xref: /linux/lib/kobject_uevent.c (revision 7c6c4ed80b874f721bc7c2c937e098c56e37d2f0)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * kernel userspace event delivery
4  *
5  * Copyright (C) 2004 Red Hat, Inc.  All rights reserved.
6  * Copyright (C) 2004 Novell, Inc.  All rights reserved.
7  * Copyright (C) 2004 IBM, Inc. All rights reserved.
8  *
9  * Authors:
10  *	Robert Love		<rml@novell.com>
11  *	Kay Sievers		<kay.sievers@vrfy.org>
12  *	Arjan van de Ven	<arjanv@redhat.com>
13  *	Greg Kroah-Hartman	<greg@kroah.com>
14  */
15 
16 #include <linux/spinlock.h>
17 #include <linux/string.h>
18 #include <linux/kobject.h>
19 #include <linux/export.h>
20 #include <linux/kmod.h>
21 #include <linux/slab.h>
22 #include <linux/socket.h>
23 #include <linux/skbuff.h>
24 #include <linux/netlink.h>
25 #include <linux/uidgid.h>
26 #include <linux/uuid.h>
27 #include <linux/ctype.h>
28 #include <net/sock.h>
29 #include <net/netlink.h>
30 #include <net/net_namespace.h>
31 
32 
33 atomic64_t uevent_seqnum;
34 #ifdef CONFIG_UEVENT_HELPER
35 char uevent_helper[UEVENT_HELPER_PATH_LEN] = CONFIG_UEVENT_HELPER_PATH;
36 #endif
37 
38 struct uevent_sock {
39 	struct list_head list;
40 	struct sock *sk;
41 };
42 
43 #ifdef CONFIG_NET
44 static LIST_HEAD(uevent_sock_list);
45 /* This lock protects uevent_sock_list */
46 static DEFINE_MUTEX(uevent_sock_mutex);
47 #endif
48 
49 /* the strings here must match the enum in include/linux/kobject.h */
50 static const char *kobject_actions[] = {
51 	[KOBJ_ADD] =		"add",
52 	[KOBJ_REMOVE] =		"remove",
53 	[KOBJ_CHANGE] =		"change",
54 	[KOBJ_MOVE] =		"move",
55 	[KOBJ_ONLINE] =		"online",
56 	[KOBJ_OFFLINE] =	"offline",
57 	[KOBJ_BIND] =		"bind",
58 	[KOBJ_UNBIND] =		"unbind",
59 };
60 
kobject_action_type(const char * buf,size_t count,enum kobject_action * type,const char ** args)61 static int kobject_action_type(const char *buf, size_t count,
62 			       enum kobject_action *type,
63 			       const char **args)
64 {
65 	enum kobject_action action;
66 	size_t count_first;
67 	const char *args_start;
68 	int ret = -EINVAL;
69 
70 	if (count && (buf[count-1] == '\n' || buf[count-1] == '\0'))
71 		count--;
72 
73 	if (!count)
74 		goto out;
75 
76 	args_start = strnchr(buf, count, ' ');
77 	if (args_start) {
78 		count_first = args_start - buf;
79 		args_start = args_start + 1;
80 	} else
81 		count_first = count;
82 
83 	for (action = 0; action < ARRAY_SIZE(kobject_actions); action++) {
84 		if (strncmp(kobject_actions[action], buf, count_first) != 0)
85 			continue;
86 		if (kobject_actions[action][count_first] != '\0')
87 			continue;
88 		if (args)
89 			*args = args_start;
90 		*type = action;
91 		ret = 0;
92 		break;
93 	}
94 out:
95 	return ret;
96 }
97 
action_arg_word_end(const char * buf,const char * buf_end,char delim)98 static const char *action_arg_word_end(const char *buf, const char *buf_end,
99 				       char delim)
100 {
101 	const char *next = buf;
102 
103 	while (next <= buf_end && *next != delim)
104 		if (!isalnum(*next++))
105 			return NULL;
106 
107 	if (next == buf)
108 		return NULL;
109 
110 	return next;
111 }
112 
kobject_action_args(const char * buf,size_t count,struct kobj_uevent_env ** ret_env)113 static int kobject_action_args(const char *buf, size_t count,
114 			       struct kobj_uevent_env **ret_env)
115 {
