param_selinux.c 12.2 KB
Newer Older
S
sun_fan 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14
/*
 * Copyright (c) 2021 Huawei Device Co., Ltd.
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 * http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
C
cheng_jinsong 已提交
15
#include <errno.h>
M
Mupceet 已提交
16 17
#include <dlfcn.h>
#include <sys/socket.h>
S
sun_fan 已提交
18

19
#include "init_utils.h"
M
Mupceet 已提交
20
#include "param_manager.h"
S
sun_fan 已提交
21 22
#include "param_security.h"
#include "param_utils.h"
M
Mupceet 已提交
23
#include "param_base.h"
M
Mupceet 已提交
24 25 26
#ifdef PARAM_SUPPORT_SELINUX
#include "selinux_parameter.h"
#endif
S
sun_fan 已提交
27

M
Mupceet 已提交
28 29
#ifdef __aarch64__
#define CHECKER_LIB_NAME "/system/lib64/libparaperm_checker.z.so"
U
unknown 已提交
30
#define CHECKER_UPDATER_LIB_NAME "/lib64/libparaperm_checker.z.so"
M
Mupceet 已提交
31 32
#else
#define CHECKER_LIB_NAME "/system/lib/libparaperm_checker.z.so"
U
unknown 已提交
33
#define CHECKER_UPDATER_LIB_NAME "/lib/libparaperm_checker.z.so"
M
Mupceet 已提交
34
#endif
C
cheng_jinsong 已提交
35
typedef int (*SelinuxSetParamCheck)(const char *paraName, const char *destContext, const SrcInfo *info);
M
Mupceet 已提交
36

A
an_xinwei 已提交
37
static int InitSelinuxOpsForInit(SelinuxSpace *selinuxSpace)
S
sun_fan 已提交
38
{
A
an_xinwei 已提交
39 40 41 42
    if (selinuxSpace->selinuxHandle == NULL) {
        const char *libname = (GetParamWorkSpace()->ops.updaterMode == 1) ? CHECKER_UPDATER_LIB_NAME : CHECKER_LIB_NAME;
        selinuxSpace->selinuxHandle = dlopen(libname, RTLD_LAZY);
        PARAM_CHECK(selinuxSpace->selinuxHandle != NULL,
M
Mupceet 已提交
43
            return 0, "Failed to dlsym selinuxHandle, %s", dlerror());
M
Mupceet 已提交
44
    }
A
an_xinwei 已提交
45 46 47 48
    void *handle = selinuxSpace->selinuxHandle;
    if (selinuxSpace->setParamCheck == NULL) {
        selinuxSpace->setParamCheck = (SelinuxSetParamCheck)dlsym(handle, "SetParamCheck");
        PARAM_CHECK(selinuxSpace->setParamCheck != NULL, return -1, "Failed to dlsym setParamCheck %s", dlerror());
M
Mupceet 已提交
49
    }
A
an_xinwei 已提交
50 51 52
    if (selinuxSpace->getParamList == NULL) {
        selinuxSpace->getParamList = (ParamContextsList *(*)()) dlsym(handle, "GetParamList");
        PARAM_CHECK(selinuxSpace->getParamList != NULL, return -1, "Failed to dlsym getParamList %s", dlerror());
M
Mupceet 已提交
53
    }
A
an_xinwei 已提交
54 55 56
    if (selinuxSpace->getParamLabel == NULL) {
        selinuxSpace->getParamLabel = (const char *(*)(const char *))dlsym(handle, "GetParamLabel");
        PARAM_CHECK(selinuxSpace->getParamLabel != NULL, return -1, "Failed to dlsym getParamLabel %s", dlerror());
M
Mupceet 已提交
57
    }
A
an_xinwei 已提交
58 59 60
    if (selinuxSpace->initParamSelinux == NULL) {
        selinuxSpace->initParamSelinux = (int (*)())dlsym(handle, "InitParamSelinux");
        PARAM_CHECK(selinuxSpace->initParamSelinux != NULL, return -1, "Failed to dlsym initParamSelinux ");
M
Mupceet 已提交
61
    }
A
an_xinwei 已提交
62 63
    if (selinuxSpace->readParamCheck == NULL) {
        selinuxSpace->readParamCheck = (int (*)(const char *))dlsym(handle, "ReadParamCheck");
M
Mupceet 已提交
64
    }
A
an_xinwei 已提交
65 66 67 68 69
    if (selinuxSpace->setSelinuxLogCallback == NULL) {
        selinuxSpace->setSelinuxLogCallback = (void (*)())dlsym(handle, "SetInitSelinuxLog");
    }
    if (selinuxSpace->destroyParamList == NULL) {
        selinuxSpace->destroyParamList =
M
Mupceet 已提交
70
            (void (*)(ParamContextsList **))dlsym(handle, "DestroyParamList");
A
an_xinwei 已提交
71
        PARAM_CHECK(selinuxSpace->destroyParamList != NULL,
M
Mupceet 已提交
72 73
            return -1, "Failed to dlsym destroyParamList %s", dlerror());
    }
A
an_xinwei 已提交
74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93

