xref: /linux/net/sunrpc/rpcb_clnt.c (revision 73e3f0710014fe6d4ed98cfc02292f6121db7558)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * In-kernel rpcbind client supporting versions 2, 3, and 4 of the rpcbind
4  * protocol
5  *
6  * Based on RFC 1833: "Binding Protocols for ONC RPC Version 2" and
7  * RFC 3530: "Network File System (NFS) version 4 Protocol"
8  *
9  * Original: Gilles Quillard, Bull Open Source, 2005 <gilles.quillard@bull.net>
10  * Updated: Chuck Lever, Oracle Corporation, 2007 <chuck.lever@oracle.com>
11  *
12  * Descended from net/sunrpc/pmap_clnt.c,
13  *  Copyright (C) 1996, Olaf Kirch <okir@monad.swb.de>
14  */
15 
16 #include <linux/module.h>
17 
18 #include <linux/types.h>
19 #include <linux/socket.h>
20 #include <linux/un.h>
21 #include <linux/in.h>
22 #include <linux/in6.h>
23 #include <linux/kernel.h>
24 #include <linux/errno.h>
25 #include <linux/mutex.h>
26 #include <linux/slab.h>
27 #include <net/ipv6.h>
28 
29 #include <linux/sunrpc/clnt.h>
30 #include <linux/sunrpc/addr.h>
31 #include <linux/sunrpc/sched.h>
32 #include <linux/sunrpc/xprtsock.h>
33 
34 #include <trace/events/sunrpc.h>
35 
36 #include "netns.h"
37 
38 #define RPCBIND_SOCK_PATHNAME	"/var/run/rpcbind.sock"
39 #define RPCBIND_SOCK_ABSTRACT_NAME "\0/run/rpcbind.sock"
40 
41 #define RPCBIND_PROGRAM		(100000u)
42 #define RPCBIND_PORT		(111u)
43 
44 #define RPCBVERS_2		(2u)
45 #define RPCBVERS_3		(3u)
46 #define RPCBVERS_4		(4u)
47 
48 enum {
49 	RPCBPROC_NULL,
50 	RPCBPROC_SET,
51 	RPCBPROC_UNSET,
52 	RPCBPROC_GETPORT,
53 	RPCBPROC_GETADDR = 3,		/* alias for GETPORT */
54 	RPCBPROC_DUMP,
55 	RPCBPROC_CALLIT,
56 	RPCBPROC_BCAST = 5,		/* alias for CALLIT */
57 	RPCBPROC_GETTIME,
58 	RPCBPROC_UADDR2TADDR,
59 	RPCBPROC_TADDR2UADDR,
60 	RPCBPROC_GETVERSADDR,
61 	RPCBPROC_INDIRECT,
62 	RPCBPROC_GETADDRLIST,
63 	RPCBPROC_GETSTAT,
64 };
65 
66 /*
67  * r_owner
68  *
69  * The "owner" is allowed to unset a service in the rpcbind database.
70  *
71  * For AF_LOCAL SET/UNSET requests, rpcbind treats this string as a
72  * UID which it maps to a local user name via a password lookup.
73  * In all other cases it is ignored.
74  *
75  * For SET/UNSET requests, user space provides a value, even for
76  * network requests, and GETADDR uses an empty string.  We follow
77  * those precedents here.
78  */
79 #define RPCB_OWNER_STRING	"0"
80 #define RPCB_MAXOWNERLEN	sizeof(RPCB_OWNER_STRING)
81 
82 /*
83  * XDR data type sizes
84  */
85 #define RPCB_program_sz		(1)
86 #define RPCB_version_sz		(1)
87 #define RPCB_protocol_sz	(1)
88 #define RPCB_port_sz		(1)
89 #define RPCB_boolean_sz		(1)
90 
91 #define RPCB_netid_sz		(1 + XDR_QUADLEN(RPCBIND_MAXNETIDLEN))
92 #define RPCB_addr_sz		(1 + XDR_QUADLEN(RPCBIND_MAXUADDRLEN))
93 #define RPCB_ownerstring_sz	(1 + XDR_QUADLEN(RPCB_MAXOWNERLEN))
94 
95 /*
96  * XDR argument and result sizes
97  */
98 #define RPCB_mappingargs_sz	(RPCB_program_sz + RPCB_version_sz + \
99 				RPCB_protocol_sz + RPCB_port_sz)
100 #define RPCB_getaddrargs_sz	(RPCB_program_sz + RPCB_version_sz + \
101 				RPCB_netid_sz + RPCB_addr_sz + \
102 				RPCB_ownerstring_sz)
103 
104 #define RPCB_getportres_sz	RPCB_port_sz
105 #define RPCB_setres_sz		RPCB_boolean_sz
106 
107 /*
108  * Note that RFC 1833 does not put any size restrictions on the
109  * address string returned by the remote rpcbind database.