116 	struct kobj_uevent_env *env = NULL;
117 	const char *next, *buf_end, *key;
118 	int key_len;
119 	int r = -EINVAL;
120 
121 	if (count && (buf[count - 1] == '\n' || buf[count - 1] == '\0'))
122 		count--;
123 
124 	if (!count)
125 		return -EINVAL;
126 
127 	env = kzalloc_obj(*env);
128 	if (!env)
129 		return -ENOMEM;
130 
131 	/* first arg is UUID */
132 	if (count < UUID_STRING_LEN || !uuid_is_valid(buf) ||
133 	    add_uevent_var(env, "SYNTH_UUID=%.*s", UUID_STRING_LEN, buf))
134 		goto out;
135 
136 	/*
137 	 * the rest are custom environment variables in KEY=VALUE
138 	 * format with ' ' delimiter between each KEY=VALUE pair
139 	 */
140 	next = buf + UUID_STRING_LEN;
141 	buf_end = buf + count - 1;
142 
143 	while (next <= buf_end) {
144 		if (*next != ' ')
145 			goto out;
146 
147 		/* skip the ' ', key must follow */
148 		key = ++next;
149 		if (key > buf_end)
150 			goto out;
151 
152 		buf = next;
153 		next = action_arg_word_end(buf, buf_end, '=');
154 		if (!next || next > buf_end || *next != '=')
155 			goto out;
156 		key_len = next - buf;
157 
158 		/* skip the '=', value must follow */
159 		if (++next > buf_end)
160 			goto out;
161 
162 		buf = next;
163 		next = action_arg_word_end(buf, buf_end, ' ');
164 		if (!next)
165 			goto out;
166 
167 		if (add_uevent_var(env, "SYNTH_ARG_%.*s=%.*s",
168 				   key_len, key, (int) (next - buf), buf))
169 			goto out;
170 	}
171 
172 	r = 0;
173 out:
174 	if (r)
175 		kfree(env);
176 	else
177 		*ret_env = env;
178 	return r;
179 }
180 
181 /**
182  * kobject_synth_uevent - send synthetic uevent with arguments
183  *
184  * @kobj: struct kobject for which synthetic uevent is to be generated
185  * @buf: buffer containing action type and action args, newline is ignored
186  * @count: length of buffer
187  *
188  * Returns 0 if kobject_synthetic_uevent() is completed with success or the
189  * corresponding error when it fails.
190  */
kobject_synth_uevent(struct kobject * kobj,const char * buf,size_t count)191 int kobject_synth_uevent(struct kobject *kobj, const char *buf, size_t count)
192 {
193 	char *no_uuid_envp[] = { "SYNTH_UUID=0", NULL };
194 	enum kobject_action action;
195 	const char *action_args;
196 	struct kobj_uevent_env *env;
197 	const char *msg = NULL, *devpath;
198 	int r;
199 
200 	r = kobject_action_type(buf, count, &action, &action_args);
201 	if (r) {
202 		msg = "unknown uevent action string";
203 		goto out;
204 	}
205 
206 	if (!action_args) {
207 		r = kobject_uevent_env(kobj, action, no_uuid_envp);
208 		goto out;
209 	}
210 
211 	r = kobject_action_args(action_args,
212 				count - (action_args - buf), &env);
213 	if (r == -EINVAL) {
214 		msg = "incorrect uevent action arguments";
215 		goto out;
216 	}
217 
218 	if (r)
219 		goto out;
220 
221 	r = kobject_uevent_env(kobj, action, env->envp);
222 	kfree(env);
223 out:
224 	if (r) {
225 		devpath = kobject_get_path(kobj, GFP_KERNEL);
226 		pr_warn("synth uevent: %s: %s\n",
227 		       devpath ?: "unknown device",
228 		       msg ?: "failed to send uevent");
229 		kfree(devpath);
230 	}
231 	return r;
232 }
233 
234 #ifdef CONFIG_UEVENT_HELPER
kobj_usermode_filter(struct kobject * kobj)235 static int kobj_usermode_filter(struct kobject *kobj)
236 {
237 	const struct kobj_ns_type_operations *ops;
238 
239 	ops = kobj_ns_ops(kobj);
240 	if (ops) {
