnaldo Carvalho de Melo 
92151d7cccfSAndrey Vagin 			if (!net_eq(sock_net(sk), net))
92251d7cccfSAndrey Vagin 				continue;
923a8c2190eSArnaldo Carvalho de Melo 			if (num < s_num)
924a8c2190eSArnaldo Carvalho de Melo 				goto next_normal;
925a8c2190eSArnaldo Carvalho de Melo 			if (!(r->idiag_states & (1 << sk->sk_state)))
926a8c2190eSArnaldo Carvalho de Melo 				goto next_normal;
927d23deaa0SPavel Emelyanov 			if (r->sdiag_family != AF_UNSPEC &&
928d23deaa0SPavel Emelyanov 			    sk->sk_family != r->sdiag_family)
929d23deaa0SPavel Emelyanov 				goto next_normal;
93005dbc7b5SEric Dumazet 			if (r->id.idiag_sport != htons(sk->sk_num) &&
931a8c2190eSArnaldo Carvalho de Melo 			    r->id.idiag_sport)
932a8c2190eSArnaldo Carvalho de Melo 				goto next_normal;
93305dbc7b5SEric Dumazet 			if (r->id.idiag_dport != sk->sk_dport &&
9344e852c02SArnaldo Carvalho de Melo 			    r->id.idiag_dport)
935a8c2190eSArnaldo Carvalho de Melo 				goto next_normal;
93605dbc7b5SEric Dumazet 			if (sk->sk_state == TCP_TIME_WAIT)
93705dbc7b5SEric Dumazet 				res = inet_twsk_diag_dump(sk, skb, cb, r, bc);
93805dbc7b5SEric Dumazet 			else
93905dbc7b5SEric Dumazet 				res = inet_csk_diag_dump(sk, skb, cb, r, bc);
94005dbc7b5SEric Dumazet 			if (res < 0) {
9417e3aab4aSDavid S. Miller 				spin_unlock_bh(lock);
942a8c2190eSArnaldo Carvalho de Melo 				goto done;
943a8c2190eSArnaldo Carvalho de Melo 			}
944a8c2190eSArnaldo Carvalho de Melo next_normal:
945a8c2190eSArnaldo Carvalho de Melo 			++num;
946a8c2190eSArnaldo Carvalho de Melo 		}
947a8c2190eSArnaldo Carvalho de Melo 
9487e3aab4aSDavid S. Miller 		spin_unlock_bh(lock);
949a8c2190eSArnaldo Carvalho de Melo 	}
950a8c2190eSArnaldo Carvalho de Melo 
951a8c2190eSArnaldo Carvalho de Melo done:
952a8c2190eSArnaldo Carvalho de Melo 	cb->args[1] = i;
953a8c2190eSArnaldo Carvalho de Melo 	cb->args[2] = num;
954efb3cb42SPavel Emelyanov out:
955efb3cb42SPavel Emelyanov 	;
956efb3cb42SPavel Emelyanov }
9571942c518SPavel Emelyanov EXPORT_SYMBOL_GPL(inet_diag_dump_icsk);
958efb3cb42SPavel Emelyanov 
959efb3cb42SPavel Emelyanov static int __inet_diag_dump(struct sk_buff *skb, struct netlink_callback *cb,
960c8991362SPavel Emelyanov 		struct inet_diag_req_v2 *r, struct nlattr *bc)
961efb3cb42SPavel Emelyanov {
962efb3cb42SPavel Emelyanov 	const struct inet_diag_handler *handler;
963cacb6ba0SCyrill Gorcunov 	int err = 0;
964efb3cb42SPavel Emelyanov 
965efb3cb42SPavel Emelyanov 	handler = inet_diag_lock_handler(r->sdiag_protocol);
966efb3cb42SPavel Emelyanov 	if (!IS_ERR(handler))
9671942c518SPavel Emelyanov 		handler->dump(skb, cb, r, bc);
968cacb6ba0SCyrill Gorcunov 	else
969cacb6ba0SCyrill Gorcunov 		err = PTR_ERR(handler);
970d523a328SHerbert Xu 	inet_diag_unlock_handler(handler);
971efb3cb42SPavel Emelyanov 
972cacb6ba0SCyrill Gorcunov 	return err ? : skb->len;
973a8c2190eSArnaldo Carvalho de Melo }
