netifd: fix a use-after-free issue on wireless config update
[project/netifd.git] / bridge.c
1 /*
2  * netifd - network interface daemon
3  * Copyright (C) 2012 Felix Fietkau <nbd@openwrt.org>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2
7  * as published by the Free Software Foundation
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  */
14 #include <string.h>
15 #include <stdlib.h>
16 #include <stdio.h>
17 #include <assert.h>
18 #include <errno.h>
19
20 #include "netifd.h"
21 #include "device.h"
22 #include "interface.h"
23 #include "system.h"
24
25 enum {
26         BRIDGE_ATTR_IFNAME,
27         BRIDGE_ATTR_STP,
28         BRIDGE_ATTR_FORWARD_DELAY,
29         BRIDGE_ATTR_PRIORITY,
30         BRIDGE_ATTR_IGMP_SNOOP,
31         BRIDGE_ATTR_AGEING_TIME,
32         BRIDGE_ATTR_HELLO_TIME,
33         BRIDGE_ATTR_MAX_AGE,
34         BRIDGE_ATTR_BRIDGE_EMPTY,
35         __BRIDGE_ATTR_MAX
36 };
37
38 static const struct blobmsg_policy bridge_attrs[__BRIDGE_ATTR_MAX] = {
39         [BRIDGE_ATTR_IFNAME] = { "ifname", BLOBMSG_TYPE_ARRAY },
40         [BRIDGE_ATTR_STP] = { "stp", BLOBMSG_TYPE_BOOL },
41         [BRIDGE_ATTR_FORWARD_DELAY] = { "forward_delay", BLOBMSG_TYPE_INT32 },
42         [BRIDGE_ATTR_PRIORITY] = { "priority", BLOBMSG_TYPE_INT32 },
43         [BRIDGE_ATTR_AGEING_TIME] = { "ageing_time", BLOBMSG_TYPE_INT32 },
44         [BRIDGE_ATTR_HELLO_TIME] = { "hello_time", BLOBMSG_TYPE_INT32 },
45         [BRIDGE_ATTR_MAX_AGE] = { "max_age", BLOBMSG_TYPE_INT32 },
46         [BRIDGE_ATTR_IGMP_SNOOP] = { "igmp_snooping", BLOBMSG_TYPE_BOOL },
47         [BRIDGE_ATTR_BRIDGE_EMPTY] = { "bridge_empty", BLOBMSG_TYPE_BOOL },
48 };
49
50 static const struct uci_blob_param_info bridge_attr_info[__BRIDGE_ATTR_MAX] = {
51         [BRIDGE_ATTR_IFNAME] = { .type = BLOBMSG_TYPE_STRING },
52 };
53
54 static const struct uci_blob_param_list bridge_attr_list = {
55         .n_params = __BRIDGE_ATTR_MAX,
56         .params = bridge_attrs,
57         .info = bridge_attr_info,
58
59         .n_next = 1,
60         .next = { &device_attr_list },
61 };
62
63 static struct device *bridge_create(const char *name, struct blob_attr *attr);
64 static void bridge_config_init(struct device *dev);
65 static void bridge_free(struct device *dev);
66 static void bridge_dump_info(struct device *dev, struct blob_buf *b);
67 enum dev_change_type
68 bridge_reload(struct device *dev, struct blob_attr *attr);
69
70 const struct device_type bridge_device_type = {
71         .name = "Bridge",
72         .config_params = &bridge_attr_list,
73
74         .create = bridge_create,
75         .config_init = bridge_config_init,
76         .reload = bridge_reload,
77         .free = bridge_free,
78         .dump_info = bridge_dump_info,
79 };
80
81 struct bridge_state {
82         struct device dev;
83         device_state_cb set_state;
84
85         struct blob_attr *config_data;
86         struct bridge_config config;
87         struct blob_attr *ifnames;
88         bool active;
89         bool force_active;
90
91         struct bridge_member *primary_port;
92         struct vlist_tree members;
93         int n_present;
94 };
95
96 struct bridge_member {
97         struct vlist_node node;
98         struct bridge_state *bst;
99         struct device_user dev;
100         bool present;
101         char name[];
102 };
103
104 static void
105 bridge_reset_primary(struct bridge_state *bst)