241 		const struct ns_common *init_ns, *ns;
242 
243 		ns = kobj->ktype->namespace(kobj);
244 		init_ns = ops->initial_ns();
245 		return ns != init_ns;
246 	}
247 
248 	return 0;
249 }
250 
init_uevent_argv(struct kobj_uevent_env * env,const char * subsystem)251 static int init_uevent_argv(struct kobj_uevent_env *env, const char *subsystem)
252 {
253 	int buffer_size = sizeof(env->buf) - env->buflen;
254 	int len;
255 
256 	len = strscpy(&env->buf[env->buflen], subsystem, buffer_size);
257 	if (len < 0) {
258 		pr_warn("%s: insufficient buffer space (%u left) for %s\n",
259 			__func__, buffer_size, subsystem);
260 		return -ENOMEM;
261 	}
262 
263 	env->argv[0] = uevent_helper;
264 	env->argv[1] = &env->buf[env->buflen];
265 	env->argv[2] = NULL;
266 
267 	env->buflen += len + 1;
268 	return 0;
269 }
270 
cleanup_uevent_env(struct subprocess_info * info)271 static void cleanup_uevent_env(struct subprocess_info *info)
272 {
273 	kfree(info->data);
274 }
275 #endif
276 
277 #ifdef CONFIG_NET
alloc_uevent_skb(struct kobj_uevent_env * env,const char * action_string,const char * devpath)278 static struct sk_buff *alloc_uevent_skb(struct kobj_uevent_env *env,
279 					const char *action_string,
280 					const char *devpath)
281 {
282 	struct netlink_skb_parms *parms;
283 	struct sk_buff *skb = NULL;
284 	char *scratch;
285 	size_t len;
286 
287 	/* allocate message with maximum possible size */
288 	len = strlen(action_string) + strlen(devpath) + 2;
289 	skb = alloc_skb(len + env->buflen, GFP_KERNEL);
290 	if (!skb)
291 		return NULL;
292 
293 	/* add header */
294 	scratch = skb_put(skb, len);
295 	sprintf(scratch, "%s@%s", action_string, devpath);
296 
297 	skb_put_data(skb, env->buf, env->buflen);
298 
299 	parms = &NETLINK_CB(skb);
300 	parms->creds.uid = GLOBAL_ROOT_UID;
301 	parms->creds.gid = GLOBAL_ROOT_GID;
302 	parms->dst_group = 1;
303 	parms->portid = 0;
304 
305 	return skb;
306 }
307 
uevent_net_broadcast_untagged(struct kobj_uevent_env * env,const char * action_string,const char * devpath)308 static int uevent_net_broadcast_untagged(struct kobj_uevent_env *env,
309 					 const char *action_string,
310 					 const char *devpath)
311 {
312 	struct sk_buff *skb = NULL;
313 	struct uevent_sock *ue_sk;
314 	int retval = 0;
315 
316 	/* send netlink message */
317 	mutex_lock(&uevent_sock_mutex);
318 	list_for_each_entry(ue_sk, &uevent_sock_list, list) {
319 		struct sock *uevent_sock = ue_sk->sk;
320 
321 		if (!netlink_has_listeners(uevent_sock, 1))
322 			continue;
323 
324 		if (!skb) {
325 			retval = -ENOMEM;
326 			skb = alloc_uevent_skb(env, action_string, devpath);
327 			if (!skb)
328 				continue;
329 		}
330 
331 		retval = netlink_broadcast(uevent_sock, skb_get(skb), 0, 1,
332 					   GFP_KERNEL);
333 		/* ENOBUFS should be handled in userspace */
334 		if (retval == -ENOBUFS || retval == -ESRCH)
335 			retval = 0;
336 	}
337 	mutex_unlock(&uevent_sock_mutex);
338 	consume_skb(skb);
339 
340 	return retval;
341 }
342 
uevent_net_broadcast_tagged(struct sock * usk,struct kobj_uevent_env * env,const char * action_string,const char * devpath)343 static int uevent_net_broadcast_tagged(struct sock *usk,
344 				       struct kobj_uevent_env *env,
345 				       const char *action_string,
346 				       const char *devpath)
347 {