974a8c2190eSArnaldo Carvalho de Melo 
97525c4cd2bSPavel Emelyanov static int inet_diag_dump(struct sk_buff *skb, struct netlink_callback *cb)
97625c4cd2bSPavel Emelyanov {
97725c4cd2bSPavel Emelyanov 	struct nlattr *bc = NULL;
978c8991362SPavel Emelyanov 	int hdrlen = sizeof(struct inet_diag_req_v2);
97925c4cd2bSPavel Emelyanov 
98025c4cd2bSPavel Emelyanov 	if (nlmsg_attrlen(cb->nlh, hdrlen))
98125c4cd2bSPavel Emelyanov 		bc = nlmsg_find_attr(cb->nlh, hdrlen, INET_DIAG_REQ_BYTECODE);
98225c4cd2bSPavel Emelyanov 
983d106352dSDavid S. Miller 	return __inet_diag_dump(skb, cb, nlmsg_data(cb->nlh), bc);
98425c4cd2bSPavel Emelyanov }
98525c4cd2bSPavel Emelyanov 
986a029fe26SPavel Emelyanov static inline int inet_diag_type2proto(int type)
987a029fe26SPavel Emelyanov {
988a029fe26SPavel Emelyanov 	switch (type) {
989a029fe26SPavel Emelyanov 	case TCPDIAG_GETSOCK:
990a029fe26SPavel Emelyanov 		return IPPROTO_TCP;
991a029fe26SPavel Emelyanov 	case DCCPDIAG_GETSOCK:
992a029fe26SPavel Emelyanov 		return IPPROTO_DCCP;
993a029fe26SPavel Emelyanov 	default:
994a029fe26SPavel Emelyanov 		return 0;
995a029fe26SPavel Emelyanov 	}
996a029fe26SPavel Emelyanov }
997a029fe26SPavel Emelyanov 
99825c4cd2bSPavel Emelyanov static int inet_diag_dump_compat(struct sk_buff *skb, struct netlink_callback *cb)
99925c4cd2bSPavel Emelyanov {
1000d106352dSDavid S. Miller 	struct inet_diag_req *rc = nlmsg_data(cb->nlh);
1001c8991362SPavel Emelyanov 	struct inet_diag_req_v2 req;
100225c4cd2bSPavel Emelyanov 	struct nlattr *bc = NULL;
10033b09c84cSPavel Emelyanov 	int hdrlen = sizeof(struct inet_diag_req);
100425c4cd2bSPavel Emelyanov 
1005d23deaa0SPavel Emelyanov 	req.sdiag_family = AF_UNSPEC; /* compatibility */
100625c4cd2bSPavel Emelyanov 	req.sdiag_protocol = inet_diag_type2proto(cb->nlh->nlmsg_type);
100725c4cd2bSPavel Emelyanov 	req.idiag_ext = rc->idiag_ext;
100825c4cd2bSPavel Emelyanov 	req.idiag_states = rc->idiag_states;
100925c4cd2bSPavel Emelyanov 	req.id = rc->id;
101025c4cd2bSPavel Emelyanov 
101125c4cd2bSPavel Emelyanov 	if (nlmsg_attrlen(cb->nlh, hdrlen))
101225c4cd2bSPavel Emelyanov 		bc = nlmsg_find_attr(cb->nlh, hdrlen, INET_DIAG_REQ_BYTECODE);
101325c4cd2bSPavel Emelyanov 
101425c4cd2bSPavel Emelyanov 	return __inet_diag_dump(skb, cb, &req, bc);
101525c4cd2bSPavel Emelyanov }
101625c4cd2bSPavel Emelyanov 
1017fe50ce28SPavel Emelyanov static int inet_diag_get_exact_compat(struct sk_buff *in_skb,
1018fe50ce28SPavel Emelyanov 			       const struct nlmsghdr *nlh)
1019fe50ce28SPavel Emelyanov {
1020d106352dSDavid S. Miller 	struct inet_diag_req *rc = nlmsg_data(nlh);
1021c8991362SPavel Emelyanov 	struct inet_diag_req_v2 req;
1022fe50ce28SPavel Emelyanov 
1023fe50ce28SPavel Emelyanov 	req.sdiag_family = rc->idiag_family;
1024fe50ce28SPavel Emelyanov 	req.sdiag_protocol = inet_diag_type2proto(nlh->nlmsg_type);