110  */
111 #define RPCB_getaddrres_sz	RPCB_addr_sz
112 
113 static void			rpcb_getport_done(struct rpc_task *, void *);
114 static void			rpcb_map_release(void *data);
115 static const struct rpc_program	rpcb_program;
116 
117 struct rpcbind_args {
118 	struct rpc_xprt *	r_xprt;
119 
120 	u32			r_prog;
121 	u32			r_vers;
122 	u32			r_prot;
123 	unsigned short		r_port;
124 	const char *		r_netid;
125 	const char *		r_addr;
126 	const char *		r_owner;
127 
128 	int			r_status;
129 };
130 
131 static const struct rpc_procinfo rpcb_procedures2[];
132 static const struct rpc_procinfo rpcb_procedures3[];
133 static const struct rpc_procinfo rpcb_procedures4[];
134 
135 struct rpcb_info {
136 	u32			rpc_vers;
137 	const struct rpc_procinfo *rpc_proc;
138 };
139 
140 static const struct rpcb_info rpcb_next_version[];
141 static const struct rpcb_info rpcb_next_version6[];
142 
143 static const struct rpc_call_ops rpcb_getport_ops = {
144 	.rpc_call_done		= rpcb_getport_done,
145 	.rpc_release		= rpcb_map_release,
146 };
147 
rpcb_wake_rpcbind_waiters(struct rpc_xprt * xprt,int status)148 static void rpcb_wake_rpcbind_waiters(struct rpc_xprt *xprt, int status)
149 {
150 	xprt_clear_binding(xprt);
151 	rpc_wake_up_status(&xprt->binding, status);
152 }
153 
rpcb_map_release(void * data)154 static void rpcb_map_release(void *data)
155 {
156 	struct rpcbind_args *map = data;
157 
158 	rpcb_wake_rpcbind_waiters(map->r_xprt, map->r_status);
159 	xprt_put(map->r_xprt);
160 	kfree(map->r_addr);
161 	kfree(map);
162 }
163 
rpcb_get_local(struct net * net)164 static int rpcb_get_local(struct net *net)
165 {
166 	int cnt;
167 	struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
168 
169 	spin_lock(&sn->rpcb_clnt_lock);
170 	if (sn->rpcb_users)
171 		sn->rpcb_users++;
172 	cnt = sn->rpcb_users;
173 	spin_unlock(&sn->rpcb_clnt_lock);
174 
175 	return cnt;
176 }
177 
rpcb_put_local(struct net * net)178 void rpcb_put_local(struct net *net)
179 {
180 	struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
181 	struct rpc_clnt *clnt = sn->rpcb_local_clnt;
182 	struct rpc_clnt *clnt4 = sn->rpcb_local_clnt4;
183 	int shutdown = 0;
184 
185 	spin_lock(&sn->rpcb_clnt_lock);
186 	if (sn->rpcb_users) {
187 		if (--sn->rpcb_users == 0) {
188 			sn->rpcb_local_clnt = NULL;
189 			sn->rpcb_local_clnt4 = NULL;
190 		}
191 		shutdown = !sn->rpcb_users;
192 	}
193 	spin_unlock(&sn->rpcb_clnt_lock);
194 
195 	if (shutdown) {
196 		/*
197 		 * cleanup_rpcb_clnt - remove xprtsock's sysctls, unregister
198 		 */
199 		if (clnt4)
200 			rpc_shutdown_client(clnt4);
201 		if (clnt)
202 			rpc_shutdown_client(clnt);
203 	}
204 }
205 
rpcb_set_local(struct net * net,struct rpc_clnt * clnt,struct rpc_clnt * clnt4,bool is_af_local)206 static void rpcb_set_local(struct net *net, struct rpc_clnt *clnt,
207 			struct rpc_clnt *clnt4,
208 			bool is_af_local)
209 {
210 	struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
211 
212 	/* Protected by rpcb_create_local_mutex */
213 	sn->rpcb_local_clnt = clnt;
214 	sn->rpcb_local_clnt4 = clnt4;
215 	sn->rpcb_is_af_local = is_af_local ? 1 : 0;
216 	smp_wmb();
217 	sn->rpcb_users = 1;
218 }
219 
220 /* Evaluate to actual length of the `sockaddr_un' structure.  */
221 # define SUN_LEN(ptr) (offsetof(struct sockaddr_un, sun_path)		\
222 		      + 1 + strlen((ptr)->sun_path + 1))
223 
224 /*
225  * Returns zero on success, otherwise a negative errno value
226  * is returned.
227  */
rpcb_create_af_local(struct net * net,const struct sockaddr_un * addr)228 static int rpcb_create_af_local(struct net *net,
229 				const struct sockaddr_un *addr)
230 {
231 	struct rpc_create_args args = {
232 		.net		= net,
233 		.protocol	= XPRT_TRANSPORT_LOCAL,
234 		.address	= (struct sockaddr *)addr,
235 		.addrsize	= SUN_LEN(addr),
236 		.servername	= "localhost",
237 		.program	= &rpcb_program,
238 		.version	= RPCBVERS_2,
239 		.authflavor	= RPC_AUTH_NULL,
240 		.cred		= current_cred(),
241 		/*
242 		 * We turn off the idle timeout to prevent the kernel
243 		 * from automatically disconnecting the socket.
244 		 * Otherwise, we'd have to cache the mount namespace
245 		 * of the caller and somehow pass that to the socket
246 		 * reconnect code.
247 		 */
248 		.flags		= RPC_CLNT_CREATE_NO_IDLE_TIMEOUT,
249 	};
250 	struct rpc_clnt *clnt, *clnt4;
251 	int result = 0;
252 
253 	/*
254 	 * Because we requested an RPC PING at transport creation time,
255 	 * this works only if the user space portmapper is rpcbind, and
256 	 * it's listening on AF_LOCAL on the named socket.
257 	 */
258 	clnt = rpc_create(&args);
259 	if (IS_ERR(clnt)) {
260 		result = PTR_ERR(clnt);
261 		goto out;
262 	}
263 
264 	clnt4 = rpc_bind_new_program(clnt, &rpcb_program, RPCBVERS_4);
265 	if (IS_ERR(clnt4))
266 		clnt4 = NULL;
267 
268 	rpcb_set_local(net, clnt, clnt4, true);
269 
270 out:
271 	return result;
272 }
273 
rpcb_create_local_abstract(struct net * net)274 static int rpcb_create_local_abstract(struct net *net)
275 {
276 	static const struct sockaddr_un rpcb_localaddr_abstract = {
277 		.sun_family		= AF_LOCAL,
278 		.sun_path		= RPCBIND_SOCK_ABSTRACT_NAME,
279 	};
280 
281 	return rpcb_create_af_local(net, &rpcb_localaddr_abstract);
282 }
283 
rpcb_create_local_unix(struct net * net)284 static int rpcb_create_local_unix(struct net *net)
285 {
286 	static const struct sockaddr_un rpcb_localaddr_unix = {
287 		.sun_family		= AF_LOCAL,
288 		.sun_path		= RPCBIND_SOCK_PATHNAME,
289 	};
290 
291 	return rpcb_create_af_local(net, &rpcb_localaddr_unix);
292 }
293 
294 /*
295  * Returns zero on success, otherwise a negative errno value
296  * is returned.