348 	struct user_namespace *owning_user_ns = sock_net(usk)->user_ns;
349 	struct sk_buff *skb = NULL;
350 	int ret = 0;
351 
352 	skb = alloc_uevent_skb(env, action_string, devpath);
353 	if (!skb)
354 		return -ENOMEM;
355 
356 	/* fix credentials */
357 	if (owning_user_ns != &init_user_ns) {
358 		struct netlink_skb_parms *parms = &NETLINK_CB(skb);
359 		kuid_t root_uid;
360 		kgid_t root_gid;
361 
362 		/* fix uid */
363 		root_uid = make_kuid(owning_user_ns, 0);
364 		if (uid_valid(root_uid))
365 			parms->creds.uid = root_uid;
366 
367 		/* fix gid */
368 		root_gid = make_kgid(owning_user_ns, 0);
369 		if (gid_valid(root_gid))
370 			parms->creds.gid = root_gid;
371 	}
372 
373 	ret = netlink_broadcast(usk, skb, 0, 1, GFP_KERNEL);
374 	/* ENOBUFS should be handled in userspace */
375 	if (ret == -ENOBUFS || ret == -ESRCH)
376 		ret = 0;
377 
378 	return ret;
379 }
380 #endif
381 
kobject_uevent_net_broadcast(struct kobject * kobj,struct kobj_uevent_env * env,const char * action_string,const char * devpath)382 static int kobject_uevent_net_broadcast(struct kobject *kobj,
383 					struct kobj_uevent_env *env,
384 					const char *action_string,
385 					const char *devpath)
386 {
387 	int ret = 0;
388 
389 #ifdef CONFIG_NET
390 	const struct kobj_ns_type_operations *ops;
391 	const struct ns_common *ns = NULL;
392 
393 	ops = kobj_ns_ops(kobj);
394 	if (!ops && kobj->kset) {
395 		struct kobject *ksobj = &kobj->kset->kobj;
396 
397 		if (ksobj->parent != NULL)
398 			ops = kobj_ns_ops(ksobj->parent);
399 	}
400 
401 	/* kobjects currently only carry network namespace tags and they
402 	 * are the only tag relevant here since we want to decide which
403 	 * network namespaces to broadcast the uevent into.
404 	 */
405 	if (ops && ops->netlink_ns && kobj->ktype->namespace)
406 		if (ops->type == KOBJ_NS_TYPE_NET)
407 			ns = kobj->ktype->namespace(kobj);
408 
409 	if (!ns)
410 		ret = uevent_net_broadcast_untagged(env, action_string,
411 						    devpath);
412 	else {
413 		const struct net *net = container_of(ns, struct net, ns);
414 
415 		ret = uevent_net_broadcast_tagged(net->uevent_sock->sk, env,
416 						  action_string, devpath);
417 	}
418 #endif
419 
420 	return ret;
421 }
422 
zap_modalias_env(struct kobj_uevent_env * env)423 static void zap_modalias_env(struct kobj_uevent_env *env)
424 {
425 	static const char modalias_prefix[] = "MODALIAS=";
426 	size_t len;
427 	int i, j;
428 
429 	for (i = 0; i < env->envp_idx;) {
430 		if (strncmp(env->envp[i], modalias_prefix,
431 			    sizeof(modalias_prefix) - 1)) {
432 			i++;
433 			continue;
434 		}
435 
436 		len = strlen(env->envp[i]) + 1;
437 
438 		if (i != env->envp_idx - 1) {
439 			/* @env->envp[] contains pointers to @env->buf[]
440 			 * with @env->buflen chars, and we are removing
441 			 * variable MODALIAS here pointed by @env->envp[i]
442 			 * with length @len as shown below:
443 			 *
444 			 * 0               @env->buf[]      @env->buflen
445 			 * ---------------------------------------------
446 			 * ^             ^              ^              ^
447 			 * |             |->   @len   <-| target block |
448 			 * @env->envp[0] @env->envp[i]  @env->envp[i + 1]
449 			 *
450 			 * so the "target block" indicated above is moved
451 			 * backward by @len, and its right size is
452 			 * @env->buflen - (@env->envp[i + 1] - @env->envp[0]).
