Commit | Line | Data |
---|---|---|
1da177e4 LT |
1 | /* |
2 | * linux/fs/nfs/callback.c | |
3 | * | |
4 | * Copyright (C) 2004 Trond Myklebust | |
5 | * | |
6 | * NFSv4 callback handling | |
7 | */ | |
8 | ||
1da177e4 LT |
9 | #include <linux/completion.h> |
10 | #include <linux/ip.h> | |
11 | #include <linux/module.h> | |
12 | #include <linux/smp_lock.h> | |
13 | #include <linux/sunrpc/svc.h> | |
14 | #include <linux/sunrpc/svcsock.h> | |
15 | #include <linux/nfs_fs.h> | |
353ab6e9 | 16 | #include <linux/mutex.h> |
83144186 | 17 | #include <linux/freezer.h> |
a277e33c | 18 | #include <linux/kthread.h> |
945b34a7 | 19 | #include <linux/sunrpc/svcauth_gss.h> |
14c85021 ACM |
20 | |
21 | #include <net/inet_sock.h> | |
22 | ||
4ce79717 | 23 | #include "nfs4_fs.h" |
1da177e4 | 24 | #include "callback.h" |
24c8dbbb | 25 | #include "internal.h" |
1da177e4 LT |
26 | |
27 | #define NFSDBG_FACILITY NFSDBG_CALLBACK | |
28 | ||
29 | struct nfs_callback_data { | |
30 | unsigned int users; | |
5afc597c | 31 | struct svc_rqst *rqst; |
a277e33c | 32 | struct task_struct *task; |
1da177e4 LT |
33 | }; |
34 | ||
35 | static struct nfs_callback_data nfs_callback_info; | |
353ab6e9 | 36 | static DEFINE_MUTEX(nfs_callback_mutex); |
1da177e4 LT |
37 | static struct svc_program nfs4_callback_program; |
38 | ||
a72b4422 | 39 | unsigned int nfs_callback_set_tcpport; |
1da177e4 | 40 | unsigned short nfs_callback_tcpport; |
f738f517 | 41 | unsigned short nfs_callback_tcpport6; |
7d4e2747 DH |
42 | static const int nfs_set_port_min = 0; |
43 | static const int nfs_set_port_max = 65535; | |
44 | ||
45 | static int param_set_port(const char *val, struct kernel_param *kp) | |
46 | { | |
47 | char *endp; | |
48 | int num = simple_strtol(val, &endp, 0); | |
49 | if (endp == val || *endp || num < nfs_set_port_min || num > nfs_set_port_max) | |
50 | return -EINVAL; | |
51 | *((int *)kp->arg) = num; | |
52 | return 0; | |
53 | } | |
54 | ||
55 | module_param_call(callback_tcpport, param_set_port, param_get_int, | |
56 | &nfs_callback_set_tcpport, 0644); | |
1da177e4 LT |
57 | |
58 | /* | |
59 | * This is the callback kernel thread. | |
60 | */ | |
a277e33c | 61 | static int |
71468513 | 62 | nfs4_callback_svc(void *vrqstp) |
1da177e4 | 63 | { |
06e02d66 | 64 | int err, preverr = 0; |
a277e33c | 65 | struct svc_rqst *rqstp = vrqstp; |
1da177e4 | 66 | |
83144186 | 67 | set_freezable(); |
1da177e4 | 68 | |
a277e33c JL |
69 | /* |
70 | * FIXME: do we really need to run this under the BKL? If so, please | |
71 | * add a comment about what it's intended to protect. | |
72 | */ | |
73 | lock_kernel(); | |
74 | while (!kthread_should_stop()) { | |
1da177e4 LT |
75 | /* |
76 | * Listen for a request on the socket | |
77 | */ | |
6fb2b47f | 78 | err = svc_recv(rqstp, MAX_SCHEDULE_TIMEOUT); |
06e02d66 JL |
79 | if (err == -EAGAIN || err == -EINTR) { |
80 | preverr = err; | |
1da177e4 | 81 | continue; |
06e02d66 | 82 | } |
1da177e4 | 83 | if (err < 0) { |
06e02d66 JL |
84 | if (err != preverr) { |
85 | printk(KERN_WARNING "%s: unexpected error " | |
86 | "from svc_recv (%d)\n", __func__, err); | |
87 | preverr = err; | |
88 | } | |
89 | schedule_timeout_uninterruptible(HZ); | |
90 | continue; | |
1da177e4 | 91 | } |
06e02d66 | 92 | preverr = err; |
6fb2b47f | 93 | svc_process(rqstp); |
1da177e4 | 94 | } |
1da177e4 | 95 | unlock_kernel(); |
a277e33c | 96 | return 0; |
1da177e4 LT |
97 | } |
98 | ||
99 | /* | |
71468513 | 100 | * Prepare to bring up the NFSv4 callback service |
