hooks.c 155 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293
  1. /*
  2. * NSA Security-Enhanced Linux (SELinux) security module
  3. *
  4. * This file contains the SELinux hook function implementations.
  5. *
  6. * Authors: Stephen Smalley, <sds@epoch.ncsc.mil>
  7. * Chris Vance, <cvance@nai.com>
  8. * Wayne Salamon, <wsalamon@nai.com>
  9. * James Morris <jmorris@redhat.com>
  10. *
  11. * Copyright (C) 2001,2002 Networks Associates Technology, Inc.
  12. * Copyright (C) 2003-2008 Red Hat, Inc., James Morris <jmorris@redhat.com>
  13. * Eric Paris <eparis@redhat.com>
  14. * Copyright (C) 2004-2005 Trusted Computer Solutions, Inc.
  15. * <dgoeddel@trustedcs.com>
  16. * Copyright (C) 2006, 2007, 2009 Hewlett-Packard Development Company, L.P.
  17. * Paul Moore <paul@paul-moore.com>
  18. * Copyright (C) 2007 Hitachi Software Engineering Co., Ltd.
  19. * Yuichi Nakamura <ynakam@hitachisoft.jp>
  20. *
  21. * This program is free software; you can redistribute it and/or modify
  22. * it under the terms of the GNU General Public License version 2,
  23. * as published by the Free Software Foundation.
  24. */
  25. #include <linux/init.h>
  26. #include <linux/kd.h>
  27. #include <linux/kernel.h>
  28. #include <linux/tracehook.h>
  29. #include <linux/errno.h>
  30. #include <linux/sched.h>
  31. #include <linux/security.h>
  32. #include <linux/xattr.h>
  33. #include <linux/capability.h>
  34. #include <linux/unistd.h>
  35. #include <linux/mm.h>
  36. #include <linux/mman.h>
  37. #include <linux/slab.h>
  38. #include <linux/pagemap.h>
  39. #include <linux/proc_fs.h>
  40. #include <linux/swap.h>
  41. #include <linux/spinlock.h>
  42. #include <linux/syscalls.h>
  43. #include <linux/dcache.h>
  44. #include <linux/file.h>
  45. #include <linux/fdtable.h>
  46. #include <linux/namei.h>
  47. #include <linux/mount.h>
  48. #include <linux/netfilter_ipv4.h>
  49. #include <linux/netfilter_ipv6.h>
  50. #include <linux/tty.h>
  51. #include <net/icmp.h>
  52. #include <net/ip.h> /* for local_port_range[] */
  53. #include <net/tcp.h> /* struct or_callable used in sock_rcv_skb */
  54. #include <net/inet_connection_sock.h>
  55. #include <net/net_namespace.h>
  56. #include <net/netlabel.h>
  57. #include <linux/uaccess.h>
  58. #include <asm/ioctls.h>
  59. #include <linux/atomic.h>
  60. #include <linux/bitops.h>
  61. #include <linux/interrupt.h>
  62. #include <linux/netdevice.h> /* for network interface checks */
  63. #include <net/netlink.h>
  64. #include <linux/tcp.h>
  65. #include <linux/udp.h>
  66. #include <linux/dccp.h>
  67. #include <linux/quota.h>
  68. #include <linux/un.h> /* for Unix socket types */
  69. #include <net/af_unix.h> /* for Unix socket types */
  70. #include <linux/parser.h>
  71. #include <linux/nfs_mount.h>
  72. #include <net/ipv6.h>
  73. #include <linux/hugetlb.h>
  74. #include <linux/personality.h>
  75. #include <linux/audit.h>
  76. #include <linux/string.h>
  77. #include <linux/selinux.h>
  78. #include <linux/mutex.h>
  79. #include <linux/posix-timers.h>
  80. #include <linux/syslog.h>
  81. #include <linux/user_namespace.h>
  82. #include <linux/export.h>
  83. #include <linux/msg.h>
  84. #include <linux/shm.h>
  85. #include <linux/pft.h>
  86. #include <linux/ratelimit.h>
  87. #include "avc.h"
  88. #include "objsec.h"
  89. #include "netif.h"
  90. #include "netnode.h"
  91. #include "netport.h"
  92. #include "xfrm.h"
  93. #include "netlabel.h"
  94. #include "audit.h"
  95. #include "avc_ss.h"
  96. #define NUM_SEL_MNT_OPTS 5
  97. extern struct security_operations *security_ops;
  98. /* SECMARK reference count */
  99. static atomic_t selinux_secmark_refcount = ATOMIC_INIT(0);
  100. #ifdef CONFIG_SECURITY_SELINUX_DEVELOP
  101. int selinux_enforcing;
  102. static int __init enforcing_setup(char *str)
  103. {
  104. unsigned long enforcing;
  105. if (!strict_strtoul(str, 0, &enforcing))
  106. #ifdef CONFIG_ALWAYS_ENFORCE
  107. selinux_enforcing = 1;
  108. #else
  109. selinux_enforcing = enforcing ? 1 : 0;
  110. #endif
  111. return 1;
  112. }
  113. __setup("enforcing=", enforcing_setup);
  114. #endif
  115. #ifdef CONFIG_SECURITY_SELINUX_BOOTPARAM
  116. int selinux_enabled = CONFIG_SECURITY_SELINUX_BOOTPARAM_VALUE;
  117. static int __init selinux_enabled_setup(char *str)
  118. {
  119. unsigned long enabled;
  120. if (!strict_strtoul(str, 0, &enabled))
  121. #ifdef CONFIG_ALWAYS_ENFORCE
  122. selinux_enabled = 1;
  123. #else
  124. selinux_enabled = enabled ? 1 : 0;
  125. #endif
  126. return 1;
  127. }
  128. __setup("selinux=", selinux_enabled_setup);
  129. #else
  130. int selinux_enabled = 1;
  131. #endif
  132. static struct kmem_cache *sel_inode_cache;
  133. /**
  134. * selinux_secmark_enabled - Check to see if SECMARK is currently enabled
  135. *
  136. * Description:
  137. * This function checks the SECMARK reference counter to see if any SECMARK
  138. * targets are currently configured, if the reference counter is greater than
  139. * zero SECMARK is considered to be enabled. Returns true (1) if SECMARK is
  140. * enabled, false (0) if SECMARK is disabled.
  141. *
  142. */
  143. static int selinux_secmark_enabled(void)
  144. {
  145. return (atomic_read(&selinux_secmark_refcount) > 0);
  146. }
  147. /*
  148. * initialise the security for the init task
  149. */
  150. static void cred_init_security(void)
  151. {
  152. struct cred *cred = (struct cred *) current->real_cred;
  153. struct task_security_struct *tsec;
  154. tsec = kzalloc(sizeof(struct task_security_struct), GFP_KERNEL);
  155. if (!tsec)
  156. panic("SELinux: Failed to initialize initial task.\n");
  157. tsec->osid = tsec->sid = SECINITSID_KERNEL;
  158. cred->security = tsec;
  159. }
  160. /*
  161. * get the security ID of a set of credentials
  162. */
  163. static inline u32 cred_sid(const struct cred *cred)
  164. {
  165. const struct task_security_struct *tsec;
  166. tsec = cred->security;
  167. return tsec->sid;
  168. }
  169. /*
  170. * get the objective security ID of a task
  171. */
  172. static inline u32 task_sid(const struct task_struct *task)
  173. {
  174. u32 sid;
  175. rcu_read_lock();
  176. sid = cred_sid(__task_cred(task));
  177. rcu_read_unlock();
  178. return sid;
  179. }
  180. /*
  181. * get the subjective security ID of the current task
  182. */
  183. static inline u32 current_sid(void)
  184. {
  185. const struct task_security_struct *tsec = current_security();
  186. return tsec->sid;
  187. }
  188. /* Allocate and free functions for each kind of security blob. */
  189. static int inode_alloc_security(struct inode *inode)
  190. {
  191. struct inode_security_struct *isec;
  192. u32 sid = current_sid();
  193. isec = kmem_cache_zalloc(sel_inode_cache, GFP_NOFS);
  194. if (!isec)
  195. return -ENOMEM;
  196. mutex_init(&isec->lock);
  197. INIT_LIST_HEAD(&isec->list);
  198. isec->inode = inode;
  199. isec->sid = SECINITSID_UNLABELED;
  200. isec->sclass = SECCLASS_FILE;
  201. isec->task_sid = sid;
  202. inode->i_security = isec;
  203. return 0;
  204. }
  205. static void inode_free_rcu(struct rcu_head *head)
  206. {
  207. struct inode_security_struct *isec;
  208. isec = container_of(head, struct inode_security_struct, rcu);
  209. kmem_cache_free(sel_inode_cache, isec);
  210. }
  211. static void inode_free_security(struct inode *inode)
  212. {
  213. struct inode_security_struct *isec = inode->i_security;
  214. struct superblock_security_struct *sbsec = inode->i_sb->s_security;
  215. /*
  216. * As not all inode security structures are in a list, we check for
  217. * empty list outside of the lock to make sure that we won't waste
  218. * time taking a lock doing nothing.
  219. *
  220. * The list_del_init() function can be safely called more than once.
  221. * It should not be possible for this function to be called with
  222. * concurrent list_add(), but for better safety against future changes
  223. * in the code, we use list_empty_careful() here.
  224. */
  225. if (!list_empty_careful(&isec->list)) {
  226. spin_lock(&sbsec->isec_lock);
  227. list_del_init(&isec->list);
  228. spin_unlock(&sbsec->isec_lock);
  229. }
  230. /*
  231. * The inode may still be referenced in a path walk and
  232. * a call to selinux_inode_permission() can be made
  233. * after inode_free_security() is called. Ideally, the VFS
  234. * wouldn't do this, but fixing that is a much harder
  235. * job. For now, simply free the i_security via RCU, and
  236. * leave the current inode->i_security pointer intact.
  237. * The inode will be freed after the RCU grace period too.
  238. */
  239. call_rcu(&isec->rcu, inode_free_rcu);
  240. }
  241. static int file_alloc_security(struct file *file)
  242. {
  243. struct file_security_struct *fsec;
  244. u32 sid = current_sid();
  245. fsec = kzalloc(sizeof(struct file_security_struct), GFP_KERNEL);
  246. if (!fsec)
  247. return -ENOMEM;
  248. fsec->sid = sid;
  249. fsec->fown_sid = sid;
  250. file->f_security = fsec;
  251. return 0;
  252. }
  253. static void file_free_security(struct file *file)
  254. {
  255. struct file_security_struct *fsec = file->f_security;
  256. file->f_security = NULL;
  257. kfree(fsec);
  258. }
  259. static int superblock_alloc_security(struct super_block *sb)
  260. {
  261. struct superblock_security_struct *sbsec;
  262. sbsec = kzalloc(sizeof(struct superblock_security_struct), GFP_KERNEL);
  263. if (!sbsec)
  264. return -ENOMEM;
  265. mutex_init(&sbsec->lock);
  266. INIT_LIST_HEAD(&sbsec->isec_head);
  267. spin_lock_init(&sbsec->isec_lock);
  268. sbsec->sb = sb;
  269. sbsec->sid = SECINITSID_UNLABELED;
  270. sbsec->def_sid = SECINITSID_FILE;
  271. sbsec->mntpoint_sid = SECINITSID_UNLABELED;
  272. sb->s_security = sbsec;
  273. return 0;
  274. }
  275. static void superblock_free_security(struct super_block *sb)
  276. {
  277. struct superblock_security_struct *sbsec = sb->s_security;
  278. sb->s_security = NULL;
  279. kfree(sbsec);
  280. }
  281. /* The file system's label must be initialized prior to use. */
  282. static const char *labeling_behaviors[6] = {
  283. "uses xattr",
  284. "uses transition SIDs",
  285. "uses task SIDs",
  286. "uses genfs_contexts",
  287. "not configured for labeling",
  288. "uses mountpoint labeling",
  289. };
  290. static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry);
  291. static inline int inode_doinit(struct inode *inode)
  292. {
  293. return inode_doinit_with_dentry(inode, NULL);
  294. }
  295. enum {
  296. Opt_error = -1,
  297. Opt_context = 1,
  298. Opt_fscontext = 2,
  299. Opt_defcontext = 3,
  300. Opt_rootcontext = 4,
  301. Opt_labelsupport = 5,
  302. };
  303. static const match_table_t tokens = {
  304. {Opt_context, CONTEXT_STR "%s"},
  305. {Opt_fscontext, FSCONTEXT_STR "%s"},
  306. {Opt_defcontext, DEFCONTEXT_STR "%s"},
  307. {Opt_rootcontext, ROOTCONTEXT_STR "%s"},
  308. {Opt_labelsupport, LABELSUPP_STR},
  309. {Opt_error, NULL},
  310. };
  311. #define SEL_MOUNT_FAIL_MSG "SELinux: duplicate or incompatible mount options\n"
  312. static int may_context_mount_sb_relabel(u32 sid,
  313. struct superblock_security_struct *sbsec,
  314. const struct cred *cred)
  315. {
  316. const struct task_security_struct *tsec = cred->security;
  317. int rc;
  318. rc = avc_has_perm(tsec->sid, sbsec->sid, SECCLASS_FILESYSTEM,
  319. FILESYSTEM__RELABELFROM, NULL);
  320. if (rc)
  321. return rc;
  322. rc = avc_has_perm(tsec->sid, sid, SECCLASS_FILESYSTEM,
  323. FILESYSTEM__RELABELTO, NULL);
  324. return rc;
  325. }
  326. static int may_context_mount_inode_relabel(u32 sid,
  327. struct superblock_security_struct *sbsec,
  328. const struct cred *cred)
  329. {
  330. const struct task_security_struct *tsec = cred->security;
  331. int rc;
  332. rc = avc_has_perm(tsec->sid, sbsec->sid, SECCLASS_FILESYSTEM,
  333. FILESYSTEM__RELABELFROM, NULL);
  334. if (rc)
  335. return rc;
  336. rc = avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM,
  337. FILESYSTEM__ASSOCIATE, NULL);
  338. return rc;
  339. }
  340. static int sb_finish_set_opts(struct super_block *sb)
  341. {
  342. struct superblock_security_struct *sbsec = sb->s_security;
  343. struct dentry *root = sb->s_root;
  344. struct inode *root_inode = root->d_inode;
  345. int rc = 0;
  346. if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
  347. /* Make sure that the xattr handler exists and that no
  348. error other than -ENODATA is returned by getxattr on
  349. the root directory. -ENODATA is ok, as this may be
  350. the first boot of the SELinux kernel before we have
  351. assigned xattr values to the filesystem. */
  352. if (!root_inode->i_op->getxattr) {
  353. printk(KERN_WARNING "SELinux: (dev %s, type %s) has no "
  354. "xattr support\n", sb->s_id, sb->s_type->name);
  355. rc = -EOPNOTSUPP;
  356. goto out;
  357. }
  358. rc = root_inode->i_op->getxattr(root, XATTR_NAME_SELINUX, NULL, 0);
  359. if (rc < 0 && rc != -ENODATA) {
  360. if (rc == -EOPNOTSUPP)
  361. printk(KERN_WARNING "SELinux: (dev %s, type "
  362. "%s) has no security xattr handler\n",
  363. sb->s_id, sb->s_type->name);
  364. else
  365. printk(KERN_WARNING "SELinux: (dev %s, type "
  366. "%s) getxattr errno %d\n", sb->s_id,
  367. sb->s_type->name, -rc);
  368. goto out;
  369. }
  370. }
  371. sbsec->flags |= (SE_SBINITIALIZED | SE_SBLABELSUPP);
  372. if (sbsec->behavior > ARRAY_SIZE(labeling_behaviors))
  373. printk(KERN_ERR "SELinux: initialized (dev %s, type %s), unknown behavior\n",
  374. sb->s_id, sb->s_type->name);
  375. else
  376. printk(KERN_DEBUG "SELinux: initialized (dev %s, type %s), %s\n",
  377. sb->s_id, sb->s_type->name,
  378. labeling_behaviors[sbsec->behavior-1]);
  379. if (sbsec->behavior == SECURITY_FS_USE_GENFS ||
  380. sbsec->behavior == SECURITY_FS_USE_MNTPOINT ||
  381. sbsec->behavior == SECURITY_FS_USE_NONE ||
  382. sbsec->behavior > ARRAY_SIZE(labeling_behaviors))
  383. sbsec->flags &= ~SE_SBLABELSUPP;
  384. /* Special handling. Is genfs but also has in-core setxattr handler*/
  385. if (!strcmp(sb->s_type->name, "sysfs") ||
  386. !strcmp(sb->s_type->name, "pstore") ||
  387. !strcmp(sb->s_type->name, "debugfs") ||
  388. !strcmp(sb->s_type->name, "tracefs") ||
  389. !strcmp(sb->s_type->name, "rootfs"))
  390. sbsec->flags |= SE_SBLABELSUPP;
  391. /* Initialize the root inode. */
  392. rc = inode_doinit_with_dentry(root_inode, root);
  393. /* Initialize any other inodes associated with the superblock, e.g.
  394. inodes created prior to initial policy load or inodes created
  395. during get_sb by a pseudo filesystem that directly
  396. populates itself. */
  397. spin_lock(&sbsec->isec_lock);
  398. next_inode:
  399. if (!list_empty(&sbsec->isec_head)) {
  400. struct inode_security_struct *isec =
  401. list_entry(sbsec->isec_head.next,
  402. struct inode_security_struct, list);
  403. struct inode *inode = isec->inode;
  404. list_del_init(&isec->list);
  405. spin_unlock(&sbsec->isec_lock);
  406. inode = igrab(inode);
  407. if (inode) {
  408. if (!IS_PRIVATE(inode))
  409. inode_doinit(inode);
  410. iput(inode);
  411. }
  412. spin_lock(&sbsec->isec_lock);
  413. goto next_inode;
  414. }
  415. spin_unlock(&sbsec->isec_lock);
  416. out:
  417. return rc;
  418. }
  419. /*
  420. * This function should allow an FS to ask what it's mount security
  421. * options were so it can use those later for submounts, displaying
  422. * mount options, or whatever.
  423. */
  424. static int selinux_get_mnt_opts(const struct super_block *sb,
  425. struct security_mnt_opts *opts)
  426. {
  427. int rc = 0, i;
  428. struct superblock_security_struct *sbsec = sb->s_security;
  429. char *context = NULL;
  430. u32 len;
  431. char tmp;
  432. security_init_mnt_opts(opts);
  433. if (!(sbsec->flags & SE_SBINITIALIZED))
  434. return -EINVAL;
  435. if (!ss_initialized)
  436. return -EINVAL;
  437. tmp = sbsec->flags & SE_MNTMASK;
  438. /* count the number of mount options for this sb */
  439. for (i = 0; i < 8; i++) {
  440. if (tmp & 0x01)
  441. opts->num_mnt_opts++;
  442. tmp >>= 1;
  443. }
  444. /* Check if the Label support flag is set */
  445. if (sbsec->flags & SE_SBLABELSUPP)
  446. opts->num_mnt_opts++;
  447. opts->mnt_opts = kcalloc(opts->num_mnt_opts, sizeof(char *), GFP_ATOMIC);
  448. if (!opts->mnt_opts) {
  449. rc = -ENOMEM;
  450. goto out_free;
  451. }
  452. opts->mnt_opts_flags = kcalloc(opts->num_mnt_opts, sizeof(int), GFP_ATOMIC);
  453. if (!opts->mnt_opts_flags) {
  454. rc = -ENOMEM;
  455. goto out_free;
  456. }
  457. i = 0;
  458. if (sbsec->flags & FSCONTEXT_MNT) {
  459. rc = security_sid_to_context(sbsec->sid, &context, &len);
  460. if (rc)
  461. goto out_free;
  462. opts->mnt_opts[i] = context;
  463. opts->mnt_opts_flags[i++] = FSCONTEXT_MNT;
  464. }
  465. if (sbsec->flags & CONTEXT_MNT) {
  466. rc = security_sid_to_context(sbsec->mntpoint_sid, &context, &len);
  467. if (rc)
  468. goto out_free;
  469. opts->mnt_opts[i] = context;
  470. opts->mnt_opts_flags[i++] = CONTEXT_MNT;
  471. }
  472. if (sbsec->flags & DEFCONTEXT_MNT) {
  473. rc = security_sid_to_context(sbsec->def_sid, &context, &len);
  474. if (rc)
  475. goto out_free;
  476. opts->mnt_opts[i] = context;
  477. opts->mnt_opts_flags[i++] = DEFCONTEXT_MNT;
  478. }
  479. if (sbsec->flags & ROOTCONTEXT_MNT) {
  480. struct inode *root = sbsec->sb->s_root->d_inode;
  481. struct inode_security_struct *isec = root->i_security;
  482. rc = security_sid_to_context(isec->sid, &context, &len);
  483. if (rc)
  484. goto out_free;
  485. opts->mnt_opts[i] = context;
  486. opts->mnt_opts_flags[i++] = ROOTCONTEXT_MNT;
  487. }
  488. if (sbsec->flags & SE_SBLABELSUPP) {
  489. opts->mnt_opts[i] = NULL;
  490. opts->mnt_opts_flags[i++] = SE_SBLABELSUPP;
  491. }
  492. BUG_ON(i != opts->num_mnt_opts);
  493. return 0;
  494. out_free:
  495. security_free_mnt_opts(opts);
  496. return rc;
  497. }
  498. static int bad_option(struct superblock_security_struct *sbsec, char flag,
  499. u32 old_sid, u32 new_sid)
  500. {
  501. char mnt_flags = sbsec->flags & SE_MNTMASK;
  502. /* check if the old mount command had the same options */
  503. if (sbsec->flags & SE_SBINITIALIZED)
  504. if (!(sbsec->flags & flag) ||
  505. (old_sid != new_sid))
  506. return 1;
  507. /* check if we were passed the same options twice,
  508. * aka someone passed context=a,context=b
  509. */
  510. if (!(sbsec->flags & SE_SBINITIALIZED))
  511. if (mnt_flags & flag)
  512. return 1;
  513. return 0;
  514. }
  515. /*
  516. * Allow filesystems with binary mount data to explicitly set mount point
  517. * labeling information.
  518. */
  519. static int selinux_set_mnt_opts(struct super_block *sb,
  520. struct security_mnt_opts *opts)
  521. {
  522. const struct cred *cred = current_cred();
  523. int rc = 0, i;
  524. struct superblock_security_struct *sbsec = sb->s_security;
  525. const char *name = sb->s_type->name;
  526. struct inode *inode = sbsec->sb->s_root->d_inode;
  527. struct inode_security_struct *root_isec = inode->i_security;
  528. u32 fscontext_sid = 0, context_sid = 0, rootcontext_sid = 0;
  529. u32 defcontext_sid = 0;
  530. char **mount_options = opts->mnt_opts;
  531. int *flags = opts->mnt_opts_flags;
  532. int num_opts = opts->num_mnt_opts;
  533. mutex_lock(&sbsec->lock);
  534. if (!ss_initialized) {
  535. if (!num_opts) {
  536. /* Defer initialization until selinux_complete_init,
  537. after the initial policy is loaded and the security
  538. server is ready to handle calls. */
  539. goto out;
  540. }
  541. rc = -EINVAL;
  542. printk(KERN_WARNING "SELinux: Unable to set superblock options "
  543. "before the security server is initialized\n");
  544. goto out;
  545. }
  546. /*
  547. * Binary mount data FS will come through this function twice. Once
  548. * from an explicit call and once from the generic calls from the vfs.
  549. * Since the generic VFS calls will not contain any security mount data
  550. * we need to skip the double mount verification.
  551. *
  552. * This does open a hole in which we will not notice if the first
  553. * mount using this sb set explict options and a second mount using
  554. * this sb does not set any security options. (The first options
  555. * will be used for both mounts)
  556. */
  557. if ((sbsec->flags & SE_SBINITIALIZED) && (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA)
  558. && (num_opts == 0))
  559. goto out;
  560. /*
  561. * parse the mount options, check if they are valid sids.
  562. * also check if someone is trying to mount the same sb more
  563. * than once with different security options.
  564. */
  565. for (i = 0; i < num_opts; i++) {
  566. u32 sid;
  567. if (flags[i] == SE_SBLABELSUPP)
  568. continue;
  569. rc = security_context_to_sid(mount_options[i],
  570. strlen(mount_options[i]), &sid);
  571. if (rc) {
  572. printk(KERN_WARNING "SELinux: security_context_to_sid"
  573. "(%s) failed for (dev %s, type %s) errno=%d\n",
  574. mount_options[i], sb->s_id, name, rc);
  575. goto out;
  576. }
  577. switch (flags[i]) {
  578. case FSCONTEXT_MNT:
  579. fscontext_sid = sid;
  580. if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid,
  581. fscontext_sid))
  582. goto out_double_mount;
  583. sbsec->flags |= FSCONTEXT_MNT;
  584. break;
  585. case CONTEXT_MNT:
  586. context_sid = sid;
  587. if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid,
  588. context_sid))
  589. goto out_double_mount;
  590. sbsec->flags |= CONTEXT_MNT;
  591. break;
  592. case ROOTCONTEXT_MNT:
  593. rootcontext_sid = sid;
  594. if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid,
  595. rootcontext_sid))
  596. goto out_double_mount;
  597. sbsec->flags |= ROOTCONTEXT_MNT;
  598. break;
  599. case DEFCONTEXT_MNT:
  600. defcontext_sid = sid;
  601. if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid,
  602. defcontext_sid))
  603. goto out_double_mount;
  604. sbsec->flags |= DEFCONTEXT_MNT;
  605. break;
  606. default:
  607. rc = -EINVAL;
  608. goto out;
  609. }
  610. }
  611. if (sbsec->flags & SE_SBINITIALIZED) {
  612. /* previously mounted with options, but not on this attempt? */
  613. if ((sbsec->flags & SE_MNTMASK) && !num_opts)
  614. goto out_double_mount;
  615. rc = 0;
  616. goto out;
  617. }
  618. if (strcmp(sb->s_type->name, "proc") == 0)
  619. sbsec->flags |= SE_SBPROC | SE_SBGENFS;
  620. if (!strcmp(sb->s_type->name, "debugfs") ||
  621. !strcmp(sb->s_type->name, "tracefs") ||
  622. !strcmp(sb->s_type->name, "sysfs") ||
  623. !strcmp(sb->s_type->name, "binder") ||
  624. !strcmp(sb->s_type->name, "pstore"))
  625. sbsec->flags |= SE_SBGENFS;
  626. /* Determine the labeling behavior to use for this filesystem type. */
  627. rc = security_fs_use(sb->s_type->name, &sbsec->behavior, &sbsec->sid);
  628. if (rc) {
  629. printk(KERN_WARNING "%s: security_fs_use(%s) returned %d\n",
  630. __func__, sb->s_type->name, rc);
  631. goto out;
  632. }
  633. /* sets the context of the superblock for the fs being mounted. */
  634. if (fscontext_sid) {
  635. rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
  636. if (rc)
  637. goto out;
  638. sbsec->sid = fscontext_sid;
  639. }
  640. /*
  641. * Switch to using mount point labeling behavior.
  642. * sets the label used on all file below the mountpoint, and will set
  643. * the superblock context if not already set.