1025fe50ce28SPavel Emelyanov 	req.idiag_ext = rc->idiag_ext;
1026fe50ce28SPavel Emelyanov 	req.idiag_states = rc->idiag_states;
1027fe50ce28SPavel Emelyanov 	req.id = rc->id;
1028fe50ce28SPavel Emelyanov 
1029fe50ce28SPavel Emelyanov 	return inet_diag_get_exact(in_skb, nlh, &req);
1030fe50ce28SPavel Emelyanov }
1031fe50ce28SPavel Emelyanov 
10328d34172dSPavel Emelyanov static int inet_diag_rcv_msg_compat(struct sk_buff *skb, struct nlmsghdr *nlh)
1033a8c2190eSArnaldo Carvalho de Melo {
10343b09c84cSPavel Emelyanov 	int hdrlen = sizeof(struct inet_diag_req);
103551d7cccfSAndrey Vagin 	struct net *net = sock_net(skb->sk);
1036a8c2190eSArnaldo Carvalho de Melo 
1037ead592baSThomas Graf 	if (nlh->nlmsg_type >= INET_DIAG_GETSOCK_MAX ||
1038ead592baSThomas Graf 	    nlmsg_len(nlh) < hdrlen)
1039ead592baSThomas Graf 		return -EINVAL;
1040a8c2190eSArnaldo Carvalho de Melo 
1041b8f3ab42SDavid S. Miller 	if (nlh->nlmsg_flags & NLM_F_DUMP) {
1042ead592baSThomas Graf 		if (nlmsg_attrlen(nlh, hdrlen)) {
1043ead592baSThomas Graf 			struct nlattr *attr;
1044ead592baSThomas Graf 
1045ead592baSThomas Graf 			attr = nlmsg_find_attr(nlh, hdrlen,
1046ead592baSThomas Graf 					       INET_DIAG_REQ_BYTECODE);
1047ead592baSThomas Graf 			if (attr == NULL ||
1048ead592baSThomas Graf 			    nla_len(attr) < sizeof(struct inet_diag_bc_op) ||
1049ead592baSThomas Graf 			    inet_diag_bc_audit(nla_data(attr), nla_len(attr)))
1050a8c2190eSArnaldo Carvalho de Melo 				return -EINVAL;
1051a8c2190eSArnaldo Carvalho de Melo 		}
105280d326faSPablo Neira Ayuso 		{
105380d326faSPablo Neira Ayuso 			struct netlink_dump_control c = {
105480d326faSPablo Neira Ayuso 				.dump = inet_diag_dump_compat,
105580d326faSPablo Neira Ayuso 			};
105651d7cccfSAndrey Vagin 			return netlink_dump_start(net->diag_nlsk, skb, nlh, &c);
105780d326faSPablo Neira Ayuso 		}
1058a8c2190eSArnaldo Carvalho de Melo 	}
1059ead592baSThomas Graf 
1060fe50ce28SPavel Emelyanov 	return inet_diag_get_exact_compat(skb, nlh);
1061a8c2190eSArnaldo Carvalho de Melo }
1062a8c2190eSArnaldo Carvalho de Melo 
1063d366477aSPavel Emelyanov static int inet_diag_handler_dump(struct sk_buff *skb, struct nlmsghdr *h)
1064d366477aSPavel Emelyanov {
1065c8991362SPavel Emelyanov 	int hdrlen = sizeof(struct inet_diag_req_v2);
106651d7cccfSAndrey Vagin 	struct net *net = sock_net(skb->sk);
1067d366477aSPavel Emelyanov 
1068d366477aSPavel Emelyanov 	if (nlmsg_len(h) < hdrlen)
1069d366477aSPavel Emelyanov 		return -EINVAL;
1070d366477aSPavel Emelyanov 
1071d366477aSPavel Emelyanov 	if (h->nlmsg_flags & NLM_F_DUMP) {
107225c4cd2bSPavel Emelyanov 		if (nlmsg_attrlen(h, hdrlen)) {
107325c4cd2bSPavel Emelyanov 			struct nlattr *attr;
107425c4cd2bSPavel Emelyanov 			attr = nlmsg_find_attr(h, hdrlen,
107525c4cd2bSPavel Emelyanov 					       INET_DIAG_REQ_BYTECODE);