    // init and open avc log
    int ret = selinuxSpace->initParamSelinux();
    if (selinuxSpace->setSelinuxLogCallback != NULL) {
        selinuxSpace->setSelinuxLogCallback();
    }
    return ret;
}

static int InitLocalSecurityLabel(ParamSecurityLabel *security, int isInit)
{
    PARAM_CHECK(GetParamWorkSpace() != NULL, return -1, "Invalid workspace");
    UNUSED(isInit);
    PARAM_CHECK(security != NULL, return -1, "Invalid security");
    security->cred.pid = getpid();
    security->cred.uid = geteuid();
    security->cred.gid = getegid();
    security->flags[PARAM_SECURITY_SELINUX] = 0;
    PARAM_LOGV("InitLocalSecurityLabel");
#if !(defined STARTUP_INIT_TEST || defined LOCAL_TEST)
C
codex  
chengjinsong 已提交
94
    if ((bool)isInit) {
A
an_xinwei 已提交
95 96 97 98 99 100 101 102 103 104 105
        int ret = InitSelinuxOpsForInit(&GetParamWorkSpace()->selinuxSpace);
        PARAM_CHECK(ret == 0, return -1, "Failed to init selinux ops");
    } else {
        SelinuxSpace *selinuxSpace = &GetParamWorkSpace()->selinuxSpace;
        selinuxSpace->initParamSelinux = InitParamSelinux;
        selinuxSpace->getParamList = GetParamList;
        selinuxSpace->getParamLabel = GetParamLabel;
        selinuxSpace->destroyParamList = DestroyParamList;
        // init
        selinuxSpace->initParamSelinux();
    }
M
Mupceet 已提交
106
#endif
C
cheng_jinsong 已提交
107
    PARAM_LOGI("Load selinux lib success.");
S
sun_fan 已提交
108 109 110 111 112 113 114 115
    return 0;
}

static int FreeLocalSecurityLabel(ParamSecurityLabel *srcLabel)
{
    return 0;
}

M
Mupceet 已提交
116 117
static void SetSelinuxFileCon(const char *name, const char *context)
{
A
an_xinwei 已提交
118 119
    PARAM_CHECK(GetParamWorkSpace() != NULL && GetParamWorkSpace()->ops.setfilecon != NULL,
        return, "Invalid workspace or setfilecon");
M
Mupceet 已提交
120 121 122 123
    static char buffer[FILENAME_LEN_MAX] = {0};
    int len = ParamSprintf(buffer, sizeof(buffer), "%s/%s", PARAM_STORAGE_PATH, context);
    if (len > 0) {
        buffer[len] = '\0';
C
cheng_jinsong 已提交
124
        PARAM_LOGV("setfilecon name %s path: %s %s ", name, context, buffer);
A
an_xinwei 已提交
125
        if (GetParamWorkSpace()->ops.setfilecon(buffer, context) < 0) {
M
Mupceet 已提交
126 127 128 129 130
            PARAM_LOGE("Failed to setfilecon %s ", context);
        }
    }
}

