Commit | Line | Data |
---|---|---|
b2441318 | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
ae5e1b22 PE |
2 | #ifndef __IPC_NAMESPACE_H__ |
3 | #define __IPC_NAMESPACE_H__ | |
4 | ||
5 | #include <linux/err.h> | |
ed2ddbf8 PP |
6 | #include <linux/idr.h> |
7 | #include <linux/rwsem.h> | |
b6b337ad | 8 | #include <linux/notifier.h> |
b0e77598 | 9 | #include <linux/nsproxy.h> |
435d5f4b | 10 | #include <linux/ns_common.h> |
a2e0602c | 11 | #include <linux/refcount.h> |
0eb71a9d | 12 | #include <linux/rhashtable-types.h> |
b6b337ad | 13 | |
b515498f | 14 | struct user_namespace; |
ed2ddbf8 PP |
15 | |
16 | struct ipc_ids { | |
17 | int in_use; | |
18 | unsigned short seq; | |
d9a605e4 | 19 | struct rw_semaphore rwsem; |
ed2ddbf8 | 20 | struct idr ipcs_idr; |
27c331a1 | 21 | int max_idx; |
b8fd9983 | 22 | #ifdef CONFIG_CHECKPOINT_RESTORE |
03f59566 | 23 | int next_id; |
b8fd9983 | 24 | #endif |
0cfb6aee | 25 | struct rhashtable key_ht; |
ed2ddbf8 | 26 | }; |
ae5e1b22 | 27 | |
ae5e1b22 | 28 | struct ipc_namespace { |
a2e0602c | 29 | refcount_t count; |
ed2ddbf8 | 30 | struct ipc_ids ids[3]; |
ae5e1b22 PE |
31 | |
32 | int sem_ctls[4]; | |
33 | int used_sems; | |
34 | ||
9bf76ca3 MK |
35 | unsigned int msg_ctlmax; |
36 | unsigned int msg_ctlmnb; | |
37 | unsigned int msg_ctlmni; | |
ae5e1b22 PE |
38 | atomic_t msg_bytes; |
39 | atomic_t msg_hdrs; | |
40 | ||
41 | size_t shm_ctlmax; | |
42 | size_t shm_ctlall; | |
d69f3bad | 43 | unsigned long shm_tot; |
ae5e1b22 | 44 | int shm_ctlmni; |
b34a6b1d VK |
45 | /* |
46 | * Defines whether IPC_RMID is forced for _all_ shm segments regardless | |
47 | * of shmctl() | |
48 | */ | |
49 | int shm_rmid_forced; | |
b6b337ad | 50 | |
b6b337ad | 51 | struct notifier_block ipcns_nb; |
614b84cf SH |
52 | |
53 | /* The kern_mount of the mqueuefs sb. We take a ref on it */ | |
54 | struct vfsmount *mq_mnt; | |
55 | ||
56 | /* # queues in this ns, protected by mq_lock */ | |
57 | unsigned int mq_queues_count; | |
58 | ||
59 | /* next fields are set through sysctl */ | |
60 | unsigned int mq_queues_max; /* initialized to DFLT_QUEUESMAX */ | |
61 | unsigned int mq_msg_max; /* initialized to DFLT_MSGMAX */ | |
62 | unsigned int mq_msgsize_max; /* initialized to DFLT_MSGSIZEMAX */ | |
cef0184c KM |
63 | unsigned int mq_msg_default; |
64 | unsigned int mq_msgsize_default; | |
614b84cf | 65 | |
b515498f SH |
66 | /* user_ns which owns the ipc ns */ |
67 | struct user_namespace *user_ns; | |
aba35661 | 68 | struct ucounts *ucounts; |
98f842e6 | 69 | |
435d5f4b | 70 | struct ns_common ns; |
3859a271 | 71 | } __randomize_layout; |
ae5e1b22 PE |
72 | |
73 | extern struct ipc_namespace init_ipc_ns; | |
7eafd7c7 | 74 | extern spinlock_t mq_lock; |
b6b337ad | 75 | |
614b84cf | 76 | #ifdef CONFIG_SYSVIPC |
b34a6b1d | 77 | extern void shm_destroy_orphaned(struct ipc_namespace *ns); |
b6b337ad | 78 | #else /* CONFIG_SYSVIPC */ |
b34a6b1d | 79 | static inline void shm_destroy_orphaned(struct ipc_namespace *ns) {} |
b6b337ad | 80 | #endif /* CONFIG_SYSVIPC */ |
ae5e1b22 | 81 | |
614b84cf | 82 | #ifdef CONFIG_POSIX_MQUEUE |
7eafd7c7 | 83 | extern int mq_init_ns(struct ipc_namespace *ns); |
5b5c4d1a DL |
84 | /* |
85 | * POSIX Message Queue default values: | |
86 | * | |
87 | * MIN_*: Lowest value an admin can set the maximum unprivileged limit to | |
