Like it was done for link and address, add the ability to perform get/dump
in another netns by specifying a target nsid attribute.

Signed-off-by: Nicolas Dichtel <nicolas.dich...@6wind.com>
---
 include/uapi/linux/net_namespace.h |  1 +
 net/core/net_namespace.c           | 97 ++++++++++++++++++++++++------
 2 files changed, 80 insertions(+), 18 deletions(-)

diff --git a/include/uapi/linux/net_namespace.h 
b/include/uapi/linux/net_namespace.h
index 0187c74d8889..0ed9dd61d32a 100644
--- a/include/uapi/linux/net_namespace.h
+++ b/include/uapi/linux/net_namespace.h
@@ -16,6 +16,7 @@ enum {
        NETNSA_NSID,
        NETNSA_PID,
        NETNSA_FD,
+       NETNSA_TARGET_NSID,
        __NETNSA_MAX,
 };
 
diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
index 3e6af99bbe53..3d02a742155f 100644
--- a/net/core/net_namespace.c
+++ b/net/core/net_namespace.c
@@ -669,6 +669,7 @@ static const struct nla_policy rtnl_net_policy[NETNSA_MAX + 
1] = {
        [NETNSA_NSID]           = { .type = NLA_S32 },
        [NETNSA_PID]            = { .type = NLA_U32 },
        [NETNSA_FD]             = { .type = NLA_U32 },
+       [NETNSA_TARGET_NSID]    = { .type = NLA_S32 },
 };
 
 static int rtnl_net_newid(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -767,9 +768,9 @@ static int rtnl_net_getid(struct sk_buff *skb, struct 
nlmsghdr *nlh,
 {
        struct net *net = sock_net(skb->sk);
        struct nlattr *tb[NETNSA_MAX + 1];
+       struct net *peer, *target = net;
        struct nlattr *nla;
        struct sk_buff *msg;
-       struct net *peer;
        int err, id;
 
        err = nlmsg_parse(nlh, sizeof(struct rtgenmsg), tb, NETNSA_MAX,
@@ -793,30 +794,47 @@ static int rtnl_net_getid(struct sk_buff *skb, struct 
nlmsghdr *nlh,
                return PTR_ERR(peer);
        }
 
+       if (tb[NETNSA_TARGET_NSID]) {
+               id = nla_get_s32(tb[NETNSA_TARGET_NSID]);
+               target = rtnl_get_net_ns_capable(NETLINK_CB(skb).sk, id);
+               if (IS_ERR(target)) {
+                       NL_SET_BAD_ATTR(extack, tb[NETNSA_TARGET_NSID]);
+                       NL_SET_ERR_MSG(extack,
+                                      "Target netns reference is invalid");
+                       err = PTR_ERR(target);
+                       goto put_peer;
+               }
+       } else {
+               get_net(target);
+       }
+
        msg = nlmsg_new(rtnl_net_get_size(), GFP_KERNEL);
        if (!msg) {
                err = -ENOMEM;
-               goto out;
+               goto put_target;
        }
 
-       id = peernet2id(net, peer);
+       id = peernet2id(target, peer);
        err = rtnl_net_fill(msg, NETLINK_CB(skb).portid, nlh->nlmsg_seq, 0,
                            RTM_NEWNSID, id);
        if (err < 0)
-               goto err_out;
+               goto free_nlmsg;
 
        err = rtnl_unicast(msg, net, NETLINK_CB(skb).portid);
-       goto out;
+       goto put_target;
 
-err_out:
+free_nlmsg:
        nlmsg_free(msg);
-out:
+put_target:
+       put_net(target);
+put_peer:
        put_net(peer);
        return err;
 }
 
 struct rtnl_net_dump_cb {
-       struct net *net;
+       struct net *tgt_net;
+       struct net *ref_net;
        struct sk_buff *skb;
        struct netlink_callback *cb;
        int idx;
@@ -842,29 +860,72 @@ static int rtnl_net_dumpid_one(int id, void *peer, void 
*data)
        return 0;
 }
 
+static int rtnl_valid_dump_net_req(const struct nlmsghdr *nlh, struct sock *sk,
+                                  struct rtnl_net_dump_cb *net_cb,
+                                  struct netlink_callback *cb)
+{
+       struct netlink_ext_ack *extack = cb->extack;
+       struct nlattr *tb[NETNSA_MAX + 1];
+       int err, i;
+
+       err = nlmsg_parse_strict(nlh, sizeof(struct rtgenmsg), tb, NETNSA_MAX,
+                                rtnl_net_policy, extack);
+       if (err < 0)
+               return err;
+
+       for (i = 0; i <= NETNSA_MAX; i++) {
+               if (!tb[i])
+                       continue;
+
+               if (i == NETNSA_TARGET_NSID) {
+                       struct net *net;
+
+                       net = rtnl_get_net_ns_capable(sk, nla_get_s32(tb[i]));
+                       if (IS_ERR(net)) {
+                               NL_SET_BAD_ATTR(extack, tb[i]);
+                               NL_SET_ERR_MSG(extack,
+                                              "Invalid target network 
namespace id");
+                               return PTR_ERR(net);
+                       }
+                       net_cb->ref_net = net_cb->tgt_net;
+                       net_cb->tgt_net = net;
+               } else {
+                       NL_SET_BAD_ATTR(extack, tb[i]);
+                       NL_SET_ERR_MSG(extack,
+                                      "Unsupported attribute in dump request");
+                       return -EINVAL;
+               }
+       }
+
+       return 0;
+}
+
 static int rtnl_net_dumpid(struct sk_buff *skb, struct netlink_callback *cb)
 {
-       struct net *net = sock_net(skb->sk);
        struct rtnl_net_dump_cb net_cb = {
-               .net = net,
+               .tgt_net = sock_net(skb->sk),
                .skb = skb,
                .cb = cb,
                .idx = 0,
                .s_idx = cb->args[0],
        };
+       int err = 0;
 
-       if (cb->strict_check &&
-           nlmsg_attrlen(cb->nlh, sizeof(struct rtgenmsg))) {
-                       NL_SET_ERR_MSG(cb->extack, "Unknown data in network 
namespace id dump request");
-                       return -EINVAL;
+       if (cb->strict_check) {
+               err = rtnl_valid_dump_net_req(cb->nlh, skb->sk, &net_cb, cb);
+               if (err < 0)
+                       goto end;
        }
 
-       spin_lock_bh(&net->nsid_lock);
-       idr_for_each(&net->netns_ids, rtnl_net_dumpid_one, &net_cb);
-       spin_unlock_bh(&net->nsid_lock);
+       spin_lock_bh(&net_cb.tgt_net->nsid_lock);
+       idr_for_each(&net_cb.tgt_net->netns_ids, rtnl_net_dumpid_one, &net_cb);
+       spin_unlock_bh(&net_cb.tgt_net->nsid_lock);
 
        cb->args[0] = net_cb.idx;
-       return skb->len;
+end:
+       if (net_cb.ref_net)
+               put_net(net_cb.tgt_net);
+       return err < 0 ? err : skb->len;
 }
 
 static void rtnl_net_notifyid(struct net *net, int cmd, int id)
-- 
2.18.0

Reply via email to