  644. */
  645. if (context_sid) {
  646. if (!fscontext_sid) {
  647. rc = may_context_mount_sb_relabel(context_sid, sbsec,
  648. cred);
  649. if (rc)
  650. goto out;
  651. sbsec->sid = context_sid;
  652. } else {
  653. rc = may_context_mount_inode_relabel(context_sid, sbsec,
  654. cred);
  655. if (rc)
  656. goto out;
  657. }
  658. if (!rootcontext_sid)
  659. rootcontext_sid = context_sid;
  660. sbsec->mntpoint_sid = context_sid;
  661. sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
  662. }
  663. if (rootcontext_sid) {
  664. rc = may_context_mount_inode_relabel(rootcontext_sid, sbsec,
  665. cred);
  666. if (rc)
  667. goto out;
  668. root_isec->sid = rootcontext_sid;
  669. root_isec->initialized = 1;
  670. }
  671. if (defcontext_sid) {
  672. if (sbsec->behavior != SECURITY_FS_USE_XATTR) {
  673. rc = -EINVAL;
  674. printk(KERN_WARNING "SELinux: defcontext option is "
  675. "invalid for this filesystem type\n");
  676. goto out;
  677. }
  678. if (defcontext_sid != sbsec->def_sid) {
  679. rc = may_context_mount_inode_relabel(defcontext_sid,
  680. sbsec, cred);
  681. if (rc)
  682. goto out;
  683. }
  684. sbsec->def_sid = defcontext_sid;
  685. }
  686. rc = sb_finish_set_opts(sb);
  687. out:
  688. mutex_unlock(&sbsec->lock);
  689. return rc;
  690. out_double_mount:
  691. rc = -EINVAL;
  692. printk(KERN_WARNING "SELinux: mount invalid. Same superblock, different "
  693. "security settings for (dev %s, type %s)\n", sb->s_id, name);
  694. goto out;
  695. }
  696. static void selinux_sb_clone_mnt_opts(const struct super_block *oldsb,
  697. struct super_block *newsb)
  698. {
  699. const struct superblock_security_struct *oldsbsec = oldsb->s_security;
  700. struct superblock_security_struct *newsbsec = newsb->s_security;
  701. int set_fscontext = (oldsbsec->flags & FSCONTEXT_MNT);
  702. int set_context = (oldsbsec->flags & CONTEXT_MNT);
  703. int set_rootcontext = (oldsbsec->flags & ROOTCONTEXT_MNT);
  704. /*
  705. * if the parent was able to be mounted it clearly had no special lsm
  706. * mount options. thus we can safely deal with this superblock later
  707. */
  708. if (!ss_initialized)
  709. return;
  710. /* how can we clone if the old one wasn't set up?? */
  711. BUG_ON(!(oldsbsec->flags & SE_SBINITIALIZED));
  712. /* if fs is reusing a sb, just let its options stand... */
  713. if (newsbsec->flags & SE_SBINITIALIZED)
  714. return;
  715. mutex_lock(&newsbsec->lock);
  716. newsbsec->flags = oldsbsec->flags;
  717. newsbsec->sid = oldsbsec->sid;
  718. newsbsec->def_sid = oldsbsec->def_sid;
  719. newsbsec->behavior = oldsbsec->behavior;
  720. if (set_context) {
  721. u32 sid = oldsbsec->mntpoint_sid;
  722. if (!set_fscontext)
  723. newsbsec->sid = sid;
  724. if (!set_rootcontext) {
  725. struct inode *newinode = newsb->s_root->d_inode;
  726. struct inode_security_struct *newisec = newinode->i_security;
  727. newisec->sid = sid;
  728. }
  729. newsbsec->mntpoint_sid = sid;
  730. }
  731. if (set_rootcontext) {
  732. const struct inode *oldinode = oldsb->s_root->d_inode;
  733. const struct inode_security_struct *oldisec = oldinode->i_security;
  734. struct inode *newinode = newsb->s_root->d_inode;
  735. struct inode_security_struct *newisec = newinode->i_security;
  736. newisec->sid = oldisec->sid;
  737. }
  738. sb_finish_set_opts(newsb);
  739. mutex_unlock(&newsbsec->lock);
  740. }
  741. static int selinux_parse_opts_str(char *options,
  742. struct security_mnt_opts *opts)
  743. {
  744. char *p;
  745. char *context = NULL, *defcontext = NULL;
  746. char *fscontext = NULL, *rootcontext = NULL;
  747. int rc, num_mnt_opts = 0;
  748. opts->num_mnt_opts = 0;
  749. /* Standard string-based options. */
  750. while ((p = strsep(&options, "|")) != NULL) {
  751. int token;
  752. substring_t args[MAX_OPT_ARGS];
  753. if (!*p)
  754. continue;
  755. token = match_token(p, tokens, args);
  756. switch (token) {
  757. case Opt_context:
  758. if (context || defcontext) {
  759. rc = -EINVAL;
  760. printk(KERN_WARNING SEL_MOUNT_FAIL_MSG);
  761. goto out_err;
  762. }
  763. context = match_strdup(&args[0]);
  764. if (!context) {
  765. rc = -ENOMEM;
  766. goto out_err;
  767. }
  768. break;
  769. case Opt_fscontext:
  770. if (fscontext) {
  771. rc = -EINVAL;
  772. printk(KERN_WARNING SEL_MOUNT_FAIL_MSG);
  773. goto out_err;
  774. }
  775. fscontext = match_strdup(&args[0]);
  776. if (!fscontext) {
  777. rc = -ENOMEM;
  778. goto out_err;
  779. }
  780. break;
  781. case Opt_rootcontext:
  782. if (rootcontext) {
  783. rc = -EINVAL;
  784. printk(KERN_WARNING SEL_MOUNT_FAIL_MSG);
  785. goto out_err;
  786. }
  787. rootcontext = match_strdup(&args[0]);
  788. if (!rootcontext) {
  789. rc = -ENOMEM;
  790. goto out_err;
  791. }
  792. break;
  793. case Opt_defcontext:
  794. if (context || defcontext) {
  795. rc = -EINVAL;
  796. printk(KERN_WARNING SEL_MOUNT_FAIL_MSG);
  797. goto out_err;
  798. }
  799. defcontext = match_strdup(&args[0]);
  800. if (!defcontext) {
  801. rc = -ENOMEM;
  802. goto out_err;
  803. }
  804. break;
  805. case Opt_labelsupport:
  806. break;
  807. default:
  808. rc = -EINVAL;
  809. printk(KERN_WARNING "SELinux: unknown mount option\n");
  810. goto out_err;
  811. }
  812. }
  813. rc = -ENOMEM;
  814. opts->mnt_opts = kcalloc(NUM_SEL_MNT_OPTS, sizeof(char *), GFP_ATOMIC);
  815. if (!opts->mnt_opts)
  816. goto out_err;
  817. opts->mnt_opts_flags = kcalloc(NUM_SEL_MNT_OPTS, sizeof(int), GFP_ATOMIC);
  818. if (!opts->mnt_opts_flags) {
  819. kfree(opts->mnt_opts);
  820. goto out_err;
  821. }
  822. if (fscontext) {
  823. opts->mnt_opts[num_mnt_opts] = fscontext;
  824. opts->mnt_opts_flags[num_mnt_opts++] = FSCONTEXT_MNT;
  825. }
  826. if (context) {
  827. opts->mnt_opts[num_mnt_opts] = context;
  828. opts->mnt_opts_flags[num_mnt_opts++] = CONTEXT_MNT;
  829. }
  830. if (rootcontext) {
  831. opts->mnt_opts[num_mnt_opts] = rootcontext;
  832. opts->mnt_opts_flags[num_mnt_opts++] = ROOTCONTEXT_MNT;
  833. }
  834. if (defcontext) {
  835. opts->mnt_opts[num_mnt_opts] = defcontext;
  836. opts->mnt_opts_flags[num_mnt_opts++] = DEFCONTEXT_MNT;
  837. }
  838. opts->num_mnt_opts = num_mnt_opts;
  839. return 0;
  840. out_err:
  841. kfree(context);
  842. kfree(defcontext);
  843. kfree(fscontext);
  844. kfree(rootcontext);
  845. return rc;
  846. }
  847. /*
  848. * string mount options parsing and call set the sbsec
  849. */
  850. static int superblock_doinit(struct super_block *sb, void *data)
  851. {
  852. int rc = 0;
  853. char *options = data;
  854. struct security_mnt_opts opts;
  855. security_init_mnt_opts(&opts);
  856. if (!data)
  857. goto out;
  858. BUG_ON(sb->s_type->fs_flags & FS_BINARY_MOUNTDATA);
  859. rc = selinux_parse_opts_str(options, &opts);
  860. if (rc)
  861. goto out_err;
  862. out:
  863. rc = selinux_set_mnt_opts(sb, &opts);
  864. out_err:
  865. security_free_mnt_opts(&opts);
  866. return rc;
  867. }
  868. static void selinux_write_opts(struct seq_file *m,
  869. struct security_mnt_opts *opts)
  870. {
  871. int i;
  872. char *prefix;
  873. for (i = 0; i < opts->num_mnt_opts; i++) {
  874. char *has_comma;
  875. if (opts->mnt_opts[i])
  876. has_comma = strchr(opts->mnt_opts[i], ',');
  877. else
  878. has_comma = NULL;
  879. switch (opts->mnt_opts_flags[i]) {
  880. case CONTEXT_MNT:
  881. prefix = CONTEXT_STR;
  882. break;
  883. case FSCONTEXT_MNT:
  884. prefix = FSCONTEXT_STR;
  885. break;
  886. case ROOTCONTEXT_MNT:
  887. prefix = ROOTCONTEXT_STR;
  888. break;
  889. case DEFCONTEXT_MNT:
  890. prefix = DEFCONTEXT_STR;
  891. break;
  892. case SE_SBLABELSUPP:
  893. seq_putc(m, ',');
  894. seq_puts(m, LABELSUPP_STR);
  895. continue;
  896. default:
  897. BUG();
  898. return;
  899. };
  900. /* we need a comma before each option */
  901. seq_putc(m, ',');
  902. seq_puts(m, prefix);
  903. if (has_comma)
  904. seq_putc(m, '\"');
  905. seq_escape(m, opts->mnt_opts[i], "\"\n\\");
  906. if (has_comma)
  907. seq_putc(m, '\"');
  908. }
  909. }
  910. static int selinux_sb_show_options(struct seq_file *m, struct super_block *sb)
  911. {
  912. struct security_mnt_opts opts;
  913. int rc;
  914. rc = selinux_get_mnt_opts(sb, &opts);
  915. if (rc) {
  916. /* before policy load we may get EINVAL, don't show anything */
  917. if (rc == -EINVAL)
  918. rc = 0;
  919. return rc;
  920. }
  921. selinux_write_opts(m, &opts);
  922. security_free_mnt_opts(&opts);
  923. return rc;
  924. }
  925. static inline u16 inode_mode_to_security_class(umode_t mode)
  926. {
  927. switch (mode & S_IFMT) {
  928. case S_IFSOCK:
  929. return SECCLASS_SOCK_FILE;
  930. case S_IFLNK:
  931. return SECCLASS_LNK_FILE;
  932. case S_IFREG:
  933. return SECCLASS_FILE;
  934. case S_IFBLK:
  935. return SECCLASS_BLK_FILE;
  936. case S_IFDIR:
  937. return SECCLASS_DIR;
  938. case S_IFCHR:
  939. return SECCLASS_CHR_FILE;
  940. case S_IFIFO:
  941. return SECCLASS_FIFO_FILE;
  942. }
  943. return SECCLASS_FILE;
  944. }
  945. static inline int default_protocol_stream(int protocol)
  946. {
  947. return (protocol == IPPROTO_IP || protocol == IPPROTO_TCP);
  948. }
  949. static inline int default_protocol_dgram(int protocol)
  950. {
  951. return (protocol == IPPROTO_IP || protocol == IPPROTO_UDP);
  952. }
  953. static inline u16 socket_type_to_security_class(int family, int type, int protocol)
  954. {
  955. switch (family) {
  956. case PF_UNIX:
  957. switch (type) {
  958. case SOCK_STREAM:
  959. case SOCK_SEQPACKET:
  960. return SECCLASS_UNIX_STREAM_SOCKET;
  961. case SOCK_DGRAM:
  962. return SECCLASS_UNIX_DGRAM_SOCKET;
  963. }
  964. break;
  965. case PF_INET:
  966. case PF_INET6:
  967. switch (type) {
  968. case SOCK_STREAM:
  969. if (default_protocol_stream(protocol))
  970. return SECCLASS_TCP_SOCKET;
  971. else
  972. return SECCLASS_RAWIP_SOCKET;
  973. case SOCK_DGRAM:
  974. if (default_protocol_dgram(protocol))
  975. return SECCLASS_UDP_SOCKET;
  976. else
  977. return SECCLASS_RAWIP_SOCKET;
  978. case SOCK_DCCP:
  979. return SECCLASS_DCCP_SOCKET;
  980. default:
  981. return SECCLASS_RAWIP_SOCKET;
  982. }
  983. break;
  984. case PF_NETLINK:
  985. switch (protocol) {
  986. case NETLINK_ROUTE:
  987. return SECCLASS_NETLINK_ROUTE_SOCKET;
  988. case NETLINK_SOCK_DIAG:
  989. return SECCLASS_NETLINK_TCPDIAG_SOCKET;
  990. case NETLINK_NFLOG:
  991. return SECCLASS_NETLINK_NFLOG_SOCKET;
  992. case NETLINK_XFRM:
  993. return SECCLASS_NETLINK_XFRM_SOCKET;
  994. case NETLINK_SELINUX:
  995. return SECCLASS_NETLINK_SELINUX_SOCKET;
  996. case NETLINK_ISCSI:
  997. return SECCLASS_NETLINK_ISCSI_SOCKET;
  998. case NETLINK_AUDIT:
  999. return SECCLASS_NETLINK_AUDIT_SOCKET;
  1000. case NETLINK_FIB_LOOKUP:
  1001. return SECCLASS_NETLINK_FIB_LOOKUP_SOCKET;
  1002. case NETLINK_CONNECTOR:
  1003. return SECCLASS_NETLINK_CONNECTOR_SOCKET;
  1004. case NETLINK_NETFILTER:
  1005. return SECCLASS_NETLINK_NETFILTER_SOCKET;
  1006. case NETLINK_DNRTMSG:
  1007. return SECCLASS_NETLINK_DNRT_SOCKET;
  1008. case NETLINK_KOBJECT_UEVENT:
  1009. return SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET;
  1010. case NETLINK_GENERIC:
  1011. return SECCLASS_NETLINK_GENERIC_SOCKET;
  1012. case NETLINK_SCSITRANSPORT:
  1013. return SECCLASS_NETLINK_SCSITRANSPORT_SOCKET;
  1014. case NETLINK_RDMA:
  1015. return SECCLASS_NETLINK_RDMA_SOCKET;
  1016. case NETLINK_CRYPTO:
  1017. return SECCLASS_NETLINK_CRYPTO_SOCKET;
  1018. default:
  1019. return SECCLASS_NETLINK_SOCKET;
  1020. }
  1021. case PF_PACKET:
  1022. return SECCLASS_PACKET_SOCKET;
  1023. case PF_KEY:
  1024. return SECCLASS_KEY_SOCKET;
  1025. case PF_APPLETALK:
  1026. return SECCLASS_APPLETALK_SOCKET;
  1027. }
  1028. return SECCLASS_SOCKET;
  1029. }
  1030. static int selinux_genfs_get_sid(struct dentry *dentry,
  1031. u16 tclass,
  1032. u16 flags,
  1033. u32 *sid)
  1034. {
  1035. int rc;
  1036. struct super_block *sb = dentry->d_inode->i_sb;
  1037. char *buffer, *path;
  1038. buffer = (char *)__get_free_page(GFP_KERNEL);
  1039. if (!buffer)
  1040. return -ENOMEM;
  1041. path = dentry_path_raw(dentry, buffer, PAGE_SIZE);
  1042. if (IS_ERR(path))
  1043. rc = PTR_ERR(path);
  1044. else {
  1045. if (flags & SE_SBPROC) {
  1046. /* each process gets a /proc/PID/ entry. Strip off the
  1047. * PID part to get a valid selinux labeling.
  1048. * e.g. /proc/1/net/rpc/nfs -> /net/rpc/nfs */
  1049. while (path[1] >= '0' && path[1] <= '9') {
  1050. path[1] = '/';
  1051. path++;
  1052. }
  1053. }
  1054. rc = security_genfs_sid(sb->s_type->name, path, tclass, sid);
  1055. }
  1056. free_page((unsigned long)buffer);
  1057. return rc;
  1058. }
  1059. /* The inode's security attributes must be initialized before first use. */
  1060. static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry)
  1061. {
  1062. struct superblock_security_struct *sbsec = NULL;
  1063. struct inode_security_struct *isec = inode->i_security;
  1064. u32 sid;
  1065. struct dentry *dentry;
  1066. #define INITCONTEXTLEN 255
  1067. char *context = NULL;
  1068. unsigned len = 0;
  1069. int rc = 0;
  1070. if (isec->initialized)
  1071. goto out;
  1072. mutex_lock(&isec->lock);
  1073. if (isec->initialized)
  1074. goto out_unlock;
  1075. sbsec = inode->i_sb->s_security;
  1076. if (!(sbsec->flags & SE_SBINITIALIZED)) {
  1077. /* Defer initialization until selinux_complete_init,
  1078. after the initial policy is loaded and the security
  1079. server is ready to handle calls. */
  1080. spin_lock(&sbsec->isec_lock);
  1081. if (list_empty(&isec->list))
  1082. list_add(&isec->list, &sbsec->isec_head);
  1083. spin_unlock(&sbsec->isec_lock);
  1084. goto out_unlock;
  1085. }
  1086. switch (sbsec->behavior) {
  1087. case SECURITY_FS_USE_XATTR:
  1088. if (!inode->i_op->getxattr) {
  1089. isec->sid = sbsec->def_sid;
  1090. break;
  1091. }
  1092. /* Need a dentry, since the xattr API requires one.
  1093. Life would be simpler if we could just pass the inode. */
  1094. if (opt_dentry) {
  1095. /* Called from d_instantiate or d_splice_alias. */
  1096. dentry = dget(opt_dentry);
  1097. } else {
  1098. /* Called from selinux_complete_init, try to find a dentry. */
  1099. dentry = d_find_alias(inode);
  1100. }
  1101. if (!dentry) {
  1102. /*
  1103. * this is can be hit on boot when a file is accessed
  1104. * before the policy is loaded. When we load policy we
  1105. * may find inodes that have no dentry on the
  1106. * sbsec->isec_head list. No reason to complain as these
  1107. * will get fixed up the next time we go through
  1108. * inode_doinit with a dentry, before these inodes could
  1109. * be used again by userspace.
  1110. */
  1111. goto out_unlock;
  1112. }
  1113. len = INITCONTEXTLEN;
  1114. context = kmalloc(len+1, GFP_NOFS);
  1115. if (!context) {
  1116. rc = -ENOMEM;
  1117. dput(dentry);
  1118. goto out_unlock;
  1119. }
  1120. context[len] = '\0';
  1121. rc = inode->i_op->getxattr(dentry, XATTR_NAME_SELINUX,
  1122. context, len);
  1123. if (rc == -ERANGE) {
  1124. kfree(context);
  1125. /* Need a larger buffer. Query for the right size. */
  1126. rc = inode->i_op->getxattr(dentry, XATTR_NAME_SELINUX,
  1127. NULL, 0);
  1128. if (rc < 0) {
  1129. dput(dentry);
  1130. goto out_unlock;
  1131. }
  1132. len = rc;
  1133. context = kmalloc(len+1, GFP_NOFS);
  1134. if (!context) {
  1135. rc = -ENOMEM;
  1136. dput(dentry);
  1137. goto out_unlock;
  1138. }
  1139. context[len] = '\0';
  1140. rc = inode->i_op->getxattr(dentry,
  1141. XATTR_NAME_SELINUX,
  1142. context, len);
  1143. }
  1144. dput(dentry);
  1145. if (rc < 0) {
  1146. if (rc != -ENODATA) {
  1147. printk(KERN_WARNING "SELinux: %s: getxattr returned "
  1148. "%d for dev=%s ino=%ld\n", __func__,
  1149. -rc, inode->i_sb->s_id, inode->i_ino);
  1150. kfree(context);
  1151. goto out_unlock;
  1152. }
  1153. /* Map ENODATA to the default file SID */
  1154. sid = sbsec->def_sid;
  1155. rc = 0;
  1156. } else {
  1157. rc = security_context_to_sid_default(context, rc, &sid,
  1158. sbsec->def_sid,
  1159. GFP_NOFS);
  1160. if (rc) {
  1161. char *dev = inode->i_sb->s_id;
  1162. unsigned long ino = inode->i_ino;
  1163. if (rc == -EINVAL) {
  1164. if (printk_ratelimit())
  1165. printk(KERN_NOTICE "SELinux: inode=%lu on dev=%s was found to have an invalid "
  1166. "context=%s. This indicates you may need to relabel the inode or the "
  1167. "filesystem in question.\n", ino, dev, context);
  1168. } else {
  1169. printk(KERN_WARNING "SELinux: %s: context_to_sid(%s) "
  1170. "returned %d for dev=%s ino=%ld\n",
  1171. __func__, context, -rc, dev, ino);
  1172. }
  1173. kfree(context);
  1174. /* Leave with the unlabeled SID */
  1175. rc = 0;
  1176. break;
  1177. }
  1178. }
  1179. kfree(context);
  1180. isec->sid = sid;
  1181. break;
  1182. case SECURITY_FS_USE_TASK:
  1183. isec->sid = isec->task_sid;
  1184. break;
  1185. case SECURITY_FS_USE_TRANS:
  1186. /* Default to the fs SID. */
  1187. isec->sid = sbsec->sid;
  1188. /* Try to obtain a transition SID. */
  1189. isec->sclass = inode_mode_to_security_class(inode->i_mode);
  1190. rc = security_transition_sid(isec->task_sid, sbsec->sid,
  1191. isec->sclass, NULL, &sid);
  1192. if (rc)
  1193. goto out_unlock;
  1194. isec->sid = sid;
  1195. break;
  1196. case SECURITY_FS_USE_MNTPOINT:
  1197. isec->sid = sbsec->mntpoint_sid;
  1198. break;
  1199. default:
  1200. /* Default to the fs superblock SID. */
  1201. isec->sid = sbsec->sid;
  1202. if ((sbsec->flags & SE_SBGENFS) && !S_ISLNK(inode->i_mode)) {
  1203. /* We must have a dentry to determine the label on
  1204. * procfs inodes */
  1205. if (opt_dentry)
  1206. /* Called from d_instantiate or
  1207. * d_splice_alias. */
  1208. dentry = dget(opt_dentry);
  1209. else
  1210. /* Called from selinux_complete_init, try to
  1211. * find a dentry. */
  1212. dentry = d_find_alias(inode);
  1213. /*
  1214. * This can be hit on boot when a file is accessed
  1215. * before the policy is loaded. When we load policy we
  1216. * may find inodes that have no dentry on the
  1217. * sbsec->isec_head list. No reason to complain as
  1218. * these will get fixed up the next time we go through
  1219. * inode_doinit() with a dentry, before these inodes
  1220. * could be used again by userspace.
  1221. */
  1222. if (!dentry)
  1223. goto out_unlock;
  1224. isec->sclass = inode_mode_to_security_class(inode->i_mode);
  1225. rc = selinux_genfs_get_sid(dentry, isec->sclass,
  1226. sbsec->flags, &sid);
  1227. dput(dentry);
  1228. if (rc)
  1229. goto out_unlock;
  1230. isec->sid = sid;
  1231. }
  1232. break;
  1233. }
  1234. isec->initialized = 1;
  1235. out_unlock:
  1236. mutex_unlock(&isec->lock);
  1237. out:
  1238. if (isec->sclass == SECCLASS_FILE)
  1239. isec->sclass = inode_mode_to_security_class(inode->i_mode);
  1240. return rc;
  1241. }
  1242. /* Convert a Linux signal to an access vector. */
  1243. static inline u32 signal_to_av(int sig)
  1244. {
  1245. u32 perm = 0;
  1246. switch (sig) {
  1247. case SIGCHLD:
  1248. /* Commonly granted from child to parent. */
  1249. perm = PROCESS__SIGCHLD;
  1250. break;
  1251. case SIGKILL:
  1252. /* Cannot be caught or ignored */
  1253. perm = PROCESS__SIGKILL;
  1254. break;
  1255. case SIGSTOP:
  1256. /* Cannot be caught or ignored */
  1257. perm = PROCESS__SIGSTOP;
  1258. break;
  1259. default:
  1260. /* All other signals. */
  1261. perm = PROCESS__SIGNAL;
  1262. break;
  1263. }
  1264. return perm;
  1265. }
  1266. /*
  1267. * Check permission between a pair of credentials
  1268. * fork check, ptrace check, etc.
  1269. */
  1270. static int cred_has_perm(const struct cred *actor,
  1271. const struct cred *target,
  1272. u32 perms)
  1273. {
  1274. u32 asid = cred_sid(actor), tsid = cred_sid(target);
  1275. return avc_has_perm(asid, tsid, SECCLASS_PROCESS, perms, NULL);
  1276. }
  1277. /*
  1278. * Check permission between a pair of tasks, e.g. signal checks,
  1279. * fork check, ptrace check, etc.
  1280. * tsk1 is the actor and tsk2 is the target
  1281. * - this uses the default subjective creds of tsk1
  1282. */
  1283. static int task_has_perm(const struct task_struct *tsk1,
  1284. const struct task_struct *tsk2,
  1285. u32 perms)
  1286. {
  1287. const struct task_security_struct *__tsec1, *__tsec2;
  1288. u32 sid1, sid2;
  1289. rcu_read_lock();
  1290. __tsec1 = __task_cred(tsk1)->security; sid1 = __tsec1->sid;
  1291. __tsec2 = __task_cred(tsk2)->security; sid2 = __tsec2->sid;
  1292. rcu_read_unlock();
  1293. return avc_has_perm(sid1, sid2, SECCLASS_PROCESS, perms, NULL);
  1294. }
  1295. /*
  1296. * Check permission between current and another task, e.g. signal checks,
  1297. * fork check, ptrace check, etc.
  1298. * current is the actor and tsk2 is the target
  1299. * - this uses current's subjective creds
  1300. */
  1301. static int current_has_perm(const struct task_struct *tsk,
  1302. u32 perms)
  1303. {
  1304. u32 sid, tsid;
  1305. sid = current_sid();
  1306. tsid = task_sid(tsk);
  1307. return avc_has_perm(sid, tsid, SECCLASS_PROCESS, perms, NULL);
  1308. }
  1309. #if CAP_LAST_CAP > 63
  1310. #error Fix SELinux to handle capabilities > 63.
  1311. #endif
  1312. /* Check whether a task is allowed to use a capability. */
  1313. static int cred_has_capability(const struct cred *cred,
  1314. int cap, int audit)
  1315. {
  1316. struct common_audit_data ad;
  1317. struct selinux_audit_data sad = {0,};
  1318. struct av_decision avd;
  1319. u16 sclass;
  1320. u32 sid = cred_sid(cred);
  1321. u32 av = CAP_TO_MASK(cap);
  1322. int rc;
  1323. COMMON_AUDIT_DATA_INIT(&ad, CAP);
  1324. ad.selinux_audit_data = &sad;
  1325. ad.tsk = current;
  1326. ad.u.cap = cap;
  1327. switch (CAP_TO_INDEX(cap)) {
  1328. case 0:
  1329. sclass = SECCLASS_CAPABILITY;
  1330. break;
  1331. case 1:
  1332. sclass = SECCLASS_CAPABILITY2;
  1333. break;
  1334. default:
  1335. printk(KERN_ERR
  1336. "SELinux: out of range capability %d\n", cap);
  1337. BUG();
  1338. return -EINVAL;
  1339. }
  1340. rc = avc_has_perm_noaudit(sid, sid, sclass, av, 0, &avd);
  1341. if (audit == SECURITY_CAP_AUDIT) {
  1342. int rc2 = avc_audit(sid, sid, sclass, av, &avd, rc, &ad, 0);
  1343. if (rc2)
  1344. return rc2;
  1345. }
  1346. return rc;
  1347. }
  1348. /* Check whether a task is allowed to use a system operation. */
  1349. static int task_has_system(struct task_struct *tsk,
  1350. u32 perms)
  1351. {
  1352. u32 sid = task_sid(tsk);
  1353. return avc_has_perm(sid, SECINITSID_KERNEL,
  1354. SECCLASS_SYSTEM, perms, NULL);
  1355. }
  1356. /* Check whether a task has a particular permission to an inode.