88 | * DFLT_*MAX: Default values for the maximum unprivileged limits | |
89 | * DFLT_{MSG,MSGSIZE}: Default values used when the user doesn't supply | |
90 | * an attribute to the open call and the queue must be created | |
91 | * HARD_*: Highest value the maximums can be set to. These are enforced | |
92 | * on CAP_SYS_RESOURCE apps as well making them inviolate (so make them | |
93 | * suitably high) | |
94 | * | |
95 | * POSIX Requirements: | |
96 | * Per app minimum openable message queues - 8. This does not map well | |
97 | * to the fact that we limit the number of queues on a per namespace | |
98 | * basis instead of a per app basis. So, make the default high enough | |
99 | * that no given app should have a hard time opening 8 queues. | |
100 | * Minimum maximum for HARD_MSGMAX - 32767. I bumped this to 65536. | |
101 | * Minimum maximum for HARD_MSGSIZEMAX - POSIX is silent on this. However, | |
102 | * we have run into a situation where running applications in the wild | |
103 | * require this to be at least 5MB, and preferably 10MB, so I set the | |
104 | * value to 16MB in hopes that this user is the worst of the bunch and | |
105 | * the new maximum will handle anyone else. I may have to revisit this | |
106 | * in the future. | |
107 | */ | |
5b5c4d1a | 108 | #define DFLT_QUEUESMAX 256 |
5b5c4d1a | 109 | #define MIN_MSGMAX 1 |
e6315bb1 KM |
110 | #define DFLT_MSG 10U |
111 | #define DFLT_MSGMAX 10 | |
5b5c4d1a DL |
112 | #define HARD_MSGMAX 65536 |
113 | #define MIN_MSGSIZEMAX 128 | |
114 | #define DFLT_MSGSIZE 8192U | |
e6315bb1 | 115 | #define DFLT_MSGSIZEMAX 8192 |
5b5c4d1a | 116 | #define HARD_MSGSIZEMAX (16*1024*1024) |
614b84cf | 117 | #else |
7eafd7c7 | 118 | static inline int mq_init_ns(struct ipc_namespace *ns) { return 0; } |
614b84cf SH |
119 | #endif |
120 | ||
121 | #if defined(CONFIG_IPC_NS) | |
ae5e1b22 | 122 | extern struct ipc_namespace *copy_ipcs(unsigned long flags, |
bcf58e72 EB |
123 | struct user_namespace *user_ns, struct ipc_namespace *ns); |
124 | ||
ae5e1b22 PE |
125 | static inline struct ipc_namespace *get_ipc_ns(struct ipc_namespace *ns) |
126 | { | |
127 | if (ns) | |
a2e0602c | 128 | refcount_inc(&ns->count); |
ae5e1b22 PE |
129 | return ns; |
130 | } | |
131 | ||
7eafd7c7 | 132 | extern void put_ipc_ns(struct ipc_namespace *ns); |
ae5e1b22 PE |
133 | #else |
134 | static inline struct ipc_namespace *copy_ipcs(unsigned long flags, | |
bcf58e72 | 135 | struct user_namespace *user_ns, struct ipc_namespace *ns) |
ae5e1b22 PE |
136 | { |
137 | if (flags & CLONE_NEWIPC) | |
138 | return ERR_PTR(-EINVAL); | |
139 | ||
bcf58e72 | 140 | return ns; |
ae5e1b22 PE |
141 | } |
142 | ||
143 | static inline struct ipc_namespace *get_ipc_ns(struct ipc_namespace *ns) | |
144 | { | |
145 | return ns; | |
146 | } | |
147 | ||
148 | static inline void put_ipc_ns(struct ipc_namespace *ns) | |
149 | { | |
150 | } | |
151 | #endif | |
bdc8e5f8 SH |
152 | |
153 | #ifdef CONFIG_POSIX_MQUEUE_SYSCTL | |
154 | ||
155 | struct ctl_table_header; | |
156 | extern struct ctl_table_header *mq_register_sysctl_table(void); | |
157 | ||
158 | #else /* CONFIG_POSIX_MQUEUE_SYSCTL */ | |
159 | ||
160 | static inline struct ctl_table_header *mq_register_sysctl_table(void) | |
161 | { | |
162 | return NULL; | |
163 | } | |
164 | ||
165 | #endif /* CONFIG_POSIX_MQUEUE_SYSCTL */ | |
ae5e1b22 | 166 | #endif |