106 {
107         struct bridge_member *bm;
108
109         if (!bst->primary_port &&
110             (bst->dev.settings.flags & DEV_OPT_MACADDR))
111                 return;
112
113         bst->primary_port = NULL;
114         bst->dev.settings.flags &= ~DEV_OPT_MACADDR;
115         vlist_for_each_element(&bst->members, bm, node) {
116                 uint8_t *macaddr;
117
118                 if (!bm->present)
119                         continue;
120
121                 bst->primary_port = bm;
122                 if (bm->dev.dev->settings.flags & DEV_OPT_MACADDR)
123                         macaddr = bm->dev.dev->settings.macaddr;
124                 else
125                         macaddr = bm->dev.dev->orig_settings.macaddr;
126                 memcpy(bst->dev.settings.macaddr, macaddr, 6);
127                 bst->dev.settings.flags |= DEV_OPT_MACADDR;
128                 return;
129         }
130 }
131
132 static int
133 bridge_disable_member(struct bridge_member *bm)
134 {
135         struct bridge_state *bst = bm->bst;
136
137         if (!bm->present)
138                 return 0;
139
140         system_bridge_delif(&bst->dev, bm->dev.dev);
141         device_release(&bm->dev);
142
143         device_broadcast_event(&bst->dev, DEV_EVENT_TOPO_CHANGE);
144
145         return 0;
146 }
147
148 static int
149 bridge_enable_member(struct bridge_member *bm)
150 {
151         struct bridge_state *bst = bm->bst;
152         int ret;
153
154         if (!bm->present)
155                 return 0;
156
157         /* Disable IPv6 for bridge members */
158         if (!(bm->dev.dev->settings.flags & DEV_OPT_IPV6)) {
159                 bm->dev.dev->settings.ipv6 = 0;
160                 bm->dev.dev->settings.flags |= DEV_OPT_IPV6;
161         }
162
163         ret = device_claim(&bm->dev);
164         if (ret < 0)
165                 goto error;
166
167         ret = system_bridge_addif(&bst->dev, bm->dev.dev);
168         if (ret < 0) {
169                 D(DEVICE, "Bridge device %s could not be added\n", bm->dev.dev->ifname);
170                 goto error;
171         }
172
173         device_broadcast_event(&bst->dev, DEV_EVENT_TOPO_CHANGE);
174
175         return 0;
176
177 error:
178         bm->present = false;
179         bst->n_present--;
180         return ret;
181 }
182
183 static void
184 bridge_remove_member(struct bridge_member *bm)
185 {
186         struct bridge_state *bst = bm->bst;
187
188         if (!bm->present)
189                 return;
190
191         if (bm == bst->primary_port)
192                 bridge_reset_primary(bst);
193
194         if (bst->dev.active)
195                 bridge_disable_member(bm);
196
197         bm->present = false;
198         bm->bst->n_present--;
199
200         if (bst->config.bridge_empty)
201                 return;
202
203         bst->force_active = false;
204         if (bst->n_present == 0)
205                 device_set_present(&bst->dev, false);
206 }
207
208 static void
209 bridge_free_member(struct bridge_member *bm)
210 {
211         struct device *dev = bm->dev.dev;
212
213         bridge_remove_member(bm);
214         device_remove_user(&bm->dev);
215
216         /*
217          * When reloading the config and moving a device from one bridge to
218          * another, the other bridge may have tried to claim this device
219          * before it was removed here.