  1357. The 'adp' parameter is optional and allows other audit
  1358. data to be passed (e.g. the dentry). */
  1359. static int inode_has_perm(const struct cred *cred,
  1360. struct inode *inode,
  1361. u32 perms,
  1362. struct common_audit_data *adp,
  1363. unsigned flags)
  1364. {
  1365. struct inode_security_struct *isec;
  1366. u32 sid;
  1367. validate_creds(cred);
  1368. if (unlikely(IS_PRIVATE(inode)))
  1369. return 0;
  1370. sid = cred_sid(cred);
  1371. isec = inode->i_security;
  1372. if (unlikely(!isec)){
  1373. printk(KERN_CRIT "[SELinux] isec is NULL, inode->i_security is already freed. \n");
  1374. return -EACCES;
  1375. }
  1376. return avc_has_perm_flags(sid, isec->sid, isec->sclass, perms, adp, flags);
  1377. }
  1378. static int inode_has_perm_noadp(const struct cred *cred,
  1379. struct inode *inode,
  1380. u32 perms,
  1381. unsigned flags)
  1382. {
  1383. struct common_audit_data ad;
  1384. struct selinux_audit_data sad = {0,};
  1385. COMMON_AUDIT_DATA_INIT(&ad, INODE);
  1386. ad.u.inode = inode;
  1387. ad.selinux_audit_data = &sad;
  1388. return inode_has_perm(cred, inode, perms, &ad, flags);
  1389. }
  1390. /* Same as inode_has_perm, but pass explicit audit data containing
  1391. the dentry to help the auditing code to more easily generate the
  1392. pathname if needed. */
  1393. static inline int dentry_has_perm(const struct cred *cred,
  1394. struct dentry *dentry,
  1395. u32 av)
  1396. {
  1397. struct inode *inode = dentry->d_inode;
  1398. struct common_audit_data ad;
  1399. struct selinux_audit_data sad = {0,};
  1400. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  1401. ad.u.dentry = dentry;
  1402. ad.selinux_audit_data = &sad;
  1403. return inode_has_perm(cred, inode, av, &ad, 0);
  1404. }
  1405. /* Same as inode_has_perm, but pass explicit audit data containing
  1406. the path to help the auditing code to more easily generate the
  1407. pathname if needed. */
  1408. static inline int path_has_perm(const struct cred *cred,
  1409. struct path *path,
  1410. u32 av)
  1411. {
  1412. struct inode *inode = path->dentry->d_inode;
  1413. struct common_audit_data ad;
  1414. struct selinux_audit_data sad = {0,};
  1415. COMMON_AUDIT_DATA_INIT(&ad, PATH);
  1416. ad.u.path = *path;
  1417. ad.selinux_audit_data = &sad;
  1418. return inode_has_perm(cred, inode, av, &ad, 0);
  1419. }
  1420. /* Check whether a task can use an open file descriptor to
  1421. access an inode in a given way. Check access to the
  1422. descriptor itself, and then use dentry_has_perm to
  1423. check a particular permission to the file.
  1424. Access to the descriptor is implicitly granted if it
  1425. has the same SID as the process. If av is zero, then
  1426. access to the file is not checked, e.g. for cases
  1427. where only the descriptor is affected like seek. */
  1428. static int file_has_perm(const struct cred *cred,
  1429. struct file *file,
  1430. u32 av)
  1431. {
  1432. struct file_security_struct *fsec = file->f_security;
  1433. struct inode *inode = file->f_path.dentry->d_inode;
  1434. struct common_audit_data ad;
  1435. struct selinux_audit_data sad = {0,};
  1436. u32 sid = cred_sid(cred);
  1437. int rc;
  1438. COMMON_AUDIT_DATA_INIT(&ad, PATH);
  1439. ad.u.path = file->f_path;
  1440. ad.selinux_audit_data = &sad;
  1441. if (sid != fsec->sid) {
  1442. rc = avc_has_perm(sid, fsec->sid,
  1443. SECCLASS_FD,
  1444. FD__USE,
  1445. &ad);
  1446. if (rc)
  1447. goto out;
  1448. }
  1449. /* av is zero if only checking access to the descriptor. */
  1450. rc = 0;
  1451. if (av)
  1452. rc = inode_has_perm(cred, inode, av, &ad, 0);
  1453. out:
  1454. return rc;
  1455. }
  1456. /* Check whether a task can create a file. */
  1457. static int may_create(struct inode *dir,
  1458. struct dentry *dentry,
  1459. u16 tclass)
  1460. {
  1461. const struct task_security_struct *tsec = current_security();
  1462. struct inode_security_struct *dsec;
  1463. struct superblock_security_struct *sbsec;
  1464. u32 sid, newsid;
  1465. struct common_audit_data ad;
  1466. struct selinux_audit_data sad = {0,};
  1467. int rc;
  1468. dsec = dir->i_security;
  1469. sbsec = dir->i_sb->s_security;
  1470. sid = tsec->sid;
  1471. newsid = tsec->create_sid;
  1472. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  1473. ad.u.dentry = dentry;
  1474. ad.selinux_audit_data = &sad;
  1475. rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR,
  1476. DIR__ADD_NAME | DIR__SEARCH,
  1477. &ad);
  1478. if (rc)
  1479. return rc;
  1480. if (!newsid || !(sbsec->flags & SE_SBLABELSUPP)) {
  1481. rc = security_transition_sid(sid, dsec->sid, tclass,
  1482. &dentry->d_name, &newsid);
  1483. if (rc)
  1484. return rc;
  1485. }
  1486. rc = avc_has_perm(sid, newsid, tclass, FILE__CREATE, &ad);
  1487. if (rc)
  1488. return rc;
  1489. rc = avc_has_perm(newsid, sbsec->sid,
  1490. SECCLASS_FILESYSTEM,
  1491. FILESYSTEM__ASSOCIATE, &ad);
  1492. if (rc)
  1493. return rc;
  1494. rc = pft_inode_mknod(dir, dentry, 0, 0);
  1495. return rc;
  1496. }
  1497. /* Check whether a task can create a key. */
  1498. static int may_create_key(u32 ksid,
  1499. struct task_struct *ctx)
  1500. {
  1501. u32 sid = task_sid(ctx);
  1502. return avc_has_perm(sid, ksid, SECCLASS_KEY, KEY__CREATE, NULL);
  1503. }
  1504. #define MAY_LINK 0
  1505. #define MAY_UNLINK 1
  1506. #define MAY_RMDIR 2
  1507. /* Check whether a task can link, unlink, or rmdir a file/directory. */
  1508. static int may_link(struct inode *dir,
  1509. struct dentry *dentry,
  1510. int kind)
  1511. {
  1512. struct inode_security_struct *dsec, *isec;
  1513. struct common_audit_data ad;
  1514. struct selinux_audit_data sad = {0,};
  1515. u32 sid = current_sid();
  1516. u32 av;
  1517. int rc;
  1518. dsec = dir->i_security;
  1519. isec = dentry->d_inode->i_security;
  1520. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  1521. ad.u.dentry = dentry;
  1522. ad.selinux_audit_data = &sad;
  1523. av = DIR__SEARCH;
  1524. av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME);
  1525. rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, av, &ad);
  1526. if (rc)
  1527. return rc;
  1528. switch (kind) {
  1529. case MAY_LINK:
  1530. av = FILE__LINK;
  1531. break;
  1532. case MAY_UNLINK:
  1533. av = FILE__UNLINK;
  1534. break;
  1535. case MAY_RMDIR:
  1536. av = DIR__RMDIR;
  1537. break;
  1538. default:
  1539. printk(KERN_WARNING "SELinux: %s: unrecognized kind %d\n",
  1540. __func__, kind);
  1541. return 0;
  1542. }
  1543. rc = avc_has_perm(sid, isec->sid, isec->sclass, av, &ad);
  1544. if (rc)
  1545. return rc;
  1546. if (kind == MAY_UNLINK)
  1547. rc = pft_inode_unlink(dir, dentry);
  1548. return rc;
  1549. }
  1550. static inline int may_rename(struct inode *old_dir,
  1551. struct dentry *old_dentry,
  1552. struct inode *new_dir,
  1553. struct dentry *new_dentry)
  1554. {
  1555. struct inode_security_struct *old_dsec, *new_dsec, *old_isec, *new_isec;
  1556. struct common_audit_data ad;
  1557. struct selinux_audit_data sad = {0,};
  1558. u32 sid = current_sid();
  1559. u32 av;
  1560. int old_is_dir, new_is_dir;
  1561. int rc;
  1562. old_dsec = old_dir->i_security;
  1563. old_isec = old_dentry->d_inode->i_security;
  1564. old_is_dir = S_ISDIR(old_dentry->d_inode->i_mode);
  1565. new_dsec = new_dir->i_security;
  1566. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  1567. ad.selinux_audit_data = &sad;
  1568. ad.u.dentry = old_dentry;
  1569. rc = avc_has_perm(sid, old_dsec->sid, SECCLASS_DIR,
  1570. DIR__REMOVE_NAME | DIR__SEARCH, &ad);
  1571. if (rc)
  1572. return rc;
  1573. rc = avc_has_perm(sid, old_isec->sid,
  1574. old_isec->sclass, FILE__RENAME, &ad);
  1575. if (rc)
  1576. return rc;
  1577. if (old_is_dir && new_dir != old_dir) {
  1578. rc = avc_has_perm(sid, old_isec->sid,
  1579. old_isec->sclass, DIR__REPARENT, &ad);
  1580. if (rc)
  1581. return rc;
  1582. }
  1583. ad.u.dentry = new_dentry;
  1584. av = DIR__ADD_NAME | DIR__SEARCH;
  1585. if (new_dentry->d_inode)
  1586. av |= DIR__REMOVE_NAME;
  1587. rc = avc_has_perm(sid, new_dsec->sid, SECCLASS_DIR, av, &ad);
  1588. if (rc)
  1589. return rc;
  1590. if (new_dentry->d_inode) {
  1591. new_isec = new_dentry->d_inode->i_security;
  1592. new_is_dir = S_ISDIR(new_dentry->d_inode->i_mode);
  1593. rc = avc_has_perm(sid, new_isec->sid,
  1594. new_isec->sclass,
  1595. (new_is_dir ? DIR__RMDIR : FILE__UNLINK), &ad);
  1596. if (rc)
  1597. return rc;
  1598. }
  1599. return 0;
  1600. }
  1601. /* Check whether a task can perform a filesystem operation. */
  1602. static int superblock_has_perm(const struct cred *cred,
  1603. struct super_block *sb,
  1604. u32 perms,
  1605. struct common_audit_data *ad)
  1606. {
  1607. struct superblock_security_struct *sbsec;
  1608. u32 sid = cred_sid(cred);
  1609. sbsec = sb->s_security;
  1610. return avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM, perms, ad);
  1611. }
  1612. /* Convert a Linux mode and permission mask to an access vector. */
  1613. static inline u32 file_mask_to_av(int mode, int mask)
  1614. {
  1615. u32 av = 0;
  1616. if (!S_ISDIR(mode)) {
  1617. if (mask & MAY_EXEC)
  1618. av |= FILE__EXECUTE;
  1619. if (mask & MAY_READ)
  1620. av |= FILE__READ;
  1621. if (mask & MAY_APPEND)
  1622. av |= FILE__APPEND;
  1623. else if (mask & MAY_WRITE)
  1624. av |= FILE__WRITE;
  1625. } else {
  1626. if (mask & MAY_EXEC)
  1627. av |= DIR__SEARCH;
  1628. if (mask & MAY_WRITE)
  1629. av |= DIR__WRITE;
  1630. if (mask & MAY_READ)
  1631. av |= DIR__READ;
  1632. }
  1633. return av;
  1634. }
  1635. /* Convert a Linux file to an access vector. */
  1636. static inline u32 file_to_av(struct file *file)
  1637. {
  1638. u32 av = 0;
  1639. if (file->f_mode & FMODE_READ)
  1640. av |= FILE__READ;
  1641. if (file->f_mode & FMODE_WRITE) {
  1642. if (file->f_flags & O_APPEND)
  1643. av |= FILE__APPEND;
  1644. else
  1645. av |= FILE__WRITE;
  1646. }
  1647. if (!av) {
  1648. /*
  1649. * Special file opened with flags 3 for ioctl-only use.
  1650. */
  1651. av = FILE__IOCTL;
  1652. }
  1653. return av;
  1654. }
  1655. /*
  1656. * Convert a file to an access vector and include the correct open
  1657. * open permission.
  1658. */
  1659. static inline u32 open_file_to_av(struct file *file)
  1660. {
  1661. u32 av = file_to_av(file);
  1662. if (selinux_policycap_openperm)
  1663. av |= FILE__OPEN;
  1664. return av;
  1665. }
  1666. /* Hook functions begin here. */
  1667. static int selinux_binder_set_context_mgr(struct task_struct *mgr)
  1668. {
  1669. u32 mysid = current_sid();
  1670. u32 mgrsid = task_sid(mgr);
  1671. return avc_has_perm(mysid, mgrsid, SECCLASS_BINDER, BINDER__SET_CONTEXT_MGR, NULL);
  1672. }
  1673. static int selinux_binder_transaction(struct task_struct *from, struct task_struct *to)
  1674. {
  1675. u32 mysid = current_sid();
  1676. u32 fromsid = task_sid(from);
  1677. u32 tosid = task_sid(to);
  1678. int rc;
  1679. if (mysid != fromsid) {
  1680. rc = avc_has_perm(mysid, fromsid, SECCLASS_BINDER, BINDER__IMPERSONATE, NULL);
  1681. if (rc)
  1682. return rc;
  1683. }
  1684. return avc_has_perm(fromsid, tosid, SECCLASS_BINDER, BINDER__CALL, NULL);
  1685. }
  1686. static int selinux_binder_transfer_binder(struct task_struct *from, struct task_struct *to)
  1687. {
  1688. u32 fromsid = task_sid(from);
  1689. u32 tosid = task_sid(to);
  1690. return avc_has_perm(fromsid, tosid, SECCLASS_BINDER, BINDER__TRANSFER, NULL);
  1691. }
  1692. static int selinux_binder_transfer_file(struct task_struct *from, struct task_struct *to, struct file *file)
  1693. {
  1694. u32 sid = task_sid(to);
  1695. struct file_security_struct *fsec = file->f_security;
  1696. struct inode *inode = file->f_path.dentry->d_inode;
  1697. struct inode_security_struct *isec = inode->i_security;
  1698. struct common_audit_data ad;
  1699. struct selinux_audit_data sad = {0,};
  1700. int rc;
  1701. COMMON_AUDIT_DATA_INIT(&ad, PATH);
  1702. ad.u.path = file->f_path;
  1703. ad.selinux_audit_data = &sad;
  1704. if (sid != fsec->sid) {
  1705. rc = avc_has_perm(sid, fsec->sid,
  1706. SECCLASS_FD,
  1707. FD__USE,
  1708. &ad);
  1709. if (rc)
  1710. return rc;
  1711. }
  1712. if (unlikely(IS_PRIVATE(inode)))
  1713. return 0;
  1714. return avc_has_perm(sid, isec->sid, isec->sclass, file_to_av(file),
  1715. &ad);
  1716. }
  1717. static int selinux_ptrace_access_check(struct task_struct *child,
  1718. unsigned int mode)
  1719. {
  1720. int rc;
  1721. rc = cap_ptrace_access_check(child, mode);
  1722. if (rc)
  1723. return rc;
  1724. if (mode & PTRACE_MODE_READ) {
  1725. u32 sid = current_sid();
  1726. u32 csid = task_sid(child);
  1727. return avc_has_perm(sid, csid, SECCLASS_FILE, FILE__READ, NULL);
  1728. }
  1729. return current_has_perm(child, PROCESS__PTRACE);
  1730. }
  1731. static int selinux_ptrace_traceme(struct task_struct *parent)
  1732. {
  1733. int rc;
  1734. rc = cap_ptrace_traceme(parent);
  1735. if (rc)
  1736. return rc;
  1737. return task_has_perm(parent, current, PROCESS__PTRACE);
  1738. }
  1739. static int selinux_capget(struct task_struct *target, kernel_cap_t *effective,
  1740. kernel_cap_t *inheritable, kernel_cap_t *permitted)
  1741. {
  1742. int error;
  1743. error = current_has_perm(target, PROCESS__GETCAP);
  1744. if (error)
  1745. return error;
  1746. return cap_capget(target, effective, inheritable, permitted);
  1747. }
  1748. static int selinux_capset(struct cred *new, const struct cred *old,
  1749. const kernel_cap_t *effective,
  1750. const kernel_cap_t *inheritable,
  1751. const kernel_cap_t *permitted)
  1752. {
  1753. int error;
  1754. error = cap_capset(new, old,
  1755. effective, inheritable, permitted);
  1756. if (error)
  1757. return error;
  1758. return cred_has_perm(old, new, PROCESS__SETCAP);
  1759. }
  1760. /*
  1761. * (This comment used to live with the selinux_task_setuid hook,
  1762. * which was removed).
  1763. *
  1764. * Since setuid only affects the current process, and since the SELinux
  1765. * controls are not based on the Linux identity attributes, SELinux does not
  1766. * need to control this operation. However, SELinux does control the use of
  1767. * the CAP_SETUID and CAP_SETGID capabilities using the capable hook.
  1768. */
  1769. static int selinux_capable(const struct cred *cred, struct user_namespace *ns,
  1770. int cap, int audit)
  1771. {
  1772. int rc;
  1773. rc = cap_capable(cred, ns, cap, audit);
  1774. if (rc)
  1775. return rc;
  1776. return cred_has_capability(cred, cap, audit);
  1777. }
  1778. static int selinux_quotactl(int cmds, int type, int id, struct super_block *sb)
  1779. {
  1780. const struct cred *cred = current_cred();
  1781. int rc = 0;
  1782. if (!sb)
  1783. return 0;
  1784. switch (cmds) {
  1785. case Q_SYNC:
  1786. case Q_QUOTAON:
  1787. case Q_QUOTAOFF:
  1788. case Q_SETINFO:
  1789. case Q_SETQUOTA:
  1790. rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAMOD, NULL);
  1791. break;
  1792. case Q_GETFMT:
  1793. case Q_GETINFO:
  1794. case Q_GETQUOTA:
  1795. rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAGET, NULL);
  1796. break;
  1797. default:
  1798. rc = 0; /* let the kernel handle invalid cmds */
  1799. break;
  1800. }
  1801. return rc;
  1802. }
  1803. static int selinux_quota_on(struct dentry *dentry)
  1804. {
  1805. const struct cred *cred = current_cred();
  1806. return dentry_has_perm(cred, dentry, FILE__QUOTAON);
  1807. }
  1808. static int selinux_syslog(int type)
  1809. {
  1810. int rc;
  1811. switch (type) {
  1812. case SYSLOG_ACTION_READ_ALL: /* Read last kernel messages */
  1813. case SYSLOG_ACTION_SIZE_BUFFER: /* Return size of the log buffer */
  1814. rc = task_has_system(current, SYSTEM__SYSLOG_READ);
  1815. break;
  1816. case SYSLOG_ACTION_CONSOLE_OFF: /* Disable logging to console */
  1817. case SYSLOG_ACTION_CONSOLE_ON: /* Enable logging to console */
  1818. /* Set level of messages printed to console */
  1819. case SYSLOG_ACTION_CONSOLE_LEVEL:
  1820. rc = task_has_system(current, SYSTEM__SYSLOG_CONSOLE);
  1821. break;
  1822. case SYSLOG_ACTION_CLOSE: /* Close log */
  1823. case SYSLOG_ACTION_OPEN: /* Open log */
  1824. case SYSLOG_ACTION_READ: /* Read from log */
  1825. case SYSLOG_ACTION_READ_CLEAR: /* Read/clear last kernel messages */
  1826. case SYSLOG_ACTION_CLEAR: /* Clear ring buffer */
  1827. default:
  1828. rc = task_has_system(current, SYSTEM__SYSLOG_MOD);
  1829. break;
  1830. }
  1831. return rc;
  1832. }
  1833. /*
  1834. * Check that a process has enough memory to allocate a new virtual
  1835. * mapping. 0 means there is enough memory for the allocation to
  1836. * succeed and -ENOMEM implies there is not.
  1837. *
  1838. * Do not audit the selinux permission check, as this is applied to all
  1839. * processes that allocate mappings.
  1840. */
  1841. static int selinux_vm_enough_memory(struct mm_struct *mm, long pages)
  1842. {
  1843. int rc, cap_sys_admin = 0;
  1844. rc = selinux_capable(current_cred(), &init_user_ns, CAP_SYS_ADMIN,
  1845. SECURITY_CAP_NOAUDIT);
  1846. if (rc == 0)
  1847. cap_sys_admin = 1;
  1848. return __vm_enough_memory(mm, pages, cap_sys_admin);
  1849. }
  1850. /* binprm security operations */
  1851. static int selinux_bprm_set_creds(struct linux_binprm *bprm)
  1852. {
  1853. const struct task_security_struct *old_tsec;
  1854. struct task_security_struct *new_tsec;
  1855. struct inode_security_struct *isec;
  1856. struct common_audit_data ad;
  1857. struct selinux_audit_data sad = {0,};
  1858. struct inode *inode = bprm->file->f_path.dentry->d_inode;
  1859. int rc;
  1860. rc = cap_bprm_set_creds(bprm);
  1861. if (rc)
  1862. return rc;
  1863. /* SELinux context only depends on initial program or script and not
  1864. * the script interpreter */
  1865. if (bprm->cred_prepared)
  1866. return 0;
  1867. old_tsec = current_security();
  1868. new_tsec = bprm->cred->security;
  1869. isec = inode->i_security;
  1870. /* Default to the current task SID. */
  1871. new_tsec->sid = old_tsec->sid;
  1872. new_tsec->osid = old_tsec->sid;
  1873. /* Reset fs, key, and sock SIDs on execve. */
  1874. new_tsec->create_sid = 0;
  1875. new_tsec->keycreate_sid = 0;
  1876. new_tsec->sockcreate_sid = 0;
  1877. if (old_tsec->exec_sid) {
  1878. new_tsec->sid = old_tsec->exec_sid;
  1879. /* Reset exec SID on execve. */
  1880. new_tsec->exec_sid = 0;
  1881. /*
  1882. * Minimize confusion: if no_new_privs and a transition is
  1883. * explicitly requested, then fail the exec.
  1884. */
  1885. if (bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS)
  1886. return -EPERM;
  1887. } else {
  1888. /* Check for a default transition on this program. */
  1889. rc = security_transition_sid(old_tsec->sid, isec->sid,
  1890. SECCLASS_PROCESS, NULL,
  1891. &new_tsec->sid);
  1892. if (rc)
  1893. return rc;
  1894. }
  1895. COMMON_AUDIT_DATA_INIT(&ad, PATH);
  1896. ad.selinux_audit_data = &sad;
  1897. ad.u.path = bprm->file->f_path;
  1898. if ((bprm->file->f_path.mnt->mnt_flags & MNT_NOSUID) ||
  1899. (bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS))
  1900. new_tsec->sid = old_tsec->sid;
  1901. if (new_tsec->sid == old_tsec->sid) {
  1902. rc = avc_has_perm(old_tsec->sid, isec->sid,
  1903. SECCLASS_FILE, FILE__EXECUTE_NO_TRANS, &ad);
  1904. if (rc)
  1905. return rc;
  1906. } else {
  1907. /* Check permissions for the transition. */
  1908. rc = avc_has_perm(old_tsec->sid, new_tsec->sid,
  1909. SECCLASS_PROCESS, PROCESS__TRANSITION, &ad);
  1910. if (rc)
  1911. return rc;
  1912. rc = avc_has_perm(new_tsec->sid, isec->sid,
  1913. SECCLASS_FILE, FILE__ENTRYPOINT, &ad);
  1914. if (rc)
  1915. return rc;
  1916. /* Check for shared state */
  1917. if (bprm->unsafe & LSM_UNSAFE_SHARE) {
  1918. rc = avc_has_perm(old_tsec->sid, new_tsec->sid,
  1919. SECCLASS_PROCESS, PROCESS__SHARE,
  1920. NULL);
  1921. if (rc)
  1922. return -EPERM;
  1923. }
  1924. /* Make sure that anyone attempting to ptrace over a task that
  1925. * changes its SID has the appropriate permit */
  1926. if (bprm->unsafe &
  1927. (LSM_UNSAFE_PTRACE | LSM_UNSAFE_PTRACE_CAP)) {
  1928. struct task_struct *tracer;
  1929. struct task_security_struct *sec;
  1930. u32 ptsid = 0;
  1931. rcu_read_lock();
  1932. tracer = ptrace_parent(current);
  1933. if (likely(tracer != NULL)) {
  1934. sec = __task_cred(tracer)->security;
  1935. ptsid = sec->sid;
  1936. }
  1937. rcu_read_unlock();
  1938. if (ptsid != 0) {
  1939. rc = avc_has_perm(ptsid, new_tsec->sid,
  1940. SECCLASS_PROCESS,
  1941. PROCESS__PTRACE, NULL);
  1942. if (rc)
  1943. return -EPERM;
  1944. }
  1945. }
  1946. /* Clear any possibly unsafe personality bits on exec: */
  1947. bprm->per_clear |= PER_CLEAR_ON_SETID;
  1948. }
  1949. return 0;
  1950. }
  1951. static int selinux_bprm_secureexec(struct linux_binprm *bprm)
  1952. {
  1953. const struct task_security_struct *tsec = current_security();
  1954. u32 sid, osid;
  1955. int atsecure = 0;
  1956. sid = tsec->sid;
  1957. osid = tsec->osid;
  1958. if (osid != sid) {
  1959. /* Enable secure mode for SIDs transitions unless
  1960. the noatsecure permission is granted between
  1961. the two SIDs, i.e. ahp returns 0. */
  1962. atsecure = avc_has_perm(osid, sid,
  1963. SECCLASS_PROCESS,
  1964. PROCESS__NOATSECURE, NULL);
  1965. }
  1966. return (atsecure || cap_bprm_secureexec(bprm));
  1967. }
  1968. /* Derived from fs/exec.c:flush_old_files. */
  1969. static inline void flush_unauthorized_files(const struct cred *cred,
  1970. struct files_struct *files)
  1971. {
  1972. struct common_audit_data ad;
  1973. struct selinux_audit_data sad = {0,};
  1974. struct file *file, *devnull = NULL;
  1975. struct tty_struct *tty;
  1976. struct fdtable *fdt;
  1977. long j = -1;
  1978. int drop_tty = 0;
  1979. tty = get_current_tty();
  1980. if (tty) {
  1981. spin_lock(&tty_files_lock);
  1982. if (!list_empty(&tty->tty_files)) {
  1983. struct tty_file_private *file_priv;
  1984. struct inode *inode;
  1985. /* Revalidate access to controlling tty.
  1986. Use inode_has_perm on the tty inode directly rather
  1987. than using file_has_perm, as this particular open
  1988. file may belong to another process and we are only
  1989. interested in the inode-based check here. */
  1990. file_priv = list_first_entry(&tty->tty_files,
  1991. struct tty_file_private, list);
  1992. file = file_priv->file;
  1993. inode = file->f_path.dentry->d_inode;
  1994. if (inode_has_perm_noadp(cred, inode,
  1995. FILE__READ | FILE__WRITE, 0)) {
  1996. drop_tty = 1;
  1997. }
  1998. }
  1999. spin_unlock(&tty_files_lock);
  2000. tty_kref_put(tty);
  2001. }
  2002. /* Reset controlling tty. */
  2003. if (drop_tty)
  2004. no_tty();
  2005. /* Revalidate access to inherited open files. */
  2006. COMMON_AUDIT_DATA_INIT(&ad, INODE);
  2007. ad.selinux_audit_data = &sad;
  2008. spin_lock(&files->file_lock);
  2009. for (;;) {
  2010. unsigned long set, i;
  2011. int fd;
  2012. j++;
  2013. i = j * BITS_PER_LONG;
  2014. fdt = files_fdtable(files);
  2015. if (i >= fdt->max_fds)
  2016. break;
  2017. set = fdt->open_fds[j];
  2018. if (!set)
  2019. continue;
  2020. spin_unlock(&files->file_lock);
  2021. for ( ; set ; i++, set >>= 1) {
  2022. if (set & 1) {
  2023. file = fget(i);
  2024. if (!file)
  2025. continue;
  2026. if (file_has_perm(cred,
  2027. file,
  2028. file_to_av(file))) {
  2029. sys_close(i);
  2030. fd = get_unused_fd();
  2031. if (fd != i) {
  2032. if (fd >= 0)
  2033. put_unused_fd(fd);
  2034. fput(file);
  2035. continue;
  2036. }
  2037. if (devnull) {
  2038. get_file(devnull);
  2039. } else {
  2040. devnull = dentry_open(
  2041. dget(selinux_null),
  2042. mntget(selinuxfs_mount),
  2043. O_RDWR, cred);
  2044. if (IS_ERR(devnull)) {
  2045. devnull = NULL;
  2046. put_unused_fd(fd);
  2047. fput(file);
  2048. continue;
  2049. }
  2050. }
  2051. fd_install(fd, devnull);
  2052. }
  2053. fput(file);
  2054. }
  2055. }
  2056. spin_lock(&files->file_lock);
  2057. }
  2058. spin_unlock(&files->file_lock);
  2059. }
  2060. /*
  2061. * Prepare a process for imminent new credential changes due to exec
  2062. */
  2063. static void selinux_bprm_committing_creds(struct linux_binprm *bprm)
  2064. {
  2065. struct task_security_struct *new_tsec;
  2066. struct rlimit *rlim, *initrlim;
  2067. int rc, i;
  2068. new_tsec = bprm->cred->security;
  2069. if (new_tsec->sid == new_tsec->osid)
  2070. return;
  2071. /* Close files for which the new task SID is not authorized. */
  2072. flush_unauthorized_files(bprm->cred, current->files);
  2073. /* Always clear parent death signal on SID transitions. */
  2074. current->pdeath_signal = 0;
  2075. /* Check whether the new SID can inherit resource limits from the old
  2076. * SID. If not, reset all soft limits to the lower of the current
  2077. * task's hard limit and the init task's soft limit.
