Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
OpenHarmony
Startup Init Lite
提交
08d61990
S
Startup Init Lite
项目概览
OpenHarmony
/
Startup Init Lite
1 年多 前同步成功
通知
3
Star
37
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
S
Startup Init Lite
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
未验证
提交
08d61990
编写于
4月 26, 2023
作者:
O
openharmony_ci
提交者:
Gitee
4月 26, 2023
浏览文件
操作
浏览文件
下载
差异文件
!1909 FIX:Add permission check for control fd
Merge pull request !1909 from cheng_jinsong/master
上级
4f069347
42166e4c
变更
4
隐藏空白更改
内联
并排
Showing
4 changed file
with
39 addition
and
27 deletion
+39
-27
interfaces/innerkits/control_fd/control_fd.h
interfaces/innerkits/control_fd/control_fd.h
+1
-2
interfaces/innerkits/control_fd/control_fd_service.c
interfaces/innerkits/control_fd/control_fd_service.c
+28
-4
services/init/standard/init_control_fd_service.c
services/init/standard/init_control_fd_service.c
+0
-19
services/loopevent/socket/le_socket.c
services/loopevent/socket/le_socket.c
+10
-2
未找到文件。
interfaces/innerkits/control_fd/control_fd.h
浏览文件 @
08d61990
...
@@ -65,7 +65,6 @@ typedef void (* CallbackControlFdProcess)(uint16_t type, const char *serviceCmd,
...
@@ -65,7 +65,6 @@ typedef void (* CallbackControlFdProcess)(uint16_t type, const char *serviceCmd,
typedef
enum
{
typedef
enum
{
ACTION_SANDBOX
=
0
,
ACTION_SANDBOX
=
0
,
ACTION_DUMP
,
ACTION_DUMP
,
ACTION_PARAM_SHELL
,
ACTION_MODULEMGR
,
ACTION_MODULEMGR
,
ACTION_MAX
ACTION_MAX
}
ActionType
;
}
ActionType
;
...
@@ -88,4 +87,4 @@ void CmdServiceProcessDestroyClient(void);
...
@@ -88,4 +87,4 @@ void CmdServiceProcessDestroyClient(void);
#endif
#endif
#endif
#endif
#endif
#endif
\ No newline at end of file
interfaces/innerkits/control_fd/control_fd_service.c
浏览文件 @
08d61990
...
@@ -15,6 +15,8 @@
...
@@ -15,6 +15,8 @@
#include <fcntl.h>
#include <fcntl.h>
#include <unistd.h>
#include <unistd.h>
#include <sys/types.h>
#include <sys/socket.h>
#include "beget_ext.h"
#include "beget_ext.h"
#include "control_fd.h"
#include "control_fd.h"
...
@@ -34,6 +36,22 @@ static void OnClose(const TaskHandle task)
...
@@ -34,6 +36,22 @@ static void OnClose(const TaskHandle task)
OH_ListInit
(
&
agent
->
item
);
OH_ListInit
(
&
agent
->
item
);
}
}
CONTROL_FD_STATIC
int
CheckSocketPermission
(
const
TaskHandle
task
)
{
struct
ucred
uc
=
{
-
1
,
-
1
,
-
1
};
socklen_t
len
=
sizeof
(
uc
);
if
(
getsockopt
(
LE_GetSocketFd
(
task
),
SOL_SOCKET
,
SO_PEERCRED
,
&
uc
,
&
len
)
<
0
)
{
BEGET_LOGE
(
"Failed to get socket option. err = %d"
,
errno
);
return
-
1
;
}
// Only root is permitted to use control fd of init.
if
(
uc
.
uid
!=
0
)
{
// non-root user
errno
=
EPERM
;
return
-
1
;
}
return
0
;
}
CONTROL_FD_STATIC
void
CmdOnRecvMessage
(
const
TaskHandle
task
,
const
uint8_t
*
buffer
,
uint32_t
buffLen
)
CONTROL_FD_STATIC
void
CmdOnRecvMessage
(
const
TaskHandle
task
,
const
uint8_t
*
buffer
,
uint32_t
buffLen
)
{
{
if
(
buffer
==
NULL
)
{
if
(
buffer
==
NULL
)
{
...
@@ -45,17 +63,23 @@ CONTROL_FD_STATIC void CmdOnRecvMessage(const TaskHandle task, const uint8_t *bu
...
