usbip: prevent leaking socket pointer address in messages
[pandora-kernel.git] / drivers / staging / usbip / stub_dev.c
1 /*
2  * Copyright (C) 2003-2008 Takahiro Hirofuchi
3  *
4  * This is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation; either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, write to the Free Software
16  * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307,
17  * USA.
18  */
19
20 #include <linux/device.h>
21 #include <linux/kthread.h>
22 #include <linux/module.h>
23
24 #include "usbip_common.h"
25 #include "stub.h"
26
27 /*
28  * Define device IDs here if you want to explicitly limit exportable devices.
29  * In most cases, wildcard matching will be okay because driver binding can be
30  * changed dynamically by a userland program.
31  */
32 static struct usb_device_id stub_table[] = {
33 #if 0
34         /* just an example */
35         { USB_DEVICE(0x05ac, 0x0301) },   /* Mac 1 button mouse */
36         { USB_DEVICE(0x0430, 0x0009) },   /* Plat Home Keyboard */
37         { USB_DEVICE(0x059b, 0x0001) },   /* Iomega USB Zip 100 */
38         { USB_DEVICE(0x04b3, 0x4427) },   /* IBM USB CD-ROM */
39         { USB_DEVICE(0x05a9, 0xa511) },   /* LifeView USB cam */
40         { USB_DEVICE(0x55aa, 0x0201) },   /* Imation card reader */
41         { USB_DEVICE(0x046d, 0x0870) },   /* Qcam Express(QV-30) */
42         { USB_DEVICE(0x04bb, 0x0101) },   /* IO-DATA HD 120GB */
43         { USB_DEVICE(0x04bb, 0x0904) },   /* IO-DATA USB-ET/TX */
44         { USB_DEVICE(0x04bb, 0x0201) },   /* IO-DATA USB-ET/TX */
45         { USB_DEVICE(0x08bb, 0x2702) },   /* ONKYO USB Speaker */
46         { USB_DEVICE(0x046d, 0x08b2) },   /* Logicool Qcam 4000 Pro */
47 #endif
48         /* magic for wild card */
49         { .driver_info = 1 },
50         { 0, }                                     /* Terminating entry */
51 };
52 MODULE_DEVICE_TABLE(usb, stub_table);
53
54 /*
55  * usbip_status shows the status of usbip-host as long as this driver is bound
56  * to the target device.
57  */
58 static ssize_t show_status(struct device *dev, struct device_attribute *attr,
59                            char *buf)
60 {
61         struct stub_device *sdev = dev_get_drvdata(dev);
62         int status;
63
64         if (!sdev) {
65                 dev_err(dev, "sdev is null\n");
66                 return -ENODEV;
67         }
68
69         spin_lock(&sdev->ud.lock);
70         status = sdev->ud.status;
71         spin_unlock(&sdev->ud.lock);
72
73         return snprintf(buf, PAGE_SIZE, "%d\n", status);
74 }
75 static DEVICE_ATTR(usbip_status, S_IRUGO, show_status, NULL);
76
77 /*
78  * usbip_sockfd gets a socket descriptor of an established TCP connection that
79  * is used to transfer usbip requests by kernel threads. -1 is a magic number
80  * by which usbip connection is finished.