  2078. *
  2079. * Note that the setting of hard limits (even to lower them) can be
  2080. * controlled by the setrlimit check. The inclusion of the init task's
  2081. * soft limit into the computation is to avoid resetting soft limits
  2082. * higher than the default soft limit for cases where the default is
  2083. * lower than the hard limit, e.g. RLIMIT_CORE or RLIMIT_STACK.
  2084. */
  2085. rc = avc_has_perm(new_tsec->osid, new_tsec->sid, SECCLASS_PROCESS,
  2086. PROCESS__RLIMITINH, NULL);
  2087. if (rc) {
  2088. /* protect against do_prlimit() */
  2089. task_lock(current);
  2090. for (i = 0; i < RLIM_NLIMITS; i++) {
  2091. rlim = current->signal->rlim + i;
  2092. initrlim = init_task.signal->rlim + i;
  2093. rlim->rlim_cur = min(rlim->rlim_max, initrlim->rlim_cur);
  2094. }
  2095. task_unlock(current);
  2096. update_rlimit_cpu(current, rlimit(RLIMIT_CPU));
  2097. }
  2098. }
  2099. /*
  2100. * Clean up the process immediately after the installation of new credentials
  2101. * due to exec
  2102. */
  2103. static void selinux_bprm_committed_creds(struct linux_binprm *bprm)
  2104. {
  2105. const struct task_security_struct *tsec = current_security();
  2106. struct itimerval itimer;
  2107. u32 osid, sid;
  2108. int rc, i;
  2109. osid = tsec->osid;
  2110. sid = tsec->sid;
  2111. if (sid == osid)
  2112. return;
  2113. /* Check whether the new SID can inherit signal state from the old SID.
  2114. * If not, clear itimers to avoid subsequent signal generation and
  2115. * flush and unblock signals.
  2116. *
  2117. * This must occur _after_ the task SID has been updated so that any
  2118. * kill done after the flush will be checked against the new SID.
  2119. */
  2120. rc = avc_has_perm(osid, sid, SECCLASS_PROCESS, PROCESS__SIGINH, NULL);
  2121. if (rc) {
  2122. memset(&itimer, 0, sizeof itimer);
  2123. for (i = 0; i < 3; i++)
  2124. do_setitimer(i, &itimer, NULL);
  2125. spin_lock_irq(&current->sighand->siglock);
  2126. if (!(current->signal->flags & SIGNAL_GROUP_EXIT)) {
  2127. __flush_signals(current);
  2128. flush_signal_handlers(current, 1);
  2129. sigemptyset(&current->blocked);
  2130. }
  2131. spin_unlock_irq(&current->sighand->siglock);
  2132. }
  2133. /* Wake up the parent if it is waiting so that it can recheck
  2134. * wait permission to the new task SID. */
  2135. read_lock(&tasklist_lock);
  2136. __wake_up_parent(current, current->real_parent);
  2137. read_unlock(&tasklist_lock);
  2138. }
  2139. /* superblock security operations */
  2140. static int selinux_sb_alloc_security(struct super_block *sb)
  2141. {
  2142. return superblock_alloc_security(sb);
  2143. }
  2144. static void selinux_sb_free_security(struct super_block *sb)
  2145. {
  2146. superblock_free_security(sb);
  2147. }
  2148. static inline int match_prefix(char *prefix, int plen, char *option, int olen)
  2149. {
  2150. if (plen > olen)
  2151. return 0;
  2152. return !memcmp(prefix, option, plen);
  2153. }
  2154. static inline int selinux_option(char *option, int len)
  2155. {
  2156. return (match_prefix(CONTEXT_STR, sizeof(CONTEXT_STR)-1, option, len) ||
  2157. match_prefix(FSCONTEXT_STR, sizeof(FSCONTEXT_STR)-1, option, len) ||
  2158. match_prefix(DEFCONTEXT_STR, sizeof(DEFCONTEXT_STR)-1, option, len) ||
  2159. match_prefix(ROOTCONTEXT_STR, sizeof(ROOTCONTEXT_STR)-1, option, len) ||
  2160. match_prefix(LABELSUPP_STR, sizeof(LABELSUPP_STR)-1, option, len));
  2161. }
  2162. static inline void take_option(char **to, char *from, int *first, int len)
  2163. {
  2164. if (!*first) {
  2165. **to = ',';
  2166. *to += 1;
  2167. } else
  2168. *first = 0;
  2169. memcpy(*to, from, len);
  2170. *to += len;
  2171. }
  2172. static inline void take_selinux_option(char **to, char *from, int *first,
  2173. int len)
  2174. {
  2175. int current_size = 0;
  2176. if (!*first) {
  2177. **to = '|';
  2178. *to += 1;
  2179. } else
  2180. *first = 0;
  2181. while (current_size < len) {
  2182. if (*from != '"') {
  2183. **to = *from;
  2184. *to += 1;
  2185. }
  2186. from += 1;
  2187. current_size += 1;
  2188. }
  2189. }
  2190. static int selinux_sb_copy_data(char *orig, char *copy)
  2191. {
  2192. int fnosec, fsec, rc = 0;
  2193. char *in_save, *in_curr, *in_end;
  2194. char *sec_curr, *nosec_save, *nosec;
  2195. int open_quote = 0;
  2196. in_curr = orig;
  2197. sec_curr = copy;
  2198. nosec = (char *)get_zeroed_page(GFP_KERNEL);
  2199. if (!nosec) {
  2200. rc = -ENOMEM;
  2201. goto out;
  2202. }
  2203. nosec_save = nosec;
  2204. fnosec = fsec = 1;
  2205. in_save = in_end = orig;
  2206. do {
  2207. if (*in_end == '"')
  2208. open_quote = !open_quote;
  2209. if ((*in_end == ',' && open_quote == 0) ||
  2210. *in_end == '\0') {
  2211. int len = in_end - in_curr;
  2212. if (selinux_option(in_curr, len))
  2213. take_selinux_option(&sec_curr, in_curr, &fsec, len);
  2214. else
  2215. take_option(&nosec, in_curr, &fnosec, len);
  2216. in_curr = in_end + 1;
  2217. }
  2218. } while (*in_end++);
  2219. strcpy(in_save, nosec_save);
  2220. free_page((unsigned long)nosec_save);
  2221. out:
  2222. return rc;
  2223. }
  2224. static int selinux_sb_remount(struct super_block *sb, void *data)
  2225. {
  2226. int rc, i, *flags;
  2227. struct security_mnt_opts opts;
  2228. char *secdata, **mount_options;
  2229. struct superblock_security_struct *sbsec = sb->s_security;
  2230. if (!(sbsec->flags & SE_SBINITIALIZED))
  2231. return 0;
  2232. if (!data)
  2233. return 0;
  2234. if (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA)
  2235. return 0;
  2236. security_init_mnt_opts(&opts);
  2237. secdata = alloc_secdata();
  2238. if (!secdata)
  2239. return -ENOMEM;
  2240. rc = selinux_sb_copy_data(data, secdata);
  2241. if (rc)
  2242. goto out_free_secdata;
  2243. rc = selinux_parse_opts_str(secdata, &opts);
  2244. if (rc)
  2245. goto out_free_secdata;
  2246. mount_options = opts.mnt_opts;
  2247. flags = opts.mnt_opts_flags;
  2248. for (i = 0; i < opts.num_mnt_opts; i++) {
  2249. u32 sid;
  2250. size_t len;
  2251. if (flags[i] == SE_SBLABELSUPP)
  2252. continue;
  2253. len = strlen(mount_options[i]);
  2254. rc = security_context_to_sid(mount_options[i], len, &sid);
  2255. if (rc) {
  2256. printk(KERN_WARNING "SELinux: security_context_to_sid"
  2257. "(%s) failed for (dev %s, type %s) errno=%d\n",
  2258. mount_options[i], sb->s_id, sb->s_type->name, rc);
  2259. goto out_free_opts;
  2260. }
  2261. rc = -EINVAL;
  2262. switch (flags[i]) {
  2263. case FSCONTEXT_MNT:
  2264. if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, sid))
  2265. goto out_bad_option;
  2266. break;
  2267. case CONTEXT_MNT:
  2268. if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, sid))
  2269. goto out_bad_option;
  2270. break;
  2271. case ROOTCONTEXT_MNT: {
  2272. struct inode_security_struct *root_isec;
  2273. root_isec = sb->s_root->d_inode->i_security;
  2274. if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, sid))
  2275. goto out_bad_option;
  2276. break;
  2277. }
  2278. case DEFCONTEXT_MNT:
  2279. if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, sid))
  2280. goto out_bad_option;
  2281. break;
  2282. default:
  2283. goto out_free_opts;
  2284. }
  2285. }
  2286. rc = 0;
  2287. out_free_opts:
  2288. security_free_mnt_opts(&opts);
  2289. out_free_secdata:
  2290. free_secdata(secdata);
  2291. return rc;
  2292. out_bad_option:
  2293. printk(KERN_WARNING "SELinux: unable to change security options "
  2294. "during remount (dev %s, type=%s)\n", sb->s_id,
  2295. sb->s_type->name);
  2296. goto out_free_opts;
  2297. }
  2298. static int selinux_sb_kern_mount(struct super_block *sb, int flags, void *data)
  2299. {
  2300. const struct cred *cred = current_cred();
  2301. struct common_audit_data ad;
  2302. struct selinux_audit_data sad = {0,};
  2303. int rc;
  2304. rc = superblock_doinit(sb, data);
  2305. if (rc)
  2306. return rc;
  2307. /* Allow all mounts performed by the kernel */
  2308. if (flags & MS_KERNMOUNT)
  2309. return 0;
  2310. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  2311. ad.selinux_audit_data = &sad;
  2312. ad.u.dentry = sb->s_root;
  2313. return superblock_has_perm(cred, sb, FILESYSTEM__MOUNT, &ad);
  2314. }
  2315. static int selinux_sb_statfs(struct dentry *dentry)
  2316. {
  2317. const struct cred *cred = current_cred();
  2318. struct common_audit_data ad;
  2319. struct selinux_audit_data sad = {0,};
  2320. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  2321. ad.selinux_audit_data = &sad;
  2322. ad.u.dentry = dentry->d_sb->s_root;
  2323. return superblock_has_perm(cred, dentry->d_sb, FILESYSTEM__GETATTR, &ad);
  2324. }
  2325. static int selinux_mount(const char *dev_name,
  2326. struct path *path,
  2327. const char *type,
  2328. unsigned long flags,
  2329. void *data)
  2330. {
  2331. const struct cred *cred = current_cred();
  2332. if (flags & MS_REMOUNT)
  2333. return superblock_has_perm(cred, path->dentry->d_sb,
  2334. FILESYSTEM__REMOUNT, NULL);
  2335. else
  2336. return path_has_perm(cred, path, FILE__MOUNTON);
  2337. }
  2338. static int selinux_umount(struct vfsmount *mnt, int flags)
  2339. {
  2340. const struct cred *cred = current_cred();
  2341. return superblock_has_perm(cred, mnt->mnt_sb,
  2342. FILESYSTEM__UNMOUNT, NULL);
  2343. }
  2344. /* inode security operations */
  2345. static int selinux_inode_alloc_security(struct inode *inode)
  2346. {
  2347. return inode_alloc_security(inode);
  2348. }
  2349. static void selinux_inode_free_security(struct inode *inode)
  2350. {
  2351. inode_free_security(inode);
  2352. }
  2353. static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
  2354. const struct qstr *qstr, char **name,
  2355. void **value, size_t *len)
  2356. {
  2357. const struct task_security_struct *tsec = current_security();
  2358. struct inode_security_struct *dsec;
  2359. struct superblock_security_struct *sbsec;
  2360. u32 sid, newsid, clen;
  2361. int rc;
  2362. char *namep = NULL, *context;
  2363. dsec = dir->i_security;
  2364. sbsec = dir->i_sb->s_security;
  2365. sid = tsec->sid;
  2366. newsid = tsec->create_sid;
  2367. if ((sbsec->flags & SE_SBINITIALIZED) &&
  2368. (sbsec->behavior == SECURITY_FS_USE_MNTPOINT))
  2369. newsid = sbsec->mntpoint_sid;
  2370. else if (!newsid || !(sbsec->flags & SE_SBLABELSUPP)) {
  2371. rc = security_transition_sid(sid, dsec->sid,
  2372. inode_mode_to_security_class(inode->i_mode),
  2373. qstr, &newsid);
  2374. if (rc) {
  2375. printk(KERN_WARNING "%s: "
  2376. "security_transition_sid failed, rc=%d (dev=%s "
  2377. "ino=%ld)\n",
  2378. __func__,
  2379. -rc, inode->i_sb->s_id, inode->i_ino);
  2380. return rc;
  2381. }
  2382. }
  2383. /* Possibly defer initialization to selinux_complete_init. */
  2384. if (sbsec->flags & SE_SBINITIALIZED) {
  2385. struct inode_security_struct *isec = inode->i_security;
  2386. isec->sclass = inode_mode_to_security_class(inode->i_mode);
  2387. isec->sid = newsid;
  2388. isec->initialized = 1;
  2389. }
  2390. if (!ss_initialized || !(sbsec->flags & SE_SBLABELSUPP))
  2391. return -EOPNOTSUPP;
  2392. if (name) {
  2393. namep = kstrdup(XATTR_SELINUX_SUFFIX, GFP_NOFS);
  2394. if (!namep)
  2395. return -ENOMEM;
  2396. *name = namep;
  2397. }
  2398. if (value && len) {
  2399. rc = security_sid_to_context_force(newsid, &context, &clen);
  2400. if (rc) {
  2401. kfree(namep);
  2402. return rc;
  2403. }
  2404. *value = context;
  2405. *len = clen;
  2406. }
  2407. return 0;
  2408. }
  2409. static int selinux_inode_create(struct inode *dir, struct dentry *dentry, umode_t mode)
  2410. {
  2411. int ret;
  2412. ret = pft_inode_create(dir, dentry, mode);
  2413. if (ret < 0)
  2414. return ret;
  2415. return may_create(dir, dentry, SECCLASS_FILE);
  2416. }
  2417. static int selinux_inode_post_create(struct inode *dir, struct dentry *dentry,
  2418. umode_t mode)
  2419. {
  2420. int ret;
  2421. ret = pft_inode_post_create(dir, dentry, mode);
  2422. return ret;
  2423. }
  2424. static int selinux_inode_link(struct dentry *old_dentry, struct inode *dir, struct dentry *new_dentry)
  2425. {
  2426. return may_link(dir, old_dentry, MAY_LINK);
  2427. }
  2428. static int selinux_inode_unlink(struct inode *dir, struct dentry *dentry)
  2429. {
  2430. return may_link(dir, dentry, MAY_UNLINK);
  2431. }
  2432. static int selinux_inode_symlink(struct inode *dir, struct dentry *dentry, const char *name)
  2433. {
  2434. return may_create(dir, dentry, SECCLASS_LNK_FILE);
  2435. }
  2436. static int selinux_inode_mkdir(struct inode *dir, struct dentry *dentry, umode_t mask)
  2437. {
  2438. return may_create(dir, dentry, SECCLASS_DIR);
  2439. }
  2440. static int selinux_inode_rmdir(struct inode *dir, struct dentry *dentry)
  2441. {
  2442. return may_link(dir, dentry, MAY_RMDIR);
  2443. }
  2444. static int selinux_inode_mknod(struct inode *dir, struct dentry *dentry, umode_t mode, dev_t dev)
  2445. {
  2446. return may_create(dir, dentry, inode_mode_to_security_class(mode));
  2447. }
  2448. static int selinux_inode_rename(struct inode *old_inode, struct dentry *old_dentry,
  2449. struct inode *new_inode, struct dentry *new_dentry)
  2450. {
  2451. int rc;
  2452. rc = pft_inode_rename(old_inode, old_dentry, new_inode, new_dentry);
  2453. if (rc)
  2454. return rc;
  2455. return may_rename(old_inode, old_dentry, new_inode, new_dentry);
  2456. }
  2457. static int selinux_inode_readlink(struct dentry *dentry)
  2458. {
  2459. const struct cred *cred = current_cred();
  2460. return dentry_has_perm(cred, dentry, FILE__READ);
  2461. }
  2462. static int selinux_inode_follow_link(struct dentry *dentry, struct nameidata *nameidata)
  2463. {
  2464. const struct cred *cred = current_cred();
  2465. return dentry_has_perm(cred, dentry, FILE__READ);
  2466. }
  2467. static int selinux_inode_permission(struct inode *inode, int mask)
  2468. {
  2469. const struct cred *cred = current_cred();
  2470. struct common_audit_data ad;
  2471. struct selinux_audit_data sad = {0,};
  2472. u32 perms;
  2473. bool from_access;
  2474. unsigned flags = mask & MAY_NOT_BLOCK;
  2475. from_access = mask & MAY_ACCESS;
  2476. mask &= (MAY_READ|MAY_WRITE|MAY_EXEC|MAY_APPEND);
  2477. /* No permission to check. Existence test. */
  2478. if (!mask)
  2479. return 0;
  2480. COMMON_AUDIT_DATA_INIT(&ad, INODE);
  2481. ad.selinux_audit_data = &sad;
  2482. ad.u.inode = inode;
  2483. if (from_access)
  2484. ad.selinux_audit_data->auditdeny |= FILE__AUDIT_ACCESS;
  2485. perms = file_mask_to_av(inode->i_mode, mask);
  2486. return inode_has_perm(cred, inode, perms, &ad, flags);
  2487. }
  2488. static int selinux_inode_setattr(struct dentry *dentry, struct iattr *iattr)
  2489. {
  2490. const struct cred *cred = current_cred();
  2491. unsigned int ia_valid = iattr->ia_valid;
  2492. /* ATTR_FORCE is just used for ATTR_KILL_S[UG]ID. */
  2493. if (ia_valid & ATTR_FORCE) {
  2494. ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID | ATTR_MODE |
  2495. ATTR_FORCE);
  2496. if (!ia_valid)
  2497. return 0;
  2498. }
  2499. if (ia_valid & (ATTR_MODE | ATTR_UID | ATTR_GID |
  2500. ATTR_ATIME_SET | ATTR_MTIME_SET | ATTR_TIMES_SET))
  2501. return dentry_has_perm(cred, dentry, FILE__SETATTR);
  2502. return dentry_has_perm(cred, dentry, FILE__WRITE);
  2503. }
  2504. static int selinux_inode_getattr(struct vfsmount *mnt, struct dentry *dentry)
  2505. {
  2506. const struct cred *cred = current_cred();
  2507. struct path path;
  2508. path.dentry = dentry;
  2509. path.mnt = mnt;
  2510. return path_has_perm(cred, &path, FILE__GETATTR);
  2511. }
  2512. static int selinux_inode_setotherxattr(struct dentry *dentry, const char *name)
  2513. {
  2514. const struct cred *cred = current_cred();
  2515. if (pft_inode_set_xattr(dentry, name) < 0)
  2516. return -EACCES;
  2517. if (!strncmp(name, XATTR_SECURITY_PREFIX,
  2518. sizeof XATTR_SECURITY_PREFIX - 1)) {
  2519. if (!strcmp(name, XATTR_NAME_CAPS)) {
  2520. if (!capable(CAP_SETFCAP))
  2521. return -EPERM;
  2522. } else if (!capable(CAP_SYS_ADMIN)) {
  2523. /* A different attribute in the security namespace.
  2524. Restrict to administrator. */
  2525. return -EPERM;
  2526. }
  2527. }
  2528. /* Not an attribute we recognize, so just check the
  2529. ordinary setattr permission. */
  2530. return dentry_has_perm(cred, dentry, FILE__SETATTR);
  2531. }
  2532. static int selinux_inode_setxattr(struct dentry *dentry, const char *name,
  2533. const void *value, size_t size, int flags)
  2534. {
  2535. struct inode *inode = dentry->d_inode;
  2536. struct inode_security_struct *isec = inode->i_security;
  2537. struct superblock_security_struct *sbsec;
  2538. struct common_audit_data ad;
  2539. struct selinux_audit_data sad = {0,};
  2540. u32 newsid, sid = current_sid();
  2541. int rc = 0;
  2542. if (strcmp(name, XATTR_NAME_SELINUX))
  2543. return selinux_inode_setotherxattr(dentry, name);
  2544. sbsec = inode->i_sb->s_security;
  2545. if (!(sbsec->flags & SE_SBLABELSUPP))
  2546. return -EOPNOTSUPP;
  2547. if (!inode_owner_or_capable(inode))
  2548. return -EPERM;
  2549. COMMON_AUDIT_DATA_INIT(&ad, DENTRY);
  2550. ad.selinux_audit_data = &sad;
  2551. ad.u.dentry = dentry;
  2552. rc = avc_has_perm(sid, isec->sid, isec->sclass,
  2553. FILE__RELABELFROM, &ad);
  2554. if (rc)
  2555. return rc;
  2556. rc = security_context_to_sid(value, size, &newsid);
  2557. if (rc == -EINVAL) {
  2558. if (!capable(CAP_MAC_ADMIN))
  2559. return rc;
  2560. rc = security_context_to_sid_force(value, size, &newsid);
  2561. }
  2562. if (rc)
  2563. return rc;
  2564. rc = avc_has_perm(sid, newsid, isec->sclass,
  2565. FILE__RELABELTO, &ad);
  2566. if (rc)
  2567. return rc;
  2568. rc = security_validate_transition(isec->sid, newsid, sid,
  2569. isec->sclass);
  2570. if (rc)
  2571. return rc;
  2572. return avc_has_perm(newsid,
  2573. sbsec->sid,
  2574. SECCLASS_FILESYSTEM,
  2575. FILESYSTEM__ASSOCIATE,
  2576. &ad);
  2577. }
  2578. static void selinux_inode_post_setxattr(struct dentry *dentry, const char *name,
  2579. const void *value, size_t size,
  2580. int flags)
  2581. {
  2582. struct inode *inode = dentry->d_inode;
  2583. struct inode_security_struct *isec = inode->i_security;
  2584. u32 newsid;
  2585. int rc;
  2586. if (strcmp(name, XATTR_NAME_SELINUX)) {
  2587. /* Not an attribute we recognize, so nothing to do. */
  2588. return;
  2589. }
  2590. rc = security_context_to_sid_force(value, size, &newsid);
  2591. if (rc) {
  2592. printk(KERN_ERR "SELinux: unable to map context to SID"
  2593. "for (%s, %lu), rc=%d\n",
  2594. inode->i_sb->s_id, inode->i_ino, -rc);
  2595. return;
  2596. }
  2597. isec->sid = newsid;
  2598. return;
  2599. }
  2600. static int selinux_inode_getxattr(struct dentry *dentry, const char *name)
  2601. {
  2602. const struct cred *cred = current_cred();
  2603. return dentry_has_perm(cred, dentry, FILE__GETATTR);
  2604. }
  2605. static int selinux_inode_listxattr(struct dentry *dentry)
  2606. {
  2607. const struct cred *cred = current_cred();
  2608. return dentry_has_perm(cred, dentry, FILE__GETATTR);
  2609. }
  2610. static int selinux_inode_removexattr(struct dentry *dentry, const char *name)
  2611. {
  2612. if (strcmp(name, XATTR_NAME_SELINUX))
  2613. return selinux_inode_setotherxattr(dentry, name);
  2614. /* No one is allowed to remove a SELinux security label.
  2615. You can change the label, but all data must be labeled. */
  2616. return -EACCES;
  2617. }
  2618. /*
  2619. * Copy the inode security context value to the user.
  2620. *
  2621. * Permission check is handled by selinux_inode_getxattr hook.
  2622. */
  2623. static int selinux_inode_getsecurity(const struct inode *inode, const char *name, void **buffer, bool alloc)
  2624. {
  2625. u32 size;
  2626. int error;
  2627. char *context = NULL;
  2628. struct inode_security_struct *isec = inode->i_security;
  2629. if (strcmp(name, XATTR_SELINUX_SUFFIX))
  2630. return -EOPNOTSUPP;
  2631. /*
  2632. * If the caller has CAP_MAC_ADMIN, then get the raw context
  2633. * value even if it is not defined by current policy; otherwise,
  2634. * use the in-core value under current policy.
  2635. * Use the non-auditing forms of the permission checks since
  2636. * getxattr may be called by unprivileged processes commonly
  2637. * and lack of permission just means that we fall back to the
  2638. * in-core context value, not a denial.
  2639. */
  2640. error = selinux_capable(current_cred(), &init_user_ns, CAP_MAC_ADMIN,
  2641. SECURITY_CAP_NOAUDIT);
  2642. if (!error)
  2643. error = security_sid_to_context_force(isec->sid, &context,
  2644. &size);
  2645. else
  2646. error = security_sid_to_context(isec->sid, &context, &size);
  2647. if (error)
  2648. return error;
  2649. error = size;
  2650. if (alloc) {
  2651. *buffer = context;
  2652. goto out_nofree;
  2653. }
  2654. kfree(context);
  2655. out_nofree:
  2656. return error;
  2657. }
  2658. static int selinux_inode_setsecurity(struct inode *inode, const char *name,
  2659. const void *value, size_t size, int flags)
  2660. {
  2661. struct inode_security_struct *isec = inode->i_security;
  2662. u32 newsid;
  2663. int rc;
  2664. if (strcmp(name, XATTR_SELINUX_SUFFIX))
  2665. return -EOPNOTSUPP;
  2666. if (!value || !size)
  2667. return -EACCES;
  2668. rc = security_context_to_sid((void *)value, size, &newsid);
  2669. if (rc)
  2670. return rc;
  2671. isec->sid = newsid;
  2672. isec->initialized = 1;
  2673. return 0;
  2674. }
  2675. static int selinux_inode_listsecurity(struct inode *inode, char *buffer, size_t buffer_size)
  2676. {
  2677. const int len = sizeof(XATTR_NAME_SELINUX);
  2678. if (buffer && len <= buffer_size)
  2679. memcpy(buffer, XATTR_NAME_SELINUX, len);
  2680. return len;
  2681. }
  2682. static void selinux_inode_getsecid(const struct inode *inode, u32 *secid)
  2683. {
  2684. struct inode_security_struct *isec = inode->i_security;
  2685. *secid = isec->sid;
  2686. }
  2687. /* file security operations */
  2688. static int selinux_revalidate_file_permission(struct file *file, int mask)
  2689. {
  2690. const struct cred *cred = current_cred();
  2691. struct inode *inode = file->f_path.dentry->d_inode;
  2692. /* file_mask_to_av won't add FILE__WRITE if MAY_APPEND is set */
  2693. if ((file->f_flags & O_APPEND) && (mask & MAY_WRITE))
  2694. mask |= MAY_APPEND;
  2695. return file_has_perm(cred, file,
  2696. file_mask_to_av(inode->i_mode, mask));
  2697. }
  2698. static int selinux_file_permission(struct file *file, int mask)
  2699. {
  2700. struct inode *inode = file->f_path.dentry->d_inode;
  2701. struct file_security_struct *fsec = file->f_security;
  2702. struct inode_security_struct *isec = inode->i_security;
  2703. u32 sid = current_sid();
  2704. int ret;
  2705. if (!mask)
  2706. /* No permission to check. Existence test. */
  2707. return 0;
  2708. ret = pft_file_permission(file, mask);
  2709. if (ret < 0)
  2710. return ret;
  2711. if (sid == fsec->sid && fsec->isid == isec->sid &&
  2712. fsec->pseqno == avc_policy_seqno())
  2713. /* No change since file_open check. */
  2714. return 0;
  2715. return selinux_revalidate_file_permission(file, mask);
  2716. }
  2717. static int selinux_file_alloc_security(struct file *file)
  2718. {
  2719. return file_alloc_security(file);
  2720. }
  2721. static void selinux_file_free_security(struct file *file)
  2722. {
  2723. file_free_security(file);
  2724. }
  2725. /*
  2726. * Check whether a task has the ioctl permission and cmd
  2727. * operation to an inode.
