]> git.saurik.com Git - apple/xnu.git/blob - bsd/kern/sys_socket.c
9988ba7c68db4a9c91d5413df71def023aaf389c
[apple/xnu.git] / bsd / kern / sys_socket.c
1 /*
2 * Copyright (c) 2000-2013 Apple Inc. All rights reserved.
3 *
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
14 *
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17 *
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
25 *
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27 */
28 /*
29 * Copyright (c) 1982, 1986, 1990, 1993
30 * The Regents of the University of California. All rights reserved.
31 *
32 * Redistribution and use in source and binary forms, with or without
33 * modification, are permitted provided that the following conditions
34 * are met:
35 * 1. Redistributions of source code must retain the above copyright
36 * notice, this list of conditions and the following disclaimer.
37 * 2. Redistributions in binary form must reproduce the above copyright
38 * notice, this list of conditions and the following disclaimer in the
39 * documentation and/or other materials provided with the distribution.
40 * 3. All advertising materials mentioning features or use of this software
41 * must display the following acknowledgement:
42 * This product includes software developed by the University of
43 * California, Berkeley and its contributors.
44 * 4. Neither the name of the University nor the names of its contributors
45 * may be used to endorse or promote products derived from this software
46 * without specific prior written permission.
47 *
48 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
49 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
50 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
51 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
52 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
53 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
54 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
55 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
56 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
57 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
58 * SUCH DAMAGE.
59 *
60 * @(#)sys_socket.c 8.1 (Berkeley) 6/10/93
61 */
62 /*
63 * NOTICE: This file was modified by SPARTA, Inc. in 2005 to introduce
64 * support for mandatory and extensible security protections. This notice
65 * is included in support of clause 2.2 (b) of the Apple Public License,
66 * Version 2.0.
67 */
68
69 #include <sys/param.h>
70 #include <sys/systm.h>
71 #include <sys/file_internal.h>
72 #include <sys/event.h>
73 #include <sys/protosw.h>
74 #include <sys/socket.h>
75 #include <sys/socketvar.h>
76 #include <sys/filio.h> /* XXX */
77 #include <sys/sockio.h>
78 #include <sys/stat.h>
79 #include <sys/uio.h>
80 #include <sys/filedesc.h>
81 #include <sys/kauth.h>
82 #include <sys/signalvar.h>
83 #include <sys/vnode.h>
84
85 #include <net/if.h>
86 #include <net/route.h>
87
88 #if CONFIG_MACF
89 #include <security/mac_framework.h>
90 #endif
91
92 /*
93 * File operations on sockets.
94 */
95 static int soo_read(struct fileproc *, struct uio *, int, vfs_context_t ctx);
96 static int soo_write(struct fileproc *, struct uio *, int, vfs_context_t ctx);
97 static int soo_close(struct fileglob *, vfs_context_t ctx);
98 static int soo_drain(struct fileproc *, vfs_context_t ctx);
99
100 const struct fileops socketops = {
101 .fo_type = DTYPE_SOCKET,
