Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 1 | /* Upcall routine, designed to work as a key type and working through |
| 2 | * /sbin/request-key to contact userspace when handling DNS queries. |
| 3 | * |
Mauro Carvalho Chehab | 9dfe136 | 2020-04-28 00:01:32 +0200 | [diff] [blame] | 4 | * See Documentation/networking/dns_resolver.rst |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 5 | * |
| 6 | * Copyright (c) 2007 Igor Mammedov |
| 7 | * Author(s): Igor Mammedov (niallain@gmail.com) |
| 8 | * Steve French (sfrench@us.ibm.com) |
| 9 | * Wang Lei (wang840925@gmail.com) |
| 10 | * David Howells (dhowells@redhat.com) |
| 11 | * |
| 12 | * The upcall wrapper used to make an arbitrary DNS query. |
| 13 | * |
| 14 | * This function requires the appropriate userspace tool dns.upcall to be |
| 15 | * installed and something like the following lines should be added to the |
| 16 | * /etc/request-key.conf file: |
| 17 | * |
| 18 | * create dns_resolver * * /sbin/dns.upcall %k |
| 19 | * |
| 20 | * For example to use this module to query AFSDB RR: |
| 21 | * |
| 22 | * create dns_resolver afsdb:* * /sbin/dns.afsdb %k |
| 23 | * |
| 24 | * This library is free software; you can redistribute it and/or modify |
| 25 | * it under the terms of the GNU Lesser General Public License as published |
| 26 | * by the Free Software Foundation; either version 2.1 of the License, or |
| 27 | * (at your option) any later version. |
| 28 | * |
| 29 | * This library is distributed in the hope that it will be useful, |
| 30 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 31 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See |
| 32 | * the GNU Lesser General Public License for more details. |
| 33 | * |
| 34 | * You should have received a copy of the GNU Lesser General Public License |
Jeff Kirsher | c057b19 | 2013-12-06 09:13:44 -0800 | [diff] [blame] | 35 | * along with this library; if not, see <http://www.gnu.org/licenses/>. |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 36 | */ |
| 37 | |
| 38 | #include <linux/module.h> |
| 39 | #include <linux/slab.h> |
Ingo Molnar | 5b825c3 | 2017-02-02 17:54:15 +0100 | [diff] [blame] | 40 | #include <linux/cred.h> |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 41 | #include <linux/dns_resolver.h> |
Stephen Rothwell | af352fe | 2010-08-06 03:13:47 +0100 | [diff] [blame] | 42 | #include <linux/err.h> |
David Howells | a58946c | 2019-06-26 21:02:33 +0100 | [diff] [blame] | 43 | #include <net/net_namespace.h> |
Ingo Molnar | 5b825c3 | 2017-02-02 17:54:15 +0100 | [diff] [blame] | 44 | |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 45 | #include <keys/dns_resolver-type.h> |
| 46 | #include <keys/user-type.h> |
| 47 | |
| 48 | #include "internal.h" |
| 49 | |
David Howells | ff9517a | 2010-08-06 03:13:52 +0100 | [diff] [blame] | 50 | /** |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 51 | * dns_query - Query the DNS |
David Howells | a58946c | 2019-06-26 21:02:33 +0100 | [diff] [blame] | 52 | * @net: The network namespace to operate in. |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 53 | * @type: Query type (or NULL for straight host->IP lookup) |
| 54 | * @name: Name to look up |
| 55 | * @namelen: Length of name |
| 56 | * @options: Request options (or NULL if no options) |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 57 | * @_result: Where to place the returned data (or NULL) |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 58 | * @_expiry: Where to store the result expiry time (or NULL) |
David Howells | d0660f0 | 2019-05-03 18:26:55 +0100 | [diff] [blame] | 59 | * @invalidate: Always invalidate the key after use |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 60 | * |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 61 | * The data will be returned in the pointer at *result, if provided, and the |
| 62 | * caller is responsible for freeing it. |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 63 | * |
| 64 | * The description should be of the form "[<query_type>:]<domain_name>", and |
| 65 | * the options need to be appropriate for the query type requested. If no |
| 66 | * query_type is given, then the query is a straight hostname to IP address |
| 67 | * lookup. |
| 68 | * |
| 69 | * The DNS resolution lookup is performed by upcalling to userspace by way of |
| 70 | * requesting a key of type dns_resolver. |
| 71 | * |
| 72 | * Returns the size of the result on success, -ve error code otherwise. |
| 73 | */ |