1da177e4 | 101 | */ |
71468513 BH |
102 | struct svc_rqst * |
103 | nfs4_callback_up(struct svc_serv *serv) | |
1da177e4 | 104 | { |
71468513 | 105 | int ret; |
482fb94e | 106 | |
26298caa | 107 | ret = svc_create_xprt(serv, "tcp", PF_INET, |
9652ada3 | 108 | nfs_callback_set_tcpport, SVC_SOCK_ANONYMOUS); |
482fb94e | 109 | if (ret <= 0) |
8e60029f | 110 | goto out_err; |
482fb94e | 111 | nfs_callback_tcpport = ret; |
18de9735 | 112 | dprintk("NFS: Callback listener port = %u (af %u)\n", |
26298caa | 113 | nfs_callback_tcpport, PF_INET); |
482fb94e | 114 | |
f738f517 CL |
115 | #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE) |
116 | ret = svc_create_xprt(serv, "tcp", PF_INET6, | |
117 | nfs_callback_set_tcpport, SVC_SOCK_ANONYMOUS); | |
118 | if (ret > 0) { | |
119 | nfs_callback_tcpport6 = ret; | |
120 | dprintk("NFS: Callback listener port = %u (af %u)\n", | |
121 | nfs_callback_tcpport6, PF_INET6); | |
122 | } else if (ret != -EAFNOSUPPORT) | |
123 | goto out_err; | |
124 | #endif /* defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE) */ | |
125 | ||
71468513 BH |
126 | return svc_prepare_thread(serv, &serv->sv_pools[0]); |
127 | ||
128 | out_err: | |
129 | if (ret == 0) | |
130 | ret = -ENOMEM; | |
131 | return ERR_PTR(ret); | |
132 | } | |
133 | ||
134 | /* | |
135 | * Bring up the callback thread if it is not already up. | |
136 | */ | |
137 | int nfs_callback_up(u32 minorversion, struct rpc_xprt *xprt) | |
138 | { | |
139 | struct svc_serv *serv = NULL; | |
140 | struct svc_rqst *rqstp; | |
141 | int (*callback_svc)(void *vrqstp); | |
142 | char svc_name[12]; | |
143 | int ret = 0; | |
144 | ||
145 | mutex_lock(&nfs_callback_mutex); | |
146 | if (nfs_callback_info.users++ || nfs_callback_info.task != NULL) | |
147 | goto out; | |
148 | serv = svc_create(&nfs4_callback_program, NFS4_CALLBACK_BUFSIZE, NULL); | |
149 | if (!serv) { | |
150 | ret = -ENOMEM; | |
151 | goto out_err; | |
152 | } | |
153 | ||
154 | if (!minorversion) { | |
155 | rqstp = nfs4_callback_up(serv); | |
156 | callback_svc = nfs4_callback_svc; | |
157 | } else { | |
158 | BUG(); /* for now */ | |
159 | } | |
160 | ||
161 | if (IS_ERR(rqstp)) { | |
162 | ret = PTR_ERR(rqstp); | |
8e60029f | 163 | goto out_err; |
a277e33c JL |
164 | } |
165 | ||
166 | svc_sock_update_bufs(serv); | |
a277e33c | 167 | |
71468513 BH |
168 | sprintf(svc_name, "nfsv4.%u-svc", minorversion); |
169 | nfs_callback_info.rqst = rqstp; | |
170 | nfs_callback_info.task = kthread_run(callback_svc, | |
5afc597c | 171 | nfs_callback_info.rqst, |
71468513 | 172 | svc_name); |
a277e33c JL |
173 | if (IS_ERR(nfs_callback_info.task)) { |
174 | ret = PTR_ERR(nfs_callback_info.task); | |
5afc597c JL |
175 | svc_exit_thread(nfs_callback_info.rqst); |
176 | nfs_callback_info.rqst = NULL; | |
a277e33c | 177 | nfs_callback_info.task = NULL; |
a277e33c JL |
178 | goto out_err; |
179 | } | |
1da177e4 | 180 | out: |
8e60029f JL |
181 | /* |
182 | * svc_create creates the svc_serv with sv_nrthreads == 1, and then | |
a277e33c | 183 | * svc_prepare_thread increments that. So we need to call svc_destroy |
8e60029f JL |
184 | * on both success and failure so that the refcount is 1 when the |
185 | * thread exits. | |
186 | */ | |
187 | if (serv) | |
188 | svc_destroy(serv); | |
353ab6e9 | 189 | mutex_unlock(&nfs_callback_mutex); |
1da177e4 | 190 | return ret; |
8e60029f | 191 | out_err: |
18de9735 CL |