297  */
rpcb_create_local_net(struct net * net)298 static int rpcb_create_local_net(struct net *net)
299 {
300 	static const struct sockaddr_in rpcb_inaddr_loopback = {
301 		.sin_family		= AF_INET,
302 		.sin_addr.s_addr	= htonl(INADDR_LOOPBACK),
303 		.sin_port		= htons(RPCBIND_PORT),
304 	};
305 	struct rpc_create_args args = {
306 		.net		= net,
307 		.protocol	= XPRT_TRANSPORT_TCP,
308 		.address	= (struct sockaddr *)&rpcb_inaddr_loopback,
309 		.addrsize	= sizeof(rpcb_inaddr_loopback),
310 		.servername	= "localhost",
311 		.program	= &rpcb_program,
312 		.version	= RPCBVERS_2,
313 		.authflavor	= RPC_AUTH_UNIX,
314 		.cred		= current_cred(),
315 		.flags		= RPC_CLNT_CREATE_NOPING,
316 	};
317 	struct rpc_clnt *clnt, *clnt4;
318 	int result = 0;
319 
320 	clnt = rpc_create(&args);
321 	if (IS_ERR(clnt)) {
322 		result = PTR_ERR(clnt);
323 		goto out;
324 	}
325 
326 	/*
327 	 * This results in an RPC ping.  On systems running portmapper,
328 	 * the v4 ping will fail.  Proceed anyway, but disallow rpcb
329 	 * v4 upcalls.
330 	 */
331 	clnt4 = rpc_bind_new_program(clnt, &rpcb_program, RPCBVERS_4);
332 	if (IS_ERR(clnt4))
333 		clnt4 = NULL;
334 
335 	rpcb_set_local(net, clnt, clnt4, false);
336 
337 out:
338 	return result;
339 }
340 
341 /*
342  * Returns zero on success, otherwise a negative errno value
343  * is returned.
344  */
rpcb_create_local(struct net * net)345 int rpcb_create_local(struct net *net)
346 {
347 	static DEFINE_MUTEX(rpcb_create_local_mutex);
348 	int result = 0;
349 
350 	if (rpcb_get_local(net))
351 		return result;
352 
353 	mutex_lock(&rpcb_create_local_mutex);
354 	if (rpcb_get_local(net))
355 		goto out;
356 
357 	if (rpcb_create_local_abstract(net) != 0 &&
358 	    rpcb_create_local_unix(net) != 0)
359 		result = rpcb_create_local_net(net);
360 
361 out:
362 	mutex_unlock(&rpcb_create_local_mutex);
363 	return result;
364 }
365 
rpcb_create(struct net * net,const char * nodename,const char * hostname,struct sockaddr * srvaddr,size_t salen,int proto,u32 version,const struct cred * cred,const struct rpc_timeout * timeo)366 static struct rpc_clnt *rpcb_create(struct net *net, const char *nodename,
367 				    const char *hostname,
368 				    struct sockaddr *srvaddr, size_t salen,
369 				    int proto, u32 version,
370 				    const struct cred *cred,
371 				    const struct rpc_timeout *timeo)
372 {
373 	struct rpc_create_args args = {
374 		.net		= net,
375 		.protocol	= proto,
376 		.address	= srvaddr,
377 		.addrsize	= salen,
378 		.timeout	= timeo,
379 		.servername	= hostname,
380 		.nodename	= nodename,
381 		.program	= &rpcb_program,
382 		.version	= version,
383 		.authflavor	= RPC_AUTH_UNIX,
384 		.cred		= cred,
385 		.flags		= (RPC_CLNT_CREATE_NOPING |
386 					RPC_CLNT_CREATE_NONPRIVPORT),
387 	};
388 
389 	switch (srvaddr->sa_family) {
390 	case AF_INET:
391 		((struct sockaddr_in *)srvaddr)->sin_port = htons(RPCBIND_PORT);
392 		break;
393 	case AF_INET6:
394 		((struct sockaddr_in6 *)srvaddr)->sin6_port = htons(RPCBIND_PORT);
395 		break;
396 	default:
397 		return ERR_PTR(-EAFNOSUPPORT);
398 	}
399 
400 	return rpc_create(&args);
401 }
402 
rpcb_register_call(struct sunrpc_net * sn,struct rpc_clnt * clnt,struct rpc_message * msg,bool is_set)403 static int rpcb_register_call(struct sunrpc_net *sn, struct rpc_clnt *clnt, struct rpc_message *msg, bool is_set)
404 {
405 	int flags = RPC_TASK_NOCONNECT;
406 	int error, result = 0;
407 
408 	if (is_set || !sn->rpcb_is_af_local)
409 		flags = RPC_TASK_SOFTCONN;
410 	msg->rpc_resp = &result;
411 
412 	error = rpc_call_sync(clnt, msg, flags);
413 	if (error < 0)
414 		return error;
415 
416 	if (!result)
417 		return -EACCES;
418 	return 0;
419 }
420 
421 /**
422  * rpcb_register - set or unset a port registration with the local rpcbind svc
423  * @net: target network namespace
424  * @prog: RPC program number to bind
425  * @vers: RPC version number to bind
426  * @prot: transport protocol to register
427  * @port: port value to register
428  *
429  * Returns zero if the registration request was dispatched successfully
430  * and the rpcbind daemon returned success.  Otherwise, returns an errno
431  * value that reflects the nature of the error (request could not be
432  * dispatched, timed out, or rpcbind returned an error).