107625c4cd2bSPavel Emelyanov 			if (attr == NULL ||
107725c4cd2bSPavel Emelyanov 			    nla_len(attr) < sizeof(struct inet_diag_bc_op) ||
107825c4cd2bSPavel Emelyanov 			    inet_diag_bc_audit(nla_data(attr), nla_len(attr)))
107925c4cd2bSPavel Emelyanov 				return -EINVAL;
108025c4cd2bSPavel Emelyanov 		}
108180d326faSPablo Neira Ayuso 		{
108280d326faSPablo Neira Ayuso 			struct netlink_dump_control c = {
108380d326faSPablo Neira Ayuso 				.dump = inet_diag_dump,
108480d326faSPablo Neira Ayuso 			};
108551d7cccfSAndrey Vagin 			return netlink_dump_start(net->diag_nlsk, skb, h, &c);
108680d326faSPablo Neira Ayuso 		}
1087d366477aSPavel Emelyanov 	}
1088d366477aSPavel Emelyanov 
1089d106352dSDavid S. Miller 	return inet_diag_get_exact(skb, h, nlmsg_data(h));
1090d366477aSPavel Emelyanov }
1091d366477aSPavel Emelyanov 
10928dcf01fcSShan Wei static const struct sock_diag_handler inet_diag_handler = {
1093d366477aSPavel Emelyanov 	.family = AF_INET,
1094d366477aSPavel Emelyanov 	.dump = inet_diag_handler_dump,
1095d366477aSPavel Emelyanov };
1096d366477aSPavel Emelyanov 
10978dcf01fcSShan Wei static const struct sock_diag_handler inet6_diag_handler = {
1098d366477aSPavel Emelyanov 	.family = AF_INET6,
1099d366477aSPavel Emelyanov 	.dump = inet_diag_handler_dump,
1100d366477aSPavel Emelyanov };
1101d366477aSPavel Emelyanov 
1102a8c2190eSArnaldo Carvalho de Melo int inet_diag_register(const struct inet_diag_handler *h)
1103a8c2190eSArnaldo Carvalho de Melo {
1104a8c2190eSArnaldo Carvalho de Melo 	const __u16 type = h->idiag_type;
1105a8c2190eSArnaldo Carvalho de Melo 	int err = -EINVAL;
1106a8c2190eSArnaldo Carvalho de Melo 
1107f13c95f0SPavel Emelyanov 	if (type >= IPPROTO_MAX)
1108a8c2190eSArnaldo Carvalho de Melo 		goto out;
1109a8c2190eSArnaldo Carvalho de Melo 
1110d523a328SHerbert Xu 	mutex_lock(&inet_diag_table_mutex);
1111a8c2190eSArnaldo Carvalho de Melo 	err = -EEXIST;
1112a8c2190eSArnaldo Carvalho de Melo 	if (inet_diag_table[type] == NULL) {
1113a8c2190eSArnaldo Carvalho de Melo 		inet_diag_table[type] = h;
1114a8c2190eSArnaldo Carvalho de Melo 		err = 0;
1115a8c2190eSArnaldo Carvalho de Melo 	}
1116d523a328SHerbert Xu 	mutex_unlock(&inet_diag_table_mutex);
1117a8c2190eSArnaldo Carvalho de Melo out:
1118a8c2190eSArnaldo Carvalho de Melo 	return err;
1119a8c2190eSArnaldo Carvalho de Melo }
1120a8c2190eSArnaldo Carvalho de Melo EXPORT_SYMBOL_GPL(inet_diag_register);
1121a8c2190eSArnaldo Carvalho de Melo 
1122a8c2190eSArnaldo Carvalho de Melo void inet_diag_unregister(const struct inet_diag_handler *h)
1123a8c2190eSArnaldo Carvalho de Melo {
1124a8c2190eSArnaldo Carvalho de Melo 	const __u16 type = h->idiag_type;
1125a8c2190eSArnaldo Carvalho de Melo 
1126f13c95f0SPavel Emelyanov 	if (type >= IPPROTO_MAX)
1127a8c2190eSArnaldo Carvalho de Melo 		return;
1128a8c2190eSArnaldo Carvalho de Melo 