C
cheng_jinsong 已提交
131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169
static uint32_t GetWorkSpaceSize(const char *content)
{
    if (strcmp(content, WORKSPACE_NAME_DEF_SELINUX) == 0) {
        return PARAM_WORKSPACE_MAX;
    }
    char name[PARAM_NAME_LEN_MAX] = {0};
    size_t len = strlen(content);
    int index = 0;
    for (size_t i = strlen("u:object_r:"); i < len; i++) {
        if (*(content + i) == ':') {
            break;
        }
        name[index++] = *(content + i);
    }
    if (index == 0) {
#ifdef STARTUP_INIT_TEST
        return PARAM_WORKSPACE_DEF;
#else
        return PARAM_WORKSPACE_MIN;
#endif
    }
    ParamNode *node = GetParamNode(WORKSPACE_NAME_DAC, name);
    if (node == NULL) {
#ifdef STARTUP_INIT_TEST
        return PARAM_WORKSPACE_DEF;
#else
        return PARAM_WORKSPACE_MIN;
#endif
    }
    int ret = ParamMemcpy(name, sizeof(name) - 1, node->data + node->keyLength + 1, node->valueLength);
    if (ret == 0) {
        name[node->valueLength] = '\0';
        errno = 0;
        uint32_t value = (uint32_t)strtoul(name, NULL, DECIMAL_BASE);
        return (errno != 0) ? PARAM_WORKSPACE_MIN : value;
    }
    return PARAM_WORKSPACE_MIN;
}

170
static int SelinuxGetAllLabel(int readOnly)
S
sun_fan 已提交
171
{
A
an_xinwei 已提交
172 173 174
    SelinuxSpace *selinuxSpace = &GetParamWorkSpace()->selinuxSpace;
    PARAM_CHECK(selinuxSpace->getParamList != NULL, return DAC_RESULT_FORBIDED, "Invalid getParamList");
    ParamContextsList *head = selinuxSpace->getParamList();
M
Mupceet 已提交
175
    ParamContextsList *node = head;
M
Mupceet 已提交
176

M
Mupceet 已提交
177 178
    int count = 0;
    while (node != NULL) {
C
cheng_jinsong 已提交
179
        PARAM_LOGV("SelinuxGetAllLabel name %s content %s", node->info.paraName, node->info.paraContext);
M
Mupceet 已提交
180 181
        if (node->info.paraContext == NULL || node->info.paraName == NULL) {
            node = node->next;
S
sun_fan 已提交
182 183
            continue;
        }
C
cheng_jinsong 已提交
184
        int ret = AddWorkSpace(node->info.paraContext, readOnly, GetWorkSpaceSize(node->info.paraContext));
M
Mupceet 已提交
185 186 187 188 189
        if (ret != 0) {
            PARAM_LOGE("Forbid to add selinux workspace %s %s", node->info.paraName, node->info.paraContext);
            node = node->next;
            continue;
        }
M
Mupceet 已提交
190
        count++;
M
Mupceet 已提交
191 192 193 194
        if (readOnly != 0) {
            node = node->next;
            continue;
        }
M
Mupceet 已提交
195
        // set selinux label
M
Mupceet 已提交
196 197
        SetSelinuxFileCon(node->info.paraName, node->info.paraContext);
        node = node->next;
4
411148299@qq.com 已提交
198
    }
M
Mupceet 已提交
199