102 .fo_read = soo_read,
103 .fo_write = soo_write,
104 .fo_ioctl = soo_ioctl,
105 .fo_select = soo_select,
106 .fo_close = soo_close,
107 .fo_kqfilter = soo_kqfilter,
108 .fo_drain = soo_drain,
109 };
110
111 /* ARGSUSED */
112 static int
113 soo_read(struct fileproc *fp, struct uio *uio, __unused int flags,
114 #if !CONFIG_MACF_SOCKET
115 __unused
116 #endif
117 vfs_context_t ctx)
118 {
119 struct socket *so;
120 int stat;
121 #if CONFIG_MACF_SOCKET
122 int error;
123 #endif
124
125 int (*fsoreceive)(struct socket *so2, struct sockaddr **paddr,
126 struct uio *uio2, struct mbuf **mp0, struct mbuf **controlp,
127 int *flagsp);
128
129 if ((so = (struct socket *)fp->f_fglob->fg_data) == NULL) {
130 /* This is not a valid open file descriptor */
131 return EBADF;
132 }
133
134 #if CONFIG_MACF_SOCKET
135 error = mac_socket_check_receive(vfs_context_ucred(ctx), so);
136 if (error) {
137 return error;
138 }
139 #endif /* CONFIG_MACF_SOCKET */
140
141 fsoreceive = so->so_proto->pr_usrreqs->pru_soreceive;
142
143 stat = (*fsoreceive)(so, 0, uio, 0, 0, 0);
144 return stat;
145 }
146
147 /* ARGSUSED */
148 static int
149 soo_write(struct fileproc *fp, struct uio *uio, __unused int flags,
150 vfs_context_t ctx)
151 {
152 struct socket *so;
153 int stat;
154 int (*fsosend)(struct socket *so2, struct sockaddr *addr,
155 struct uio *uio2, struct mbuf *top, struct mbuf *control,
156 int flags2);
157 proc_t procp;
158
159 #if CONFIG_MACF_SOCKET
160 int error;
161 #endif
162
163 if ((so = (struct socket *)fp->f_fglob->fg_data) == NULL) {
164 /* This is not a valid open file descriptor */
165 return EBADF;
166 }
167
168 #if CONFIG_MACF_SOCKET
169 /* JMM - have to fetch the socket's remote addr */
170 error = mac_socket_check_send(vfs_context_ucred(ctx), so, NULL);
171 if (error) {
172 return error;
173 }
174 #endif /* CONFIG_MACF_SOCKET */
175
176 fsosend = so->so_proto->pr_usrreqs->pru_sosend;
177
178 stat = (*fsosend)(so, 0, uio, 0, 0, 0);
179
180 /* Generation of SIGPIPE can be controlled per socket */
181 procp = vfs_context_proc(ctx);
182 if (stat == EPIPE && !(so->so_flags & SOF_NOSIGPIPE)) {
183 psignal(procp, SIGPIPE);
184 }
185
186 return stat;
187 }
188
189 __private_extern__ int
190 soioctl(struct socket *so, u_long cmd, caddr_t data, struct proc *p)
191 {
192 int error = 0;
193 int int_arg;
194
195 #if CONFIG_MACF_SOCKET_SUBSET
196 error = mac_socket_check_ioctl(kauth_cred_get(), so, cmd);
197 if (error) {
198 return error;
199 }
200 #endif
201
202 socket_lock(so, 1);
203
204 /* call the socket filter's ioctl handler anything but ours */
205 if (IOCGROUP(cmd) != 'i' && IOCGROUP(cmd) != 'r') {
206 switch (cmd) {
207 case SIOCGASSOCIDS32:
208 case SIOCGASSOCIDS64:
209 case SIOCGCONNIDS32:
210 case SIOCGCONNIDS64:
211 case SIOCGCONNINFO32:
212 case SIOCGCONNINFO64:
213 case SIOCSCONNORDER:
214 case SIOCGCONNORDER:
215 /* don't pass to filter */
216 break;
217
218 default:
219 error = sflt_ioctl(so, cmd, data);
220 if (error != 0) {
221 goto out;
222 }
223 break;
224 }
225 }
226
227 switch (cmd) {
228 case FIONBIO: /* int */
229 bcopy(data, &int_arg, sizeof(int_arg));
230 if (int_arg) {
231 so->so_state |= SS_NBIO;
232 } else {
233 so->so_state &= ~SS_NBIO;
234 }
235
236 goto out;
237
238 case FIOASYNC: /* int */
239 bcopy(data, &int_arg, sizeof(int_arg));
240 if (int_arg) {
241 so->so_state |= SS_ASYNC;
242 so->so_rcv.sb_flags |= SB_ASYNC;
243 so->so_snd.sb_flags |= SB_ASYNC;