192 | dprintk("NFS: Couldn't create callback socket or server thread; " |
193 | "err = %d\n", ret); | |
1da177e4 LT |
194 | nfs_callback_info.users--; |
195 | goto out; | |
196 | } | |
197 | ||
198 | /* | |
5afc597c | 199 | * Kill the callback thread if it's no longer being used. |
1da177e4 | 200 | */ |
5ae1fbce | 201 | void nfs_callback_down(void) |
1da177e4 | 202 | { |
353ab6e9 | 203 | mutex_lock(&nfs_callback_mutex); |
1dd761e9 | 204 | nfs_callback_info.users--; |
5afc597c | 205 | if (nfs_callback_info.users == 0 && nfs_callback_info.task != NULL) { |
a277e33c | 206 | kthread_stop(nfs_callback_info.task); |
5afc597c JL |
207 | svc_exit_thread(nfs_callback_info.rqst); |
208 | nfs_callback_info.rqst = NULL; | |
209 | nfs_callback_info.task = NULL; | |
210 | } | |
353ab6e9 | 211 | mutex_unlock(&nfs_callback_mutex); |
1da177e4 LT |
212 | } |
213 | ||
945b34a7 OK |
214 | static int check_gss_callback_principal(struct nfs_client *clp, |
215 | struct svc_rqst *rqstp) | |
216 | { | |
217 | struct rpc_clnt *r = clp->cl_rpcclient; | |
218 | char *p = svc_gss_principal(rqstp); | |
219 | ||
220 | /* | |
221 | * It might just be a normal user principal, in which case | |
222 | * userspace won't bother to tell us the name at all. | |
223 | */ | |
224 | if (p == NULL) | |
225 | return SVC_DENIED; | |
226 | ||
227 | /* Expect a GSS_C_NT_HOSTBASED_NAME like "nfs@serverhostname" */ | |
228 | ||
229 | if (memcmp(p, "nfs@", 4) != 0) | |
230 | return SVC_DENIED; | |
231 | p += 4; | |
232 | if (strcmp(p, r->cl_server) != 0) | |
233 | return SVC_DENIED; | |
234 | return SVC_OK; | |
235 | } | |
236 | ||
1da177e4 LT |
237 | static int nfs_callback_authenticate(struct svc_rqst *rqstp) |
238 | { | |
adfa6f98 | 239 | struct nfs_client *clp; |
5216a8e7 | 240 | RPC_IFDEBUG(char buf[RPC_MAX_ADDRBUFLEN]); |
945b34a7 | 241 | int ret = SVC_OK; |
1da177e4 LT |
242 | |
243 | /* Don't talk to strangers */ | |
ff052645 | 244 | clp = nfs_find_client(svc_addr(rqstp), 4); |
1da177e4 LT |
245 | if (clp == NULL) |
246 | return SVC_DROP; | |
ad06e4bd | 247 | |
3110ff80 | 248 | dprintk("%s: %s NFSv4 callback!\n", __func__, |
ad06e4bd | 249 | svc_print_addr(rqstp, buf, sizeof(buf))); |
ad06e4bd | 250 | |
1da177e4 LT |
251 | switch (rqstp->rq_authop->flavour) { |
252 | case RPC_AUTH_NULL: | |
253 | if (rqstp->rq_proc != CB_NULL) | |
945b34a7 | 254 | ret = SVC_DENIED; |
1da177e4 LT |
255 | break; |
256 | case RPC_AUTH_UNIX: | |
257 | break; | |
258 | case RPC_AUTH_GSS: | |
945b34a7 OK |
259 | ret = check_gss_callback_principal(clp, rqstp); |
260 | break; | |
1da177e4 | 261 | default: |
945b34a7 | 262 | ret = SVC_DENIED; |
1da177e4 | 263 | } |
945b34a7 OK |
264 | nfs_put_client(clp); |
265 | return ret; | |
1da177e4 LT |
266 | } |
267 | ||
268 | /* | |
269 | * Define NFS4 callback program | |
270 | */ | |
1da177e4 LT |
271 | static struct svc_version *nfs4_callback_version[] = { |
272 | [1] = &nfs4_callback_version1, | |
273 | }; | |
274 | ||
275 | static struct svc_stat nfs4_callback_stats; | |
276 | ||
277 | static struct svc_program nfs4_callback_program = { | |
278 | .pg_prog = NFS4_CALLBACK, /* RPC service number */ | |
279 | .pg_nvers = ARRAY_SIZE(nfs4_callback_version), /* Number of entries */ | |
280 | .pg_vers = nfs4_callback_version, /* version table */ | |
281 | .pg_name = "NFSv4 callback", /* service name */ | |
282 | .pg_class = "nfs", /* authentication class */ | |
283 | .pg_stats = &nfs4_callback_stats, | |
284 | .pg_authenticate = nfs_callback_authenticate, | |
285 | }; |