453 			 */
454 			memmove(env->envp[i], env->envp[i + 1],
455 				env->buflen - (env->envp[i + 1] - env->envp[0]));
456 
457 			for (j = i; j < env->envp_idx - 1; j++)
458 				env->envp[j] = env->envp[j + 1] - len;
459 		}
460 
461 		env->envp_idx--;
462 		env->buflen -= len;
463 	}
464 }
465 
466 /**
467  * kobject_uevent_env - send an uevent with environmental data
468  *
469  * @kobj: struct kobject that the action is happening to
470  * @action: action that is happening
471  * @envp_ext: pointer to environmental data
472  *
473  * Returns 0 if kobject_uevent_env() is completed with success or the
474  * corresponding error when it fails.
475  */
kobject_uevent_env(struct kobject * kobj,enum kobject_action action,char * envp_ext[])476 int kobject_uevent_env(struct kobject *kobj, enum kobject_action action,
477 		       char *envp_ext[])
478 {
479 	struct kobj_uevent_env *env;
480 	const char *action_string = kobject_actions[action];
481 	const char *devpath = NULL;
482 	const char *subsystem;
483 	struct kobject *top_kobj;
484 	struct kset *kset;
485 	const struct kset_uevent_ops *uevent_ops;
486 	int i = 0;
487 	int retval = 0;
488 
489 	/*
490 	 * Mark "remove" event done regardless of result, for some subsystems
491 	 * do not want to re-trigger "remove" event via automatic cleanup.
492 	 */
493 	if (action == KOBJ_REMOVE)
494 		kobj->state_remove_uevent_sent = 1;
495 
496 	pr_debug("kobject: '%s' (%p): %s\n",
497 		 kobject_name(kobj), kobj, __func__);
498 
499 	/* search the kset we belong to */
500 	top_kobj = kobj;
501 	while (!top_kobj->kset && top_kobj->parent)
502 		top_kobj = top_kobj->parent;
503 
504 	if (!top_kobj->kset) {
505 		pr_debug("kobject: '%s' (%p): %s: attempted to send uevent "
506 			 "without kset!\n", kobject_name(kobj), kobj,
507 			 __func__);
508 		return -EINVAL;
509 	}
510 
511 	kset = top_kobj->kset;
512 	uevent_ops = kset->uevent_ops;
513 
514 	/* skip the event, if uevent_suppress is set*/
515 	if (kobj->uevent_suppress) {
516 		pr_debug("kobject: '%s' (%p): %s: uevent_suppress "
517 				 "caused the event to drop!\n",
518 				 kobject_name(kobj), kobj, __func__);
519 		return 0;
520 	}
521 	/* skip the event, if the filter returns zero. */
522 	if (uevent_ops && uevent_ops->filter)
523 		if (!uevent_ops->filter(kobj)) {
524 			pr_debug("kobject: '%s' (%p): %s: filter function "
525 				 "caused the event to drop!\n",
526 				 kobject_name(kobj), kobj, __func__);
527 			return 0;
528 		}
529 
530 	/* originating subsystem */
531 	if (uevent_ops && uevent_ops->name)
532 		subsystem = uevent_ops->name(kobj);
533 	else
534 		subsystem = kobject_name(&kset->kobj);
535 	if (!subsystem) {
536 		pr_debug("kobject: '%s' (%p): %s: unset subsystem caused the "
537 			 "event to drop!\n", kobject_name(kobj), kobj,
538 			 __func__);
539 		return 0;
540 	}
541 
542 	/* environment buffer */
543 	env = kzalloc_obj(struct kobj_uevent_env);
544 	if (!env)
545 		return -ENOMEM;
546 
547 	/* complete object path */