433  *
434  * RPC services invoke this function to advertise their contact
435  * information via the system's rpcbind daemon.  RPC services
436  * invoke this function once for each [program, version, transport]
437  * tuple they wish to advertise.
438  *
439  * Callers may also unregister RPC services that are no longer
440  * available by setting the passed-in port to zero.  This removes
441  * all registered transports for [program, version] from the local
442  * rpcbind database.
443  *
444  * This function uses rpcbind protocol version 2 to contact the
445  * local rpcbind daemon.
446  *
447  * Registration works over both AF_INET and AF_INET6, and services
448  * registered via this function are advertised as available for any
449  * address.  If the local rpcbind daemon is listening on AF_INET6,
450  * services registered via this function will be advertised on
451  * IN6ADDR_ANY (ie available for all AF_INET and AF_INET6
452  * addresses).
453  */
rpcb_register(struct net * net,u32 prog,u32 vers,int prot,unsigned short port)454 int rpcb_register(struct net *net, u32 prog, u32 vers, int prot, unsigned short port)
455 {
456 	struct rpcbind_args map = {
457 		.r_prog		= prog,
458 		.r_vers		= vers,
459 		.r_prot		= prot,
460 		.r_port		= port,
461 	};
462 	struct rpc_message msg = {
463 		.rpc_argp	= &map,
464 	};
465 	struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
466 	bool is_set = false;
467 
468 	trace_pmap_register(prog, vers, prot, port);
469 
470 	msg.rpc_proc = &rpcb_procedures2[RPCBPROC_UNSET];
471 	if (port != 0) {
472 		msg.rpc_proc = &rpcb_procedures2[RPCBPROC_SET];
473 		is_set = true;
474 	}
475 
476 	return rpcb_register_call(sn, sn->rpcb_local_clnt, &msg, is_set);
477 }
478 
479 /*
480  * Fill in AF_INET family-specific arguments to register
481  */
rpcb_register_inet4(struct sunrpc_net * sn,const struct sockaddr * sap,struct rpc_message * msg)482 static int rpcb_register_inet4(struct sunrpc_net *sn,
483 			       const struct sockaddr *sap,
484 			       struct rpc_message *msg)
485 {
486 	const struct sockaddr_in *sin = (const struct sockaddr_in *)sap;
487 	struct rpcbind_args *map = msg->rpc_argp;
488 	unsigned short port = ntohs(sin->sin_port);
489 	bool is_set = false;
490 	int result;
491 
492 	map->r_addr = rpc_sockaddr2uaddr(sap, GFP_KERNEL);
493 	if (!map->r_addr)
494 		return -ENOMEM;
495 
496 	msg->rpc_proc = &rpcb_procedures4[RPCBPROC_UNSET];
497 	if (port != 0) {
498 		msg->rpc_proc = &rpcb_procedures4[RPCBPROC_SET];
499 		is_set = true;
500 	}
501 
502 	result = rpcb_register_call(sn, sn->rpcb_local_clnt4, msg, is_set);
503 	kfree(map->r_addr);
504 	return result;
505 }
506 
507 /*
508  * Fill in AF_INET6 family-specific arguments to register
509  */
rpcb_register_inet6(struct sunrpc_net * sn,const struct sockaddr * sap,struct rpc_message * msg)510 static int rpcb_register_inet6(struct sunrpc_net *sn,
511 			       const struct sockaddr *sap,
512 			       struct rpc_message *msg)
513 {
514 	const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sap;
515 	struct rpcbind_args *map = msg->rpc_argp;
516 	unsigned short port = ntohs(sin6->sin6_port);
517 	bool is_set = false;
518 	int result;
519 
520 	map->r_addr = rpc_sockaddr2uaddr(sap, GFP_KERNEL);
521 	if (!map->r_addr)
522 		return -ENOMEM;
523 
524 	msg->rpc_proc = &rpcb_procedures4[RPCBPROC_UNSET];
525 	if (port != 0) {
526 		msg->rpc_proc = &rpcb_procedures4[RPCBPROC_SET];
527 		is_set = true;
528 	}
529 
530 	result = rpcb_register_call(sn, sn->rpcb_local_clnt4, msg, is_set);
531 	kfree(map->r_addr);
532 	return result;
533 }
534 
rpcb_unregister_all_protofamilies(struct sunrpc_net * sn,struct rpc_message * msg)535 static int rpcb_unregister_all_protofamilies(struct sunrpc_net *sn,
536 					     struct rpc_message *msg)
537 {
538 	struct rpcbind_args *map = msg->rpc_argp;
539 
540 	trace_rpcb_unregister(map->r_prog, map->r_vers, map->r_netid);
541 
542 	map->r_addr = "";
543 	msg->rpc_proc = &rpcb_procedures4[RPCBPROC_UNSET];
544 
545 	return rpcb_register_call(sn, sn->rpcb_local_clnt4, msg, false);
546 }
547 
548 /**
549  * rpcb_v4_register - set or unset a port registration with the local rpcbind
550  * @net: target network namespace
551  * @program: RPC program number of service to (un)register
552  * @version: RPC version number of service to (un)register
553  * @address: address family, IP address, and port to (un)register
554  * @netid: netid of transport protocol to (un)register
555  *
556  * Returns zero if the registration request was dispatched successfully
557  * and the rpcbind daemon returned success.  Otherwise, returns an errno
558  * value that reflects the nature of the error (request could not be
559  * dispatched, timed out, or rpcbind returned an error).
560  *
561  * RPC services invoke this function to advertise their contact
562  * information via the system's rpcbind daemon.  RPC services
563  * invoke this function once for each [program, version, address,
564  * netid] tuple they wish to advertise.
565  *
566  * Callers may also unregister RPC services that are registered at a
567  * specific address by setting the port number in @address to zero.