81  */
82 static ssize_t store_sockfd(struct device *dev, struct device_attribute *attr,
83                             const char *buf, size_t count)
84 {
85         struct stub_device *sdev = dev_get_drvdata(dev);
86         int sockfd = 0;
87         struct socket *socket;
88
89         if (!sdev) {
90                 dev_err(dev, "sdev is null\n");
91                 return -ENODEV;
92         }
93
94         sscanf(buf, "%d", &sockfd);
95
96         if (sockfd != -1) {
97                 dev_info(dev, "stub up\n");
98
99                 spin_lock(&sdev->ud.lock);
100
101                 if (sdev->ud.status != SDEV_ST_AVAILABLE) {
102                         dev_err(dev, "not ready\n");
103                         spin_unlock(&sdev->ud.lock);
104                         return -EINVAL;
105                 }
106
107                 socket = sockfd_to_socket(sockfd);
108                 if (!socket) {
109                         spin_unlock(&sdev->ud.lock);
110                         return -EINVAL;
111                 }
112 #if 0
113                 setnodelay(socket);
114                 setkeepalive(socket);
115                 setreuse(socket);
116 #endif
117                 sdev->ud.tcp_socket = socket;
118
119                 spin_unlock(&sdev->ud.lock);
120
121                 sdev->ud.tcp_rx = kthread_run(stub_rx_loop, &sdev->ud, "stub_rx");
122                 sdev->ud.tcp_tx = kthread_run(stub_tx_loop, &sdev->ud, "stub_tx");
123
124                 spin_lock(&sdev->ud.lock);
125                 sdev->ud.status = SDEV_ST_USED;
126                 spin_unlock(&sdev->ud.lock);
127
128         } else {
129                 dev_info(dev, "stub down\n");
130
131                 spin_lock(&sdev->ud.lock);
132                 if (sdev->ud.status != SDEV_ST_USED) {
133                         spin_unlock(&sdev->ud.lock);
134                         return -EINVAL;
135                 }
136                 spin_unlock(&sdev->ud.lock);
137
138                 usbip_event_add(&sdev->ud, SDEV_EVENT_DOWN);
139         }
140
141         return count;
142 }
143 static DEVICE_ATTR(usbip_sockfd, S_IWUSR, NULL, store_sockfd);
144
145 static int stub_add_files(struct device *dev)
146 {
147         int err = 0;
148
149         err = device_create_file(dev, &dev_attr_usbip_status);
150         if (err)
151                 goto err_status;
152
153         err = device_create_file(dev, &dev_attr_usbip_sockfd);
154         if (err)
155                 goto err_sockfd;
156
157         err = device_create_file(dev, &dev_attr_usbip_debug);
158         if (err)
159                 goto err_debug;
160
161         return 0;
162
163 err_debug:
164         device_remove_file(dev, &dev_attr_usbip_sockfd);
165 err_sockfd:
166         device_remove_file(dev, &dev_attr_usbip_status);
167 err_status:
168         return err;
169 }
170
171 static void stub_remove_files(struct device *dev)
172 {
173         device_remove_file(dev, &dev_attr_usbip_status);
174         device_remove_file(dev, &dev_attr_usbip_sockfd);
175         device_remove_file(dev, &dev_attr_usbip_debug);
176 }
177
178 static void stub_shutdown_connection(struct usbip_device *ud)
179 {
180         struct stub_device *sdev = container_of(ud, struct stub_device, ud);
181
182         /*
183          * When removing an exported device, kernel panic sometimes occurred
184          * and then EIP was sk_wait_data of stub_rx thread. Is this because
185          * sk_wait_data returned though stub_rx thread was already finished by
186          * step 1?
187          */
188         if (ud->tcp_socket) {
189                 dev_dbg(&sdev->udev->dev, "shutdown sockfd %d\n", ud->sockfd);
190                 kernel_sock_shutdown(ud->tcp_socket, SHUT_RDWR);
191         }
192
193         /* 1. stop threads */
194         if (ud->tcp_rx && !task_is_dead(ud->tcp_rx))
195                 kthread_stop(ud->tcp_rx);
196         if (ud->tcp_tx && !task_is_dead(ud->tcp_tx))
197                 kthread_stop(ud->tcp_tx);
198
199         /*
200          * 2. close the socket
201          *
202          * tcp_socket is freed after threads are killed so that usbip_xmit does
203          * not touch NULL socket.