220          * Ensure that claiming the device is retried by toggling its present
221          * state
222          */
223         if (dev->present) {
224                 device_set_present(dev, false);
225                 device_set_present(dev, true);
226         }
227
228         free(bm);
229 }
230
231 static void
232 bridge_member_cb(struct device_user *dev, enum device_event ev)
233 {
234         struct bridge_member *bm = container_of(dev, struct bridge_member, dev);
235         struct bridge_state *bst = bm->bst;
236
237         switch (ev) {
238         case DEV_EVENT_ADD:
239                 assert(!bm->present);
240
241                 bm->present = true;
242                 bst->n_present++;
243
244                 if (bst->n_present == 1)
245                         device_set_present(&bst->dev, true);
246                 if (bst->dev.active && !bridge_enable_member(bm)) {
247                         /*
248                          * Adding a bridge member can overwrite the bridge mtu
249                          * in the kernel, apply the bridge settings in case the
250                          * bridge mtu is set
251                          */
252                         system_if_apply_settings(&bst->dev, &bst->dev.settings,
253                                                  DEV_OPT_MTU);
254                 }
255
256                 break;
257         case DEV_EVENT_REMOVE:
258                 if (dev->hotplug) {
259                         vlist_delete(&bst->members, &bm->node);
260                         return;
261                 }
262
263                 if (bm->present)
264                         bridge_remove_member(bm);
265
266                 break;
267         default:
268                 return;
269         }
270 }
271
272 static int
273 bridge_set_down(struct bridge_state *bst)
274 {
275         struct bridge_member *bm;
276
277         bst->set_state(&bst->dev, false);
278
279         vlist_for_each_element(&bst->members, bm, node)
280                 bridge_disable_member(bm);
281
282         system_bridge_delbr(&bst->dev);
283
284         return 0;
285 }
286
287 static int
288 bridge_set_up(struct bridge_state *bst)
289 {
290         struct bridge_member *bm;
291         int ret;
292
293         if (!bst->force_active && !bst->n_present)
294                 return -ENOENT;
295
296         ret = system_bridge_addbr(&bst->dev, &bst->config);
297         if (ret < 0)
298                 goto out;
299
300         vlist_for_each_element(&bst->members, bm, node)
301                 bridge_enable_member(bm);
302
303         if (!bst->force_active && !bst->n_present) {
304                 /* initialization of all member interfaces failed */
305                 system_bridge_delbr(&bst->dev);
306                 device_set_present(&bst->dev, false);
307                 return -ENOENT;
308         }
309
310         bridge_reset_primary(bst);
311         ret = bst->set_state(&bst->dev, true);
312         if (ret < 0)
313                 bridge_set_down(bst);
314
315 out:
316         return ret;
317 }
318
319 static int
320 bridge_set_state(struct device *dev, bool up)
321 {
322         struct bridge_state *bst;
323
324         bst = container_of(dev, struct bridge_state, dev);
325
326         if (up)
327                 return bridge_set_up(bst);
328         else
329                 return bridge_set_down(bst);
330 }
331
332 static struct bridge_member *
333 bridge_create_member(struct bridge_state *bst, struct device *dev, bool hotplug)
334 {
335         struct bridge_member *bm;
336
337         bm = calloc(1, sizeof(*bm) + strlen(dev->ifname) + 1);
338         if (!bm)
339                 return NULL;
340
341         bm->bst = bst;
342         bm->dev.cb = bridge_member_cb;
343         bm->dev.hotplug = hotplug;
344         strcpy(bm->name, dev->ifname);
345         bm->dev.dev = dev;
346         vlist_add(&bst->members, &bm->node, bm->name);
347         if (hotplug)
348                 bm->node.version = -1;
349
350         return bm;