568  * They may unregister all registered protocol families at once for
569  * a service by passing a NULL @address argument.  If @netid is ""
570  * then all netids for [program, version, address] are unregistered.
571  *
572  * This function uses rpcbind protocol version 4 to contact the
573  * local rpcbind daemon.  The local rpcbind daemon must support
574  * version 4 of the rpcbind protocol in order for these functions
575  * to register a service successfully.
576  *
577  * Supported netids include "udp" and "tcp" for UDP and TCP over
578  * IPv4, and "udp6" and "tcp6" for UDP and TCP over IPv6,
579  * respectively.
580  *
581  * The contents of @address determine the address family and the
582  * port to be registered.  The usual practice is to pass INADDR_ANY
583  * as the raw address, but specifying a non-zero address is also
584  * supported by this API if the caller wishes to advertise an RPC
585  * service on a specific network interface.
586  *
587  * Note that passing in INADDR_ANY does not create the same service
588  * registration as IN6ADDR_ANY.  The former advertises an RPC
589  * service on any IPv4 address, but not on IPv6.  The latter
590  * advertises the service on all IPv4 and IPv6 addresses.
591  */
rpcb_v4_register(struct net * net,const u32 program,const u32 version,const struct sockaddr * address,const char * netid)592 int rpcb_v4_register(struct net *net, const u32 program, const u32 version,
593 		     const struct sockaddr *address, const char *netid)
594 {
595 	struct rpcbind_args map = {
596 		.r_prog		= program,
597 		.r_vers		= version,
598 		.r_netid	= netid,
599 		.r_owner	= RPCB_OWNER_STRING,
600 	};
601 	struct rpc_message msg = {
602 		.rpc_argp	= &map,
603 	};
604 	struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
605 
606 	if (sn->rpcb_local_clnt4 == NULL)
607 		return -EPROTONOSUPPORT;
608 
609 	if (address == NULL)
610 		return rpcb_unregister_all_protofamilies(sn, &msg);
611 
612 	trace_rpcb_register(map.r_prog, map.r_vers, map.r_addr, map.r_netid);
613 
614 	switch (address->sa_family) {
615 	case AF_INET:
616 		return rpcb_register_inet4(sn, address, &msg);
617 	case AF_INET6:
618 		return rpcb_register_inet6(sn, address, &msg);
619 	}
620 
621 	return -EAFNOSUPPORT;
622 }
623 
rpcb_call_async(struct rpc_clnt * rpcb_clnt,struct rpcbind_args * map,const struct rpc_procinfo * proc)624 static struct rpc_task *rpcb_call_async(struct rpc_clnt *rpcb_clnt,
625 		struct rpcbind_args *map, const struct rpc_procinfo *proc)
626 {
627 	struct rpc_message msg = {
628 		.rpc_proc = proc,
629 		.rpc_argp = map,
630 		.rpc_resp = map,
631 	};
632 	struct rpc_task_setup task_setup_data = {
633 		.rpc_client = rpcb_clnt,
634 		.rpc_message = &msg,
635 		.callback_ops = &rpcb_getport_ops,
636 		.callback_data = map,
637 		.flags = RPC_TASK_ASYNC | RPC_TASK_SOFTCONN,
638 	};
639 
640 	return rpc_run_task(&task_setup_data);
641 }
642 
643 /*
644  * In the case where rpc clients have been cloned, we want to make
645  * sure that we use the program number/version etc of the actual
646  * owner of the xprt. To do so, we walk back up the tree of parents
647  * to find whoever created the transport and/or whoever has the
648  * autobind flag set.
649  */
rpcb_find_transport_owner(struct rpc_clnt * clnt)650 static struct rpc_clnt *rpcb_find_transport_owner(struct rpc_clnt *clnt)
651 {
652 	struct rpc_clnt *parent = clnt->cl_parent;
653 	struct rpc_xprt_switch *xps = rcu_access_pointer(clnt->cl_xpi.xpi_xpswitch);
654 
655 	while (parent != clnt) {
656 		if (rcu_access_pointer(parent->cl_xpi.xpi_xpswitch) != xps)
657 			break;
658 		if (clnt->cl_autobind)
659 			break;
660 		clnt = parent;
661 		parent = parent->cl_parent;
662 	}
663 	return clnt;
664 }
665 
666 /**
667  * rpcb_getport_async - obtain the port for a given RPC service on a given host
668  * @task: task that is waiting for portmapper request
669  *
670  * This one can be called for an ongoing RPC request, and can be used in
671  * an async (rpciod) context.