1129d523a328SHerbert Xu 	mutex_lock(&inet_diag_table_mutex);
1130a8c2190eSArnaldo Carvalho de Melo 	inet_diag_table[type] = NULL;
1131d523a328SHerbert Xu 	mutex_unlock(&inet_diag_table_mutex);
1132a8c2190eSArnaldo Carvalho de Melo }
1133a8c2190eSArnaldo Carvalho de Melo EXPORT_SYMBOL_GPL(inet_diag_unregister);
1134a8c2190eSArnaldo Carvalho de Melo 
1135a8c2190eSArnaldo Carvalho de Melo static int __init inet_diag_init(void)
1136a8c2190eSArnaldo Carvalho de Melo {
1137f13c95f0SPavel Emelyanov 	const int inet_diag_table_size = (IPPROTO_MAX *
1138a8c2190eSArnaldo Carvalho de Melo 					  sizeof(struct inet_diag_handler *));
1139a8c2190eSArnaldo Carvalho de Melo 	int err = -ENOMEM;
1140a8c2190eSArnaldo Carvalho de Melo 
11410da974f4SPanagiotis Issaris 	inet_diag_table = kzalloc(inet_diag_table_size, GFP_KERNEL);
1142a8c2190eSArnaldo Carvalho de Melo 	if (!inet_diag_table)
1143a8c2190eSArnaldo Carvalho de Melo 		goto out;
1144a8c2190eSArnaldo Carvalho de Melo 
1145d366477aSPavel Emelyanov 	err = sock_diag_register(&inet_diag_handler);
1146d366477aSPavel Emelyanov 	if (err)
1147d366477aSPavel Emelyanov 		goto out_free_nl;
1148d366477aSPavel Emelyanov 
1149d366477aSPavel Emelyanov 	err = sock_diag_register(&inet6_diag_handler);
1150d366477aSPavel Emelyanov 	if (err)
1151d366477aSPavel Emelyanov 		goto out_free_inet;
1152d366477aSPavel Emelyanov 
11538ef874bfSPavel Emelyanov 	sock_diag_register_inet_compat(inet_diag_rcv_msg_compat);
1154a8c2190eSArnaldo Carvalho de Melo out:
1155a8c2190eSArnaldo Carvalho de Melo 	return err;
1156d366477aSPavel Emelyanov 
1157d366477aSPavel Emelyanov out_free_inet:
1158d366477aSPavel Emelyanov 	sock_diag_unregister(&inet_diag_handler);
1159d366477aSPavel Emelyanov out_free_nl:
1160a8c2190eSArnaldo Carvalho de Melo 	kfree(inet_diag_table);
1161a8c2190eSArnaldo Carvalho de Melo 	goto out;
1162a8c2190eSArnaldo Carvalho de Melo }
1163a8c2190eSArnaldo Carvalho de Melo 
1164a8c2190eSArnaldo Carvalho de Melo static void __exit inet_diag_exit(void)
1165a8c2190eSArnaldo Carvalho de Melo {
1166d366477aSPavel Emelyanov 	sock_diag_unregister(&inet6_diag_handler);
1167d366477aSPavel Emelyanov 	sock_diag_unregister(&inet_diag_handler);
11688ef874bfSPavel Emelyanov 	sock_diag_unregister_inet_compat(inet_diag_rcv_msg_compat);
1169a8c2190eSArnaldo Carvalho de Melo 	kfree(inet_diag_table);
1170a8c2190eSArnaldo Carvalho de Melo }
1171a8c2190eSArnaldo Carvalho de Melo 
1172a8c2190eSArnaldo Carvalho de Melo module_init(inet_diag_init);
1173a8c2190eSArnaldo Carvalho de Melo module_exit(inet_diag_exit);
1174a8c2190eSArnaldo Carvalho de Melo MODULE_LICENSE("GPL");
1175aec8dc62SPavel Emelyanov MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_NETLINK, NETLINK_SOCK_DIAG, 2 /* AF_INET */);
1176aec8dc62SPavel Emelyanov MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_NETLINK, NETLINK_SOCK_DIAG, 10 /* AF_INET6 */);
1177