351 }
352
353 static void
354 bridge_member_update(struct vlist_tree *tree, struct vlist_node *node_new,
355                      struct vlist_node *node_old)
356 {
357         struct bridge_member *bm;
358         struct device *dev;
359
360         if (node_new) {
361                 bm = container_of(node_new, struct bridge_member, node);
362
363                 if (node_old) {
364                         free(bm);
365                         return;
366                 }
367
368                 dev = bm->dev.dev;
369                 bm->dev.dev = NULL;
370                 device_add_user(&bm->dev, dev);
371         }
372
373
374         if (node_old) {
375                 bm = container_of(node_old, struct bridge_member, node);
376                 bridge_free_member(bm);
377         }
378 }
379
380
381 static void
382 bridge_add_member(struct bridge_state *bst, const char *name)
383 {
384         struct device *dev;
385
386         dev = device_get(name, true);
387         if (!dev)
388                 return;
389
390         bridge_create_member(bst, dev, false);
391 }
392
393 static int
394 bridge_hotplug_add(struct device *dev, struct device *member)
395 {
396         struct bridge_state *bst = container_of(dev, struct bridge_state, dev);
397
398         bridge_create_member(bst, member, true);
399
400         return 0;
401 }
402
403 static int
404 bridge_hotplug_del(struct device *dev, struct device *member)
405 {
406         struct bridge_state *bst = container_of(dev, struct bridge_state, dev);
407         struct bridge_member *bm;
408
409         bm = vlist_find(&bst->members, member->ifname, bm, node);
410         if (!bm)
411                 return UBUS_STATUS_NOT_FOUND;
412
413         vlist_delete(&bst->members, &bm->node);
414         return 0;
415 }
416
417 static int
418 bridge_hotplug_prepare(struct device *dev)
419 {
420         struct bridge_state *bst;
421
422         bst = container_of(dev, struct bridge_state, dev);
423         bst->force_active = true;
424         device_set_present(&bst->dev, true);
425
426         return 0;
427 }
428
429 static const struct device_hotplug_ops bridge_ops = {
430         .prepare = bridge_hotplug_prepare,
431         .add = bridge_hotplug_add,
432         .del = bridge_hotplug_del
433 };
434
435 static void
436 bridge_free(struct device *dev)
437 {
438         struct bridge_state *bst;
439
440         bst = container_of(dev, struct bridge_state, dev);
441         vlist_flush_all(&bst->members);
442         free(bst);
443 }
444
445 static void
446 bridge_dump_info(struct device *dev, struct blob_buf *b)
447 {
448         struct bridge_state *bst;
449         struct bridge_member *bm;
450         void *list;
451
452         bst = container_of(dev, struct bridge_state, dev);
453
454         system_if_dump_info(dev, b);
455         list = blobmsg_open_array(b, "bridge-members");
456
457         vlist_for_each_element(&bst->members, bm, node)
458                 blobmsg_add_string(b, NULL, bm->dev.dev->ifname);
459
460         blobmsg_close_array(b, list);
461 }
462
463 static void
464 bridge_config_init(struct device *dev)
465 {
466         struct bridge_state *bst;
467         struct blob_attr *cur;
468         int rem;
469
470         bst = container_of(dev, struct bridge_state, dev);
471
472         if (bst->config.bridge_empty) {
473                 bst->force_active = true;
474                 device_set_present(&bst->dev, true);
475         }
476
477         vlist_update(&bst->members);
478         if (bst->ifnames) {
479                 blobmsg_for_each_attr(cur, bst->ifnames, rem) {
480                         bridge_add_member(bst, blobmsg_data(cur));
481                 }
482         }
483         vlist_flush(&bst->members);
484 }
485
486 static void
487 bridge_apply_settings(struct bridge_state *bst, struct blob_attr **tb)
488 {
489         struct bridge_config *cfg = &bst->config;
490         struct blob_attr *cur;
491
492         /* defaults */
493         cfg->stp = false;
