xref: /openbmc/linux/include/linux/ipc_namespace.h (revision eb3fcf007fffe5830d815e713591f3e858f2a365)
1 #ifndef __IPC_NAMESPACE_H__
2 #define __IPC_NAMESPACE_H__
3 
4 #include <linux/err.h>
5 #include <linux/idr.h>
6 #include <linux/rwsem.h>
7 #include <linux/notifier.h>
8 #include <linux/nsproxy.h>
9 #include <linux/ns_common.h>
10 
11 struct user_namespace;
12 
13 struct ipc_ids {
14 	int in_use;
15 	unsigned short seq;
16 	struct rw_semaphore rwsem;
17 	struct idr ipcs_idr;
18 	int next_id;
19 };
20 
21 struct ipc_namespace {
22 	atomic_t	count;
23 	struct ipc_ids	ids[3];
24 
25 	int		sem_ctls[4];
26 	int		used_sems;
27 
28 	unsigned int	msg_ctlmax;
29 	unsigned int	msg_ctlmnb;
30 	unsigned int	msg_ctlmni;
31 	atomic_t	msg_bytes;
32 	atomic_t	msg_hdrs;
33 
34 	size_t		shm_ctlmax;
35 	size_t		shm_ctlall;
36 	unsigned long	shm_tot;
37 	int		shm_ctlmni;
38 	/*
39 	 * Defines whether IPC_RMID is forced for _all_ shm segments regardless
40 	 * of shmctl()
41 	 */
42 	int		shm_rmid_forced;
43 
44 	struct notifier_block ipcns_nb;
45 
46 	/* The kern_mount of the mqueuefs sb.  We take a ref on it */
47 	struct vfsmount	*mq_mnt;
48 
49 	/* # queues in this ns, protected by mq_lock */
50 	unsigned int    mq_queues_count;
51 
52 	/* next fields are set through sysctl */
53 	unsigned int    mq_queues_max;   /* initialized to DFLT_QUEUESMAX */
54 	unsigned int    mq_msg_max;      /* initialized to DFLT_MSGMAX */
55 	unsigned int    mq_msgsize_max;  /* initialized to DFLT_MSGSIZEMAX */
56 	unsigned int    mq_msg_default;
57 	unsigned int    mq_msgsize_default;
58 
59 	/* user_ns which owns the ipc ns */
60 	struct user_namespace *user_ns;
61 
62 	struct ns_common ns;
63 };
64 
65 extern struct ipc_namespace init_ipc_ns;
66 extern atomic_t nr_ipc_ns;
67 
68 extern spinlock_t mq_lock;
69 
70 #ifdef CONFIG_SYSVIPC
71 extern void shm_destroy_orphaned(struct ipc_namespace *ns);
72 #else /* CONFIG_SYSVIPC */
73 static inline void shm_destroy_orphaned(struct ipc_namespace *ns) {}
74 #endif /* CONFIG_SYSVIPC */
75 
76 #ifdef CONFIG_POSIX_MQUEUE
77 extern int mq_init_ns(struct ipc_namespace *ns);
78 /*
79  * POSIX Message Queue default values:
80  *
81  * MIN_*: Lowest value an admin can set the maximum unprivileged limit to
82  * DFLT_*MAX: Default values for the maximum unprivileged limits
83  * DFLT_{MSG,MSGSIZE}: Default values used when the user doesn't supply
84  *   an attribute to the open call and the queue must be created
85  * HARD_*: Highest value the maximums can be set to.  These are enforced
86  *   on CAP_SYS_RESOURCE apps as well making them inviolate (so make them
87  *   suitably high)
88  *
89  * POSIX Requirements:
90  *   Per app minimum openable message queues - 8.  This does not map well
91  *     to the fact that we limit the number of queues on a per namespace
92  *     basis instead of a per app basis.  So, make the default high enough
93  *     that no given app should have a hard time opening 8 queues.
94  *   Minimum maximum for HARD_MSGMAX - 32767.  I bumped this to 65536.
95  *   Minimum maximum for HARD_MSGSIZEMAX - POSIX is silent on this.  However,
96  *     we have run into a situation where running applications in the wild
97  *     require this to be at least 5MB, and preferably 10MB, so I set the
98  *     value to 16MB in hopes that this user is the worst of the bunch and
99  *     the new maximum will handle anyone else.  I may have to revisit this
100  *     in the future.
101  */
102 #define DFLT_QUEUESMAX		      256
103 #define MIN_MSGMAX			1
104 #define DFLT_MSG		       10U
105 #define DFLT_MSGMAX		       10
106 #define HARD_MSGMAX		    65536
107 #define MIN_MSGSIZEMAX		      128
108 #define DFLT_MSGSIZE		     8192U
109 #define DFLT_MSGSIZEMAX		     8192
110 #define HARD_MSGSIZEMAX	    (16*1024*1024)
111 #else
112 static inline int mq_init_ns(struct ipc_namespace *ns) { return 0; }
113 #endif
114 
115 #if defined(CONFIG_IPC_NS)
116 extern struct ipc_namespace *copy_ipcs(unsigned long flags,
117 	struct user_namespace *user_ns, struct ipc_namespace *ns);
118 
119 static inline struct ipc_namespace *get_ipc_ns(struct ipc_namespace *ns)
120 {
121 	if (ns)
122 		atomic_inc(&ns->count);
123 	return ns;
124 }
125 
126 extern void put_ipc_ns(struct ipc_namespace *ns);
127 #else
128 static inline struct ipc_namespace *copy_ipcs(unsigned long flags,
129 	struct user_namespace *user_ns, struct ipc_namespace *ns)
130 {
131 	if (flags & CLONE_NEWIPC)
132 		return ERR_PTR(-EINVAL);
133 
134 	return ns;
135 }
136 
137 static inline struct ipc_namespace *get_ipc_ns(struct ipc_namespace *ns)
138 {
139 	return ns;
140 }
141 
142 static inline void put_ipc_ns(struct ipc_namespace *ns)
143 {
144 }
145 #endif
146 
147 #ifdef CONFIG_POSIX_MQUEUE_SYSCTL
148 
149 struct ctl_table_header;
150 extern struct ctl_table_header *mq_register_sysctl_table(void);
151 
152 #else /* CONFIG_POSIX_MQUEUE_SYSCTL */
153 
154 static inline struct ctl_table_header *mq_register_sysctl_table(void)
155 {
156 	return NULL;
157 }
158 
159 #endif /* CONFIG_POSIX_MQUEUE_SYSCTL */
160 #endif
161