548 	devpath = kobject_get_path(kobj, GFP_KERNEL);
549 	if (!devpath) {
550 		retval = -ENOENT;
551 		goto exit;
552 	}
553 
554 	/* default keys */
555 	retval = add_uevent_var(env, "ACTION=%s", action_string);
556 	if (retval)
557 		goto exit;
558 	retval = add_uevent_var(env, "DEVPATH=%s", devpath);
559 	if (retval)
560 		goto exit;
561 	retval = add_uevent_var(env, "SUBSYSTEM=%s", subsystem);
562 	if (retval)
563 		goto exit;
564 
565 	/* keys passed in from the caller */
566 	if (envp_ext) {
567 		for (i = 0; envp_ext[i]; i++) {
568 			retval = add_uevent_var(env, "%s", envp_ext[i]);
569 			if (retval)
570 				goto exit;
571 		}
572 	}
573 
574 	/* let the kset specific function add its stuff */
575 	if (uevent_ops && uevent_ops->uevent) {
576 		retval = uevent_ops->uevent(kobj, env);
577 		if (retval) {
578 			pr_debug("kobject: '%s' (%p): %s: uevent() returned "
579 				 "%d\n", kobject_name(kobj), kobj,
580 				 __func__, retval);
581 			goto exit;
582 		}
583 	}
584 
585 	switch (action) {
586 	case KOBJ_ADD:
587 		/*
588 		 * Mark "add" event so we can make sure we deliver "remove"
589 		 * event to userspace during automatic cleanup. If
590 		 * the object did send an "add" event, "remove" will
591 		 * automatically generated by the core, if not already done
592 		 * by the caller.
593 		 */
594 		kobj->state_add_uevent_sent = 1;
595 		break;
596 
597 	case KOBJ_UNBIND:
598 		zap_modalias_env(env);
599 		break;
600 
601 	default:
602 		break;
603 	}
604 
605 	/* we will send an event, so request a new sequence number */
606 	retval = add_uevent_var(env, "SEQNUM=%llu",
607 				atomic64_inc_return(&uevent_seqnum));
608 	if (retval)
609 		goto exit;
610 
611 	retval = kobject_uevent_net_broadcast(kobj, env, action_string,
612 					      devpath);
613 
614 #ifdef CONFIG_UEVENT_HELPER
615 	/* call uevent_helper, usually only enabled during early boot */
616 	if (uevent_helper[0] && !kobj_usermode_filter(kobj)) {
617 		struct subprocess_info *info;
618 
619 		retval = add_uevent_var(env, "HOME=/");
620 		if (retval)
621 			goto exit;
622 		retval = add_uevent_var(env,
623 					"PATH=/sbin:/bin:/usr/sbin:/usr/bin");
624 		if (retval)
625 			goto exit;
626 		retval = init_uevent_argv(env, subsystem);
627 		if (retval)
628 			goto exit;
629 
630 		retval = -ENOMEM;
631 		info = call_usermodehelper_setup(env->argv[0], env->argv,
632 						 env->envp, GFP_KERNEL,
633 						 NULL, cleanup_uevent_env, env);
634 		if (info) {
635 			retval = call_usermodehelper_exec(info, UMH_NO_WAIT);
636 			env = NULL;	/* freed by cleanup_uevent_env */
637 		}
638 	}
639 #endif
640 
641 exit:
642 	kfree(devpath);
643 	kfree(env);
644 	return retval;
645 }
646 EXPORT_SYMBOL_GPL(kobject_uevent_env);
647 
648 /**
649  * kobject_uevent - notify userspace by sending an uevent
650  *
651  * @kobj: struct kobject that the action is happening to
652  * @action: action that is happening
653  *
654  * Returns 0 if kobject_uevent() is completed with success or the
655  * corresponding error when it fails.