C
cheng_jinsong 已提交
200
    int ret = AddWorkSpace(WORKSPACE_NAME_DEF_SELINUX, readOnly, GetWorkSpaceSize(WORKSPACE_NAME_DEF_SELINUX));
M
Mupceet 已提交
201
    PARAM_CHECK(ret == 0, return -1,
M
Mupceet 已提交
202
        "Failed to add selinux workspace %s", WORKSPACE_NAME_DEF_SELINUX);
M
Mupceet 已提交
203 204 205
    if (readOnly == 0) {
        SetSelinuxFileCon(WORKSPACE_NAME_DEF_SELINUX, WORKSPACE_NAME_DEF_SELINUX);
    }
C
fix log  
cheng_jinsong 已提交
206
    PARAM_LOGV("Selinux get all label counts %d.", count);
M
Mupceet 已提交
207
    return 0;
S
sun_fan 已提交
208 209
}

210 211 212 213 214 215
static int SelinuxGetParamSecurityLabel(const char *path)
{
    UNUSED(path);
    return SelinuxGetAllLabel(0);
}

S
sun_fan 已提交
216 217 218 219 220 221 222
static int CheckFilePermission(const ParamSecurityLabel *localLabel, const char *fileName, int flags)
{
    UNUSED(flags);
    PARAM_CHECK(localLabel != NULL && fileName != NULL, return -1, "Invalid param");
    return 0;
}

A
an_xinwei 已提交
223 224 225 226 227 228 229 230 231 232 233
static const char *GetSelinuxContent(const char *name)
{
    SelinuxSpace *selinuxSpace = &GetParamWorkSpace()->selinuxSpace;
    if (selinuxSpace->getParamLabel != NULL) {
        return selinuxSpace->getParamLabel(name);
    } else {
        PARAM_LOGE("Can not init selinux");
        return WORKSPACE_NAME_DEF_SELINUX;
    }
}

C
cheng_jinsong 已提交
234
static int CheckContentPermission(const char *name, const char *label)
235
{
C
cheng_jinsong 已提交
236
    PARAM_CHECK(name != NULL && label != NULL, return DAC_RESULT_FORBIDED, "The label is null");
237
    int ret = DAC_RESULT_FORBIDED;
C
cheng_jinsong 已提交
238 239 240 241 242 243
    char buffer[FILENAME_LEN_MAX] = {0};
    int size = ParamSprintf(buffer, sizeof(buffer), "%s/%s", PARAM_STORAGE_PATH, label);
    PARAM_CHECK(size > 0, return -1, "Failed to format file name %s", label);
    buffer[size] = '\0';
    if (access(buffer, R_OK) == 0) {
        ret = AddWorkSpace(label, 1, PARAM_WORKSPACE_MAX);
M
Mupceet 已提交
244
    }
C
cheng_jinsong 已提交
245 246
    if (ret != 0) {
        PARAM_LOGE("SelinuxReadParamCheck name %s label %s ", name, label);
247 248 249 250 251
        return DAC_RESULT_FORBIDED;
    }
    return DAC_RESULT_PERMISSION;
}

C
cheng_jinsong 已提交
252 253 254 255 256 257 258 259 260
static int SelinuxReadParamCheck(const char *name)
{
    const char *label = GetSelinuxContent(name);
    if (label == NULL) {
        return CheckContentPermission(name, WORKSPACE_NAME_DEF_SELINUX);
    }
    return CheckContentPermission(name, label);
}

