1 // SPDX-License-Identifier: GPL-2.0-or-later 2 /* 3 * Ioctl handler 4 * Linux ethernet bridge 5 * 6 * Authors: 7 * Lennert Buytenhek <buytenh@gnu.org> 8 */ 9 10 #include <linux/capability.h> 11 #include <linux/compat.h> 12 #include <linux/kernel.h> 13 #include <linux/if_bridge.h> 14 #include <linux/netdevice.h> 15 #include <linux/slab.h> 16 #include <linux/times.h> 17 #include <net/net_namespace.h> 18 #include <linux/uaccess.h> 19 #include "br_private.h" 20 21 static int get_bridge_ifindices(struct net *net, int *indices, int num) 22 { 23 struct net_device *dev; 24 int i = 0; 25 26 rcu_read_lock(); 27 for_each_netdev_rcu(net, dev) { 28 if (i >= num) 29 break; 30 if (netif_is_bridge_master(dev)) 31 indices[i++] = dev->ifindex; 32 } 33 rcu_read_unlock(); 34 35 return i; 36 } 37 38 /* called with RTNL */ 39 static void get_port_ifindices(struct net_bridge *br, int *ifindices, int num) 40 { 41 struct net_bridge_port *p; 42 43 list_for_each_entry(p, &br->port_list, list) { 44 if (p->port_no < num) 45 ifindices[p->port_no] = p->dev->ifindex; 46 } 47 } 48 49 /* 50 * Format up to a page worth of forwarding table entries 51 * userbuf -- where to copy result 52 * maxnum -- maximum number of entries desired 53 * (limited to a page for sanity) 54 * offset -- number of records to skip 55 */ 56 static int get_fdb_entries(struct net_bridge *br, void __user *userbuf, 57 unsigned long maxnum, unsigned long offset) 58 { 59 int num; 60 void *buf; 61 size_t size; 62 63 /* Clamp size to PAGE_SIZE, test maxnum to avoid overflow */ 64 if (maxnum > PAGE_SIZE/sizeof(struct __fdb_entry)) 65 maxnum = PAGE_SIZE/sizeof(struct __fdb_entry); 66 67 size = maxnum * sizeof(struct __fdb_entry); 68 69 buf = kmalloc(size, GFP_USER); 70 if (!buf) 71 return -ENOMEM; 72 73 num = br_fdb_fillbuf(br, buf, maxnum, offset); 74 if (num > 0) { 75 if (copy_to_user(userbuf, buf, 76 array_size(num, sizeof(struct __fdb_entry)))) 77 num = -EFAULT; 78 } 79 kfree(buf); 80 81 return num; 82 } 83 84 /* called with RTNL */ 85 static int add_del_if(struct net_bridge *br, int ifindex, int isadd) 86 { 87 struct net *net = dev_net(br->dev); 88 struct net_device *dev; 89 int ret; 90 91 if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) 92 return -EPERM; 93 94 dev = __dev_get_by_index(net, ifindex); 95 if (dev == NULL) 96 return -EINVAL; 97 98 if (isadd) 99 ret = br_add_if(br, dev, NULL); 100 else 101 ret = br_del_if(br, dev); 102 103 return ret; 104 } 105 106 /* 107 * Legacy ioctl's through SIOCDEVPRIVATE 108 * This interface is deprecated because it was too difficult 109 * to do the translation for 32/64bit ioctl compatibility. 110 */ 111 int br_dev_siocdevprivate(struct net_device *dev, struct ifreq *rq, void __user *data, int cmd) 112 { 113 struct net_bridge *br = netdev_priv(dev); 114 struct net_bridge_port *p = NULL; 115 unsigned long args[4]; 116 void __user *argp; 117 int ret = -EOPNOTSUPP; 118 119 if (in_compat_syscall()) { 120 unsigned int cargs[4]; 121 122 if (copy_from_user(cargs, data, sizeof(cargs))) 123 return -EFAULT; 124 125 args[0] = cargs[0]; 126 args[1] = cargs[1]; 127 args[2] = cargs[2]; 128 args[3] = cargs[3]; 129 130 argp = compat_ptr(args[1]); 131 } else { 132 if (copy_from_user(args, data, sizeof(args))) 133 return -EFAULT; 134 135 argp = (void __user *)args[1]; 136 } 137 138 switch (args[0]) { 139 case BRCTL_ADD_IF: 140 case BRCTL_DEL_IF: 141 