672  */
rpcb_getport_async(struct rpc_task * task)673 void rpcb_getport_async(struct rpc_task *task)
674 {
675 	struct rpc_clnt *clnt;
676 	const struct rpc_procinfo *proc;
677 	u32 bind_version;
678 	struct rpc_xprt *xprt;
679 	struct rpc_clnt	*rpcb_clnt;
680 	struct rpcbind_args *map;
681 	struct rpc_task	*child;
682 	struct sockaddr_storage addr;
683 	struct sockaddr *sap = (struct sockaddr *)&addr;
684 	size_t salen;
685 	int status;
686 
687 	rcu_read_lock();
688 	clnt = rpcb_find_transport_owner(task->tk_client);
689 	rcu_read_unlock();
690 	xprt = xprt_get(task->tk_xprt);
691 
692 	/* Put self on the wait queue to ensure we get notified if
693 	 * some other task is already attempting to bind the port */
694 	rpc_sleep_on_timeout(&xprt->binding, task,
695 			NULL, jiffies + xprt->bind_timeout);
696 
697 	if (xprt_test_and_set_binding(xprt)) {
698 		xprt_put(xprt);
699 		return;
700 	}
701 
702 	/* Someone else may have bound if we slept */
703 	if (xprt_bound(xprt)) {
704 		status = 0;
705 		goto bailout_nofree;
706 	}
707 
708 	/* Parent transport's destination address */
709 	salen = rpc_peeraddr(clnt, sap, sizeof(addr));
710 
711 	/* Don't ever use rpcbind v2 for AF_INET6 requests */
712 	switch (sap->sa_family) {
713 	case AF_INET:
714 		proc = rpcb_next_version[xprt->bind_index].rpc_proc;
715 		bind_version = rpcb_next_version[xprt->bind_index].rpc_vers;
716 		break;
717 	case AF_INET6:
718 		proc = rpcb_next_version6[xprt->bind_index].rpc_proc;
719 		bind_version = rpcb_next_version6[xprt->bind_index].rpc_vers;
720 		break;
721 	default:
722 		status = -EAFNOSUPPORT;
723 		goto bailout_nofree;
724 	}
725 	if (proc == NULL) {
726 		xprt->bind_index = 0;
727 		status = -EPFNOSUPPORT;
728 		goto bailout_nofree;
729 	}
730 
731 	trace_rpcb_getport(clnt, task, bind_version);
732 
733 	rpcb_clnt = rpcb_create(xprt->xprt_net,
734 				clnt->cl_nodename,
735 				xprt->servername, sap, salen,
736 				xprt->prot, bind_version,
737 				clnt->cl_cred,
738 				task->tk_client->cl_timeout);
739 	if (IS_ERR(rpcb_clnt)) {
740 		status = PTR_ERR(rpcb_clnt);
741 		goto bailout_nofree;
742 	}
743 
744 	map = kzalloc_obj(struct rpcbind_args, rpc_task_gfp_mask());
745 	if (!map) {
746 		status = -ENOMEM;
747 		goto bailout_release_client;
748 	}
749 	map->r_prog = clnt->cl_prog;
750 	map->r_vers = clnt->cl_vers;
751 	map->r_prot = xprt->prot;
752 	map->r_port = 0;
753 	map->r_xprt = xprt;
754 	map->r_status = -EIO;
755 
756 	switch (bind_version) {
757 	case RPCBVERS_4:
758 	case RPCBVERS_3:
759 		map->r_netid = xprt->address_strings[RPC_DISPLAY_NETID];
760 		map->r_addr = rpc_sockaddr2uaddr(sap, rpc_task_gfp_mask());
761 		if (!map->r_addr) {
762 			status = -ENOMEM;
763 			goto bailout_free_args;
764 		}
765 		map->r_owner = "";
766 		break;
767 	case RPCBVERS_2:
768 		map->r_addr = NULL;
769 		break;
770 	default:
771 		BUG();
772 	}
773 
774 	child = rpcb_call_async(rpcb_clnt, map, proc);
775 	rpc_release_client(rpcb_clnt);
776 	if (IS_ERR(child)) {
777 		/* rpcb_map_release() has freed the arguments */
778 		return;
779 	}
780 
781 	xprt->stat.bind_count++;
782 	rpc_put_task(child);
783 	return;
784 
785 bailout_free_args:
786 	kfree(map);
787 bailout_release_client:
788 	rpc_release_client(rpcb_clnt);
789 bailout_nofree:
790 	rpcb_wake_rpcbind_waiters(xprt, status);
791 	task->tk_status = status;
792 	xprt_put(xprt);
793 }
794 EXPORT_SYMBOL_GPL(rpcb_getport_async);
795 
796 /*
797  * Rpcbind child task calls this callback via tk_exit.
798  */
rpcb_getport_done(struct rpc_task * child,void * data)799 static void rpcb_getport_done(struct rpc_task *child, void *data)
800 {
801 	struct rpcbind_args *map = data;
802 	struct rpc_xprt *xprt = map->r_xprt;
803 
804 	map->r_status = child->tk_status;
805 
806 	/* Garbage reply: retry with a lesser rpcbind version */
807 	if (map->r_status == -EIO)
808 		map->r_status = -EPROTONOSUPPORT;
809 
810 	/* rpcbind server doesn't support this rpcbind protocol version */
811 	if (map->r_status == -EPROTONOSUPPORT)
812 		xprt->bind_index++;
813 
814 	if (map->r_status < 0) {
815 		/* rpcbind server not available on remote host? */
816 		map->r_port = 0;
817 
818 	} else if (map->r_port == 0) {
819 		/* Requested RPC service wasn't registered on remote host */
820 		map->r_status = -EACCES;
821 	} else {
822 		/* Succeeded */
823 		map->r_status = 0;
824 	}
825 