David Howells | a58946c | 2019-06-26 21:02:33 +0100 | [diff] [blame] | 74 | int dns_query(struct net *net, |
| 75 | const char *type, const char *name, size_t namelen, |
David Howells | d0660f0 | 2019-05-03 18:26:55 +0100 | [diff] [blame] | 76 | const char *options, char **_result, time64_t *_expiry, |
| 77 | bool invalidate) |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 78 | { |
| 79 | struct key *rkey; |
David Howells | 0837e49 | 2017-03-01 15:11:23 +0000 | [diff] [blame] | 80 | struct user_key_payload *upayload; |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 81 | const struct cred *saved_cred; |
| 82 | size_t typelen, desclen; |
| 83 | char *desc, *cp; |
| 84 | int ret, len; |
| 85 | |
| 86 | kenter("%s,%*.*s,%zu,%s", |
| 87 | type, (int)namelen, (int)namelen, name, namelen, options); |
| 88 | |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 89 | if (!name || namelen == 0) |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 90 | return -EINVAL; |
| 91 | |
| 92 | /* construct the query key description as "[<type>:]<name>" */ |
| 93 | typelen = 0; |
| 94 | desclen = 0; |
| 95 | if (type) { |
| 96 | typelen = strlen(type); |
| 97 | if (typelen < 1) |
| 98 | return -EINVAL; |
| 99 | desclen += typelen + 1; |
| 100 | } |
| 101 | |
Manuel Schölling | 9638f67 | 2014-05-31 23:37:40 +0200 | [diff] [blame] | 102 | if (namelen < 3 || namelen > 255) |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 103 | return -EINVAL; |
| 104 | desclen += namelen + 1; |
| 105 | |
| 106 | desc = kmalloc(desclen, GFP_KERNEL); |
| 107 | if (!desc) |
| 108 | return -ENOMEM; |
| 109 | |
| 110 | cp = desc; |
| 111 | if (type) { |
| 112 | memcpy(cp, type, typelen); |
| 113 | cp += typelen; |
| 114 | *cp++ = ':'; |
| 115 | } |
| 116 | memcpy(cp, name, namelen); |
| 117 | cp += namelen; |
| 118 | *cp = '\0'; |
| 119 | |
| 120 | if (!options) |
| 121 | options = ""; |
| 122 | kdebug("call request_key(,%s,%s)", desc, options); |
| 123 | |
| 124 | /* make the upcall, using special credentials to prevent the use of |
| 125 | * add_key() to preinstall malicious redirections |
| 126 | */ |
| 127 | saved_cred = override_creds(dns_resolver_cache); |
Linus Torvalds | 028db3e | 2019-07-10 18:43:43 -0700 | [diff] [blame] | 128 | rkey = request_key_net(&key_type_dns_resolver, desc, net, options); |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 129 | revert_creds(saved_cred); |
| 130 | kfree(desc); |
| 131 | if (IS_ERR(rkey)) { |
| 132 | ret = PTR_ERR(rkey); |
| 133 | goto out; |
| 134 | } |
| 135 | |
| 136 | down_read(&rkey->sem); |
David Howells | 0c7774a | 2014-07-17 20:45:08 +0100 | [diff] [blame] | 137 | set_bit(KEY_FLAG_ROOT_CAN_INVAL, &rkey->flags); |
Linus Torvalds | 028db3e | 2019-07-10 18:43:43 -0700 | [diff] [blame] | 138 | rkey->perm |= KEY_USR_VIEW; |
| 139 | |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 140 | ret = key_validate(rkey); |
| 141 | if (ret < 0) |
| 142 | goto put; |
| 143 | |
Wang Lei | 4a2d789 | 2010-08-11 09:37:58 +0100 | [diff] [blame] | 144 | /* If the DNS server gave an error, return that to the caller */ |
David Howells | 146aa8b | 2015-10-21 14:04:48 +0100 | [diff] [blame] | 145 | ret = PTR_ERR(rkey->payload.data[dns_key_error]); |
Wang Lei | 4a2d789 | 2010-08-11 09:37:58 +0100 | [diff] [blame] | 146 | if (ret) |
| 147 | goto put; |
| 148 | |
David Howells | 0837e49 | 2017-03-01 15:11:23 +0000 | [diff] [blame] | 149 | upayload = user_key_payload_locked(rkey); |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 150 | len = upayload->datalen; |
| 151 | |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 152 | if (_result) { |
| 153 | ret = -ENOMEM; |
David Howells | bbb4c43 | 2018-10-04 14:27:55 +0100 | [diff] [blame] | 154 | *_result = kmemdup_nul(upayload->data, len, GFP_KERNEL); |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 155 | if (!*_result) |
| 156 | goto put; |
David Howells | 4d673da | 2018-02-06 06:26:30 +0000 | [diff] [blame] | 157 | } |
Manuel Schölling | 84a7c0b | 2014-06-07 23:57:25 +0200 | [diff] [blame] | 158 | |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 159 | if (_expiry) |
| 160 | *_expiry = rkey->expiry; |
| 161 | |
| 162 | ret = len; |
| 163 | put: |
| 164 | up_read(&rkey->sem); |
David Howells | d0660f0 | 2019-05-03 18:26:55 +0100 | [diff] [blame] | 165 | if (invalidate) |
| 166 | key_invalidate(rkey); |
Wang Lei | 1a4240f | 2010-08-04 15:16:33 +0100 | [diff] [blame] | 167 | key_put(rkey); |
| 168 | out: |
| 169 | kleave(" = %d", ret); |
| 170 | return ret; |
| 171 | } |
| 172 | EXPORT_SYMBOL(dns_query); |