trelay: fix deadlock on remove
[openwrt/staging/rmilecki.git] / package / kernel / trelay / src / trelay.c
1 /*
2 * trelay.c: Trivial Ethernet Relay
3 *
4 * Copyright (C) 2012 Felix Fietkau <nbd@nbd.name>
5 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License
8 * as published by the Free Software Foundation; either version 2
9 * of the License, or (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 */
16 #include <linux/module.h>
17 #include <linux/list.h>
18 #include <linux/mutex.h>
19 #include <linux/netdevice.h>
20 #include <linux/rtnetlink.h>
21 #include <linux/debugfs.h>
22
23 static LIST_HEAD(trelay_devs);
24 static struct dentry *debugfs_dir;
25
26 struct trelay {
27 struct list_head list;
28 struct net_device *dev1, *dev2;
29 struct dentry *debugfs;
30 int to_remove;
31 char name[];
32 };
33
34 rx_handler_result_t trelay_handle_frame(struct sk_buff **pskb)
35 {
36 struct net_device *dev;
37 struct sk_buff *skb = *pskb;
38
39 dev = rcu_dereference(skb->dev->rx_handler_data);
40 if (!dev)
41 return RX_HANDLER_PASS;
42
43 if (skb->protocol == htons(ETH_P_PAE))
44 return RX_HANDLER_PASS;
45
46 skb_push(skb, ETH_HLEN);
47 skb->dev = dev;
48 skb_forward_csum(skb);
49 dev_queue_xmit(skb);
50
51 return RX_HANDLER_CONSUMED;
52 }
53
54 static int trelay_open(struct inode *inode, struct file *file)
55 {
56 file->private_data = inode->i_private;
57 return 0;
58 }
59
60 static int trelay_do_remove(struct trelay *tr)
61 {
62 list_del(&tr->list);
63
64 /* First and before all, ensure that the debugfs file is removed
65 * to prevent dangling pointer in file->private_data */
66 debugfs_remove_recursive(tr->debugfs);
67
68 dev_put(tr->dev1);
69 dev_put(tr->dev2);
70
71 netdev_rx_handler_unregister(tr->dev1);
72 netdev_rx_handler_unregister(tr->dev2);
73
74 kfree(tr);
75
76 return 0;
77 }
78
79 static struct trelay *trelay_find(struct net_device *dev)
80 {
81 struct trelay *tr;
82
83 list_for_each_entry(tr, &trelay_devs, list) {
84 if (tr->dev1 == dev || tr->dev2 == dev)
85 return tr;
86 }
87 return NULL;
88 }
89
90 static int tr_device_event(struct notifier_block *unused, unsigned long event,
91 void *ptr)
92 {
93 struct net_device *dev = netdev_notifier_info_to_dev(ptr);
94 struct trelay *tr;
95
96 if (event != NETDEV_UNREGISTER)
97 goto out;
98
99 tr = trelay_find(dev);
100 if (!tr)
101 goto out;
102
103 trelay_do_remove(tr);
104
105 out:
106 return NOTIFY_DONE;
107 }
108
109 static ssize_t trelay_remove_write(struct file *file, const char __user *ubuf,
110 size_t count, loff_t *ppos)
111 {
112 struct trelay *tr = file->private_data;
113 tr->to_remove = 1;
114
115 return count;
116 }
117
118 static int trelay_remove_release(struct inode *inode, struct file *file)
119 {
120 struct trelay *tr, *tmp;
121
122 /* This is the only file op that is called outside debugfs_use_file_*()
123 * context which means that: (1) this file can be removed and
124 * (2) file->private_data may no longer be valid */
125 rtnl_lock();
126 list_for_each_entry_safe(tr, tmp, &trelay_devs, list)
127 if (tr->to_remove)
128 trelay_do_remove(tr);
129 rtnl_unlock();
130
131 return 0;
132 }
133
134 static const struct file_operations fops_remove = {
135 .owner = THIS_MODULE,
136 .open = trelay_open,