M
Mupceet 已提交
261
static int SelinuxCheckParamPermission(const ParamSecurityLabel *srcLabel, const char *name, uint32_t mode)
S
sun_fan 已提交
262
{
A
an_xinwei 已提交
263
    SelinuxSpace *selinuxSpace = &GetParamWorkSpace()->selinuxSpace;
M
Mupceet 已提交
264 265
    int ret = DAC_RESULT_FORBIDED;
    // check
266
    SrcInfo info;
R
renwei 已提交
267 268 269 270
    info.uc.pid = srcLabel->cred.pid;
    info.uc.uid = srcLabel->cred.uid;
    info.uc.gid = srcLabel->cred.gid;
    info.sockFd = srcLabel->sockFd;
M
Mupceet 已提交
271
    if (mode == DAC_WRITE) {
A
an_xinwei 已提交
272
        PARAM_CHECK(selinuxSpace->setParamCheck != NULL, return ret, "Invalid setParamCheck");
M
Mupceet 已提交
273
        const char *context = GetSelinuxContent(name);
R
renwei 已提交
274
        ret = selinuxSpace->setParamCheck(name, context, &info);
M
Mupceet 已提交
275
    } else {
L
laiguizhong 已提交
276
#ifndef STARTUP_INIT_TEST
277
        ret = SelinuxReadParamCheck(name);
L
laiguizhong 已提交
278
#else
A
an_xinwei 已提交
279
        ret = selinuxSpace->readParamCheck(name);
L
laiguizhong 已提交
280
#endif
M
Mupceet 已提交
281 282
    }
    if (ret != 0) {
C
cheng_jinsong 已提交
283 284
        PARAM_LOGW("Selinux check name %s in %s info [%d %d %d] result %d",
            name, GetSelinuxContent(name), info.uc.pid, info.uc.uid, info.uc.gid, ret);
M
Mupceet 已提交
285 286 287
        ret = DAC_RESULT_FORBIDED;
    } else {
        ret = DAC_RESULT_PERMISSION;
M
Mupceet 已提交
288 289
    }
    return ret;
S
sun_fan 已提交
290 291
}

M
Mupceet 已提交
292 293 294 295 296
static int UpdaterCheckParamPermission(const ParamSecurityLabel *srcLabel, const char *name, uint32_t mode)
{
    return DAC_RESULT_PERMISSION;
}

C
cheng_jinsong 已提交
297 298
static int OpenPermissionWorkSpace(const char *path)
{
C
cheng_jinsong 已提交
299
    static int loadLabels = 0;
C
cheng_jinsong 已提交
300
    UNUSED(path);
C
cheng_jinsong 已提交
301 302 303 304 305 306 307
    int ret = 0;
    if (loadLabels == 0) {
        // open workspace by readonly
        ret =  SelinuxGetAllLabel(1);
    }
    loadLabels = 1;
    return ret;
C
cheng_jinsong 已提交
308 309
}

M
Mupceet 已提交
310
INIT_LOCAL_API int RegisterSecuritySelinuxOps(ParamSecurityOps *ops, int isInit)
S
sun_fan 已提交
311
{
A
an_xinwei 已提交
312
    PARAM_CHECK(GetParamWorkSpace() != NULL, return -1, "Invalid workspace");
S
sun_fan 已提交
313
    PARAM_CHECK(ops != NULL, return -1, "Invalid param");
M
Mupceet 已提交
314
    int ret = ParamStrCpy(ops->name, sizeof(ops->name), "selinux");
S
sun_fan 已提交
315 316 317
    ops->securityGetLabel = NULL;
    ops->securityInitLabel = InitLocalSecurityLabel;
    ops->securityCheckFilePermission = CheckFilePermission;
A
an_xinwei 已提交
318
    if (GetParamWorkSpace()->ops.updaterMode == 1) {
M
Mupceet 已提交
319 320 321 322
        ops->securityCheckParamPermission = UpdaterCheckParamPermission;
    } else {
        ops->securityCheckParamPermission = SelinuxCheckParamPermission;
    }
S
sun_fan 已提交
323
    ops->securityFreeLabel = FreeLocalSecurityLabel;
324
    if (isInit != 0) {
M
Mupceet 已提交
325
        ops->securityGetLabel = SelinuxGetParamSecurityLabel;
C
cheng_jinsong 已提交
326 327
    } else {
        ops->securityGetLabel = OpenPermissionWorkSpace;
S
sun_fan 已提交
328
    }
M
Mupceet 已提交
329
    return ret;
S
sun_fan 已提交
330
}