  2728. */
  2729. int ioctl_has_perm(const struct cred *cred, struct file *file,
  2730. u32 requested, u16 cmd)
  2731. {
  2732. struct common_audit_data ad;
  2733. struct file_security_struct *fsec = file->f_security;
  2734. struct inode *inode = file->f_path.dentry->d_inode;
  2735. struct inode_security_struct *isec = inode->i_security;
  2736. struct lsm_ioctlop_audit ioctl;
  2737. u32 ssid = cred_sid(cred);
  2738. struct selinux_audit_data sad = {0,};
  2739. int rc;
  2740. u8 driver = cmd >> 8;
  2741. u8 xperm = cmd & 0xff;
  2742. COMMON_AUDIT_DATA_INIT(&ad, IOCTL_OP);
  2743. ad.u.op = &ioctl;
  2744. ad.u.op->cmd = cmd;
  2745. ad.selinux_audit_data = &sad;
  2746. ad.u.op->path = file->f_path;
  2747. if (ssid != fsec->sid) {
  2748. rc = avc_has_perm(ssid, fsec->sid,
  2749. SECCLASS_FD,
  2750. FD__USE,
  2751. &ad);
  2752. if (rc)
  2753. goto out;
  2754. }
  2755. if (unlikely(IS_PRIVATE(inode)))
  2756. return 0;
  2757. rc = avc_has_extended_perms(ssid, isec->sid, isec->sclass,
  2758. requested, driver, xperm, &ad);
  2759. out:
  2760. return rc;
  2761. }
  2762. static int selinux_file_ioctl(struct file *file, unsigned int cmd,
  2763. unsigned long arg)
  2764. {
  2765. const struct cred *cred = current_cred();
  2766. int error = 0;
  2767. switch (cmd) {
  2768. case FIONREAD:
  2769. /* fall through */
  2770. case FIBMAP:
  2771. /* fall through */
  2772. case FIGETBSZ:
  2773. /* fall through */
  2774. case FS_IOC_GETFLAGS:
  2775. /* fall through */
  2776. case FS_IOC_GETVERSION:
  2777. error = file_has_perm(cred, file, FILE__GETATTR);
  2778. break;
  2779. case FS_IOC_SETFLAGS:
  2780. /* fall through */
  2781. case FS_IOC_SETVERSION:
  2782. error = file_has_perm(cred, file, FILE__SETATTR);
  2783. break;
  2784. /* sys_ioctl() checks */
  2785. case FIONBIO:
  2786. /* fall through */
  2787. case FIOASYNC:
  2788. error = file_has_perm(cred, file, 0);
  2789. break;
  2790. case KDSKBENT:
  2791. case KDSKBSENT:
  2792. error = cred_has_capability(cred, CAP_SYS_TTY_CONFIG,
  2793. SECURITY_CAP_AUDIT);
  2794. break;
  2795. /* default case assumes that the command will go
  2796. * to the file's ioctl() function.
  2797. */
  2798. default:
  2799. error = ioctl_has_perm(cred, file, FILE__IOCTL, (u16) cmd);
  2800. }
  2801. return error;
  2802. }
  2803. static int default_noexec;
  2804. static int file_map_prot_check(struct file *file, unsigned long prot, int shared)
  2805. {
  2806. const struct cred *cred = current_cred();
  2807. int rc = 0;
  2808. if (default_noexec &&
  2809. (prot & PROT_EXEC) && (!file || IS_PRIVATE(file_inode(file)) ||
  2810. (!shared && (prot & PROT_WRITE)))) {
  2811. /*
  2812. * We are making executable an anonymous mapping or a
  2813. * private file mapping that will also be writable.
  2814. * This has an additional check.
  2815. */
  2816. rc = cred_has_perm(cred, cred, PROCESS__EXECMEM);
  2817. if (rc)
  2818. goto error;
  2819. }
  2820. if (file) {
  2821. /* read access is always possible with a mapping */
  2822. u32 av = FILE__READ;
  2823. /* write access only matters if the mapping is shared */
  2824. if (shared && (prot & PROT_WRITE))
  2825. av |= FILE__WRITE;
  2826. if (prot & PROT_EXEC)
  2827. av |= FILE__EXECUTE;
  2828. return file_has_perm(cred, file, av);
  2829. }
  2830. error:
  2831. return rc;
  2832. }
  2833. static int selinux_mmap_addr(unsigned long addr)
  2834. {
  2835. int rc = 0;
  2836. u32 sid = current_sid();
  2837. /*
  2838. * notice that we are intentionally putting the SELinux check before
  2839. * the secondary cap_file_mmap check. This is such a likely attempt
  2840. * at bad behaviour/exploit that we always want to get the AVC, even
  2841. * if DAC would have also denied the operation.
  2842. */
  2843. if (addr < CONFIG_LSM_MMAP_MIN_ADDR) {
  2844. rc = avc_has_perm(sid, sid, SECCLASS_MEMPROTECT,
  2845. MEMPROTECT__MMAP_ZERO, NULL);
  2846. if (rc)
  2847. return rc;
  2848. }
  2849. /* do DAC check on address space usage */
  2850. return cap_mmap_addr(addr);
  2851. }
  2852. static int selinux_mmap_file(struct file *file, unsigned long reqprot,
  2853. unsigned long prot, unsigned long flags)
  2854. {
  2855. if (selinux_checkreqprot)
  2856. prot = reqprot;
  2857. return file_map_prot_check(file, prot,
  2858. (flags & MAP_TYPE) == MAP_SHARED);
  2859. }
  2860. static int selinux_file_mprotect(struct vm_area_struct *vma,
  2861. unsigned long reqprot,
  2862. unsigned long prot)
  2863. {
  2864. const struct cred *cred = current_cred();
  2865. if (selinux_checkreqprot)
  2866. prot = reqprot;
  2867. if (default_noexec &&
  2868. (prot & PROT_EXEC) && !(vma->vm_flags & VM_EXEC)) {
  2869. int rc = 0;
  2870. if (vma->vm_start >= vma->vm_mm->start_brk &&
  2871. vma->vm_end <= vma->vm_mm->brk) {
  2872. rc = cred_has_perm(cred, cred, PROCESS__EXECHEAP);
  2873. } else if (!vma->vm_file &&
  2874. vma->vm_start <= vma->vm_mm->start_stack &&
  2875. vma->vm_end >= vma->vm_mm->start_stack) {
  2876. rc = current_has_perm(current, PROCESS__EXECSTACK);
  2877. } else if (vma->vm_file && vma->anon_vma) {
  2878. /*
  2879. * We are making executable a file mapping that has
  2880. * had some COW done. Since pages might have been
  2881. * written, check ability to execute the possibly
  2882. * modified content. This typically should only
  2883. * occur for text relocations.
  2884. */
  2885. rc = file_has_perm(cred, vma->vm_file, FILE__EXECMOD);
  2886. }
  2887. if (rc)
  2888. return rc;
  2889. }
  2890. return file_map_prot_check(vma->vm_file, prot, vma->vm_flags&VM_SHARED);
  2891. }
  2892. static int selinux_file_lock(struct file *file, unsigned int cmd)
  2893. {
  2894. const struct cred *cred = current_cred();
  2895. return file_has_perm(cred, file, FILE__LOCK);
  2896. }
  2897. static int selinux_file_fcntl(struct file *file, unsigned int cmd,
  2898. unsigned long arg)
  2899. {
  2900. const struct cred *cred = current_cred();
  2901. int err = 0;
  2902. switch (cmd) {
  2903. case F_SETFL:
  2904. if ((file->f_flags & O_APPEND) && !(arg & O_APPEND)) {
  2905. err = file_has_perm(cred, file, FILE__WRITE);
  2906. break;
  2907. }
  2908. /* fall through */
  2909. case F_SETOWN:
  2910. case F_SETSIG:
  2911. case F_GETFL:
  2912. case F_GETOWN:
  2913. case F_GETSIG:
  2914. case F_GETOWNER_UIDS:
  2915. /* Just check FD__USE permission */
  2916. err = file_has_perm(cred, file, 0);
  2917. break;
  2918. case F_GETLK:
  2919. case F_SETLK:
  2920. case F_SETLKW:
  2921. case F_OFD_GETLK:
  2922. case F_OFD_SETLK:
  2923. case F_OFD_SETLKW:
  2924. #if BITS_PER_LONG == 32
  2925. case F_GETLK64:
  2926. case F_SETLK64:
  2927. case F_SETLKW64:
  2928. #endif
  2929. err = file_has_perm(cred, file, FILE__LOCK);
  2930. break;
  2931. }
  2932. return err;
  2933. }
  2934. static int selinux_file_set_fowner(struct file *file)
  2935. {
  2936. struct file_security_struct *fsec;
  2937. fsec = file->f_security;
  2938. fsec->fown_sid = current_sid();
  2939. return 0;
  2940. }
  2941. static int selinux_file_send_sigiotask(struct task_struct *tsk,
  2942. struct fown_struct *fown, int signum)
  2943. {
  2944. struct file *file;
  2945. u32 sid = task_sid(tsk);
  2946. u32 perm;
  2947. struct file_security_struct *fsec;
  2948. /* struct fown_struct is never outside the context of a struct file */
  2949. file = container_of(fown, struct file, f_owner);
  2950. fsec = file->f_security;
  2951. if (!signum)
  2952. perm = signal_to_av(SIGIO); /* as per send_sigio_to_task */
  2953. else
  2954. perm = signal_to_av(signum);
  2955. return avc_has_perm(fsec->fown_sid, sid,
  2956. SECCLASS_PROCESS, perm, NULL);
  2957. }
  2958. static int selinux_file_receive(struct file *file)
  2959. {
  2960. const struct cred *cred = current_cred();
  2961. return file_has_perm(cred, file, file_to_av(file));
  2962. }
  2963. static int selinux_file_open(struct file *file, const struct cred *cred)
  2964. {
  2965. struct file_security_struct *fsec;
  2966. struct inode *inode;
  2967. struct inode_security_struct *isec;
  2968. int ret;
  2969. ret = pft_file_open(file, cred);
  2970. if (ret < 0)
  2971. return ret;
  2972. inode = file->f_path.dentry->d_inode;
  2973. fsec = file->f_security;
  2974. isec = inode->i_security;
  2975. /*
  2976. * Save inode label and policy sequence number
  2977. * at open-time so that selinux_file_permission
  2978. * can determine whether revalidation is necessary.
  2979. * Task label is already saved in the file security
  2980. * struct as its SID.
  2981. */
  2982. fsec->isid = isec->sid;
  2983. fsec->pseqno = avc_policy_seqno();
  2984. /*
  2985. * Since the inode label or policy seqno may have changed
  2986. * between the selinux_inode_permission check and the saving
  2987. * of state above, recheck that access is still permitted.
  2988. * Otherwise, access might never be revalidated against the
  2989. * new inode label or new policy.
  2990. * This check is not redundant - do not remove.
  2991. */
  2992. return inode_has_perm_noadp(cred, inode, open_file_to_av(file), 0);
  2993. }
  2994. static int selinux_file_close(struct file *file)
  2995. {
  2996. return pft_file_close(file);
  2997. }
  2998. static bool selinux_allow_merge_bio(struct bio *bio1, struct bio *bio2)
  2999. {
  3000. return pft_allow_merge_bio(bio1, bio2);
  3001. }
  3002. /* task security operations */
  3003. static int selinux_task_create(unsigned long clone_flags)
  3004. {
  3005. return current_has_perm(current, PROCESS__FORK);
  3006. }
  3007. /*
  3008. * allocate the SELinux part of blank credentials
  3009. */
  3010. static int selinux_cred_alloc_blank(struct cred *cred, gfp_t gfp)
  3011. {
  3012. struct task_security_struct *tsec;
  3013. tsec = kzalloc(sizeof(struct task_security_struct), gfp);
  3014. if (!tsec)
  3015. return -ENOMEM;
  3016. cred->security = tsec;
  3017. return 0;
  3018. }
  3019. /*
  3020. * detach and free the LSM part of a set of credentials
  3021. */
  3022. static void selinux_cred_free(struct cred *cred)
  3023. {
  3024. struct task_security_struct *tsec = cred->security;
  3025. /*
  3026. * cred->security == NULL if security_cred_alloc_blank() or
  3027. * security_prepare_creds() returned an error.
  3028. */
  3029. BUG_ON(cred->security && (unsigned long) cred->security < PAGE_SIZE);
  3030. cred->security = (void *) 0x7UL;
  3031. kfree(tsec);
  3032. }
  3033. /*
  3034. * prepare a new set of credentials for modification
  3035. */
  3036. static int selinux_cred_prepare(struct cred *new, const struct cred *old,
  3037. gfp_t gfp)
  3038. {
  3039. const struct task_security_struct *old_tsec;
  3040. struct task_security_struct *tsec;
  3041. old_tsec = old->security;
  3042. tsec = kmemdup(old_tsec, sizeof(struct task_security_struct), gfp);
  3043. if (!tsec)
  3044. return -ENOMEM;
  3045. new->security = tsec;
  3046. return 0;
  3047. }
  3048. /*
  3049. * transfer the SELinux data to a blank set of creds
  3050. */
  3051. static void selinux_cred_transfer(struct cred *new, const struct cred *old)
  3052. {
  3053. const struct task_security_struct *old_tsec = old->security;
  3054. struct task_security_struct *tsec = new->security;
  3055. *tsec = *old_tsec;
  3056. }
  3057. static void selinux_cred_getsecid(const struct cred *c, u32 *secid)
  3058. {
  3059. *secid = cred_sid(c);
  3060. }
  3061. /*
  3062. * set the security data for a kernel service
  3063. * - all the creation contexts are set to unlabelled
  3064. */
  3065. static int selinux_kernel_act_as(struct cred *new, u32 secid)
  3066. {
  3067. struct task_security_struct *tsec = new->security;
  3068. u32 sid = current_sid();
  3069. int ret;
  3070. ret = avc_has_perm(sid, secid,
  3071. SECCLASS_KERNEL_SERVICE,
  3072. KERNEL_SERVICE__USE_AS_OVERRIDE,
  3073. NULL);
  3074. if (ret == 0) {
  3075. tsec->sid = secid;
  3076. tsec->create_sid = 0;
  3077. tsec->keycreate_sid = 0;
  3078. tsec->sockcreate_sid = 0;
  3079. }
  3080. return ret;
  3081. }
  3082. /*
  3083. * set the file creation context in a security record to the same as the
  3084. * objective context of the specified inode
  3085. */
  3086. static int selinux_kernel_create_files_as(struct cred *new, struct inode *inode)
  3087. {
  3088. struct inode_security_struct *isec = inode->i_security;
  3089. struct task_security_struct *tsec = new->security;
  3090. u32 sid = current_sid();
  3091. int ret;
  3092. ret = avc_has_perm(sid, isec->sid,
  3093. SECCLASS_KERNEL_SERVICE,
  3094. KERNEL_SERVICE__CREATE_FILES_AS,
  3095. NULL);
  3096. if (ret == 0)
  3097. tsec->create_sid = isec->sid;
  3098. return ret;
  3099. }
  3100. static int selinux_kernel_module_request(char *kmod_name)
  3101. {
  3102. u32 sid;
  3103. struct common_audit_data ad;
  3104. struct selinux_audit_data sad = {0,};
  3105. sid = task_sid(current);
  3106. COMMON_AUDIT_DATA_INIT(&ad, KMOD);
  3107. ad.selinux_audit_data = &sad;
  3108. ad.u.kmod_name = kmod_name;
  3109. return avc_has_perm(sid, SECINITSID_KERNEL, SECCLASS_SYSTEM,
  3110. SYSTEM__MODULE_REQUEST, &ad);
  3111. }
  3112. static int selinux_task_setpgid(struct task_struct *p, pid_t pgid)
  3113. {
  3114. return current_has_perm(p, PROCESS__SETPGID);
  3115. }
  3116. static int selinux_task_getpgid(struct task_struct *p)
  3117. {
  3118. return current_has_perm(p, PROCESS__GETPGID);
  3119. }
  3120. static int selinux_task_getsid(struct task_struct *p)
  3121. {
  3122. return current_has_perm(p, PROCESS__GETSESSION);
  3123. }
  3124. static void selinux_task_getsecid(struct task_struct *p, u32 *secid)
  3125. {
  3126. *secid = task_sid(p);
  3127. }
  3128. static int selinux_task_setnice(struct task_struct *p, int nice)
  3129. {
  3130. int rc;
  3131. rc = cap_task_setnice(p, nice);
  3132. if (rc)
  3133. return rc;
  3134. return current_has_perm(p, PROCESS__SETSCHED);
  3135. }
  3136. static int selinux_task_setioprio(struct task_struct *p, int ioprio)
  3137. {
  3138. int rc;
  3139. rc = cap_task_setioprio(p, ioprio);
  3140. if (rc)
  3141. return rc;
  3142. return current_has_perm(p, PROCESS__SETSCHED);
  3143. }
  3144. static int selinux_task_getioprio(struct task_struct *p)
  3145. {
  3146. return current_has_perm(p, PROCESS__GETSCHED);
  3147. }
  3148. static int selinux_task_setrlimit(struct task_struct *p, unsigned int resource,
  3149. struct rlimit *new_rlim)
  3150. {
  3151. struct rlimit *old_rlim = p->signal->rlim + resource;
  3152. /* Control the ability to change the hard limit (whether
  3153. lowering or raising it), so that the hard limit can
  3154. later be used as a safe reset point for the soft limit
  3155. upon context transitions. See selinux_bprm_committing_creds. */
  3156. if (old_rlim->rlim_max != new_rlim->rlim_max)
  3157. return current_has_perm(p, PROCESS__SETRLIMIT);
  3158. return 0;
  3159. }
  3160. static int selinux_task_setscheduler(struct task_struct *p)
  3161. {
  3162. int rc;
  3163. rc = cap_task_setscheduler(p);
  3164. if (rc)
  3165. return rc;
  3166. return current_has_perm(p, PROCESS__SETSCHED);
  3167. }
  3168. static int selinux_task_getscheduler(struct task_struct *p)
  3169. {
  3170. return current_has_perm(p, PROCESS__GETSCHED);
  3171. }
  3172. static int selinux_task_movememory(struct task_struct *p)
  3173. {
  3174. return current_has_perm(p, PROCESS__SETSCHED);
  3175. }
  3176. static int selinux_task_kill(struct task_struct *p, struct siginfo *info,
  3177. int sig, u32 secid)
  3178. {
  3179. u32 perm;
  3180. int rc;
  3181. if (!sig)
  3182. perm = PROCESS__SIGNULL; /* null signal; existence test */
  3183. else
  3184. perm = signal_to_av(sig);
  3185. if (secid)
  3186. rc = avc_has_perm(secid, task_sid(p),
  3187. SECCLASS_PROCESS, perm, NULL);
  3188. else
  3189. rc = current_has_perm(p, perm);
  3190. return rc;
  3191. }
  3192. static int selinux_task_wait(struct task_struct *p)
  3193. {
  3194. return task_has_perm(p, current, PROCESS__SIGCHLD);
  3195. }
  3196. static void selinux_task_to_inode(struct task_struct *p,
  3197. struct inode *inode)
  3198. {
  3199. struct inode_security_struct *isec = inode->i_security;
  3200. u32 sid = task_sid(p);
  3201. isec->sid = sid;
  3202. isec->initialized = 1;
  3203. }
  3204. /* Returns error only if unable to parse addresses */
  3205. static int selinux_parse_skb_ipv4(struct sk_buff *skb,
  3206. struct common_audit_data *ad, u8 *proto)
  3207. {
  3208. int offset, ihlen, ret = -EINVAL;
  3209. struct iphdr _iph, *ih;
  3210. offset = skb_network_offset(skb);
  3211. ih = skb_header_pointer(skb, offset, sizeof(_iph), &_iph);
  3212. if (ih == NULL)
  3213. goto out;
  3214. ihlen = ih->ihl * 4;
  3215. if (ihlen < sizeof(_iph))
  3216. goto out;
  3217. ad->u.net->v4info.saddr = ih->saddr;
  3218. ad->u.net->v4info.daddr = ih->daddr;
  3219. ret = 0;
  3220. if (proto)
  3221. *proto = ih->protocol;
  3222. switch (ih->protocol) {
  3223. case IPPROTO_TCP: {
  3224. struct tcphdr _tcph, *th;
  3225. if (ntohs(ih->frag_off) & IP_OFFSET)
  3226. break;
  3227. offset += ihlen;
  3228. th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph);
  3229. if (th == NULL)
  3230. break;
  3231. ad->u.net->sport = th->source;
  3232. ad->u.net->dport = th->dest;
  3233. break;
  3234. }
  3235. case IPPROTO_UDP: {
  3236. struct udphdr _udph, *uh;
  3237. if (ntohs(ih->frag_off) & IP_OFFSET)
  3238. break;
  3239. offset += ihlen;
  3240. uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph);
  3241. if (uh == NULL)
  3242. break;
  3243. ad->u.net->sport = uh->source;
  3244. ad->u.net->dport = uh->dest;
  3245. break;
  3246. }
  3247. case IPPROTO_DCCP: {
  3248. struct dccp_hdr _dccph, *dh;
  3249. if (ntohs(ih->frag_off) & IP_OFFSET)
  3250. break;
  3251. offset += ihlen;
  3252. dh = skb_header_pointer(skb, offset, sizeof(_dccph), &_dccph);
  3253. if (dh == NULL)
  3254. break;
  3255. ad->u.net->sport = dh->dccph_sport;
  3256. ad->u.net->dport = dh->dccph_dport;
  3257. break;
  3258. }
  3259. default:
  3260. break;
  3261. }
  3262. out:
  3263. return ret;
  3264. }
  3265. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  3266. /* Returns error only if unable to parse addresses */
  3267. static int selinux_parse_skb_ipv6(struct sk_buff *skb,
  3268. struct common_audit_data *ad, u8 *proto)
  3269. {
  3270. u8 nexthdr;
  3271. int ret = -EINVAL, offset;
  3272. struct ipv6hdr _ipv6h, *ip6;
  3273. __be16 frag_off;
  3274. offset = skb_network_offset(skb);
  3275. ip6 = skb_header_pointer(skb, offset, sizeof(_ipv6h), &_ipv6h);
  3276. if (ip6 == NULL)
  3277. goto out;
  3278. ad->u.net->v6info.saddr = ip6->saddr;
  3279. ad->u.net->v6info.daddr = ip6->daddr;
  3280. ret = 0;
  3281. nexthdr = ip6->nexthdr;
  3282. offset += sizeof(_ipv6h);
  3283. offset = ipv6_skip_exthdr(skb, offset, &nexthdr, &frag_off);
  3284. if (offset < 0)
  3285. goto out;
  3286. if (proto)
  3287. *proto = nexthdr;
  3288. switch (nexthdr) {
  3289. case IPPROTO_TCP: {
  3290. struct tcphdr _tcph, *th;
  3291. th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph);
  3292. if (th == NULL)
  3293. break;
  3294. ad->u.net->sport = th->source;
  3295. ad->u.net->dport = th->dest;
  3296. break;
  3297. }
  3298. case IPPROTO_UDP: {
  3299. struct udphdr _udph, *uh;
  3300. uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph);
  3301. if (uh == NULL)
  3302. break;
  3303. ad->u.net->sport = uh->source;
  3304. ad->u.net->dport = uh->dest;
  3305. break;
  3306. }
  3307. case IPPROTO_DCCP: {
  3308. struct dccp_hdr _dccph, *dh;
  3309. dh = skb_header_pointer(skb, offset, sizeof(_dccph), &_dccph);
  3310. if (dh == NULL)
  3311. break;
  3312. ad->u.net->sport = dh->dccph_sport;
  3313. ad->u.net->dport = dh->dccph_dport;
  3314. break;
  3315. }
  3316. /* includes fragments */
  3317. default:
  3318. break;
  3319. }
  3320. out:
  3321. return ret;
  3322. }
  3323. #endif /* IPV6 */
  3324. static int selinux_parse_skb(struct sk_buff *skb, struct common_audit_data *ad,
  3325. char **_addrp, int src, u8 *proto)
  3326. {
  3327. char *addrp;
  3328. int ret;
  3329. switch (ad->u.net->family) {
  3330. case PF_INET:
  3331. ret = selinux_parse_skb_ipv4(skb, ad, proto);
  3332. if (ret)
  3333. goto parse_error;
  3334. addrp = (char *)(src ? &ad->u.net->v4info.saddr :
  3335. &ad->u.net->v4info.daddr);
  3336. goto okay;
  3337. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  3338. case PF_INET6:
  3339. ret = selinux_parse_skb_ipv6(skb, ad, proto);
  3340. if (ret)
  3341. goto parse_error;
  3342. addrp = (char *)(src ? &ad->u.net->v6info.saddr :
  3343. &ad->u.net->v6info.daddr);
  3344. goto okay;
  3345. #endif /* IPV6 */
  3346. default:
  3347. addrp = NULL;
  3348. goto okay;
  3349. }
  3350. parse_error:
  3351. printk(KERN_WARNING
  3352. "SELinux: failure in selinux_parse_skb(),"
  3353. " unable to parse packet\n");
  3354. return ret;
  3355. okay:
  3356. if (_addrp)
  3357. *_addrp = addrp;
  3358. return 0;
  3359. }
  3360. /**
  3361. * selinux_skb_peerlbl_sid - Determine the peer label of a packet
  3362. * @skb: the packet
  3363. * @family: protocol family
  3364. * @sid: the packet's peer label SID
  3365. *
  3366. * Description:
  3367. * Check the various different forms of network peer labeling and determine
  3368. * the peer label/SID for the packet; most of the magic actually occurs in
  3369. * the security server function security_net_peersid_cmp(). The function
  3370. * returns zero if the value in @sid is valid (although it may be SECSID_NULL)
  3371. * or -EACCES if @sid is invalid due to inconsistencies with the different
  3372. * peer labels.
  3373. *
  3374. */
  3375. static int selinux_skb_peerlbl_sid(struct sk_buff *skb, u16 family, u32 *sid)
  3376. {
  3377. int err;
  3378. u32 xfrm_sid;
  3379. u32 nlbl_sid;
  3380. u32 nlbl_type;
  3381. selinux_xfrm_skb_sid(skb, &xfrm_sid);
  3382. selinux_netlbl_skbuff_getsid(skb, family, &nlbl_type, &nlbl_sid);
  3383. err = security_net_peersid_resolve(nlbl_sid, nlbl_type, xfrm_sid, sid);
  3384. if (unlikely(err)) {
  3385. printk(KERN_WARNING
  3386. "SELinux: failure in selinux_skb_peerlbl_sid(),"
  3387. " unable to determine packet's peer label\n");
  3388. return -EACCES;
  3389. }
  3390. return 0;
  3391. }
  3392. /**
  3393. * selinux_conn_sid - Determine the child socket label for a connection
  3394. * @sk_sid: the parent socket's SID
  3395. * @skb_sid: the packet's SID
  3396. * @conn_sid: the resulting connection SID
  3397. *
  3398. * If @skb_sid is valid then the user:role:type information from @sk_sid is
  3399. * combined with the MLS information from @skb_sid in order to create
  3400. * @conn_sid. If @skb_sid is not valid then then @conn_sid is simply a copy
  3401. * of @sk_sid. Returns zero on success, negative values on failure.