494         cfg->forward_delay = 2;
495         cfg->igmp_snoop = false;
496         cfg->bridge_empty = false;
497         cfg->priority = 0x7FFF;
498
499         if ((cur = tb[BRIDGE_ATTR_STP]))
500                 cfg->stp = blobmsg_get_bool(cur);
501
502         if ((cur = tb[BRIDGE_ATTR_FORWARD_DELAY]))
503                 cfg->forward_delay = blobmsg_get_u32(cur);
504
505         if ((cur = tb[BRIDGE_ATTR_PRIORITY]))
506                 cfg->priority = blobmsg_get_u32(cur);
507
508         if ((cur = tb[BRIDGE_ATTR_IGMP_SNOOP]))
509                 cfg->igmp_snoop = blobmsg_get_bool(cur);
510
511         if ((cur = tb[BRIDGE_ATTR_AGEING_TIME])) {
512                 cfg->ageing_time = blobmsg_get_u32(cur);
513                 cfg->flags |= BRIDGE_OPT_AGEING_TIME;
514         }
515
516         if ((cur = tb[BRIDGE_ATTR_HELLO_TIME])) {
517                 cfg->hello_time = blobmsg_get_u32(cur);
518                 cfg->flags |= BRIDGE_OPT_HELLO_TIME;
519         }
520
521         if ((cur = tb[BRIDGE_ATTR_MAX_AGE])) {
522                 cfg->max_age = blobmsg_get_u32(cur);
523                 cfg->flags |= BRIDGE_OPT_MAX_AGE;
524         }
525
526         if ((cur = tb[BRIDGE_ATTR_BRIDGE_EMPTY]))
527                 cfg->bridge_empty = blobmsg_get_bool(cur);
528 }
529
530 enum dev_change_type
531 bridge_reload(struct device *dev, struct blob_attr *attr)
532 {
533         struct blob_attr *tb_dev[__DEV_ATTR_MAX];
534         struct blob_attr *tb_br[__BRIDGE_ATTR_MAX];
535         enum dev_change_type ret = DEV_CONFIG_APPLIED;
536         unsigned long diff;
537         struct bridge_state *bst;
538
539         BUILD_BUG_ON(sizeof(diff) < __BRIDGE_ATTR_MAX / 8);
540         BUILD_BUG_ON(sizeof(diff) < __DEV_ATTR_MAX / 8);
541
542         bst = container_of(dev, struct bridge_state, dev);
543
544         blobmsg_parse(device_attr_list.params, __DEV_ATTR_MAX, tb_dev,
545                 blob_data(attr), blob_len(attr));
546         blobmsg_parse(bridge_attrs, __BRIDGE_ATTR_MAX, tb_br,
547                 blob_data(attr), blob_len(attr));
548
549         bst->ifnames = tb_br[BRIDGE_ATTR_IFNAME];
550         device_init_settings(dev, tb_dev);
551         bridge_apply_settings(bst, tb_br);
552
553         if (bst->config_data) {
554                 struct blob_attr *otb_dev[__DEV_ATTR_MAX];
555                 struct blob_attr *otb_br[__BRIDGE_ATTR_MAX];
556
557                 blobmsg_parse(device_attr_list.params, __DEV_ATTR_MAX, otb_dev,
558                         blob_data(bst->config_data), blob_len(bst->config_data));
559
560                 diff = 0;
561                 uci_blob_diff(tb_dev, otb_dev, &device_attr_list, &diff);
562                 if (diff & ~(1 << DEV_ATTR_IFNAME))
563                     ret = DEV_CONFIG_RESTART;
564
565                 blobmsg_parse(bridge_attrs, __BRIDGE_ATTR_MAX, otb_br,
566                         blob_data(bst->config_data), blob_len(bst->config_data));
567
568                 diff = 0;
569                 uci_blob_diff(tb_br, otb_br, &bridge_attr_list, &diff);
570                 if (diff & ~(1 << BRIDGE_ATTR_IFNAME))
571                     ret = DEV_CONFIG_RESTART;
572
573                 bridge_config_init(dev);
574         }
575
576         bst->config_data = attr;
577         return ret;
578 }
579
580 static struct device *
581 bridge_create(const char *name, struct blob_attr *attr)
582 {
583         struct bridge_state *bst;
584         struct device *dev = NULL;
585
586         bst = calloc(1, sizeof(*bst));
587         if (!bst)
588                 return NULL;
589
590         dev = &bst->dev;
591         device_init(dev, &bridge_device_type, name);
592         dev->config_pending = true;
593
594         bst->set_state = dev->set_state;
595         dev->set_state = bridge_set_state;
596
597         dev->hotplug_ops = &bridge_ops;
598
599         vlist_init(&bst->members, avl_strcmp, bridge_member_update);
600         bst->members.keep_old = true;
601         bridge_reload(dev, attr);
602
603         return dev;
604 }