656  */
kobject_uevent(struct kobject * kobj,enum kobject_action action)657 int kobject_uevent(struct kobject *kobj, enum kobject_action action)
658 {
659 	return kobject_uevent_env(kobj, action, NULL);
660 }
661 EXPORT_SYMBOL_GPL(kobject_uevent);
662 
663 /**
664  * add_uevent_var - add key value string to the environment buffer
665  * @env: environment buffer structure
666  * @format: printf format for the key=value pair
667  *
668  * Returns 0 if environment variable was added successfully or -ENOMEM
669  * if no space was available.
670  */
add_uevent_var(struct kobj_uevent_env * env,const char * format,...)671 int add_uevent_var(struct kobj_uevent_env *env, const char *format, ...)
672 {
673 	va_list args;
674 	int len;
675 
676 	if (env->envp_idx >= ARRAY_SIZE(env->envp)) {
677 		WARN(1, KERN_ERR "add_uevent_var: too many keys\n");
678 		return -ENOMEM;
679 	}
680 
681 	va_start(args, format);
682 	len = vsnprintf(&env->buf[env->buflen],
683 			sizeof(env->buf) - env->buflen,
684 			format, args);
685 	va_end(args);
686 
687 	if (len >= (sizeof(env->buf) - env->buflen)) {
688 		WARN(1, KERN_ERR "add_uevent_var: buffer size too small\n");
689 		return -ENOMEM;
690 	}
691 
692 	env->envp[env->envp_idx++] = &env->buf[env->buflen];
693 	env->buflen += len + 1;
694 	return 0;
695 }
696 EXPORT_SYMBOL_GPL(add_uevent_var);
697 
698 #if defined(CONFIG_NET)
uevent_net_broadcast(struct sock * usk,struct sk_buff * skb,struct netlink_ext_ack * extack)699 static int uevent_net_broadcast(struct sock *usk, struct sk_buff *skb,
700 				struct netlink_ext_ack *extack)
701 {
702 	/* u64 to chars: 2^64 - 1 = 21 chars */
703 	char buf[sizeof("SEQNUM=") + 21];
704 	struct sk_buff *skbc;
705 	int ret;
706 
707 	/* bump and prepare sequence number */
708 	ret = snprintf(buf, sizeof(buf), "SEQNUM=%llu",
709 		       atomic64_inc_return(&uevent_seqnum));
710 	if (ret < 0 || (size_t)ret >= sizeof(buf))
711 		return -ENOMEM;
712 	ret++;
713 
714 	/* verify message does not overflow */
715 	if ((skb->len + ret) > UEVENT_BUFFER_SIZE) {
716 		NL_SET_ERR_MSG(extack, "uevent message too big");
717 		return -EINVAL;
718 	}
719 
720 	/* copy skb and extend to accommodate sequence number */
721 	skbc = skb_copy_expand(skb, 0, ret, GFP_KERNEL);
722 	if (!skbc)
723 		return -ENOMEM;
724 
725 	/* append sequence number */
726 	skb_put_data(skbc, buf, ret);
727 
728 	/* remove msg header */
729 	skb_pull(skbc, NLMSG_HDRLEN);
730 
731 	/* set portid 0 to inform userspace message comes from kernel */
732 	NETLINK_CB(skbc).portid = 0;
733 	NETLINK_CB(skbc).dst_group = 1;
734 
735 	ret = netlink_broadcast(usk, skbc, 0, 1, GFP_KERNEL);
736 	/* ENOBUFS should be handled in userspace */
737 	if (ret == -ENOBUFS || ret == -ESRCH)
738 		ret = 0;
739 
740 	return ret;
741 }
742 
uevent_net_rcv_skb(struct sk_buff * skb,struct nlmsghdr * nlh,struct netlink_ext_ack * extack)743 static int uevent_net_rcv_skb(struct sk_buff *skb, struct nlmsghdr *nlh,
744 			      struct netlink_ext_ack *extack)
745 {
746 	struct net *net;
747 	int ret;
748 
749 	if (!nlmsg_data(nlh))
750 		return -EINVAL;
751 
752 	/*
753 	 * Verify that we are allowed to send messages to the target
754 	 * network namespace. The caller must have CAP_SYS_ADMIN in the
755 	 * owning user namespace of the target network namespace.