  3402. *
  3403. */
  3404. static int selinux_conn_sid(u32 sk_sid, u32 skb_sid, u32 *conn_sid)
  3405. {
  3406. int err = 0;
  3407. if (skb_sid != SECSID_NULL)
  3408. err = security_sid_mls_copy(sk_sid, skb_sid, conn_sid);
  3409. else
  3410. *conn_sid = sk_sid;
  3411. return err;
  3412. }
  3413. /* socket security operations */
  3414. static int socket_sockcreate_sid(const struct task_security_struct *tsec,
  3415. u16 secclass, u32 *socksid)
  3416. {
  3417. if (tsec->sockcreate_sid > SECSID_NULL) {
  3418. *socksid = tsec->sockcreate_sid;
  3419. return 0;
  3420. }
  3421. return security_transition_sid(tsec->sid, tsec->sid, secclass, NULL,
  3422. socksid);
  3423. }
  3424. static int sock_has_perm(struct task_struct *task, struct sock *sk, u32 perms)
  3425. {
  3426. struct sk_security_struct *sksec = sk->sk_security;
  3427. struct common_audit_data ad;
  3428. struct selinux_audit_data sad = {0,};
  3429. struct lsm_network_audit net = {0,};
  3430. u32 tsid = task_sid(task);
  3431. if (unlikely(!sksec)){
  3432. printk(KERN_CRIT "[SELinux] sksec is NULL, socket is already freed. \n");
  3433. return -EINVAL;
  3434. }
  3435. if (sksec->sid == SECINITSID_KERNEL)
  3436. return 0;
  3437. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3438. ad.selinux_audit_data = &sad;
  3439. ad.u.net = &net;
  3440. ad.u.net->sk = sk;
  3441. return avc_has_perm(tsid, sksec->sid, sksec->sclass, perms, &ad);
  3442. }
  3443. static int selinux_socket_create(int family, int type,
  3444. int protocol, int kern)
  3445. {
  3446. const struct task_security_struct *tsec = current_security();
  3447. u32 newsid;
  3448. u16 secclass;
  3449. int rc;
  3450. if (kern)
  3451. return 0;
  3452. secclass = socket_type_to_security_class(family, type, protocol);
  3453. rc = socket_sockcreate_sid(tsec, secclass, &newsid);
  3454. if (rc)
  3455. return rc;
  3456. return avc_has_perm(tsec->sid, newsid, secclass, SOCKET__CREATE, NULL);
  3457. }
  3458. static int selinux_socket_post_create(struct socket *sock, int family,
  3459. int type, int protocol, int kern)
  3460. {
  3461. const struct task_security_struct *tsec = current_security();
  3462. struct inode_security_struct *isec = SOCK_INODE(sock)->i_security;
  3463. struct sk_security_struct *sksec;
  3464. int err = 0;
  3465. isec->sclass = socket_type_to_security_class(family, type, protocol);
  3466. if (kern)
  3467. isec->sid = SECINITSID_KERNEL;
  3468. else {
  3469. err = socket_sockcreate_sid(tsec, isec->sclass, &(isec->sid));
  3470. if (err)
  3471. return err;
  3472. }
  3473. isec->initialized = 1;
  3474. if (sock->sk) {
  3475. sksec = sock->sk->sk_security;
  3476. sksec->sid = isec->sid;
  3477. sksec->sclass = isec->sclass;
  3478. err = selinux_netlbl_socket_post_create(sock->sk, family);
  3479. }
  3480. return err;
  3481. }
  3482. /* Range of port numbers used to automatically bind.
  3483. Need to determine whether we should perform a name_bind
  3484. permission check between the socket and the port number. */
  3485. static int selinux_socket_bind(struct socket *sock, struct sockaddr *address, int addrlen)
  3486. {
  3487. struct sock *sk = sock->sk;
  3488. u16 family;
  3489. int err;
  3490. err = sock_has_perm(current, sk, SOCKET__BIND);
  3491. if (err)
  3492. goto out;
  3493. /*
  3494. * If PF_INET or PF_INET6, check name_bind permission for the port.
  3495. * Multiple address binding for SCTP is not supported yet: we just
  3496. * check the first address now.
  3497. */
  3498. family = sk->sk_family;
  3499. if (family == PF_INET || family == PF_INET6) {
  3500. char *addrp;
  3501. struct sk_security_struct *sksec = sk->sk_security;
  3502. struct common_audit_data ad;
  3503. struct selinux_audit_data sad = {0,};
  3504. struct lsm_network_audit net = {0,};
  3505. struct sockaddr_in *addr4 = NULL;
  3506. struct sockaddr_in6 *addr6 = NULL;
  3507. unsigned short snum;
  3508. u32 sid, node_perm;
  3509. if (family == PF_INET) {
  3510. if (addrlen < sizeof(struct sockaddr_in)) {
  3511. err = -EINVAL;
  3512. goto out;
  3513. }
  3514. addr4 = (struct sockaddr_in *)address;
  3515. snum = ntohs(addr4->sin_port);
  3516. addrp = (char *)&addr4->sin_addr.s_addr;
  3517. } else {
  3518. if (addrlen < SIN6_LEN_RFC2133) {
  3519. err = -EINVAL;
  3520. goto out;
  3521. }
  3522. addr6 = (struct sockaddr_in6 *)address;
  3523. snum = ntohs(addr6->sin6_port);
  3524. addrp = (char *)&addr6->sin6_addr.s6_addr;
  3525. }
  3526. if (snum) {
  3527. int low, high;
  3528. inet_get_local_port_range(&low, &high);
  3529. if (snum < max(PROT_SOCK, low) || snum > high) {
  3530. err = sel_netport_sid(sk->sk_protocol,
  3531. snum, &sid);
  3532. if (err)
  3533. goto out;
  3534. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3535. ad.selinux_audit_data = &sad;
  3536. ad.u.net = &net;
  3537. ad.u.net->sport = htons(snum);
  3538. ad.u.net->family = family;
  3539. err = avc_has_perm(sksec->sid, sid,
  3540. sksec->sclass,
  3541. SOCKET__NAME_BIND, &ad);
  3542. if (err)
  3543. goto out;
  3544. }
  3545. }
  3546. switch (sksec->sclass) {
  3547. case SECCLASS_TCP_SOCKET:
  3548. node_perm = TCP_SOCKET__NODE_BIND;
  3549. break;
  3550. case SECCLASS_UDP_SOCKET:
  3551. node_perm = UDP_SOCKET__NODE_BIND;
  3552. break;
  3553. case SECCLASS_DCCP_SOCKET:
  3554. node_perm = DCCP_SOCKET__NODE_BIND;
  3555. break;
  3556. default:
  3557. node_perm = RAWIP_SOCKET__NODE_BIND;
  3558. break;
  3559. }
  3560. err = sel_netnode_sid(addrp, family, &sid);
  3561. if (err)
  3562. goto out;
  3563. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3564. ad.selinux_audit_data = &sad;
  3565. ad.u.net = &net;
  3566. ad.u.net->sport = htons(snum);
  3567. ad.u.net->family = family;
  3568. if (family == PF_INET)
  3569. ad.u.net->v4info.saddr = addr4->sin_addr.s_addr;
  3570. else
  3571. ad.u.net->v6info.saddr = addr6->sin6_addr;
  3572. err = avc_has_perm(sksec->sid, sid,
  3573. sksec->sclass, node_perm, &ad);
  3574. if (err)
  3575. goto out;
  3576. }
  3577. out:
  3578. return err;
  3579. }
  3580. static int selinux_socket_connect(struct socket *sock, struct sockaddr *address, int addrlen)
  3581. {
  3582. struct sock *sk = sock->sk;
  3583. struct sk_security_struct *sksec = sk->sk_security;
  3584. int err;
  3585. err = sock_has_perm(current, sk, SOCKET__CONNECT);
  3586. if (err)
  3587. return err;
  3588. /*
  3589. * If a TCP or DCCP socket, check name_connect permission for the port.
  3590. */
  3591. if (sksec->sclass == SECCLASS_TCP_SOCKET ||
  3592. sksec->sclass == SECCLASS_DCCP_SOCKET) {
  3593. struct common_audit_data ad;
  3594. struct selinux_audit_data sad = {0,};
  3595. struct lsm_network_audit net = {0,};
  3596. struct sockaddr_in *addr4 = NULL;
  3597. struct sockaddr_in6 *addr6 = NULL;
  3598. unsigned short snum;
  3599. u32 sid, perm;
  3600. if (sk->sk_family == PF_INET) {
  3601. addr4 = (struct sockaddr_in *)address;
  3602. if (addrlen < sizeof(struct sockaddr_in))
  3603. return -EINVAL;
  3604. snum = ntohs(addr4->sin_port);
  3605. } else {
  3606. addr6 = (struct sockaddr_in6 *)address;
  3607. if (addrlen < SIN6_LEN_RFC2133)
  3608. return -EINVAL;
  3609. snum = ntohs(addr6->sin6_port);
  3610. }
  3611. err = sel_netport_sid(sk->sk_protocol, snum, &sid);
  3612. if (err)
  3613. goto out;
  3614. perm = (sksec->sclass == SECCLASS_TCP_SOCKET) ?
  3615. TCP_SOCKET__NAME_CONNECT : DCCP_SOCKET__NAME_CONNECT;
  3616. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3617. ad.selinux_audit_data = &sad;
  3618. ad.u.net = &net;
  3619. ad.u.net->dport = htons(snum);
  3620. ad.u.net->family = sk->sk_family;
  3621. err = avc_has_perm(sksec->sid, sid, sksec->sclass, perm, &ad);
  3622. if (err)
  3623. goto out;
  3624. }
  3625. err = selinux_netlbl_socket_connect(sk, address);
  3626. out:
  3627. return err;
  3628. }
  3629. static int selinux_socket_listen(struct socket *sock, int backlog)
  3630. {
  3631. return sock_has_perm(current, sock->sk, SOCKET__LISTEN);
  3632. }
  3633. static int selinux_socket_accept(struct socket *sock, struct socket *newsock)
  3634. {
  3635. int err;
  3636. struct inode_security_struct *isec;
  3637. struct inode_security_struct *newisec;
  3638. err = sock_has_perm(current, sock->sk, SOCKET__ACCEPT);
  3639. if (err)
  3640. return err;
  3641. newisec = SOCK_INODE(newsock)->i_security;
  3642. isec = SOCK_INODE(sock)->i_security;
  3643. newisec->sclass = isec->sclass;
  3644. newisec->sid = isec->sid;
  3645. newisec->initialized = 1;
  3646. return 0;
  3647. }
  3648. static int selinux_socket_sendmsg(struct socket *sock, struct msghdr *msg,
  3649. int size)
  3650. {
  3651. return sock_has_perm(current, sock->sk, SOCKET__WRITE);
  3652. }
  3653. static int selinux_socket_recvmsg(struct socket *sock, struct msghdr *msg,
  3654. int size, int flags)
  3655. {
  3656. return sock_has_perm(current, sock->sk, SOCKET__READ);
  3657. }
  3658. static int selinux_socket_getsockname(struct socket *sock)
  3659. {
  3660. return sock_has_perm(current, sock->sk, SOCKET__GETATTR);
  3661. }
  3662. static int selinux_socket_getpeername(struct socket *sock)
  3663. {
  3664. return sock_has_perm(current, sock->sk, SOCKET__GETATTR);
  3665. }
  3666. static int selinux_socket_setsockopt(struct socket *sock, int level, int optname)
  3667. {
  3668. int err;
  3669. err = sock_has_perm(current, sock->sk, SOCKET__SETOPT);
  3670. if (err)
  3671. return err;
  3672. return selinux_netlbl_socket_setsockopt(sock, level, optname);
  3673. }
  3674. static int selinux_socket_getsockopt(struct socket *sock, int level,
  3675. int optname)
  3676. {
  3677. return sock_has_perm(current, sock->sk, SOCKET__GETOPT);
  3678. }
  3679. static int selinux_socket_shutdown(struct socket *sock, int how)
  3680. {
  3681. return sock_has_perm(current, sock->sk, SOCKET__SHUTDOWN);
  3682. }
  3683. static int selinux_socket_unix_stream_connect(struct sock *sock,
  3684. struct sock *other,
  3685. struct sock *newsk)
  3686. {
  3687. struct sk_security_struct *sksec_sock = sock->sk_security;
  3688. struct sk_security_struct *sksec_other = other->sk_security;
  3689. struct sk_security_struct *sksec_new = newsk->sk_security;
  3690. struct common_audit_data ad;
  3691. struct selinux_audit_data sad = {0,};
  3692. struct lsm_network_audit net = {0,};
  3693. int err;
  3694. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3695. ad.selinux_audit_data = &sad;
  3696. ad.u.net = &net;
  3697. ad.u.net->sk = other;
  3698. err = avc_has_perm(sksec_sock->sid, sksec_other->sid,
  3699. sksec_other->sclass,
  3700. UNIX_STREAM_SOCKET__CONNECTTO, &ad);
  3701. if (err)
  3702. return err;
  3703. /* server child socket */
  3704. sksec_new->peer_sid = sksec_sock->sid;
  3705. err = security_sid_mls_copy(sksec_other->sid, sksec_sock->sid,
  3706. &sksec_new->sid);
  3707. if (err)
  3708. return err;
  3709. /* connecting socket */
  3710. sksec_sock->peer_sid = sksec_new->sid;
  3711. return 0;
  3712. }
  3713. static int selinux_socket_unix_may_send(struct socket *sock,
  3714. struct socket *other)
  3715. {
  3716. struct sk_security_struct *ssec = sock->sk->sk_security;
  3717. struct sk_security_struct *osec = other->sk->sk_security;
  3718. struct common_audit_data ad;
  3719. struct selinux_audit_data sad = {0,};
  3720. struct lsm_network_audit net = {0,};
  3721. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3722. ad.selinux_audit_data = &sad;
  3723. ad.u.net = &net;
  3724. ad.u.net->sk = other->sk;
  3725. return avc_has_perm(ssec->sid, osec->sid, osec->sclass, SOCKET__SENDTO,
  3726. &ad);
  3727. }
  3728. static int selinux_inet_sys_rcv_skb(int ifindex, char *addrp, u16 family,
  3729. u32 peer_sid,
  3730. struct common_audit_data *ad)
  3731. {
  3732. int err;
  3733. u32 if_sid;
  3734. u32 node_sid;
  3735. err = sel_netif_sid(ifindex, &if_sid);
  3736. if (err)
  3737. return err;
  3738. err = avc_has_perm(peer_sid, if_sid,
  3739. SECCLASS_NETIF, NETIF__INGRESS, ad);
  3740. if (err)
  3741. return err;
  3742. err = sel_netnode_sid(addrp, family, &node_sid);
  3743. if (err)
  3744. return err;
  3745. return avc_has_perm(peer_sid, node_sid,
  3746. SECCLASS_NODE, NODE__RECVFROM, ad);
  3747. }
  3748. static int selinux_sock_rcv_skb_compat(struct sock *sk, struct sk_buff *skb,
  3749. u16 family)
  3750. {
  3751. int err = 0;
  3752. struct sk_security_struct *sksec = sk->sk_security;
  3753. u32 sk_sid = sksec->sid;
  3754. struct common_audit_data ad;
  3755. struct selinux_audit_data sad = {0,};
  3756. struct lsm_network_audit net = {0,};
  3757. char *addrp;
  3758. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3759. ad.selinux_audit_data = &sad;
  3760. ad.u.net = &net;
  3761. ad.u.net->netif = skb->skb_iif;
  3762. ad.u.net->family = family;
  3763. err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL);
  3764. if (err)
  3765. return err;
  3766. if (selinux_secmark_enabled()) {
  3767. err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET,
  3768. PACKET__RECV, &ad);
  3769. if (err)
  3770. return err;
  3771. }
  3772. err = selinux_netlbl_sock_rcv_skb(sksec, skb, family, &ad);
  3773. if (err)
  3774. return err;
  3775. err = selinux_xfrm_sock_rcv_skb(sksec->sid, skb, &ad);
  3776. return err;
  3777. }
  3778. static int selinux_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
  3779. {
  3780. int err;
  3781. struct sk_security_struct *sksec = sk->sk_security;
  3782. u16 family = sk->sk_family;
  3783. u32 sk_sid = sksec->sid;
  3784. struct common_audit_data ad;
  3785. struct selinux_audit_data sad = {0,};
  3786. struct lsm_network_audit net = {0,};
  3787. char *addrp;
  3788. u8 secmark_active;
  3789. u8 peerlbl_active;
  3790. if (family != PF_INET && family != PF_INET6)
  3791. return 0;
  3792. /* Handle mapped IPv4 packets arriving via IPv6 sockets */
  3793. if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
  3794. family = PF_INET;
  3795. /* If any sort of compatibility mode is enabled then handoff processing
  3796. * to the selinux_sock_rcv_skb_compat() function to deal with the
  3797. * special handling. We do this in an attempt to keep this function
  3798. * as fast and as clean as possible. */
  3799. if (!selinux_policycap_netpeer)
  3800. return selinux_sock_rcv_skb_compat(sk, skb, family);
  3801. secmark_active = selinux_secmark_enabled();
  3802. peerlbl_active = netlbl_enabled() || selinux_xfrm_enabled();
  3803. if (!secmark_active && !peerlbl_active)
  3804. return 0;
  3805. COMMON_AUDIT_DATA_INIT(&ad, NET);
  3806. ad.selinux_audit_data = &sad;
  3807. ad.u.net = &net;
  3808. ad.u.net->netif = skb->skb_iif;
  3809. ad.u.net->family = family;
  3810. err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL);
  3811. if (err)
  3812. return err;
  3813. if (peerlbl_active) {
  3814. u32 peer_sid;
  3815. err = selinux_skb_peerlbl_sid(skb, family, &peer_sid);
  3816. if (err)
  3817. return err;
  3818. err = selinux_inet_sys_rcv_skb(skb->skb_iif, addrp, family,
  3819. peer_sid, &ad);
  3820. if (err) {
  3821. selinux_netlbl_err(skb, err, 0);
  3822. return err;
  3823. }
  3824. err = avc_has_perm(sk_sid, peer_sid, SECCLASS_PEER,
  3825. PEER__RECV, &ad);
  3826. if (err) {
  3827. selinux_netlbl_err(skb, err, 0);
  3828. return err;
  3829. }
  3830. }
  3831. if (secmark_active) {
  3832. err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET,
  3833. PACKET__RECV, &ad);
  3834. if (err)
  3835. return err;
  3836. }
  3837. return err;
  3838. }
  3839. static int selinux_socket_getpeersec_stream(struct socket *sock, char __user *optval,
  3840. int __user *optlen, unsigned len)
  3841. {
  3842. int err = 0;
  3843. char *scontext;
  3844. u32 scontext_len;
  3845. struct sk_security_struct *sksec = sock->sk->sk_security;
  3846. u32 peer_sid = SECSID_NULL;
  3847. if (sksec->sclass == SECCLASS_UNIX_STREAM_SOCKET ||
  3848. sksec->sclass == SECCLASS_TCP_SOCKET)
  3849. peer_sid = sksec->peer_sid;
  3850. if (peer_sid == SECSID_NULL)
  3851. return -ENOPROTOOPT;
  3852. err = security_sid_to_context(peer_sid, &scontext, &scontext_len);
  3853. if (err)
  3854. return err;
  3855. if (scontext_len > len) {
  3856. err = -ERANGE;
  3857. goto out_len;
  3858. }
  3859. if (copy_to_user(optval, scontext, scontext_len))
  3860. err = -EFAULT;
  3861. out_len:
  3862. if (put_user(scontext_len, optlen))
  3863. err = -EFAULT;
  3864. kfree(scontext);
  3865. return err;
  3866. }
  3867. static int selinux_socket_getpeersec_dgram(struct socket *sock, struct sk_buff *skb, u32 *secid)
  3868. {
  3869. u32 peer_secid = SECSID_NULL;
  3870. u16 family;
  3871. if (skb && skb->protocol == htons(ETH_P_IP))
  3872. family = PF_INET;
  3873. else if (skb && skb->protocol == htons(ETH_P_IPV6))
  3874. family = PF_INET6;
  3875. else if (sock)
  3876. family = sock->sk->sk_family;
  3877. else
  3878. goto out;
  3879. if (sock && family == PF_UNIX)
  3880. selinux_inode_getsecid(SOCK_INODE(sock), &peer_secid);
  3881. else if (skb)
  3882. selinux_skb_peerlbl_sid(skb, family, &peer_secid);
  3883. out:
  3884. *secid = peer_secid;
  3885. if (peer_secid == SECSID_NULL)
  3886. return -EINVAL;
  3887. return 0;
  3888. }
  3889. static int selinux_sk_alloc_security(struct sock *sk, int family, gfp_t priority)
  3890. {
  3891. struct sk_security_struct *sksec;
  3892. sksec = kzalloc(sizeof(*sksec), priority);
  3893. if (!sksec)
  3894. return -ENOMEM;
  3895. sksec->peer_sid = SECINITSID_UNLABELED;
  3896. sksec->sid = SECINITSID_UNLABELED;
  3897. sksec->sclass = SECCLASS_SOCKET;
  3898. selinux_netlbl_sk_security_reset(sksec);
  3899. sk->sk_security = sksec;
  3900. return 0;
  3901. }
  3902. static void selinux_sk_free_security(struct sock *sk)
  3903. {
  3904. struct sk_security_struct *sksec = sk->sk_security;
  3905. sk->sk_security = NULL;
  3906. selinux_netlbl_sk_security_free(sksec);
  3907. kfree(sksec);
  3908. }
  3909. static void selinux_sk_clone_security(const struct sock *sk, struct sock *newsk)
  3910. {
  3911. struct sk_security_struct *sksec = sk->sk_security;
  3912. struct sk_security_struct *newsksec = newsk->sk_security;
  3913. newsksec->sid = sksec->sid;
  3914. newsksec->peer_sid = sksec->peer_sid;
  3915. newsksec->sclass = sksec->sclass;
  3916. selinux_netlbl_sk_security_reset(newsksec);
  3917. }
  3918. static void selinux_sk_getsecid(struct sock *sk, u32 *secid)
  3919. {
  3920. if (!sk)
  3921. *secid = SECINITSID_ANY_SOCKET;
  3922. else {
  3923. struct sk_security_struct *sksec = sk->sk_security;
  3924. *secid = sksec->sid;
  3925. }
  3926. }
  3927. static void selinux_sock_graft(struct sock *sk, struct socket *parent)
  3928. {
  3929. struct inode_security_struct *isec = SOCK_INODE(parent)->i_security;
  3930. struct sk_security_struct *sksec = sk->sk_security;
  3931. if (sk->sk_family == PF_INET || sk->sk_family == PF_INET6 ||
  3932. sk->sk_family == PF_UNIX)
  3933. isec->sid = sksec->sid;
  3934. sksec->sclass = isec->sclass;
  3935. }
  3936. static int selinux_inet_conn_request(struct sock *sk, struct sk_buff *skb,
  3937. struct request_sock *req)
  3938. {
  3939. struct sk_security_struct *sksec = sk->sk_security;
  3940. int err;
  3941. u16 family = sk->sk_family;
  3942. u32 connsid;
  3943. u32 peersid;
  3944. /* handle mapped IPv4 packets arriving via IPv6 sockets */
  3945. if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
  3946. family = PF_INET;
  3947. err = selinux_skb_peerlbl_sid(skb, family, &peersid);
  3948. if (err)
  3949. return err;
  3950. err = selinux_conn_sid(sksec->sid, peersid, &connsid);
  3951. if (err)
  3952. return err;
  3953. req->secid = connsid;
  3954. req->peer_secid = peersid;
  3955. return selinux_netlbl_inet_conn_request(req, family);
  3956. }
  3957. static void selinux_inet_csk_clone(struct sock *newsk,
  3958. const struct request_sock *req)
  3959. {
  3960. struct sk_security_struct *newsksec = newsk->sk_security;
  3961. newsksec->sid = req->secid;
  3962. newsksec->peer_sid = req->peer_secid;
  3963. /* NOTE: Ideally, we should also get the isec->sid for the
  3964. new socket in sync, but we don't have the isec available yet.