return add_del_if(br, args[1], args[0] == BRCTL_ADD_IF); 142 143 case BRCTL_GET_BRIDGE_INFO: 144 { 145 struct __bridge_info b; 146 147 memset(&b, 0, sizeof(struct __bridge_info)); 148 rcu_read_lock(); 149 memcpy(&b.designated_root, &br->designated_root, 8); 150 memcpy(&b.bridge_id, &br->bridge_id, 8); 151 b.root_path_cost = br->root_path_cost; 152 b.max_age = jiffies_to_clock_t(br->max_age); 153 b.hello_time = jiffies_to_clock_t(br->hello_time); 154 b.forward_delay = br->forward_delay; 155 b.bridge_max_age = br->bridge_max_age; 156 b.bridge_hello_time = br->bridge_hello_time; 157 b.bridge_forward_delay = jiffies_to_clock_t(br->bridge_forward_delay); 158 b.topology_change = br->topology_change; 159 b.topology_change_detected = br->topology_change_detected; 160 b.root_port = br->root_port; 161 162 b.stp_enabled = (br->stp_enabled != BR_NO_STP); 163 b.ageing_time = jiffies_to_clock_t(br->ageing_time); 164 b.hello_timer_value = br_timer_value(&br->hello_timer); 165 b.tcn_timer_value = br_timer_value(&br->tcn_timer); 166 b.topology_change_timer_value = br_timer_value(&br->topology_change_timer); 167 b.gc_timer_value = br_timer_value(&br->gc_work.timer); 168 rcu_read_unlock(); 169 170 if (copy_to_user((void __user *)args[1], &b, sizeof(b))) 171 return -EFAULT; 172 173 return 0; 174 } 175 176 case BRCTL_GET_PORT_LIST: 177 { 178 int num, *indices; 179 180 num = args[2]; 181 if (num < 0) 182 return -EINVAL; 183 if (num == 0) 184 num = 256; 185 if (num > BR_MAX_PORTS) 186 num = BR_MAX_PORTS; 187 188 indices = kcalloc(num, sizeof(int), GFP_KERNEL); 189 if (indices == NULL) 190 return -ENOMEM; 191 192 get_port_ifindices(br, indices, num); 193 if (copy_to_user(argp, indices, array_size(num, sizeof(int)))) 194 num = -EFAULT; 195 kfree(indices); 196 return num; 197 } 198 199 case BRCTL_SET_BRIDGE_FORWARD_DELAY: 200 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 201 return -EPERM; 202 203 ret = br_set_forward_delay(br, args[1]); 204 break; 205 206 case BRCTL_SET_BRIDGE_HELLO_TIME: 207 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 208 return -EPERM; 209 210 ret = br_set_hello_time(br, args[1]); 211 break; 212 213 case BRCTL_SET_BRIDGE_MAX_AGE: 214 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 215 return -EPERM; 216 217 ret = br_set_max_age(br, args[1]); 218 break; 219 220 case BRCTL_SET_AGEING_TIME: 221 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 222 return -EPERM; 223 224 ret = br_set_ageing_time(br, args[1]); 225 break; 226 227 case BRCTL_GET_PORT_INFO: 228 { 229 struct __port_info p; 230 struct net_bridge_port *pt; 231 232 rcu_read_lock(); 233 if ((pt = br_get_port(br, args[2])) == NULL) { 234 rcu_read_unlock(); 235 return -EINVAL; 236 } 237 238 memset(&p, 0, sizeof(struct __port_info)); 239 memcpy(&p.designated_root, &pt->designated_root, 8); 240 memcpy(&p.designated_bridge, &pt->designated_bridge, 8); 241 p.port_id = pt->port_id; 242 p.designated_port = pt->designated_port; 243 p.path_cost = pt->path_cost; 244 p.designated_cost = pt->designated_cost; 245 p.state = pt->state; 246 p.top_change_ack = pt->topology_change_ack; 247 p.config_pending = pt->config_pending; 248 p.message_age_timer_value = br_timer_value(&pt->message_age_timer); 249 p.forward_delay_timer_value = br_timer_value(&pt->forward_delay_timer); 250 p.hold_timer_value = br_timer_value(&pt->hold_timer); 251 252 rcu_read_unlock(); 