756 	 */
757 	net = sock_net(NETLINK_CB(skb).sk);
758 	if (!netlink_ns_capable(skb, net->user_ns, CAP_SYS_ADMIN)) {
759 		NL_SET_ERR_MSG(extack, "missing CAP_SYS_ADMIN capability");
760 		return -EPERM;
761 	}
762 
763 	ret = uevent_net_broadcast(net->uevent_sock->sk, skb, extack);
764 
765 	return ret;
766 }
767 
uevent_net_rcv(struct sk_buff * skb)768 static void uevent_net_rcv(struct sk_buff *skb)
769 {
770 	netlink_rcv_skb(skb, &uevent_net_rcv_skb);
771 }
772 
uevent_net_init(struct net * net)773 static int uevent_net_init(struct net *net)
774 {
775 	struct uevent_sock *ue_sk;
776 	struct netlink_kernel_cfg cfg = {
777 		.groups	= 1,
778 		.input = uevent_net_rcv,
779 		.flags	= NL_CFG_F_NONROOT_RECV
780 	};
781 
782 	ue_sk = kzalloc_obj(*ue_sk);
783 	if (!ue_sk)
784 		return -ENOMEM;
785 
786 	ue_sk->sk = netlink_kernel_create(net, NETLINK_KOBJECT_UEVENT, &cfg);
787 	if (!ue_sk->sk) {
788 		pr_err("kobject_uevent: unable to create netlink socket!\n");
789 		kfree(ue_sk);
790 		return -ENODEV;
791 	}
792 
793 	net->uevent_sock = ue_sk;
794 
795 	/* Restrict uevents to initial user namespace. */
796 	if (sock_net(ue_sk->sk)->user_ns == &init_user_ns) {
797 		mutex_lock(&uevent_sock_mutex);
798 		list_add_tail(&ue_sk->list, &uevent_sock_list);
799 		mutex_unlock(&uevent_sock_mutex);
800 	}
801 
802 	return 0;
803 }
804 
uevent_net_exit(struct net * net)805 static void uevent_net_exit(struct net *net)
806 {
807 	struct uevent_sock *ue_sk = net->uevent_sock;
808 
809 	if (sock_net(ue_sk->sk)->user_ns == &init_user_ns) {
810 		mutex_lock(&uevent_sock_mutex);
811 		list_del(&ue_sk->list);
812 		mutex_unlock(&uevent_sock_mutex);
813 	}
814 
815 	netlink_kernel_release(ue_sk->sk);
816 	kfree(ue_sk);
817 }
818 
819 static struct pernet_operations uevent_net_ops = {
820 	.init	= uevent_net_init,
821 	.exit	= uevent_net_exit,
822 };
823 
kobject_uevent_init(void)824 static int __init kobject_uevent_init(void)
825 {
826 	return register_pernet_subsys(&uevent_net_ops);
827 }
828 
829 
830 postcore_initcall(kobject_uevent_init);
831 #endif
832 
833 #ifdef CONFIG_UEVENT_HELPER
834 static const struct ctl_table uevent_helper_sysctl_table[] = {
835 	{
836 		.procname	= "hotplug",
837 		.data		= &uevent_helper,
838 		.maxlen		= UEVENT_HELPER_PATH_LEN,
839 		.mode		= 0644,
840 		.proc_handler	= proc_dostring,
841 	},
842 };
843 
init_uevent_helper_sysctl(void)844 static int __init init_uevent_helper_sysctl(void)
845 {
846 	register_sysctl_init("kernel", uevent_helper_sysctl_table);
847 	return 0;
848 }
849 
850 postcore_initcall(init_uevent_helper_sysctl);
851 #endif
852