826 	trace_rpcb_setport(child, map->r_status, map->r_port);
827 	if (map->r_port) {
828 		xprt->ops->set_port(xprt, map->r_port);
829 		xprt_set_bound(xprt);
830 	}
831 }
832 
833 /*
834  * XDR functions for rpcbind
835  */
836 
rpcb_enc_mapping(struct rpc_rqst * req,struct xdr_stream * xdr,const void * data)837 static void rpcb_enc_mapping(struct rpc_rqst *req, struct xdr_stream *xdr,
838 			     const void *data)
839 {
840 	const struct rpcbind_args *rpcb = data;
841 	__be32 *p;
842 
843 	p = xdr_reserve_space(xdr, RPCB_mappingargs_sz << 2);
844 	*p++ = cpu_to_be32(rpcb->r_prog);
845 	*p++ = cpu_to_be32(rpcb->r_vers);
846 	*p++ = cpu_to_be32(rpcb->r_prot);
847 	*p   = cpu_to_be32(rpcb->r_port);
848 }
849 
rpcb_dec_getport(struct rpc_rqst * req,struct xdr_stream * xdr,void * data)850 static int rpcb_dec_getport(struct rpc_rqst *req, struct xdr_stream *xdr,
851 			    void *data)
852 {
853 	struct rpcbind_args *rpcb = data;
854 	unsigned long port;
855 	__be32 *p;
856 
857 	rpcb->r_port = 0;
858 
859 	p = xdr_inline_decode(xdr, 4);
860 	if (unlikely(p == NULL))
861 		return -EIO;
862 
863 	port = be32_to_cpup(p);
864 	if (unlikely(port > USHRT_MAX))
865 		return -EIO;
866 
867 	rpcb->r_port = port;
868 	return 0;
869 }
870 
rpcb_dec_set(struct rpc_rqst * req,struct xdr_stream * xdr,void * data)871 static int rpcb_dec_set(struct rpc_rqst *req, struct xdr_stream *xdr,
872 			void *data)
873 {
874 	unsigned int *boolp = data;
875 	__be32 *p;
876 
877 	p = xdr_inline_decode(xdr, 4);
878 	if (unlikely(p == NULL))
879 		return -EIO;
880 
881 	*boolp = 0;
882 	if (*p != xdr_zero)
883 		*boolp = 1;
884 	return 0;
885 }
886 
encode_rpcb_string(struct xdr_stream * xdr,const char * string,const u32 maxstrlen)887 static void encode_rpcb_string(struct xdr_stream *xdr, const char *string,
888 			       const u32 maxstrlen)
889 {
890 	__be32 *p;
891 	u32 len;
892 
893 	len = strlen(string);
894 	WARN_ON_ONCE(len > maxstrlen);
895 	if (len > maxstrlen)
896 		/* truncate and hope for the best */
897 		len = maxstrlen;
898 	p = xdr_reserve_space(xdr, 4 + len);
899 	xdr_encode_opaque(p, string, len);
900 }
901 
rpcb_enc_getaddr(struct rpc_rqst * req,struct xdr_stream * xdr,const void * data)902 static void rpcb_enc_getaddr(struct rpc_rqst *req, struct xdr_stream *xdr,
903 			     const void *data)
904 {
905 	const struct rpcbind_args *rpcb = data;
906 	__be32 *p;
907 
908 	p = xdr_reserve_space(xdr, (RPCB_program_sz + RPCB_version_sz) << 2);
909 	*p++ = cpu_to_be32(rpcb->r_prog);
910 	*p = cpu_to_be32(rpcb->r_vers);
911 
912 	encode_rpcb_string(xdr, rpcb->r_netid, RPCBIND_MAXNETIDLEN);
913 	encode_rpcb_string(xdr, rpcb->r_addr, RPCBIND_MAXUADDRLEN);
914 	encode_rpcb_string(xdr, rpcb->r_owner, RPCB_MAXOWNERLEN);
915 }
916 
rpcb_dec_getaddr(struct rpc_rqst * req,struct xdr_stream * xdr,void * data)917 static int rpcb_dec_getaddr(struct rpc_rqst *req, struct xdr_stream *xdr,
918 			    void *data)
919 {
920 	struct rpcbind_args *rpcb = data;
921 	struct sockaddr_storage address;
922 	struct sockaddr *sap = (struct sockaddr *)&address;
923 	__be32 *p;
924 	u32 len;
925 
926 	rpcb->r_port = 0;
927 
928 	p = xdr_inline_decode(xdr, 4);
929 	if (unlikely(p == NULL))
930 		goto out_fail;
931 	len = be32_to_cpup(p);
932 
933 	/*
934 	 * If the returned universal address is a null string,
935 	 * the requested RPC service was not registered.
936 	 */
937 	if (len == 0)
938 		return 0;
939 
940 	if (unlikely(len > RPCBIND_MAXUADDRLEN))
941 		goto out_fail;
942 
943 	p = xdr_inline_decode(xdr, len);
944 	if (unlikely(p == NULL))
945 		goto out_fail;
946 
947 	if (rpc_uaddr2sockaddr(req->rq_xprt->xprt_net, (char *)p, len,
948 				sap, sizeof(address)) == 0)
949 		goto out_fail;
950 	rpcb->r_port = rpc_get_port(sap);
951 
952 	return 0;
953 
954 out_fail:
955 	return -EIO;
956 }
957 
958 /*
959  * Not all rpcbind procedures described in RFC 1833 are implemented
960  * since the Linux kernel RPC code requires only these.
961  */
962 
963 static const struct rpc_procinfo rpcb_procedures2[] = {
964 	[RPCBPROC_SET] = {
965 		.p_proc		= RPCBPROC_SET,
966 		.p_encode	= rpcb_enc_mapping,
967 		.p_decode	= rpcb_dec_set,
968 		.p_arglen	= RPCB_mappingargs_sz,
969 		.p_replen	= RPCB_setres_sz,
970 		.p_statidx	= RPCBPROC_SET,
971 		.p_timer	= 0,
972 		.p_name		= "SET",
973 	},
974 	[RPCBPROC_UNSET] = {
975 		.p_proc		= RPCBPROC_UNSET,