253 254 if (copy_to_user(argp, &p, sizeof(p))) 255 return -EFAULT; 256 257 return 0; 258 } 259 260 case BRCTL_SET_BRIDGE_STP_STATE: 261 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 262 return -EPERM; 263 264 ret = br_stp_set_enabled(br, args[1], NULL); 265 break; 266 267 case BRCTL_SET_BRIDGE_PRIORITY: 268 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 269 return -EPERM; 270 271 br_stp_set_bridge_priority(br, args[1]); 272 ret = 0; 273 break; 274 275 case BRCTL_SET_PORT_PRIORITY: 276 { 277 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 278 return -EPERM; 279 280 spin_lock_bh(&br->lock); 281 if ((p = br_get_port(br, args[1])) == NULL) 282 ret = -EINVAL; 283 else 284 ret = br_stp_set_port_priority(p, args[2]); 285 spin_unlock_bh(&br->lock); 286 break; 287 } 288 289 case BRCTL_SET_PATH_COST: 290 { 291 if (!ns_capable(dev_net(dev)->user_ns, CAP_NET_ADMIN)) 292 return -EPERM; 293 294 spin_lock_bh(&br->lock); 295 if ((p = br_get_port(br, args[1])) == NULL) 296 ret = -EINVAL; 297 else 298 ret = br_stp_set_path_cost(p, args[2]); 299 spin_unlock_bh(&br->lock); 300 break; 301 } 302 303 case BRCTL_GET_FDB_ENTRIES: 304 return get_fdb_entries(br, argp, args[2], args[3]); 305 } 306 307 if (!ret) { 308 if (p) 309 br_ifinfo_notify(RTM_NEWLINK, NULL, p); 310 else 311 netdev_state_change(br->dev); 312 } 313 314 return ret; 315 } 316 317 static int old_deviceless(struct net *net, void __user *uarg) 318 { 319 unsigned long args[3]; 320 321 if (copy_from_user(args, uarg, sizeof(args))) 322 return -EFAULT; 323 324 switch (args[0]) { 325 case BRCTL_GET_VERSION: 326 return BRCTL_VERSION; 327 328 case BRCTL_GET_BRIDGES: 329 { 330 int *indices; 331 int ret = 0; 332 333 if (args[2] >= 2048) 334 return -ENOMEM; 335 indices = kcalloc(args[2], sizeof(int), GFP_KERNEL); 336 if (indices == NULL) 337 return -ENOMEM; 338 339 args[2] = get_bridge_ifindices(net, indices, args[2]); 340 341 ret = copy_to_user(uarg, indices, 342 array_size(args[2], sizeof(int))) 343 ? -EFAULT : args[2]; 344 345 kfree(indices); 346 return ret; 347 } 348 349 case BRCTL_ADD_BRIDGE: 350 case BRCTL_DEL_BRIDGE: 351 { 352 char buf[IFNAMSIZ]; 353 354 if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) 355 return -EPERM; 356 357 if (copy_from_user(buf, (void __user *)args[1], IFNAMSIZ)) 358 return -EFAULT; 359 360 buf[IFNAMSIZ-1] = 0; 361 362 if (args[0] == BRCTL_ADD_BRIDGE) 363 return br_add_bridge(net, buf); 364 365 return br_del_bridge(net, buf); 366 } 367 } 368 369 return -EOPNOTSUPP; 370 } 371 372 int br_ioctl_stub(struct net *net, struct net_bridge *br, unsigned int cmd, 373 struct ifreq *ifr, void __user *uarg) 374 { 375 int ret = -EOPNOTSUPP; 376 377 rtnl_lock(); 378 379 switch (cmd) { 380 case SIOCGIFBR: 381 case SIOCSIFBR: 382 ret = old_deviceless(net, uarg); 383 break; 384 case SIOCBRADDBR: 385 case SIOCBRDELBR: 386 { 387 char buf[IFNAMSIZ]; 388 389 if (!ns_capable(net->user_ns, CAP_NET_ADMIN)) { 390 ret = -EPERM; 391 break; 392 } 393 394 if (copy_from_user(buf, uarg, IFNAMSIZ)) { 395 ret = -EFAULT; 396 break; 397 } 398 399 buf[IFNAMSIZ-1] = 0; 400 if (cmd == SIOCBRADDBR) 401 ret = br_add_bridge(net, buf); 402 else 403 ret = br_del_bridge(net, buf); 404 } 405 break; 406 case SIOCBRADDIF: 407 case SIOCBRDELIF: 408 ret = add_del_if(br, ifr->ifr_ifindex, cmd == SIOCBRADDIF); 409 break; 410 } 411 412 rtnl_unlock(); 413 414 return ret; 415 } 416