137 .write = trelay_remove_write,
138 .llseek = default_llseek,
139 .release = trelay_remove_release,
140 };
141
142
143 static int trelay_do_add(char *name, char *devn1, char *devn2)
144 {
145 struct net_device *dev1, *dev2;
146 struct trelay *tr, *tr1;
147 int ret;
148
149 tr = kzalloc(sizeof(*tr) + strlen(name) + 1, GFP_KERNEL);
150 if (!tr)
151 return -ENOMEM;
152
153 rtnl_lock();
154 rcu_read_lock();
155
156 ret = -EEXIST;
157 list_for_each_entry(tr1, &trelay_devs, list) {
158 if (!strcmp(tr1->name, name))
159 goto out;
160 }
161
162 ret = -ENOENT;
163 dev1 = dev_get_by_name_rcu(&init_net, devn1);
164 dev2 = dev_get_by_name_rcu(&init_net, devn2);
165 if (!dev1 || !dev2)
166 goto out;
167
168 ret = netdev_rx_handler_register(dev1, trelay_handle_frame, dev2);
169 if (ret < 0)
170 goto out;
171
172 ret = netdev_rx_handler_register(dev2, trelay_handle_frame, dev1);
173 if (ret < 0) {
174 netdev_rx_handler_unregister(dev1);
175 goto out;
176 }
177
178 dev_hold(dev1);
179 dev_hold(dev2);
180
181 strcpy(tr->name, name);
182 tr->dev1 = dev1;
183 tr->dev2 = dev2;
184 list_add_tail(&tr->list, &trelay_devs);
185
186 tr->debugfs = debugfs_create_dir(name, debugfs_dir);
187 debugfs_create_file("remove", S_IWUSR, tr->debugfs, tr, &fops_remove);
188 ret = 0;
189
190 out:
191 rcu_read_unlock();
192 rtnl_unlock();
193 if (ret < 0)
194 kfree(tr);
195
196 return ret;
197 }
198
199 static ssize_t trelay_add_write(struct file *file, const char __user *ubuf,
200 size_t count, loff_t *ppos)
201 {
202 char buf[256];
203 char *dev1, *dev2, *tmp;
204 ssize_t len, ret;
205
206 len = min(count, sizeof(buf) - 1);
207 if (copy_from_user(buf, ubuf, len))
208 return -EFAULT;
209
210 buf[len] = 0;
211
212 if ((tmp = strchr(buf, '\n')))
213 *tmp = 0;
214
215 dev1 = strchr(buf, ',');
216 if (!dev1)
217 return -EINVAL;
218
219 *(dev1++) = 0;
220
221 dev2 = strchr(dev1, ',');
222 if (!dev2)
223 return -EINVAL;
224
225 *(dev2++) = 0;
226 if (strchr(dev2, ','))
227 return -EINVAL;
228
229 if (!strlen(buf) || !strlen(dev1) || !strlen(dev2))
230 return -EINVAL;
231
232 ret = trelay_do_add(buf, dev1, dev2);
233 if (ret < 0)
234 return ret;
235
236 return count;
237 }
238
239 static const struct file_operations fops_add = {
240 .owner = THIS_MODULE,
241 .write = trelay_add_write,
242 .llseek = default_llseek,
243 };
244
245 static struct notifier_block tr_dev_notifier = {
246 .notifier_call = tr_device_event
247 };
248
249 static int __init trelay_init(void)
250 {
251 int ret;
252
253 debugfs_dir = debugfs_create_dir("trelay", NULL);
254 if (!debugfs_dir)
255 return -ENOMEM;
256
257 debugfs_create_file("add", S_IWUSR, debugfs_dir, NULL, &fops_add);
258
259 ret = register_netdevice_notifier(&tr_dev_notifier);
260 if (ret < 0)
261 goto error;
262
263 return 0;
264
265 error:
266 debugfs_remove_recursive(debugfs_dir);
267 return ret;
268 }
269
270 static void __exit trelay_exit(void)
271 {
272 struct trelay *tr, *tmp;
273
274 unregister_netdevice_notifier(&tr_dev_notifier);
275
276 rtnl_lock();
277 list_for_each_entry_safe(tr, tmp, &trelay_devs, list)
278 trelay_do_remove(tr);
279 rtnl_unlock();
280
281 debugfs_remove_recursive(debugfs_dir);
282 }
283
284 module_init(trelay_init);
285 module_exit(trelay_exit);
286 MODULE_LICENSE("GPL");