  3965. So we will wait until sock_graft to do it, by which
  3966. time it will have been created and available. */
  3967. /* We don't need to take any sort of lock here as we are the only
  3968. * thread with access to newsksec */
  3969. selinux_netlbl_inet_csk_clone(newsk, req->rsk_ops->family);
  3970. }
  3971. static void selinux_inet_conn_established(struct sock *sk, struct sk_buff *skb)
  3972. {
  3973. u16 family = sk->sk_family;
  3974. struct sk_security_struct *sksec = sk->sk_security;
  3975. /* handle mapped IPv4 packets arriving via IPv6 sockets */
  3976. if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
  3977. family = PF_INET;
  3978. selinux_skb_peerlbl_sid(skb, family, &sksec->peer_sid);
  3979. }
  3980. static int selinux_secmark_relabel_packet(u32 sid)
  3981. {
  3982. const struct task_security_struct *__tsec;
  3983. u32 tsid;
  3984. __tsec = current_security();
  3985. tsid = __tsec->sid;
  3986. return avc_has_perm(tsid, sid, SECCLASS_PACKET, PACKET__RELABELTO, NULL);
  3987. }
  3988. static void selinux_secmark_refcount_inc(void)
  3989. {
  3990. atomic_inc(&selinux_secmark_refcount);
  3991. }
  3992. static void selinux_secmark_refcount_dec(void)
  3993. {
  3994. atomic_dec(&selinux_secmark_refcount);
  3995. }
  3996. static void selinux_req_classify_flow(const struct request_sock *req,
  3997. struct flowi *fl)
  3998. {
  3999. fl->flowi_secid = req->secid;
  4000. }
  4001. static int selinux_tun_dev_create(void)
  4002. {
  4003. u32 sid = current_sid();
  4004. /* we aren't taking into account the "sockcreate" SID since the socket
  4005. * that is being created here is not a socket in the traditional sense,
  4006. * instead it is a private sock, accessible only to the kernel, and
  4007. * representing a wide range of network traffic spanning multiple
  4008. * connections unlike traditional sockets - check the TUN driver to
  4009. * get a better understanding of why this socket is special */
  4010. return avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET, TUN_SOCKET__CREATE,
  4011. NULL);
  4012. }
  4013. static void selinux_tun_dev_post_create(struct sock *sk)
  4014. {
  4015. struct sk_security_struct *sksec = sk->sk_security;
  4016. /* we don't currently perform any NetLabel based labeling here and it
  4017. * isn't clear that we would want to do so anyway; while we could apply
  4018. * labeling without the support of the TUN user the resulting labeled
  4019. * traffic from the other end of the connection would almost certainly
  4020. * cause confusion to the TUN user that had no idea network labeling
  4021. * protocols were being used */
  4022. /* see the comments in selinux_tun_dev_create() about why we don't use
  4023. * the sockcreate SID here */
  4024. sksec->sid = current_sid();
  4025. sksec->sclass = SECCLASS_TUN_SOCKET;
  4026. }
  4027. static int selinux_tun_dev_attach(struct sock *sk)
  4028. {
  4029. struct sk_security_struct *sksec = sk->sk_security;
  4030. u32 sid = current_sid();
  4031. int err;
  4032. err = avc_has_perm(sid, sksec->sid, SECCLASS_TUN_SOCKET,
  4033. TUN_SOCKET__RELABELFROM, NULL);
  4034. if (err)
  4035. return err;
  4036. err = avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET,
  4037. TUN_SOCKET__RELABELTO, NULL);
  4038. if (err)
  4039. return err;
  4040. sksec->sid = sid;
  4041. return 0;
  4042. }
  4043. static int selinux_nlmsg_perm(struct sock *sk, struct sk_buff *skb)
  4044. {
  4045. int rc = 0;
  4046. unsigned int msg_len;
  4047. unsigned int data_len = skb->len;
  4048. unsigned char *data = skb->data;
  4049. struct nlmsghdr *nlh;
  4050. struct sk_security_struct *sksec = sk->sk_security;
  4051. u16 sclass = sksec->sclass;
  4052. u32 perm;
  4053. while (data_len >= nlmsg_total_size(0)) {
  4054. nlh = (struct nlmsghdr *)data;
  4055. /* NOTE: the nlmsg_len field isn't reliably set by some netlink
  4056. * users which means we can't reject skb's with bogus
  4057. * length fields; our solution is to follow what
  4058. * netlink_rcv_skb() does and simply skip processing at
  4059. * messages with length fields that are clearly junk
  4060. */
  4061. if (nlh->nlmsg_len < NLMSG_HDRLEN || nlh->nlmsg_len > data_len)
  4062. return 0;
  4063. rc = selinux_nlmsg_lookup(sclass, nlh->nlmsg_type, &perm);
  4064. if (rc == 0) {
  4065. rc = sock_has_perm(current, sk, perm);
  4066. if (rc)
  4067. return rc;
  4068. } else if (rc == -EINVAL) {
  4069. /* -EINVAL is a missing msg/perm mapping */
  4070. pr_warn_ratelimited("SELinux: unrecognized netlink"
  4071. " message: protocol=%hu nlmsg_type=%hu sclass=%s"
  4072. " pid=%d comm=%s\n",
  4073. sk->sk_protocol, nlh->nlmsg_type,
  4074. secclass_map[sclass - 1].name,
  4075. task_pid_nr(current), current->comm);
  4076. #ifdef CONFIG_ALWAYS_ENFORCE
  4077. if (security_get_allow_unknown())
  4078. #else
  4079. if (selinux_enforcing && !security_get_allow_unknown())
  4080. #endif
  4081. return rc;
  4082. rc = 0;
  4083. } else if (rc == -ENOENT) {
  4084. /* -ENOENT is a missing socket/class mapping, ignore */
  4085. rc = 0;
  4086. } else {
  4087. return rc;
  4088. }
  4089. /* move to the next message after applying netlink padding */
  4090. msg_len = NLMSG_ALIGN(nlh->nlmsg_len);
  4091. if (msg_len >= data_len)
  4092. return 0;
  4093. data_len -= msg_len;
  4094. data += msg_len;
  4095. }
  4096. return rc;
  4097. }
  4098. #ifdef CONFIG_NETFILTER
  4099. static unsigned int selinux_ip_forward(struct sk_buff *skb, int ifindex,
  4100. u16 family)
  4101. {
  4102. int err;
  4103. char *addrp;
  4104. u32 peer_sid;
  4105. struct common_audit_data ad;
  4106. struct selinux_audit_data sad = {0,};
  4107. struct lsm_network_audit net = {0,};
  4108. u8 secmark_active;
  4109. u8 netlbl_active;
  4110. u8 peerlbl_active;
  4111. if (!selinux_policycap_netpeer)
  4112. return NF_ACCEPT;
  4113. secmark_active = selinux_secmark_enabled();
  4114. netlbl_active = netlbl_enabled();
  4115. peerlbl_active = netlbl_active || selinux_xfrm_enabled();
  4116. if (!secmark_active && !peerlbl_active)
  4117. return NF_ACCEPT;
  4118. if (selinux_skb_peerlbl_sid(skb, family, &peer_sid) != 0)
  4119. return NF_DROP;
  4120. COMMON_AUDIT_DATA_INIT(&ad, NET);
  4121. ad.selinux_audit_data = &sad;
  4122. ad.u.net = &net;
  4123. ad.u.net->netif = ifindex;
  4124. ad.u.net->family = family;
  4125. if (selinux_parse_skb(skb, &ad, &addrp, 1, NULL) != 0)
  4126. return NF_DROP;
  4127. if (peerlbl_active) {
  4128. err = selinux_inet_sys_rcv_skb(ifindex, addrp, family,
  4129. peer_sid, &ad);
  4130. if (err) {
  4131. selinux_netlbl_err(skb, err, 1);
  4132. return NF_DROP;
  4133. }
  4134. }
  4135. if (secmark_active)
  4136. if (avc_has_perm(peer_sid, skb->secmark,
  4137. SECCLASS_PACKET, PACKET__FORWARD_IN, &ad))
  4138. return NF_DROP;
  4139. if (netlbl_active)
  4140. /* we do this in the FORWARD path and not the POST_ROUTING
  4141. * path because we want to make sure we apply the necessary
  4142. * labeling before IPsec is applied so we can leverage AH
  4143. * protection */
  4144. if (selinux_netlbl_skbuff_setsid(skb, family, peer_sid) != 0)
  4145. return NF_DROP;
  4146. return NF_ACCEPT;
  4147. }
  4148. static unsigned int selinux_ipv4_forward(unsigned int hooknum,
  4149. struct sk_buff *skb,
  4150. const struct net_device *in,
  4151. const struct net_device *out,
  4152. int (*okfn)(struct sk_buff *))
  4153. {
  4154. return selinux_ip_forward(skb, in->ifindex, PF_INET);
  4155. }
  4156. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  4157. static unsigned int selinux_ipv6_forward(unsigned int hooknum,
  4158. struct sk_buff *skb,
  4159. const struct net_device *in,
  4160. const struct net_device *out,
  4161. int (*okfn)(struct sk_buff *))
  4162. {
  4163. return selinux_ip_forward(skb, in->ifindex, PF_INET6);
  4164. }
  4165. #endif /* IPV6 */
  4166. static unsigned int selinux_ip_output(struct sk_buff *skb,
  4167. u16 family)
  4168. {
  4169. struct sock *sk;
  4170. u32 sid;
  4171. if (!netlbl_enabled())
  4172. return NF_ACCEPT;
  4173. /* we do this in the LOCAL_OUT path and not the POST_ROUTING path
  4174. * because we want to make sure we apply the necessary labeling
  4175. * before IPsec is applied so we can leverage AH protection */
  4176. sk = skb->sk;
  4177. if (sk) {
  4178. struct sk_security_struct *sksec;
  4179. if (sk->sk_state == TCP_LISTEN)
  4180. /* if the socket is the listening state then this
  4181. * packet is a SYN-ACK packet which means it needs to
  4182. * be labeled based on the connection/request_sock and
  4183. * not the parent socket. unfortunately, we can't
  4184. * lookup the request_sock yet as it isn't queued on
  4185. * the parent socket until after the SYN-ACK is sent.
  4186. * the "solution" is to simply pass the packet as-is
  4187. * as any IP option based labeling should be copied
  4188. * from the initial connection request (in the IP
  4189. * layer). it is far from ideal, but until we get a
  4190. * security label in the packet itself this is the
  4191. * best we can do. */
  4192. return NF_ACCEPT;
  4193. /* standard practice, label using the parent socket */
  4194. sksec = sk->sk_security;
  4195. sid = sksec->sid;
  4196. } else
  4197. sid = SECINITSID_KERNEL;
  4198. if (selinux_netlbl_skbuff_setsid(skb, family, sid) != 0)
  4199. return NF_DROP;
  4200. return NF_ACCEPT;
  4201. }
  4202. static unsigned int selinux_ipv4_output(unsigned int hooknum,
  4203. struct sk_buff *skb,
  4204. const struct net_device *in,
  4205. const struct net_device *out,
  4206. int (*okfn)(struct sk_buff *))
  4207. {
  4208. return selinux_ip_output(skb, PF_INET);
  4209. }
  4210. static unsigned int selinux_ip_postroute_compat(struct sk_buff *skb,
  4211. int ifindex,
  4212. u16 family)
  4213. {
  4214. struct sock *sk = skb->sk;
  4215. struct sk_security_struct *sksec;
  4216. struct common_audit_data ad;
  4217. struct selinux_audit_data sad = {0,};
  4218. struct lsm_network_audit net = {0,};
  4219. char *addrp;
  4220. u8 proto;
  4221. if (sk == NULL)
  4222. return NF_ACCEPT;
  4223. sksec = sk->sk_security;
  4224. COMMON_AUDIT_DATA_INIT(&ad, NET);
  4225. ad.selinux_audit_data = &sad;
  4226. ad.u.net = &net;
  4227. ad.u.net->netif = ifindex;
  4228. ad.u.net->family = family;
  4229. if (selinux_parse_skb(skb, &ad, &addrp, 0, &proto))
  4230. return NF_DROP;
  4231. if (selinux_secmark_enabled())
  4232. if (avc_has_perm(sksec->sid, skb->secmark,
  4233. SECCLASS_PACKET, PACKET__SEND, &ad))
  4234. return NF_DROP_ERR(-ECONNREFUSED);
  4235. if (selinux_xfrm_postroute_last(sksec->sid, skb, &ad, proto))
  4236. return NF_DROP_ERR(-ECONNREFUSED);
  4237. return NF_ACCEPT;
  4238. }
  4239. static unsigned int selinux_ip_postroute(struct sk_buff *skb, int ifindex,
  4240. u16 family)
  4241. {
  4242. u32 secmark_perm;
  4243. u32 peer_sid;
  4244. struct sock *sk;
  4245. struct common_audit_data ad;
  4246. struct selinux_audit_data sad = {0,};
  4247. struct lsm_network_audit net = {0,};
  4248. char *addrp;
  4249. u8 secmark_active;
  4250. u8 peerlbl_active;
  4251. /* If any sort of compatibility mode is enabled then handoff processing
  4252. * to the selinux_ip_postroute_compat() function to deal with the
  4253. * special handling. We do this in an attempt to keep this function
  4254. * as fast and as clean as possible. */
  4255. if (!selinux_policycap_netpeer)
  4256. return selinux_ip_postroute_compat(skb, ifindex, family);
  4257. secmark_active = selinux_secmark_enabled();
  4258. peerlbl_active = netlbl_enabled() || selinux_xfrm_enabled();
  4259. if (!secmark_active && !peerlbl_active)
  4260. return NF_ACCEPT;
  4261. sk = skb->sk;
  4262. #ifdef CONFIG_XFRM
  4263. /* If skb->dst->xfrm is non-NULL then the packet is undergoing an IPsec
  4264. * packet transformation so allow the packet to pass without any checks
  4265. * since we'll have another chance to perform access control checks
  4266. * when the packet is on it's final way out.
  4267. * NOTE: there appear to be some IPv6 multicast cases where skb->dst
  4268. * is NULL, in this case go ahead and apply access control.
  4269. * is NULL, in this case go ahead and apply access control.
  4270. * NOTE: if this is a local socket (skb->sk != NULL) that is in the
  4271. * TCP listening state we cannot wait until the XFRM processing
  4272. * is done as we will miss out on the SA label if we do;
  4273. * unfortunately, this means more work, but it is only once per
  4274. * connection. */
  4275. if (skb_dst(skb) != NULL && skb_dst(skb)->xfrm != NULL &&
  4276. !(sk != NULL && sk->sk_state == TCP_LISTEN))
  4277. return NF_ACCEPT;
  4278. #endif
  4279. if (sk == NULL) {
  4280. /* Without an associated socket the packet is either coming
  4281. * from the kernel or it is being forwarded; check the packet
  4282. * to determine which and if the packet is being forwarded
  4283. * query the packet directly to determine the security label. */
  4284. if (skb->skb_iif) {
  4285. secmark_perm = PACKET__FORWARD_OUT;
  4286. if (selinux_skb_peerlbl_sid(skb, family, &peer_sid))
  4287. return NF_DROP;
  4288. } else {
  4289. secmark_perm = PACKET__SEND;
  4290. peer_sid = SECINITSID_KERNEL;
  4291. }
  4292. } else if (sk->sk_state == TCP_LISTEN) {
  4293. /* Locally generated packet but the associated socket is in the
  4294. * listening state which means this is a SYN-ACK packet. In
  4295. * this particular case the correct security label is assigned
  4296. * to the connection/request_sock but unfortunately we can't
  4297. * query the request_sock as it isn't queued on the parent
  4298. * socket until after the SYN-ACK packet is sent; the only
  4299. * viable choice is to regenerate the label like we do in
  4300. * selinux_inet_conn_request(). See also selinux_ip_output()
  4301. * for similar problems. */
  4302. u32 skb_sid;
  4303. struct sk_security_struct *sksec = sk->sk_security;
  4304. if (selinux_skb_peerlbl_sid(skb, family, &skb_sid))
  4305. return NF_DROP;
  4306. /* At this point, if the returned skb peerlbl is SECSID_NULL
  4307. * and the packet has been through at least one XFRM
  4308. * transformation then we must be dealing with the "final"
  4309. * form of labeled IPsec packet; since we've already applied
  4310. * all of our access controls on this packet we can safely
  4311. * pass the packet. */
  4312. if (skb_sid == SECSID_NULL) {
  4313. switch (family) {
  4314. case PF_INET:
  4315. if (IPCB(skb)->flags & IPSKB_XFRM_TRANSFORMED)
  4316. return NF_ACCEPT;
  4317. break;
  4318. case PF_INET6:
  4319. if (IP6CB(skb)->flags & IP6SKB_XFRM_TRANSFORMED)
  4320. return NF_ACCEPT;
  4321. default:
  4322. return NF_DROP_ERR(-ECONNREFUSED);
  4323. }
  4324. }
  4325. if (selinux_conn_sid(sksec->sid, skb_sid, &peer_sid))
  4326. return NF_DROP;
  4327. secmark_perm = PACKET__SEND;
  4328. } else {
  4329. /* Locally generated packet, fetch the security label from the
  4330. * associated socket. */
  4331. struct sk_security_struct *sksec = sk->sk_security;
  4332. peer_sid = sksec->sid;
  4333. secmark_perm = PACKET__SEND;
  4334. }
  4335. COMMON_AUDIT_DATA_INIT(&ad, NET);
  4336. ad.selinux_audit_data = &sad;
  4337. ad.u.net = &net;
  4338. ad.u.net->netif = ifindex;
  4339. ad.u.net->family = family;
  4340. if (selinux_parse_skb(skb, &ad, &addrp, 0, NULL))
  4341. return NF_DROP;
  4342. if (secmark_active)
  4343. if (avc_has_perm(peer_sid, skb->secmark,
  4344. SECCLASS_PACKET, secmark_perm, &ad))
  4345. return NF_DROP_ERR(-ECONNREFUSED);
  4346. if (peerlbl_active) {
  4347. u32 if_sid;
  4348. u32 node_sid;
  4349. if (sel_netif_sid(ifindex, &if_sid))
  4350. return NF_DROP;
  4351. if (avc_has_perm(peer_sid, if_sid,
  4352. SECCLASS_NETIF, NETIF__EGRESS, &ad))
  4353. return NF_DROP_ERR(-ECONNREFUSED);
  4354. if (sel_netnode_sid(addrp, family, &node_sid))
  4355. return NF_DROP;
  4356. if (avc_has_perm(peer_sid, node_sid,
  4357. SECCLASS_NODE, NODE__SENDTO, &ad))
  4358. return NF_DROP_ERR(-ECONNREFUSED);
  4359. }
  4360. return NF_ACCEPT;
  4361. }
  4362. static unsigned int selinux_ipv4_postroute(unsigned int hooknum,
  4363. struct sk_buff *skb,
  4364. const struct net_device *in,
  4365. const struct net_device *out,
  4366. int (*okfn)(struct sk_buff *))
  4367. {
  4368. return selinux_ip_postroute(skb, out->ifindex, PF_INET);
  4369. }
  4370. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  4371. static unsigned int selinux_ipv6_postroute(unsigned int hooknum,
  4372. struct sk_buff *skb,
  4373. const struct net_device *in,
  4374. const struct net_device *out,
  4375. int (*okfn)(struct sk_buff *))
  4376. {
  4377. return selinux_ip_postroute(skb, out->ifindex, PF_INET6);
  4378. }
  4379. #endif /* IPV6 */
  4380. #endif /* CONFIG_NETFILTER */
  4381. static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb)
  4382. {
  4383. int err;
  4384. err = cap_netlink_send(sk, skb);
  4385. if (err)
  4386. return err;
  4387. return selinux_nlmsg_perm(sk, skb);
  4388. }
  4389. static int ipc_alloc_security(struct task_struct *task,
  4390. struct kern_ipc_perm *perm,
  4391. u16 sclass)
  4392. {
  4393. struct ipc_security_struct *isec;
  4394. u32 sid;
  4395. isec = kzalloc(sizeof(struct ipc_security_struct), GFP_KERNEL);
  4396. if (!isec)
  4397. return -ENOMEM;
  4398. sid = task_sid(task);
  4399. isec->sclass = sclass;
  4400. isec->sid = sid;
  4401. perm->security = isec;
  4402. return 0;
  4403. }
  4404. static void ipc_free_security(struct kern_ipc_perm *perm)
  4405. {
  4406. struct ipc_security_struct *isec = perm->security;
  4407. perm->security = NULL;
  4408. kfree(isec);
  4409. }
  4410. static int msg_msg_alloc_security(struct msg_msg *msg)
  4411. {
  4412. struct msg_security_struct *msec;
  4413. msec = kzalloc(sizeof(struct msg_security_struct), GFP_KERNEL);
  4414. if (!msec)
  4415. return -ENOMEM;
  4416. msec->sid = SECINITSID_UNLABELED;
  4417. msg->security = msec;
  4418. return 0;
  4419. }
  4420. static void msg_msg_free_security(struct msg_msg *msg)
  4421. {
  4422. struct msg_security_struct *msec = msg->security;
  4423. msg->security = NULL;
  4424. kfree(msec);
  4425. }
  4426. static int ipc_has_perm(struct kern_ipc_perm *ipc_perms,
  4427. u32 perms)
  4428. {
  4429. struct ipc_security_struct *isec;
  4430. struct common_audit_data ad;
  4431. struct selinux_audit_data sad = {0,};
  4432. u32 sid = current_sid();
  4433. isec = ipc_perms->security;
  4434. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4435. ad.selinux_audit_data = &sad;
  4436. ad.u.ipc_id = ipc_perms->key;
  4437. return avc_has_perm(sid, isec->sid, isec->sclass, perms, &ad);
  4438. }
  4439. static int selinux_msg_msg_alloc_security(struct msg_msg *msg)
  4440. {
  4441. return msg_msg_alloc_security(msg);
  4442. }
  4443. static void selinux_msg_msg_free_security(struct msg_msg *msg)
  4444. {
  4445. msg_msg_free_security(msg);
  4446. }
  4447. /* message queue security operations */
  4448. static int selinux_msg_queue_alloc_security(struct msg_queue *msq)
  4449. {
  4450. struct ipc_security_struct *isec;
  4451. struct common_audit_data ad;
  4452. struct selinux_audit_data sad = {0,};
  4453. u32 sid = current_sid();
  4454. int rc;
  4455. rc = ipc_alloc_security(current, &msq->q_perm, SECCLASS_MSGQ);
  4456. if (rc)
  4457. return rc;
  4458. isec = msq->q_perm.security;
  4459. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4460. ad.selinux_audit_data = &sad;
  4461. ad.u.ipc_id = msq->q_perm.key;
  4462. rc = avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
  4463. MSGQ__CREATE, &ad);
  4464. if (rc) {
  4465. ipc_free_security(&msq->q_perm);
  4466. return rc;
  4467. }
  4468. return 0;
  4469. }
  4470. static void selinux_msg_queue_free_security(struct msg_queue *msq)
  4471. {
  4472. ipc_free_security(&msq->q_perm);
  4473. }
  4474. static int selinux_msg_queue_associate(struct msg_queue *msq, int msqflg)
  4475. {
  4476. struct ipc_security_struct *isec;
  4477. struct common_audit_data ad;
  4478. struct selinux_audit_data sad = {0,};
  4479. u32 sid = current_sid();
  4480. isec = msq->q_perm.security;
  4481. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4482. ad.selinux_audit_data = &sad;
  4483. ad.u.ipc_id = msq->q_perm.key;
  4484. return avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
  4485. MSGQ__ASSOCIATE, &ad);
  4486. }
  4487. static int selinux_msg_queue_msgctl(struct msg_queue *msq, int cmd)
  4488. {
  4489. int err;
  4490. int perms;
  4491. switch (cmd) {
  4492. case IPC_INFO:
  4493. case MSG_INFO:
  4494. /* No specific object, just general system-wide information. */
  4495. return task_has_system(current, SYSTEM__IPC_INFO);
  4496. case IPC_STAT:
  4497. case MSG_STAT:
  4498. perms = MSGQ__GETATTR | MSGQ__ASSOCIATE;
  4499. break;
  4500. case IPC_SET:
  4501. perms = MSGQ__SETATTR;
  4502. break;
  4503. case IPC_RMID:
  4504. perms = MSGQ__DESTROY;
  4505. break;
  4506. default:
  4507. return 0;
  4508. }
  4509. err = ipc_has_perm(&msq->q_perm, perms);
  4510. return err;
  4511. }
  4512. static int selinux_msg_queue_msgsnd(struct msg_queue *msq, struct msg_msg *msg, int msqflg)
  4513. {
  4514. struct ipc_security_struct *isec;
  4515. struct msg_security_struct *msec;
  4516. struct common_audit_data ad;
  4517. struct selinux_audit_data sad = {0,};
  4518. u32 sid = current_sid();
  4519. int rc;
  4520. isec = msq->q_perm.security;
  4521. msec = msg->security;
  4522. /*
  4523. * First time through, need to assign label to the message
  4524. */
  4525. if (msec->sid == SECINITSID_UNLABELED) {
  4526. /*
  4527. * Compute new sid based on current process and
  4528. * message queue this message will be stored in
  4529. */
  4530. rc = security_transition_sid(sid, isec->sid, SECCLASS_MSG,
  4531. NULL, &msec->sid);
  4532. if (rc)
  4533. return rc;
  4534. }
  4535. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4536. ad.selinux_audit_data = &sad;
  4537. ad.u.ipc_id = msq->q_perm.key;
  4538. /* Can this process write to the queue? */
  4539. rc = avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
  4540. MSGQ__WRITE, &ad);
  4541. if (!rc)
  4542. /* Can this process send the message */
  4543. rc = avc_has_perm(sid, msec->sid, SECCLASS_MSG,
  4544. MSG__SEND, &ad);
  4545. if (!rc)
  4546. /* Can the message be put in the queue? */
  4547. rc = avc_has_perm(msec->sid, isec->sid, SECCLASS_MSGQ,
  4548. MSGQ__ENQUEUE, &ad);
  4549. return rc;
  4550. }
  4551. static int selinux_msg_queue_msgrcv(struct msg_queue *msq, struct msg_msg *msg,
  4552. struct task_struct *target,
  4553. long type, int mode)
  4554. {
  4555. struct ipc_security_struct *isec;
  4556. struct msg_security_struct *msec;
  4557. struct common_audit_data ad;
  4558. struct selinux_audit_data sad = {0,};
  4559. u32 sid = task_sid(target);
  4560. int rc;
  4561. isec = msq->q_perm.security;
  4562. msec = msg->security;
  4563. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4564. ad.selinux_audit_data = &sad;
  4565. ad.u.ipc_id = msq->q_perm.key;
  4566. rc = avc_has_perm(sid, isec->sid,
  4567. SECCLASS_MSGQ, MSGQ__READ, &ad);
  4568. if (!rc)
  4569. rc = avc_has_perm(sid, msec->sid,
  4570. SECCLASS_MSG, MSG__RECEIVE, &ad);
  4571. return rc;
  4572. }
  4573. /* Shared Memory security operations */
  4574. static int selinux_shm_alloc_security(struct shmid_kernel *shp)
  4575. {
  4576. struct ipc_security_struct *isec;
  4577. struct common_audit_data ad;
  4578. struct selinux_audit_data sad = {0,};
  4579. u32 sid = current_sid();
  4580. int rc;
  4581. rc = ipc_alloc_security(current, &shp->shm_perm, SECCLASS_SHM);
  4582. if (rc)
  4583. return rc;
  4584. isec = shp->shm_perm.security;
  4585. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4586. ad.selinux_audit_data = &sad;
  4587. ad.u.ipc_id = shp->shm_perm.key;
  4588. rc = avc_has_perm(sid, isec->sid, SECCLASS_SHM,
  4589. SHM__CREATE, &ad);
  4590. if (rc) {
  4591. ipc_free_security(&shp->shm_perm);
  4592. return rc;
  4593. }
  4594. return 0;
  4595. }
  4596. static void selinux_shm_free_security(struct shmid_kernel *shp)
  4597. {
  4598. ipc_free_security(&shp->shm_perm);
  4599. }
  4600. static int selinux_shm_associate(struct shmid_kernel *shp, int shmflg)
  4601. {
  4602. struct ipc_security_struct *isec;
  4603. struct common_audit_data ad;
  4604. struct selinux_audit_data sad = {0,};
  4605. u32 sid = current_sid();
  4606. isec = shp->shm_perm.security;
  4607. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4608. ad.selinux_audit_data = &sad;
  4609. ad.u.ipc_id = shp->shm_perm.key;
  4610. return avc_has_perm(sid, isec->sid, SECCLASS_SHM,
  4611. SHM__ASSOCIATE, &ad);
  4612. }
  4613. /* Note, at this point, shp is locked down */
  4614. static int selinux_shm_shmctl(struct shmid_kernel *shp, int cmd)
  4615. {
  4616. int perms;
  4617. int err;
  4618. switch (cmd) {
  4619. case IPC_INFO:
  4620. case SHM_INFO:
  4621. /* No specific object, just general system-wide information. */
  4622. return task_has_system(current, SYSTEM__IPC_INFO);
  4623. case IPC_STAT:
  4624. case SHM_STAT:
  4625. perms = SHM__GETATTR | SHM__ASSOCIATE;
  4626. break;
  4627. case IPC_SET:
  4628. perms = SHM__SETATTR;
  4629. break;
  4630. case SHM_LOCK:
  4631. case SHM_UNLOCK:
  4632. perms = SHM__LOCK;
  4633. break;
  4634. case IPC_RMID:
  4635. perms = SHM__DESTROY;
  4636. break;
  4637. default:
  4638. return 0;
  4639. }
  4640. err = ipc_has_perm(&shp->shm_perm, perms);
  4641. return err;
  4642. }
  4643. static int selinux_shm_shmat(struct shmid_kernel *shp,
  4644. char __user *shmaddr, int shmflg)
  4645. {
  4646. u32 perms;
  4647. if (shmflg & SHM_RDONLY)
  4648. perms = SHM__READ;
  4649. else
  4650. perms = SHM__READ | SHM__WRITE;
  4651. return ipc_has_perm(&shp->shm_perm, perms);
  4652. }
  4653. /* Semaphore security operations */
  4654. static int selinux_sem_alloc_security(struct sem_array *sma)
  4655. {
  4656. struct ipc_security_struct *isec;
  4657. struct common_audit_data ad;
  4658. struct selinux_audit_data sad = {0,};
  4659. u32 sid = current_sid();
  4660. int rc;
  4661. rc = ipc_alloc_security(current, &sma->sem_perm, SECCLASS_SEM);
  4662. if (rc)
  4663. return rc;
  4664. isec = sma->sem_perm.security;
  4665. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4666. ad.selinux_audit_data = &sad;
  4667. ad.u.ipc_id = sma->sem_perm.key;
  4668. rc = avc_has_perm(sid, isec->sid, SECCLASS_SEM,
  4669. SEM__CREATE, &ad);
  4670. if (rc) {
  4671. ipc_free_security(&sma->sem_perm);
  4672. return rc;
  4673. }
  4674. return 0;
  4675. }
  4676. static void selinux_sem_free_security(struct sem_array *sma)
  4677. {
  4678. ipc_free_security(&sma->sem_perm);
  4679. }
  4680. static int selinux_sem_associate(struct sem_array *sma, int semflg)
  4681. {
  4682. struct ipc_security_struct *isec;
  4683. struct common_audit_data ad;
  4684. struct selinux_audit_data sad = {0,};
  4685. u32 sid = current_sid();
  4686. isec = sma->sem_perm.security;
  4687. COMMON_AUDIT_DATA_INIT(&ad, IPC);
  4688. ad.selinux_audit_data = &sad;
  4689. ad.u.ipc_id = sma->sem_perm.key;
  4690. return avc_has_perm(sid, isec->sid, SECCLASS_SEM,
  4691. SEM__ASSOCIATE, &ad);
  4692. }
  4693. /* Note, at this point, sma is locked down */
  4694. static int selinux_sem_semctl(struct sem_array *sma, int cmd)
  4695. {
  4696. int err;
  4697. u32 perms;
  4698. switch (cmd) {
  4699. case IPC_INFO:
  4700. case SEM_INFO:
  4701. /* No specific object, just general system-wide information. */
  4702. return task_has_system(current, SYSTEM__IPC_INFO);
  4703. case GETPID:
  4704. case GETNCNT:
  4705. case GETZCNT:
  4706. perms = SEM__GETATTR;
  4707. break;
  4708. case GETVAL:
  4709. case GETALL:
  4710. perms = SEM__READ;
  4711. break;
  4712. case SETVAL:
  4713. case SETALL:
  4714. perms = SEM__WRITE;
  4715. break;
  4716. case IPC_RMID:
  4717. perms = SEM__DESTROY;
  4718. break;
  4719. case IPC_SET:
  4720. perms = SEM__SETATTR;
  4721. break;
  4722. case IPC_STAT:
  4723. case SEM_STAT:
  4724. perms = SEM__GETATTR | SEM__ASSOCIATE;
  4725. break;
  4726. default:
  4727. return 0;
  4728. }
  4729. err = ipc_has_perm(&sma->sem_perm, perms);
  4730. return err;
  4731. }
  4732. static int selinux_sem_semop(struct sem_array *sma,
  4733. struct sembuf *sops, unsigned nsops, int alter)
  4734. {
  4735. u32 perms;
  4736. if (alter)
  4737. perms = SEM__READ | SEM__WRITE;
  4738. else
  4739. perms = SEM__READ;
  4740. return ipc_has_perm(&sma->sem_perm, perms);
  4741. }
  4742. static int selinux_ipc_permission(struct kern_ipc_perm *ipcp, short flag)
  4743. {
  4744. u32 av = 0;
  4745. av = 0;
  4746. if (flag & S_IRUGO)
  4747. av |= IPC__UNIX_READ;
  4748. if (flag & S_IWUGO)
  4749. av |= IPC__UNIX_WRITE;
  4750. if (av == 0)
  4751. return 0;
  4752. return ipc_has_perm(ipcp, av);
  4753. }
  4754. static void selinux_ipc_getsecid(struct kern_ipc_perm *ipcp, u32 *secid)
  4755. {
  4756. struct ipc_security_struct *isec = ipcp->security;
  4757. *secid = isec->sid;
  4758. }
  4759. static void selinux_d_instantiate(struct dentry *dentry, struct inode *inode)
  4760. {
  4761. if (inode)
  4762. inode_doinit_with_dentry(inode, dentry);
  4763. }
  4764. static int selinux_getprocattr(struct task_struct *p,
  4765. char *name, char **value)
  4766. {
  4767. const struct task_security_struct *__tsec;
  4768. u32 sid;
  4769. int error;
  4770. unsigned len;
  4771. if (current != p) {
  4772. error = current_has_perm(p, PROCESS__GETATTR);
  4773. if (error)
  4774. return error;
  4775. }
  4776. rcu_read_lock();
  4777. __tsec = __task_cred(p)->security;
  4778. if (!strcmp(name, "current"))
  4779. sid = __tsec->sid;
  4780. else if (!strcmp(name, "prev"))
  4781. sid = __tsec->osid;
  4782. else if (!strcmp(name, "exec"))
  4783. sid = __tsec->exec_sid;
  4784. else if (!strcmp(name, "fscreate"))
  4785. sid = __tsec->create_sid;
  4786. else if (!strcmp(name, "keycreate"))
  4787. sid = __tsec->keycreate_sid;
  4788. else if (!strcmp(name, "sockcreate"))
  4789. sid = __tsec->sockcreate_sid;
  4790. else
  4791. goto invalid;
  4792. rcu_read_unlock();
  4793. if (!sid)
  4794. return 0;
  4795. error = security_sid_to_context(sid, value, &len);
  4796. if (error)
  4797. return error;
  4798. return len;
  4799. invalid:
  4800. rcu_read_unlock();
  4801. return -EINVAL;
  4802. }
  4803. static int selinux_setprocattr(struct task_struct *p,
  4804. char *name, void *value, size_t size)
  4805. {
  4806. struct task_security_struct *tsec;
  4807. struct task_struct *tracer;
  4808. struct cred *new;
  4809. u32 sid = 0, ptsid;
  4810. int error;
  4811. char *str = value;
  4812. if (current != p) {
  4813. /* SELinux only allows a process to change its own
  4814. security attributes. */
  4815. return -EACCES;
  4816. }
  4817. /*
  4818. * Basic control over ability to set these attributes at all.