204          */
205         if (ud->tcp_socket) {
206                 sock_release(ud->tcp_socket);
207                 ud->tcp_socket = NULL;
208         }
209
210         /* 3. free used data */
211         stub_device_cleanup_urbs(sdev);
212
213         /* 4. free stub_unlink */
214         {
215                 unsigned long flags;
216                 struct stub_unlink *unlink, *tmp;
217
218                 spin_lock_irqsave(&sdev->priv_lock, flags);
219                 list_for_each_entry_safe(unlink, tmp, &sdev->unlink_tx, list) {
220                         list_del(&unlink->list);
221                         kfree(unlink);
222                 }
223                 list_for_each_entry_safe(unlink, tmp, &sdev->unlink_free,
224                                          list) {
225                         list_del(&unlink->list);
226                         kfree(unlink);
227                 }
228                 spin_unlock_irqrestore(&sdev->priv_lock, flags);
229         }
230 }
231
232 static void stub_device_reset(struct usbip_device *ud)
233 {
234         struct stub_device *sdev = container_of(ud, struct stub_device, ud);
235         struct usb_device *udev = sdev->udev;
236         int ret;
237
238         dev_dbg(&udev->dev, "device reset");
239
240         ret = usb_lock_device_for_reset(udev, sdev->interface);
241         if (ret < 0) {
242                 dev_err(&udev->dev, "lock for reset\n");
243                 spin_lock(&ud->lock);
244                 ud->status = SDEV_ST_ERROR;
245                 spin_unlock(&ud->lock);
246                 return;
247         }
248
249         /* try to reset the device */
250         ret = usb_reset_device(udev);
251         usb_unlock_device(udev);
252
253         spin_lock(&ud->lock);
254         if (ret) {
255                 dev_err(&udev->dev, "device reset\n");
256                 ud->status = SDEV_ST_ERROR;
257         } else {
258                 dev_info(&udev->dev, "device reset\n");
259                 ud->status = SDEV_ST_AVAILABLE;
260         }
261         spin_unlock(&ud->lock);
262 }
263
264 static void stub_device_unusable(struct usbip_device *ud)
265 {
266         spin_lock(&ud->lock);
267         ud->status = SDEV_ST_ERROR;
268         spin_unlock(&ud->lock);
269 }
270
271 /**
272  * stub_device_alloc - allocate a new stub_device struct
273  * @interface: usb_interface of a new device
274  *
275  * Allocates and initializes a new stub_device struct.
276  */
277 static struct stub_device *stub_device_alloc(struct usb_device *udev,
278                                              struct usb_interface *interface)
279 {
280         struct stub_device *sdev;
281         int busnum = interface_to_busnum(interface);
282         int devnum = interface_to_devnum(interface);
283
284         dev_dbg(&interface->dev, "allocating stub device");
285
286         /* yes, it's a new device */
287         sdev = kzalloc(sizeof(struct stub_device), GFP_KERNEL);
288         if (!sdev) {
289                 dev_err(&interface->dev, "no memory for stub_device\n");
290                 return NULL;
291         }
292
293         sdev->interface = usb_get_intf(interface);
294         sdev->udev = usb_get_dev(udev);
295
296         /*
297          * devid is defined with devnum when this driver is first allocated.
298          * devnum may change later if a device is reset. However, devid never
299          * changes during a usbip connection.
300          */
301         sdev->devid             = (busnum << 16) | devnum;
302         sdev->ud.side           = USBIP_STUB;
303         sdev->ud.status         = SDEV_ST_AVAILABLE;
304         /* sdev->ud.lock = SPIN_LOCK_UNLOCKED; */
305         spin_lock_init(&sdev->ud.lock);
306         sdev->ud.tcp_socket     = NULL;
307
308         INIT_LIST_HEAD(&sdev->priv_init);
309         INIT_LIST_HEAD(&sdev->priv_tx);
310         INIT_LIST_HEAD(&sdev->priv_free);
311         INIT_LIST_HEAD(&sdev->unlink_free);
312         INIT_LIST_HEAD(&sdev->unlink_tx);
313         /* sdev->priv_lock = SPIN_LOCK_UNLOCKED; */
314         spin_lock_init(&sdev->priv_lock);
315
316         init_waitqueue_head(&sdev->tx_waitq);
317
318         sdev->ud.eh_ops.shutdown = stub_shutdown_connection;
319         sdev->ud.eh_ops.reset    = stub_device_reset;
320         sdev->ud.eh_ops.unusable = stub_device_unusable;
321
322         usbip_start_eh(&sdev->ud);
323
324         dev_dbg(&interface->dev, "register new interface\n");
325
326         return sdev;
327 }
328
329 static int stub_device_free(struct stub_device *sdev)
330 {
331         if (!sdev)
332                 return -EINVAL;
333
334         kfree(sdev);
335         pr_debug("kfree udev ok\n");
336
337         return 0;
338 }
339
340 /*
341  * If a usb device has multiple active interfaces, this driver is bound to all
342  * the active interfaces. However, usbip exports *a* usb device (i.e., not *an*
343  * active interface). Currently, a userland program must ensure that it
344  * looks at the usbip's sysfs entries of only the first active interface.