244 } else {
245 so->so_state &= ~SS_ASYNC;
246 so->so_rcv.sb_flags &= ~SB_ASYNC;
247 so->so_snd.sb_flags &= ~SB_ASYNC;
248 }
249 goto out;
250
251 case FIONREAD: /* int */
252 bcopy(&so->so_rcv.sb_cc, data, sizeof(u_int32_t));
253 goto out;
254
255 case SIOCSPGRP: /* int */
256 bcopy(data, &so->so_pgid, sizeof(pid_t));
257 goto out;
258
259 case SIOCGPGRP: /* int */
260 bcopy(&so->so_pgid, data, sizeof(pid_t));
261 goto out;
262
263 case SIOCATMARK: /* int */
264 int_arg = (so->so_state & SS_RCVATMARK) != 0;
265 bcopy(&int_arg, data, sizeof(int_arg));
266 goto out;
267
268 case SIOCSETOT: /* int; deprecated */
269 error = EOPNOTSUPP;
270 goto out;
271
272 case SIOCGASSOCIDS32: /* so_aidreq32 */
273 case SIOCGASSOCIDS64: /* so_aidreq64 */
274 case SIOCGCONNIDS32: /* so_cidreq32 */
275 case SIOCGCONNIDS64: /* so_cidreq64 */
276 case SIOCGCONNINFO32: /* so_cinforeq32 */
277 case SIOCGCONNINFO64: /* so_cinforeq64 */
278 case SIOCSCONNORDER: /* so_cordreq */
279 case SIOCGCONNORDER: /* so_cordreq */
280 error = (*so->so_proto->pr_usrreqs->pru_control)(so,
281 cmd, data, NULL, p);
282 goto out;
283 }
284
285 /*
286 * Interface/routing/protocol specific ioctls:
287 * interface and routing ioctls should have a
288 * different entry since a socket's unnecessary
289 */
290 if (IOCGROUP(cmd) == 'i') {
291 error = ifioctllocked(so, cmd, data, p);
292 } else {
293 if (IOCGROUP(cmd) == 'r') {
294 error = rtioctl(cmd, data, p);
295 } else {
296 error = (*so->so_proto->pr_usrreqs->pru_control)(so,
297 cmd, data, NULL, p);
298 }
299 }
300
301 out:
302 socket_unlock(so, 1);
303
304 if (error == EJUSTRETURN) {
305 error = 0;
306 }
307
308 return error;
309 }
310
311 int
312 soo_ioctl(struct fileproc *fp, u_long cmd, caddr_t data, vfs_context_t ctx)
313 {
314 struct socket *so;
315 proc_t procp = vfs_context_proc(ctx);
316
317 if ((so = (struct socket *)fp->f_fglob->fg_data) == NULL) {
318 /* This is not a valid open file descriptor */
319 return EBADF;
320 }
321
322 return soioctl(so, cmd, data, procp);
323 }
324
325 int
326 soo_select(struct fileproc *fp, int which, void *wql, vfs_context_t ctx)
327 {
328 struct socket *so = (struct socket *)fp->f_fglob->fg_data;
329 int retnum = 0;
330 proc_t procp;
331
332 if (so == NULL || so == (struct socket *)-1) {
333 return 0;
334 }
335
336 procp = vfs_context_proc(ctx);
337
338 #if CONFIG_MACF_SOCKET
339 if (mac_socket_check_select(vfs_context_ucred(ctx), so, which) != 0) {
340 return 0;
341 }
342 #endif /* CONFIG_MACF_SOCKET */
343
344
345 socket_lock(so, 1);
346 switch (which) {
347 case FREAD:
348 so->so_rcv.sb_flags |= SB_SEL;
349 if (soreadable(so)) {
350 retnum = 1;
351 so->so_rcv.sb_flags &= ~SB_SEL;
352 goto done;
353 }
354 selrecord(procp, &so->so_rcv.sb_sel, wql);
355 break;
356
357 case FWRITE:
358 so->so_snd.sb_flags |= SB_SEL;
359 if (sowriteable(so)) {
360 retnum = 1;
361 so->so_snd.sb_flags &= ~SB_SEL;
362 goto done;
363 }
364 selrecord(procp, &so->so_snd.sb_sel, wql);
365 break;
366
367 case 0:
368 so->so_rcv.sb_flags |= SB_SEL;
369 if (so->so_oobmark || (so->so_state & SS_RCVATMARK)) {
370 retnum = 1;
371 so->so_rcv.sb_flags &= ~SB_SEL;
372 goto done;
373 }
374 selrecord(procp, &so->so_rcv.sb_sel, wql);
375 break;
376 }
377
378 done:
379 socket_unlock(so, 1);
380 return retnum;
381 }
382
383 int
384 soo_stat(struct socket *so, void *ub, int isstat64)
385 {
386 int ret;