  4819. * current == p, but we'll pass them separately in case the
  4820. * above restriction is ever removed.
  4821. */
  4822. if (!strcmp(name, "exec"))
  4823. error = current_has_perm(p, PROCESS__SETEXEC);
  4824. else if (!strcmp(name, "fscreate"))
  4825. error = current_has_perm(p, PROCESS__SETFSCREATE);
  4826. else if (!strcmp(name, "keycreate"))
  4827. error = current_has_perm(p, PROCESS__SETKEYCREATE);
  4828. else if (!strcmp(name, "sockcreate"))
  4829. error = current_has_perm(p, PROCESS__SETSOCKCREATE);
  4830. else if (!strcmp(name, "current"))
  4831. error = current_has_perm(p, PROCESS__SETCURRENT);
  4832. else
  4833. error = -EINVAL;
  4834. if (error)
  4835. return error;
  4836. /* Obtain a SID for the context, if one was specified. */
  4837. if (size && str[0] && str[0] != '\n') {
  4838. if (str[size-1] == '\n') {
  4839. str[size-1] = 0;
  4840. size--;
  4841. }
  4842. error = security_context_to_sid(value, size, &sid);
  4843. if (error == -EINVAL && !strcmp(name, "fscreate")) {
  4844. if (!capable(CAP_MAC_ADMIN))
  4845. return error;
  4846. error = security_context_to_sid_force(value, size,
  4847. &sid);
  4848. }
  4849. if (error)
  4850. return error;
  4851. }
  4852. new = prepare_creds();
  4853. if (!new)
  4854. return -ENOMEM;
  4855. /* Permission checking based on the specified context is
  4856. performed during the actual operation (execve,
  4857. open/mkdir/...), when we know the full context of the
  4858. operation. See selinux_bprm_set_creds for the execve
  4859. checks and may_create for the file creation checks. The
  4860. operation will then fail if the context is not permitted. */
  4861. tsec = new->security;
  4862. if (!strcmp(name, "exec")) {
  4863. tsec->exec_sid = sid;
  4864. } else if (!strcmp(name, "fscreate")) {
  4865. tsec->create_sid = sid;
  4866. } else if (!strcmp(name, "keycreate")) {
  4867. error = may_create_key(sid, p);
  4868. if (error)
  4869. goto abort_change;
  4870. tsec->keycreate_sid = sid;
  4871. } else if (!strcmp(name, "sockcreate")) {
  4872. tsec->sockcreate_sid = sid;
  4873. } else if (!strcmp(name, "current")) {
  4874. error = -EINVAL;
  4875. if (sid == 0)
  4876. goto abort_change;
  4877. /* Only allow single threaded processes to change context */
  4878. error = -EPERM;
  4879. if (!current_is_single_threaded()) {
  4880. error = security_bounded_transition(tsec->sid, sid);
  4881. if (error)
  4882. goto abort_change;
  4883. }
  4884. /* Check permissions for the transition. */
  4885. error = avc_has_perm(tsec->sid, sid, SECCLASS_PROCESS,
  4886. PROCESS__DYNTRANSITION, NULL);
  4887. if (error)
  4888. goto abort_change;
  4889. /* Check for ptracing, and update the task SID if ok.
  4890. Otherwise, leave SID unchanged and fail. */
  4891. ptsid = 0;
  4892. rcu_read_lock();
  4893. tracer = ptrace_parent(p);
  4894. if (tracer)
  4895. ptsid = task_sid(tracer);
  4896. rcu_read_unlock();
  4897. if (tracer) {
  4898. error = avc_has_perm(ptsid, sid, SECCLASS_PROCESS,
  4899. PROCESS__PTRACE, NULL);
  4900. if (error)
  4901. goto abort_change;
  4902. }
  4903. tsec->sid = sid;
  4904. } else {
  4905. error = -EINVAL;
  4906. goto abort_change;
  4907. }
  4908. commit_creds(new);
  4909. return size;
  4910. abort_change:
  4911. abort_creds(new);
  4912. return error;
  4913. }
  4914. static int selinux_secid_to_secctx(u32 secid, char **secdata, u32 *seclen)
  4915. {
  4916. return security_sid_to_context(secid, secdata, seclen);
  4917. }
  4918. static int selinux_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid)
  4919. {
  4920. return security_context_to_sid(secdata, seclen, secid);
  4921. }
  4922. static void selinux_release_secctx(char *secdata, u32 seclen)
  4923. {
  4924. kfree(secdata);
  4925. }
  4926. /*
  4927. * called with inode->i_mutex locked
  4928. */
  4929. static int selinux_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen)
  4930. {
  4931. return selinux_inode_setsecurity(inode, XATTR_SELINUX_SUFFIX, ctx, ctxlen, 0);
  4932. }
  4933. /*
  4934. * called with inode->i_mutex locked
  4935. */
  4936. static int selinux_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen)
  4937. {
  4938. return __vfs_setxattr_noperm(dentry, XATTR_NAME_SELINUX, ctx, ctxlen, 0);
  4939. }
  4940. static int selinux_inode_getsecctx(struct inode *inode, void **ctx, u32 *ctxlen)
  4941. {
  4942. int len = 0;
  4943. len = selinux_inode_getsecurity(inode, XATTR_SELINUX_SUFFIX,
  4944. ctx, true);
  4945. if (len < 0)
  4946. return len;
  4947. *ctxlen = len;
  4948. return 0;
  4949. }
  4950. #ifdef CONFIG_KEYS
  4951. static int selinux_key_alloc(struct key *k, const struct cred *cred,
  4952. unsigned long flags)
  4953. {
  4954. const struct task_security_struct *tsec;
  4955. struct key_security_struct *ksec;
  4956. ksec = kzalloc(sizeof(struct key_security_struct), GFP_KERNEL);
  4957. if (!ksec)
  4958. return -ENOMEM;
  4959. tsec = cred->security;
  4960. if (tsec->keycreate_sid)
  4961. ksec->sid = tsec->keycreate_sid;
  4962. else
  4963. ksec->sid = tsec->sid;
  4964. k->security = ksec;
  4965. return 0;
  4966. }
  4967. static void selinux_key_free(struct key *k)
  4968. {
  4969. struct key_security_struct *ksec = k->security;
  4970. k->security = NULL;
  4971. kfree(ksec);
  4972. }
  4973. static int selinux_key_permission(key_ref_t key_ref,
  4974. const struct cred *cred,
  4975. key_perm_t perm)
  4976. {
  4977. struct key *key;
  4978. struct key_security_struct *ksec;
  4979. u32 sid;
  4980. /* if no specific permissions are requested, we skip the
  4981. permission check. No serious, additional covert channels
  4982. appear to be created. */
  4983. if (perm == 0)
  4984. return 0;
  4985. sid = cred_sid(cred);
  4986. key = key_ref_to_ptr(key_ref);
  4987. ksec = key->security;
  4988. return avc_has_perm(sid, ksec->sid, SECCLASS_KEY, perm, NULL);
  4989. }
  4990. static int selinux_key_getsecurity(struct key *key, char **_buffer)
  4991. {
  4992. struct key_security_struct *ksec = key->security;
  4993. char *context = NULL;
  4994. unsigned len;
  4995. int rc;
  4996. rc = security_sid_to_context(ksec->sid, &context, &len);
  4997. if (!rc)
  4998. rc = len;
  4999. *_buffer = context;
  5000. return rc;
  5001. }
  5002. #endif
  5003. static struct security_operations selinux_ops = {
  5004. .name = "selinux",
  5005. .binder_set_context_mgr = selinux_binder_set_context_mgr,
  5006. .binder_transaction = selinux_binder_transaction,
  5007. .binder_transfer_binder = selinux_binder_transfer_binder,
  5008. .binder_transfer_file = selinux_binder_transfer_file,
  5009. .ptrace_access_check = selinux_ptrace_access_check,
  5010. .ptrace_traceme = selinux_ptrace_traceme,
  5011. .capget = selinux_capget,
  5012. .capset = selinux_capset,
  5013. .capable = selinux_capable,
  5014. .quotactl = selinux_quotactl,
  5015. .quota_on = selinux_quota_on,
  5016. .syslog = selinux_syslog,
  5017. .vm_enough_memory = selinux_vm_enough_memory,
  5018. .netlink_send = selinux_netlink_send,
  5019. .bprm_set_creds = selinux_bprm_set_creds,
  5020. .bprm_committing_creds = selinux_bprm_committing_creds,
  5021. .bprm_committed_creds = selinux_bprm_committed_creds,
  5022. .bprm_secureexec = selinux_bprm_secureexec,
  5023. .sb_alloc_security = selinux_sb_alloc_security,
  5024. .sb_free_security = selinux_sb_free_security,
  5025. .sb_copy_data = selinux_sb_copy_data,
  5026. .sb_remount = selinux_sb_remount,
  5027. .sb_kern_mount = selinux_sb_kern_mount,
  5028. .sb_show_options = selinux_sb_show_options,
  5029. .sb_statfs = selinux_sb_statfs,
  5030. .sb_mount = selinux_mount,
  5031. .sb_umount = selinux_umount,
  5032. .sb_set_mnt_opts = selinux_set_mnt_opts,
  5033. .sb_clone_mnt_opts = selinux_sb_clone_mnt_opts,
  5034. .sb_parse_opts_str = selinux_parse_opts_str,
  5035. .inode_alloc_security = selinux_inode_alloc_security,
  5036. .inode_free_security = selinux_inode_free_security,
  5037. .inode_init_security = selinux_inode_init_security,
  5038. .inode_create = selinux_inode_create,
  5039. .inode_post_create = selinux_inode_post_create,
  5040. .inode_link = selinux_inode_link,
  5041. .inode_unlink = selinux_inode_unlink,
  5042. .inode_symlink = selinux_inode_symlink,
  5043. .inode_mkdir = selinux_inode_mkdir,
  5044. .inode_rmdir = selinux_inode_rmdir,
  5045. .inode_mknod = selinux_inode_mknod,
  5046. .inode_rename = selinux_inode_rename,
  5047. .inode_readlink = selinux_inode_readlink,
  5048. .inode_follow_link = selinux_inode_follow_link,
  5049. .inode_permission = selinux_inode_permission,
  5050. .inode_setattr = selinux_inode_setattr,
  5051. .inode_getattr = selinux_inode_getattr,
  5052. .inode_setxattr = selinux_inode_setxattr,
  5053. .inode_post_setxattr = selinux_inode_post_setxattr,
  5054. .inode_getxattr = selinux_inode_getxattr,
  5055. .inode_listxattr = selinux_inode_listxattr,
  5056. .inode_removexattr = selinux_inode_removexattr,
  5057. .inode_getsecurity = selinux_inode_getsecurity,
  5058. .inode_setsecurity = selinux_inode_setsecurity,
  5059. .inode_listsecurity = selinux_inode_listsecurity,
  5060. .inode_getsecid = selinux_inode_getsecid,
  5061. .file_permission = selinux_file_permission,
  5062. .file_alloc_security = selinux_file_alloc_security,
  5063. .file_free_security = selinux_file_free_security,
  5064. .file_ioctl = selinux_file_ioctl,
  5065. .mmap_file = selinux_mmap_file,
  5066. .mmap_addr = selinux_mmap_addr,
  5067. .file_mprotect = selinux_file_mprotect,
  5068. .file_lock = selinux_file_lock,
  5069. .file_fcntl = selinux_file_fcntl,
  5070. .file_set_fowner = selinux_file_set_fowner,
  5071. .file_send_sigiotask = selinux_file_send_sigiotask,
  5072. .file_receive = selinux_file_receive,
  5073. .file_open = selinux_file_open,
  5074. .file_close = selinux_file_close,
  5075. .allow_merge_bio = selinux_allow_merge_bio,
  5076. .task_create = selinux_task_create,
  5077. .cred_alloc_blank = selinux_cred_alloc_blank,
  5078. .cred_free = selinux_cred_free,
  5079. .cred_prepare = selinux_cred_prepare,
  5080. .cred_transfer = selinux_cred_transfer,
  5081. .cred_getsecid = selinux_cred_getsecid,
  5082. .kernel_act_as = selinux_kernel_act_as,
  5083. .kernel_create_files_as = selinux_kernel_create_files_as,
  5084. .kernel_module_request = selinux_kernel_module_request,
  5085. .task_setpgid = selinux_task_setpgid,
  5086. .task_getpgid = selinux_task_getpgid,
  5087. .task_getsid = selinux_task_getsid,
  5088. .task_getsecid = selinux_task_getsecid,
  5089. .task_setnice = selinux_task_setnice,
  5090. .task_setioprio = selinux_task_setioprio,
  5091. .task_getioprio = selinux_task_getioprio,
  5092. .task_setrlimit = selinux_task_setrlimit,
  5093. .task_setscheduler = selinux_task_setscheduler,
  5094. .task_getscheduler = selinux_task_getscheduler,
  5095. .task_movememory = selinux_task_movememory,
  5096. .task_kill = selinux_task_kill,
  5097. .task_wait = selinux_task_wait,
  5098. .task_to_inode = selinux_task_to_inode,
  5099. .ipc_permission = selinux_ipc_permission,
  5100. .ipc_getsecid = selinux_ipc_getsecid,
  5101. .msg_msg_alloc_security = selinux_msg_msg_alloc_security,
  5102. .msg_msg_free_security = selinux_msg_msg_free_security,
  5103. .msg_queue_alloc_security = selinux_msg_queue_alloc_security,
  5104. .msg_queue_free_security = selinux_msg_queue_free_security,
  5105. .msg_queue_associate = selinux_msg_queue_associate,
  5106. .msg_queue_msgctl = selinux_msg_queue_msgctl,
  5107. .msg_queue_msgsnd = selinux_msg_queue_msgsnd,
  5108. .msg_queue_msgrcv = selinux_msg_queue_msgrcv,
  5109. .shm_alloc_security = selinux_shm_alloc_security,
  5110. .shm_free_security = selinux_shm_free_security,
  5111. .shm_associate = selinux_shm_associate,
  5112. .shm_shmctl = selinux_shm_shmctl,
  5113. .shm_shmat = selinux_shm_shmat,
  5114. .sem_alloc_security = selinux_sem_alloc_security,
  5115. .sem_free_security = selinux_sem_free_security,
  5116. .sem_associate = selinux_sem_associate,
  5117. .sem_semctl = selinux_sem_semctl,
  5118. .sem_semop = selinux_sem_semop,
  5119. .d_instantiate = selinux_d_instantiate,
  5120. .getprocattr = selinux_getprocattr,
  5121. .setprocattr = selinux_setprocattr,
  5122. .secid_to_secctx = selinux_secid_to_secctx,
  5123. .secctx_to_secid = selinux_secctx_to_secid,
  5124. .release_secctx = selinux_release_secctx,
  5125. .inode_notifysecctx = selinux_inode_notifysecctx,
  5126. .inode_setsecctx = selinux_inode_setsecctx,
  5127. .inode_getsecctx = selinux_inode_getsecctx,
  5128. .unix_stream_connect = selinux_socket_unix_stream_connect,
  5129. .unix_may_send = selinux_socket_unix_may_send,
  5130. .socket_create = selinux_socket_create,
  5131. .socket_post_create = selinux_socket_post_create,
  5132. .socket_bind = selinux_socket_bind,
  5133. .socket_connect = selinux_socket_connect,
  5134. .socket_listen = selinux_socket_listen,
  5135. .socket_accept = selinux_socket_accept,
  5136. .socket_sendmsg = selinux_socket_sendmsg,
  5137. .socket_recvmsg = selinux_socket_recvmsg,
  5138. .socket_getsockname = selinux_socket_getsockname,
  5139. .socket_getpeername = selinux_socket_getpeername,
  5140. .socket_getsockopt = selinux_socket_getsockopt,
  5141. .socket_setsockopt = selinux_socket_setsockopt,
  5142. .socket_shutdown = selinux_socket_shutdown,
  5143. .socket_sock_rcv_skb = selinux_socket_sock_rcv_skb,
  5144. .socket_getpeersec_stream = selinux_socket_getpeersec_stream,
  5145. .socket_getpeersec_dgram = selinux_socket_getpeersec_dgram,
  5146. .sk_alloc_security = selinux_sk_alloc_security,
  5147. .sk_free_security = selinux_sk_free_security,
  5148. .sk_clone_security = selinux_sk_clone_security,
  5149. .sk_getsecid = selinux_sk_getsecid,
  5150. .sock_graft = selinux_sock_graft,
  5151. .inet_conn_request = selinux_inet_conn_request,
  5152. .inet_csk_clone = selinux_inet_csk_clone,
  5153. .inet_conn_established = selinux_inet_conn_established,
  5154. .secmark_relabel_packet = selinux_secmark_relabel_packet,
  5155. .secmark_refcount_inc = selinux_secmark_refcount_inc,
  5156. .secmark_refcount_dec = selinux_secmark_refcount_dec,
  5157. .req_classify_flow = selinux_req_classify_flow,
  5158. .tun_dev_create = selinux_tun_dev_create,
  5159. .tun_dev_post_create = selinux_tun_dev_post_create,
  5160. .tun_dev_attach = selinux_tun_dev_attach,
  5161. #ifdef CONFIG_SECURITY_NETWORK_XFRM
  5162. .xfrm_policy_alloc_security = selinux_xfrm_policy_alloc,
  5163. .xfrm_policy_clone_security = selinux_xfrm_policy_clone,
  5164. .xfrm_policy_free_security = selinux_xfrm_policy_free,
  5165. .xfrm_policy_delete_security = selinux_xfrm_policy_delete,
  5166. .xfrm_state_alloc = selinux_xfrm_state_alloc,
  5167. .xfrm_state_alloc_acquire = selinux_xfrm_state_alloc_acquire,
  5168. .xfrm_state_free_security = selinux_xfrm_state_free,
  5169. .xfrm_state_delete_security = selinux_xfrm_state_delete,
  5170. .xfrm_policy_lookup = selinux_xfrm_policy_lookup,
  5171. .xfrm_state_pol_flow_match = selinux_xfrm_state_pol_flow_match,
  5172. .xfrm_decode_session = selinux_xfrm_decode_session,
  5173. #endif
  5174. #ifdef CONFIG_KEYS
  5175. .key_alloc = selinux_key_alloc,
  5176. .key_free = selinux_key_free,
  5177. .key_permission = selinux_key_permission,
  5178. .key_getsecurity = selinux_key_getsecurity,
  5179. #endif
  5180. #ifdef CONFIG_AUDIT
  5181. .audit_rule_init = selinux_audit_rule_init,
  5182. .audit_rule_known = selinux_audit_rule_known,
  5183. .audit_rule_match = selinux_audit_rule_match,
  5184. .audit_rule_free = selinux_audit_rule_free,
  5185. #endif
  5186. };
  5187. static __init int selinux_init(void)
  5188. {
  5189. if (!security_module_enable(&selinux_ops)) {
  5190. selinux_enabled = 0;
  5191. return 0;
  5192. }
  5193. if (!selinux_enabled) {
  5194. printk(KERN_INFO "SELinux: Disabled at boot.\n");
  5195. return 0;
  5196. }
  5197. printk(KERN_INFO "SELinux: Initializing.\n");
  5198. /* Set the security state for the initial task. */
  5199. cred_init_security();
  5200. default_noexec = !(VM_DATA_DEFAULT_FLAGS & VM_EXEC);
  5201. sel_inode_cache = kmem_cache_create("selinux_inode_security",
  5202. sizeof(struct inode_security_struct),
  5203. 0, SLAB_PANIC, NULL);
  5204. avc_init();
  5205. if (register_security(&selinux_ops))
  5206. panic("SELinux: Unable to register with kernel.\n");
  5207. #ifdef CONFIG_ALWAYS_ENFORCE
  5208. selinux_enforcing = 1;
  5209. #endif
  5210. if (selinux_enforcing)
  5211. printk(KERN_DEBUG "SELinux: Starting in enforcing mode\n");
  5212. else
  5213. printk(KERN_DEBUG "SELinux: Starting in permissive mode\n");
  5214. return 0;
  5215. }
  5216. static void delayed_superblock_init(struct super_block *sb, void *unused)
  5217. {
  5218. superblock_doinit(sb, NULL);
  5219. }
  5220. void selinux_complete_init(void)
  5221. {
  5222. printk(KERN_DEBUG "SELinux: Completing initialization.\n");
  5223. /* Set up any superblocks initialized prior to the policy load. */
  5224. printk(KERN_DEBUG "SELinux: Setting up existing superblocks.\n");
  5225. iterate_supers(delayed_superblock_init, NULL);
  5226. }
  5227. /* SELinux requires early initialization in order to label
  5228. all processes and objects when they are created. */
  5229. security_initcall(selinux_init);
  5230. #if defined(CONFIG_NETFILTER)
  5231. static struct nf_hook_ops selinux_ipv4_ops[] = {
  5232. {
  5233. .hook = selinux_ipv4_postroute,
  5234. .owner = THIS_MODULE,
  5235. .pf = PF_INET,
  5236. .hooknum = NF_INET_POST_ROUTING,
  5237. .priority = NF_IP_PRI_SELINUX_LAST,
  5238. },
  5239. {
  5240. .hook = selinux_ipv4_forward,
  5241. .owner = THIS_MODULE,
  5242. .pf = PF_INET,
  5243. .hooknum = NF_INET_FORWARD,
  5244. .priority = NF_IP_PRI_SELINUX_FIRST,
  5245. },
  5246. {
  5247. .hook = selinux_ipv4_output,
  5248. .owner = THIS_MODULE,
  5249. .pf = PF_INET,
  5250. .hooknum = NF_INET_LOCAL_OUT,
  5251. .priority = NF_IP_PRI_SELINUX_FIRST,
  5252. }
  5253. };
  5254. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  5255. static struct nf_hook_ops selinux_ipv6_ops[] = {
  5256. {
  5257. .hook = selinux_ipv6_postroute,
  5258. .owner = THIS_MODULE,
  5259. .pf = PF_INET6,
  5260. .hooknum = NF_INET_POST_ROUTING,
  5261. .priority = NF_IP6_PRI_SELINUX_LAST,
  5262. },
  5263. {
  5264. .hook = selinux_ipv6_forward,
  5265. .owner = THIS_MODULE,
  5266. .pf = PF_INET6,
  5267. .hooknum = NF_INET_FORWARD,
  5268. .priority = NF_IP6_PRI_SELINUX_FIRST,
  5269. }
  5270. };
  5271. #endif /* IPV6 */
  5272. static int __init selinux_nf_ip_init(void)
  5273. {
  5274. int err = 0;
  5275. #ifdef CONFIG_ALWAYS_ENFORCE
  5276. selinux_enabled = 1;
  5277. #endif
  5278. if (!selinux_enabled)
  5279. goto out;
  5280. printk(KERN_DEBUG "SELinux: Registering netfilter hooks\n");
  5281. err = nf_register_hooks(selinux_ipv4_ops, ARRAY_SIZE(selinux_ipv4_ops));
  5282. if (err)
  5283. panic("SELinux: nf_register_hooks for IPv4: error %d\n", err);
  5284. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  5285. err = nf_register_hooks(selinux_ipv6_ops, ARRAY_SIZE(selinux_ipv6_ops));
  5286. if (err)
  5287. panic("SELinux: nf_register_hooks for IPv6: error %d\n", err);
  5288. #endif /* IPV6 */
  5289. out:
  5290. return err;
  5291. }
  5292. __initcall(selinux_nf_ip_init);
  5293. #ifdef CONFIG_SECURITY_SELINUX_DISABLE
  5294. static void selinux_nf_ip_exit(void)
  5295. {
  5296. printk(KERN_DEBUG "SELinux: Unregistering netfilter hooks\n");
  5297. nf_unregister_hooks(selinux_ipv4_ops, ARRAY_SIZE(selinux_ipv4_ops));
  5298. #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
  5299. nf_unregister_hooks(selinux_ipv6_ops, ARRAY_SIZE(selinux_ipv6_ops));
  5300. #endif /* IPV6 */
  5301. }
  5302. #endif
  5303. #else /* CONFIG_NETFILTER */
  5304. #ifdef CONFIG_SECURITY_SELINUX_DISABLE
  5305. #define selinux_nf_ip_exit()
  5306. #endif
  5307. #endif /* CONFIG_NETFILTER */
  5308. #ifdef CONFIG_SECURITY_SELINUX_DISABLE
  5309. static int selinux_disabled;
  5310. int selinux_disable(void)
  5311. {
  5312. if (ss_initialized) {
  5313. /* Not permitted after initial policy load. */
  5314. return -EINVAL;
  5315. }
  5316. if (selinux_disabled) {
  5317. /* Only do this once. */
  5318. return -EINVAL;
  5319. }
  5320. printk(KERN_INFO "SELinux: Disabled at runtime.\n");
  5321. selinux_disabled = 1;
  5322. selinux_enabled = 0;
  5323. reset_security_ops();
  5324. /* Try to destroy the avc node cache */
  5325. avc_disable();
  5326. /* Unregister netfilter hooks. */
  5327. selinux_nf_ip_exit();
  5328. /* Unregister selinuxfs. */
  5329. exit_sel_fs();
  5330. return 0;
  5331. }
  5332. #endif