345  *
346  * TODO: use "struct usb_device_driver" to bind a usb device.
347  * However, it seems it is not fully supported in mainline kernel yet
348  * (2.6.19.2).
349  */
350 static int stub_probe(struct usb_interface *interface,
351                       const struct usb_device_id *id)
352 {
353         struct usb_device *udev = interface_to_usbdev(interface);
354         struct stub_device *sdev = NULL;
355         const char *udev_busid = dev_name(interface->dev.parent);
356         int err = 0;
357         struct bus_id_priv *busid_priv;
358
359         dev_dbg(&interface->dev, "Enter\n");
360
361         /* check we should claim or not by busid_table */
362         busid_priv = get_busid_priv(udev_busid);
363         if (!busid_priv || (busid_priv->status == STUB_BUSID_REMOV) ||
364             (busid_priv->status == STUB_BUSID_OTHER)) {
365                 dev_info(&interface->dev, "%s is not in match_busid table... "
366                          "skip!\n", udev_busid);
367
368                 /*
369                  * Return value should be ENODEV or ENOXIO to continue trying
370                  * other matched drivers by the driver core.
371                  * See driver_probe_device() in driver/base/dd.c
372                  */
373                 return -ENODEV;
374         }
375
376         if (udev->descriptor.bDeviceClass == USB_CLASS_HUB) {
377                 dev_dbg(&udev->dev, "%s is a usb hub device... skip!\n",
378                          udev_busid);
379                 return -ENODEV;
380         }
381
382         if (!strcmp(udev->bus->bus_name, "vhci_hcd")) {
383                 dev_dbg(&udev->dev, "%s is attached on vhci_hcd... skip!\n",
384                          udev_busid);
385                 return -ENODEV;
386         }
387
388         if (busid_priv->status == STUB_BUSID_ALLOC) {
389                 sdev = busid_priv->sdev;
390                 if (!sdev)
391                         return -ENODEV;
392
393                 busid_priv->interf_count++;
394                 dev_info(&interface->dev, "usbip-host: register new interface "
395                          "(bus %u dev %u ifn %u)\n",
396                          udev->bus->busnum, udev->devnum,
397                          interface->cur_altsetting->desc.bInterfaceNumber);
398
399                 /* set private data to usb_interface */
400                 usb_set_intfdata(interface, sdev);
401
402                 err = stub_add_files(&interface->dev);
403                 if (err) {
404                         dev_err(&interface->dev, "stub_add_files for %s\n",
405                                 udev_busid);
406                         usb_set_intfdata(interface, NULL);
407                         busid_priv->interf_count--;
408                         return err;
409                 }
410
411                 usb_get_intf(interface);
412                 return 0;
413         }
414
415         /* ok, this is my device */
416         sdev = stub_device_alloc(udev, interface);
417         if (!sdev)
418                 return -ENOMEM;
419
420         dev_info(&interface->dev, "usbip-host: register new device "
421                  "(bus %u dev %u ifn %u)\n", udev->bus->busnum, udev->devnum,
422                  interface->cur_altsetting->desc.bInterfaceNumber);
423
424         busid_priv->interf_count = 0;
425         busid_priv->shutdown_busid = 0;
426
427         /* set private data to usb_interface */
428         usb_set_intfdata(interface, sdev);
429         busid_priv->interf_count++;
430         busid_priv->sdev = sdev;
431
432         err = stub_add_files(&interface->dev);
433         if (err) {