976 		.p_encode	= rpcb_enc_mapping,
977 		.p_decode	= rpcb_dec_set,
978 		.p_arglen	= RPCB_mappingargs_sz,
979 		.p_replen	= RPCB_setres_sz,
980 		.p_statidx	= RPCBPROC_UNSET,
981 		.p_timer	= 0,
982 		.p_name		= "UNSET",
983 	},
984 	[RPCBPROC_GETPORT] = {
985 		.p_proc		= RPCBPROC_GETPORT,
986 		.p_encode	= rpcb_enc_mapping,
987 		.p_decode	= rpcb_dec_getport,
988 		.p_arglen	= RPCB_mappingargs_sz,
989 		.p_replen	= RPCB_getportres_sz,
990 		.p_statidx	= RPCBPROC_GETPORT,
991 		.p_timer	= 0,
992 		.p_name		= "GETPORT",
993 	},
994 };
995 
996 static const struct rpc_procinfo rpcb_procedures3[] = {
997 	[RPCBPROC_SET] = {
998 		.p_proc		= RPCBPROC_SET,
999 		.p_encode	= rpcb_enc_getaddr,
1000 		.p_decode	= rpcb_dec_set,
1001 		.p_arglen	= RPCB_getaddrargs_sz,
1002 		.p_replen	= RPCB_setres_sz,
1003 		.p_statidx	= RPCBPROC_SET,
1004 		.p_timer	= 0,
1005 		.p_name		= "SET",
1006 	},
1007 	[RPCBPROC_UNSET] = {
1008 		.p_proc		= RPCBPROC_UNSET,
1009 		.p_encode	= rpcb_enc_getaddr,
1010 		.p_decode	= rpcb_dec_set,
1011 		.p_arglen	= RPCB_getaddrargs_sz,
1012 		.p_replen	= RPCB_setres_sz,
1013 		.p_statidx	= RPCBPROC_UNSET,
1014 		.p_timer	= 0,
1015 		.p_name		= "UNSET",
1016 	},
1017 	[RPCBPROC_GETADDR] = {
1018 		.p_proc		= RPCBPROC_GETADDR,
1019 		.p_encode	= rpcb_enc_getaddr,
1020 		.p_decode	= rpcb_dec_getaddr,
1021 		.p_arglen	= RPCB_getaddrargs_sz,
1022 		.p_replen	= RPCB_getaddrres_sz,
1023 		.p_statidx	= RPCBPROC_GETADDR,
1024 		.p_timer	= 0,
1025 		.p_name		= "GETADDR",
1026 	},
1027 };
1028 
1029 static const struct rpc_procinfo rpcb_procedures4[] = {
1030 	[RPCBPROC_SET] = {
1031 		.p_proc		= RPCBPROC_SET,
1032 		.p_encode	= rpcb_enc_getaddr,
1033 		.p_decode	= rpcb_dec_set,
1034 		.p_arglen	= RPCB_getaddrargs_sz,
1035 		.p_replen	= RPCB_setres_sz,
1036 		.p_statidx	= RPCBPROC_SET,
1037 		.p_timer	= 0,
1038 		.p_name		= "SET",
1039 	},
1040 	[RPCBPROC_UNSET] = {
1041 		.p_proc		= RPCBPROC_UNSET,
1042 		.p_encode	= rpcb_enc_getaddr,
1043 		.p_decode	= rpcb_dec_set,
1044 		.p_arglen	= RPCB_getaddrargs_sz,
1045 		.p_replen	= RPCB_setres_sz,
1046 		.p_statidx	= RPCBPROC_UNSET,
1047 		.p_timer	= 0,
1048 		.p_name		= "UNSET",
1049 	},
1050 	[RPCBPROC_GETADDR] = {
1051 		.p_proc		= RPCBPROC_GETADDR,
1052 		.p_encode	= rpcb_enc_getaddr,
1053 		.p_decode	= rpcb_dec_getaddr,
1054 		.p_arglen	= RPCB_getaddrargs_sz,
1055 		.p_replen	= RPCB_getaddrres_sz,
1056 		.p_statidx	= RPCBPROC_GETADDR,
1057 		.p_timer	= 0,
1058 		.p_name		= "GETADDR",
1059 	},
1060 };
1061 
1062 static const struct rpcb_info rpcb_next_version[] = {
1063 	{
1064 		.rpc_vers	= RPCBVERS_2,
1065 		.rpc_proc	= &rpcb_procedures2[RPCBPROC_GETPORT],
1066 	},
1067 	{
1068 		.rpc_proc	= NULL,
1069 	},
1070 };
1071 
1072 static const struct rpcb_info rpcb_next_version6[] = {
1073 	{
1074 		.rpc_vers	= RPCBVERS_4,
1075 		.rpc_proc	= &rpcb_procedures4[RPCBPROC_GETADDR],
1076 	},
1077 	{
1078 		.rpc_vers	= RPCBVERS_3,
1079 		.rpc_proc	= &rpcb_procedures3[RPCBPROC_GETADDR],
1080 	},
1081 	{
1082 		.rpc_proc	= NULL,
1083 	},
1084 };
1085 
1086 static unsigned int rpcb_version2_counts[ARRAY_SIZE(rpcb_procedures2)];
1087 static const struct rpc_version rpcb_version2 = {
1088 	.number		= RPCBVERS_2,
1089 	.nrprocs	= ARRAY_SIZE(rpcb_procedures2),
1090 	.procs		= rpcb_procedures2,
1091 	.counts		= rpcb_version2_counts,
1092 };
1093 
1094 static unsigned int rpcb_version3_counts[ARRAY_SIZE(rpcb_procedures3)];
1095 static const struct rpc_version rpcb_version3 = {
1096 	.number		= RPCBVERS_3,
1097 	.nrprocs	= ARRAY_SIZE(rpcb_procedures3),
1098 	.procs		= rpcb_procedures3,
1099 	.counts		= rpcb_version3_counts,
1100 };
1101 
1102 static unsigned int rpcb_version4_counts[ARRAY_SIZE(rpcb_procedures4)];
1103 static const struct rpc_version rpcb_version4 = {
1104 	.number		= RPCBVERS_4,
1105 	.nrprocs	= ARRAY_SIZE(rpcb_procedures4),
1106 	.procs		= rpcb_procedures4,
1107 	.counts		= rpcb_version4_counts,
1108 };
1109 
1110 static const struct rpc_version *rpcb_version[] = {
1111 	NULL,
1112 	NULL,
1113 	&rpcb_version2,
1114 	&rpcb_version3,
1115 	&rpcb_version4
1116 };
1117 
1118 static struct rpc_stat rpcb_stats;
1119 
1120 static const struct rpc_program rpcb_program = {
1121 	.name		= "rpcbind",
1122 	.number		= RPCBIND_PROGRAM,
1123 	.nrvers		= ARRAY_SIZE(rpcb_version),
1124 	.version	= rpcb_version,
1125 	.stats		= &rpcb_stats,
1126 };
1127