387 /* warning avoidance ; protected by isstat64 */
388 struct stat *sb = (struct stat *)0;
389 /* warning avoidance ; protected by isstat64 */
390 struct stat64 *sb64 = (struct stat64 *)0;
391
392 #if CONFIG_MACF_SOCKET_SUBSET
393 ret = mac_socket_check_stat(kauth_cred_get(), so);
394 if (ret) {
395 return ret;
396 }
397 #endif
398
399 if (isstat64 != 0) {
400 sb64 = (struct stat64 *)ub;
401 bzero((caddr_t)sb64, sizeof(*sb64));
402 } else {
403 sb = (struct stat *)ub;
404 bzero((caddr_t)sb, sizeof(*sb));
405 }
406
407 socket_lock(so, 1);
408 if (isstat64 != 0) {
409 sb64->st_mode = S_IFSOCK;
410 if ((so->so_state & SS_CANTRCVMORE) == 0 ||
411 so->so_rcv.sb_cc != 0) {
412 sb64->st_mode |= S_IRUSR | S_IRGRP | S_IROTH;
413 }
414 if ((so->so_state & SS_CANTSENDMORE) == 0) {
415 sb64->st_mode |= S_IWUSR | S_IWGRP | S_IWOTH;
416 }
417 sb64->st_size = so->so_rcv.sb_cc - so->so_rcv.sb_ctl;
418 sb64->st_uid = kauth_cred_getuid(so->so_cred);
419 sb64->st_gid = kauth_cred_getgid(so->so_cred);
420 } else {
421 sb->st_mode = S_IFSOCK;
422 if ((so->so_state & SS_CANTRCVMORE) == 0 ||
423 so->so_rcv.sb_cc != 0) {
424 sb->st_mode |= S_IRUSR | S_IRGRP | S_IROTH;
425 }
426 if ((so->so_state & SS_CANTSENDMORE) == 0) {
427 sb->st_mode |= S_IWUSR | S_IWGRP | S_IWOTH;
428 }
429 sb->st_size = so->so_rcv.sb_cc - so->so_rcv.sb_ctl;
430 sb->st_uid = kauth_cred_getuid(so->so_cred);
431 sb->st_gid = kauth_cred_getgid(so->so_cred);
432 }
433
434 ret = (*so->so_proto->pr_usrreqs->pru_sense)(so, ub, isstat64);
435 socket_unlock(so, 1);
436 return ret;
437 }
438
439 /* ARGSUSED */
440 static int
441 soo_close(struct fileglob *fg, __unused vfs_context_t ctx)
442 {
443 int error = 0;
444 struct socket *sp;
445
446 sp = (struct socket *)fg->fg_data;
447 fg->fg_data = NULL;
448
449 if (sp) {
450 error = soclose(sp);
451 }
452
453 return error;
454 }
455
456 static int
457 soo_drain(struct fileproc *fp, __unused vfs_context_t ctx)
458 {
459 int error = 0;
460 struct socket *so = (struct socket *)fp->f_fglob->fg_data;
461
462 if (so) {
463 socket_lock(so, 1);
464 so->so_state |= SS_DRAINING;
465
466 wakeup((caddr_t)&so->so_timeo);
467 sorwakeup(so);
468 sowwakeup(so);
469 soevent(so, SO_FILT_HINT_LOCKED);
470
471 socket_unlock(so, 1);
472 }
473
474 return error;
475 }
476
477 /*
478 * 's' group ioctls.
479 *
480 * The switch statement below does nothing at runtime, as it serves as a
481 * compile time check to ensure that all of the socket 's' ioctls (those
482 * in the 's' group going thru soo_ioctl) that are made available by the
483 * networking stack is unique. This works as long as this routine gets
484 * updated each time a new interface ioctl gets added.
485 *
486 * Any failures at compile time indicates duplicated ioctl values.
487 */
488 static __attribute__((unused)) void
489 soioctl_cassert(void)
490 {
491 /*
492 * This is equivalent to _CASSERT() and the compiler wouldn't
493 * generate any instructions, thus for compile time only.
494 */
495 switch ((u_long)0) {
496 case 0:
497
498 /* bsd/sys/sockio.h */
499 case SIOCSHIWAT:
500 case SIOCGHIWAT:
501 case SIOCSLOWAT:
502 case SIOCGLOWAT:
503 case SIOCATMARK:
504 case SIOCSPGRP:
505 case SIOCGPGRP:
506 case SIOCSETOT:
507 case SIOCGASSOCIDS32:
508 case SIOCGASSOCIDS64:
509 case SIOCGCONNIDS32:
510 case SIOCGCONNIDS64:
511 case SIOCGCONNINFO32:
512 case SIOCGCONNINFO64:
513 case SIOCSCONNORDER:
514 case SIOCGCONNORDER:
515 ;
516 }
517 }