434                 dev_err(&interface->dev, "stub_add_files for %s\n", udev_busid);
435                 usb_set_intfdata(interface, NULL);
436                 usb_put_intf(interface);
437
438                 busid_priv->interf_count = 0;
439                 busid_priv->sdev = NULL;
440                 stub_device_free(sdev);
441                 return err;
442         }
443         busid_priv->status = STUB_BUSID_ALLOC;
444
445         return 0;
446 }
447
448 static void shutdown_busid(struct bus_id_priv *busid_priv)
449 {
450         if (busid_priv->sdev && !busid_priv->shutdown_busid) {
451                 busid_priv->shutdown_busid = 1;
452                 usbip_event_add(&busid_priv->sdev->ud, SDEV_EVENT_REMOVED);
453
454                 /* 2. wait for the stop of the event handler */
455                 usbip_stop_eh(&busid_priv->sdev->ud);
456         }
457 }
458
459 /*
460  * called in usb_disconnect() or usb_deregister()
461  * but only if actconfig(active configuration) exists
462  */
463 static void stub_disconnect(struct usb_interface *interface)
464 {
465         struct stub_device *sdev;
466         const char *udev_busid = dev_name(interface->dev.parent);
467         struct bus_id_priv *busid_priv;
468
469         dev_dbg(&interface->dev, "Enter\n");
470
471         busid_priv = get_busid_priv(udev_busid);
472         if (!busid_priv) {
473                 BUG();
474                 return;
475         }
476
477         sdev = usb_get_intfdata(interface);
478
479         /* get stub_device */
480         if (!sdev) {
481                 dev_err(&interface->dev, "could not get device");
482                 /* BUG(); */
483                 return;
484         }
485
486         usb_set_intfdata(interface, NULL);
487
488         /*
489          * NOTE:
490          * rx/tx threads are invoked for each usb_device.
491          */
492         stub_remove_files(&interface->dev);
493
494         /*If usb reset called from event handler*/
495         if (busid_priv->sdev->ud.eh == current) {
496                 busid_priv->interf_count--;
497                 return;
498         }
499
500         if (busid_priv->interf_count > 1) {
501                 busid_priv->interf_count--;
502                 shutdown_busid(busid_priv);
503                 usb_put_intf(interface);
504                 return;
505         }
506
507         busid_priv->interf_count = 0;
508
509         /* 1. shutdown the current connection */
510         shutdown_busid(busid_priv);
511
512         usb_put_dev(sdev->udev);
513         usb_put_intf(interface);
514
515         /* 3. free sdev */
516         busid_priv->sdev = NULL;
517         stub_device_free(sdev);
518
519         if (busid_priv->status == STUB_BUSID_ALLOC) {
520                 busid_priv->status = STUB_BUSID_ADDED;
521         } else {
522                 busid_priv->status = STUB_BUSID_OTHER;
523                 del_match_busid((char *)udev_busid);
524         }
525 }
526
527 /*
528  * Presence of pre_reset and post_reset prevents the driver from being unbound
529  * when the device is being reset
530  */
531
532 int stub_pre_reset(struct usb_interface *interface)
533 {
534         dev_dbg(&interface->dev, "pre_reset\n");
535         return 0;
536 }
537
538 int stub_post_reset(struct usb_interface *interface)
539 {
540         dev_dbg(&interface->dev, "post_reset\n");
541         return 0;
542 }
543
544 struct usb_driver stub_driver = {
545         .name           = "usbip-host",
546         .probe          = stub_probe,
547         .disconnect     = stub_disconnect,
548         .id_table       = stub_table,
549         .pre_reset      = stub_pre_reset,
550         .post_reset     = stub_post_reset,
551 };