1 // SPDX-License-Identifier: GPL-2.0
2 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
3 #include <linux/init.h>
4 #include <linux/module.h>
6 #include <linux/bpfilter.h>
7 #include <linux/sched.h>
8 #include <linux/sched/signal.h>
10 #include <linux/file.h>
13 extern char bpfilter_umh_start;
14 extern char bpfilter_umh_end;
16 static struct umh_info info;
17 /* since ip_getsockopt() can run in parallel, serialize access to umh */
18 static DEFINE_MUTEX(bpfilter_lock);
20 static void shutdown_umh(struct umh_info *info)
22 struct task_struct *tsk;
26 tsk = get_pid_task(find_vpid(info->pid), PIDTYPE_PID);
28 force_sig(SIGKILL, tsk);
31 fput(info->pipe_to_umh);
32 fput(info->pipe_from_umh);
36 static void __stop_umh(void)
38 if (IS_ENABLED(CONFIG_INET)) {
39 bpfilter_process_sockopt = NULL;
44 static void stop_umh(void)
46 mutex_lock(&bpfilter_lock);
48 mutex_unlock(&bpfilter_lock);
51 static int __bpfilter_process_sockopt(struct sock *sk, int optname,
53 unsigned int optlen, bool is_set)
55 struct mbox_request req;
56 struct mbox_reply reply;
62 req.pid = current->pid;
64 req.addr = (long __force __user)optval;
66 mutex_lock(&bpfilter_lock);
69 n = __kernel_write(info.pipe_to_umh, &req, sizeof(req), &pos);
70 if (n != sizeof(req)) {
71 pr_err("write fail %zd\n", n);
77 n = kernel_read(info.pipe_from_umh, &reply, sizeof(reply), &pos);
78 if (n != sizeof(reply)) {
79 pr_err("read fail %zd\n", n);
86 mutex_unlock(&bpfilter_lock);
90 static int __init load_umh(void)
94 /* fork usermode process */
95 info.cmdline = "bpfilter_umh";
96 err = fork_usermode_blob(&bpfilter_umh_start,
97 &bpfilter_umh_end - &bpfilter_umh_start,
101 pr_info("Loaded bpfilter_umh pid %d\n", info.pid);
103 /* health check that usermode process started correctly */
104 if (__bpfilter_process_sockopt(NULL, 0, NULL, 0, 0) != 0) {
108 if (IS_ENABLED(CONFIG_INET))
109 bpfilter_process_sockopt = &__bpfilter_process_sockopt;
114 static void __exit fini_umh(void)
118 module_init(load_umh);
119 module_exit(fini_umh);
120 MODULE_LICENSE("GPL");