cmd-filter.c 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235
  1. /*
  2. * Copyright 2004 Peter M. Jones <pjones@redhat.com>
  3. *
  4. * This program is free software; you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License version 2 as
  6. * published by the Free Software Foundation.
  7. *
  8. * This program is distributed in the hope that it will be useful,
  9. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. *
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public Licens
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-
  17. *
  18. */
  19. #include <linux/list.h>
  20. #include <linux/genhd.h>
  21. #include <linux/spinlock.h>
  22. #include <linux/capability.h>
  23. #include <linux/bitops.h>
  24. #include <scsi/scsi.h>
  25. #include <linux/cdrom.h>
  26. int blk_verify_command(struct blk_cmd_filter *filter,
  27. unsigned char *cmd, int has_write_perm)
  28. {
  29. /* root can do any command. */
  30. if (capable(CAP_SYS_RAWIO))
  31. return 0;
  32. /* if there's no filter set, assume we're filtering everything out */
  33. if (!filter)
  34. return -EPERM;
  35. /* Anybody who can open the device can do a read-safe command */
  36. if (test_bit(cmd[0], filter->read_ok))
  37. return 0;
  38. /* Write-safe commands require a writable open */
  39. if (test_bit(cmd[0], filter->write_ok) && has_write_perm)
  40. return 0;
  41. return -EPERM;
  42. }
  43. EXPORT_SYMBOL(blk_verify_command);
  44. /* and now, the sysfs stuff */
  45. static ssize_t rcf_cmds_show(struct blk_cmd_filter *filter, char *page,
  46. int rw)
  47. {
  48. char *npage = page;
  49. unsigned long *okbits;
  50. int i;
  51. if (rw == READ)
  52. okbits = filter->read_ok;
  53. else
  54. okbits = filter->write_ok;
  55. for (i = 0; i < BLK_SCSI_MAX_CMDS; i++) {
  56. if (test_bit(i, okbits)) {
  57. npage += sprintf(npage, "0x%02x", i);
  58. if (i < BLK_SCSI_MAX_CMDS - 1)
  59. sprintf(npage++, " ");
  60. }
  61. }
  62. if (npage != page)
  63. npage += sprintf(npage, "\n");
  64. return npage - page;
  65. }
  66. static ssize_t rcf_readcmds_show(struct blk_cmd_filter *filter, char *page)
  67. {
  68. return rcf_cmds_show(filter, page, READ);
  69. }
  70. static ssize_t rcf_writecmds_show(struct blk_cmd_filter *filter,
  71. char *page)
  72. {
  73. return rcf_cmds_show(filter, page, WRITE);
  74. }
  75. static ssize_t rcf_cmds_store(struct blk_cmd_filter *filter,
  76. const char *page, size_t count, int rw)
  77. {
  78. unsigned long okbits[BLK_SCSI_CMD_PER_LONG], *target_okbits;
  79. int cmd, set;
  80. char *p, *status;
  81. if (rw == READ) {
  82. memcpy(&okbits, filter->read_ok, sizeof(okbits));
  83. target_okbits = filter->read_ok;
  84. } else {
  85. memcpy(&okbits, filter->write_ok, sizeof(okbits));
  86. target_okbits = filter->write_ok;
  87. }
  88. while ((p = strsep((char **)&page, " ")) != NULL) {
  89. set = 1;
  90. if (p[0] == '+') {
  91. p++;
  92. } else if (p[0] == '-') {
  93. set = 0;
  94. p++;
  95. }
  96. cmd = simple_strtol(p, &status, 16);
  97. /* either of these cases means invalid input, so do nothing. */
  98. if ((status == p) || cmd >= BLK_SCSI_MAX_CMDS)
  99. return -EINVAL;
  100. if (set)
  101. __set_bit(cmd, okbits);
  102. else
  103. __clear_bit(cmd, okbits);
  104. }
  105. memcpy(target_okbits, okbits, sizeof(okbits));
  106. return count;
  107. }
  108. static ssize_t rcf_readcmds_store(struct blk_cmd_filter *filter,
  109. const char *page, size_t count)
  110. {
  111. return rcf_cmds_store(filter, page, count, READ);
  112. }
  113. static ssize_t rcf_writecmds_store(struct blk_cmd_filter *filter,
  114. const char *page, size_t count)
  115. {
  116. return rcf_cmds_store(filter, page, count, WRITE);
  117. }
  118. struct rcf_sysfs_entry {
  119. struct attribute attr;
  120. ssize_t (*show)(struct blk_cmd_filter *, char *);
  121. ssize_t (*store)(struct blk_cmd_filter *, const char *, size_t);
  122. };
  123. static struct rcf_sysfs_entry rcf_readcmds_entry = {
  124. .attr = { .name = "read_table", .mode = S_IRUGO | S_IWUSR },
  125. .show = rcf_readcmds_show,
  126. .store = rcf_readcmds_store,
  127. };
  128. static struct rcf_sysfs_entry rcf_writecmds_entry = {
  129. .attr = {.name = "write_table", .mode = S_IRUGO | S_IWUSR },
  130. .show = rcf_writecmds_show,
  131. .store = rcf_writecmds_store,
  132. };
  133. static struct attribute *default_attrs[] = {
  134. &rcf_readcmds_entry.attr,
  135. &rcf_writecmds_entry.attr,
  136. NULL,
  137. };
  138. #define to_rcf(atr) container_of((atr), struct rcf_sysfs_entry, attr)
  139. static ssize_t
  140. rcf_attr_show(struct kobject *kobj, struct attribute *attr, char *page)
  141. {
  142. struct rcf_sysfs_entry *entry = to_rcf(attr);
  143. struct blk_cmd_filter *filter;
  144. filter = container_of(kobj, struct blk_cmd_filter, kobj);
  145. if (entry->show)
  146. return entry->show(filter, page);
  147. return 0;
  148. }
  149. static ssize_t
  150. rcf_attr_store(struct kobject *kobj, struct attribute *attr,
  151. const char *page, size_t length)
  152. {
  153. struct rcf_sysfs_entry *entry = to_rcf(attr);
  154. struct blk_cmd_filter *filter;
  155. if (!capable(CAP_SYS_RAWIO))
  156. return -EPERM;
  157. if (!entry->store)
  158. return -EINVAL;
  159. filter = container_of(kobj, struct blk_cmd_filter, kobj);
  160. return entry->store(filter, page, length);
  161. }
  162. static struct sysfs_ops rcf_sysfs_ops = {
  163. .show = rcf_attr_show,
  164. .store = rcf_attr_store,
  165. };
  166. static struct kobj_type rcf_ktype = {
  167. .sysfs_ops = &rcf_sysfs_ops,
  168. .default_attrs = default_attrs,
  169. };
  170. int blk_register_filter(struct gendisk *disk)
  171. {
  172. int ret;
  173. struct blk_cmd_filter *filter = &disk->queue->cmd_filter;
  174. struct kobject *parent = kobject_get(disk->holder_dir->parent);
  175. if (!parent)
  176. return -ENODEV;
  177. ret = kobject_init_and_add(&filter->kobj, &rcf_ktype, parent,
  178. "%s", "cmd_filter");
  179. if (ret < 0)
  180. return ret;
  181. return 0;
  182. }
  183. EXPORT_SYMBOL(blk_register_filter);
  184. void blk_unregister_filter(struct gendisk *disk)
  185. {
  186. struct blk_cmd_filter *filter = &disk->queue->cmd_filter;
  187. kobject_put(&filter->kobj);
  188. kobject_put(disk->holder_dir->parent);
  189. }
  190. EXPORT_SYMBOL(blk_unregister_filter);