@@ -45,17 +63,23 @@ CONTROL_FD_STATIC void CmdOnRecvMessage(const TaskHandle task, const uint8_t *bu
// parse msg to exec
// parse msg to exec
CmdMessage
*
msg
=
(
CmdMessage
*
)
buffer
;
CmdMessage
*
msg
=
(
CmdMessage
*
)
buffer
;
if
((
msg
->
type
>=
ACTION_MAX
)
||
(
msg
->
cmd
[
0
]
==
'\0'
)
||
(
msg
->
ptyName
[
0
]
==
'\0'
))
{
if
((
msg
->
type
>=
ACTION_MAX
)
||
(
msg
->
cmd
[
0
]
==
'\0'
)
||
(
msg
->
ptyName
[
0
]
==
'\0'
))
{
BEGET_LOGE
(
"[control_fd] Received msg is invaild"
);
BEGET_LOGE
(
"[control_fd] Received msg is invalid"
);
return
;
}
if
(
CheckSocketPermission
(
task
)
<
0
)
{
BEGET_LOGE
(
"Check socket permission failed, err = %d"
,
errno
);
return
;
return
;
}
}
#ifndef STARTUP_INIT_TEST
#ifndef STARTUP_INIT_TEST
agent
->
pid
=
fork
();
agent
->
pid
=
fork
();
if
(
agent
->
pid
==
0
)
{
if
(
agent
->
pid
==
0
)
{
OpenConsole
();
OpenConsole
();
char
*
realPath
=
GetRealPath
(
msg
->
ptyName
);
char
*
realPath
=
GetRealPath
(
msg
->
ptyName
);
BEGET_ERROR_CHECK
(
realPath
!=
NULL
,
_exit
(
1
),
"Failed get realpath, err=%d"
,
errno
);
BEGET_ERROR_CHECK
(
realPath
!=
NULL
,
_exit
(
1
),
"Failed get realpath, err=%d"
,
errno
);
char
*
strl
=
strstr
(
realPath
,
"/dev/pts"
);
int
n
=
strncmp
(
realPath
,
"/dev/pts/"
,
strlen
(
"/dev/pts/"
)
);
BEGET_ERROR_CHECK
(
strl
!=
NULL
,
free
(
realPath
);
_exit
(
1
),
"pts path %s is invaild"
,
realPath
);
BEGET_ERROR_CHECK
(
n
==
0
,
free
(
realPath
);
_exit
(
1
),
"pts path %s is invaild"
,
realPath
);
int
fd
=
open
(
realPath
,
O_RDWR
);
int
fd
=
open
(
realPath
,
O_RDWR
);
free
(
realPath
);
free
(
realPath
);
BEGET_ERROR_CHECK
(
fd
>=
0
,
_exit
(
1
),
"Failed open %s, err=%d"
,
msg
->
ptyName
,
errno
);
BEGET_ERROR_CHECK
(
fd
>=
0
,
_exit
(
1
),
"Failed open %s, err=%d"
,
msg
->
ptyName
,
errno
);
...
@@ -68,7 +92,7 @@ CONTROL_FD_STATIC void CmdOnRecvMessage(const TaskHandle task, const uint8_t *bu
...
@@ -68,7 +92,7 @@ CONTROL_FD_STATIC void CmdOnRecvMessage(const TaskHandle task, const uint8_t *bu
}
}
_exit
(
0
);
_exit
(
0
);
}
else
if
(
agent
->
pid
<
0
)
{
}
else
if
(
agent
->
pid
<
0
)
{
BEGET_LOGE
(
"[control_fd] Failed
fork service"
);
BEGET_LOGE
(
"[control_fd] Failed
to fork child process, err = %d"
,
errno
);
}
}
#endif
#endif
return
;
return
;
...
...
services/init/standard/init_control_fd_service.c
浏览文件 @
08d61990
...
@@ -218,22 +218,6 @@ static void ProcessModuleMgrControlFd(uint16_t type, const char *serviceCmd)
...
@@ -218,22 +218,6 @@ static void ProcessModuleMgrControlFd(uint16_t type, const char *serviceCmd)
}
}
}
}
static
void
ProcessParamShellControlFd
(
uint16_t
type
,
const
char
*
serviceCmd
)
{
if
((
type
!=
ACTION_PARAM_SHELL
)
||
(
serviceCmd
==
NULL
))
{
return
;
}
(
void
)
setuid
(
2000
);
// 2000 shell group
(
void
)
setgid
(
2000
);
// 2000 shell group
char
*
args
[]
=
{(
char
*
)
serviceCmd
,
NULL
};
int
ret
=
execv
(
args
[
0
],
args
);
if
(
ret
<
0
)
{
INIT_LOGE
(
"error on exec %d
\n
"
,
errno
);
exit
(
-
1
);
}
exit
(
0
);
}
void
ProcessControlFd
(
uint16_t
type
,
const
char
*
serviceCmd
,
const
void
*
context
)
void
ProcessControlFd
(
uint16_t
type
,
const
char
*
serviceCmd
,
const
void
*
context
)
{
{
if
((
type
>=
ACTION_MAX
)
||
(
serviceCmd
==
NULL
))
{
if
((
type
>=
ACTION_MAX
)
||
(
serviceCmd
==
NULL
))
{
...
@@ -246,9 +230,6 @@ void ProcessControlFd(uint16_t type, const char *serviceCmd, const void *context
...
@@ -246,9 +230,6 @@ void ProcessControlFd(uint16_t type, const char *serviceCmd, const void *context
case
ACTION_DUMP
:
case
ACTION_DUMP
:
ProcessDumpServiceControlFd
(
type
,
serviceCmd
);
ProcessDumpServiceControlFd
(
type
,
serviceCmd
);
break
;
break
;
case
ACTION_PARAM_SHELL
:
ProcessParamShellControlFd
(
type
,
serviceCmd
);
break
;
case
ACTION_MODULEMGR
:
case
ACTION_MODULEMGR
:
ProcessModuleMgrControlFd
(
type
,
serviceCmd
);
ProcessModuleMgrControlFd
(
type
,
serviceCmd
);
break
;
break
;
...
...
services/loopevent/socket/le_socket.c
浏览文件 @
08d61990
...
@@ -63,8 +63,12 @@ static int CreatePipeSocket_(const char *server)
...
@@ -63,8 +63,12 @@ static int CreatePipeSocket_(const char *server)
LE_CHECK
(
fd
>
0
,
return
fd
,
"Failed to create socket"
);
LE_CHECK
(
fd
>
0
,
return
fd
,
"Failed to create socket"
);
SetNoBlock
(
fd
);
SetNoBlock
(
fd
);
int
on
=
1
;
int
ret
=
setsockopt
(
fd
,
SOL_SOCKET
,
SO_PASSCRED
,
&
on
,
sizeof
(
on
));
LE_CHECK
(
ret
==
0
,
return
ret
,
"Failed to set socket option"
);
struct
sockaddr_un
serverAddr
;
struct
sockaddr_un
serverAddr
;
int
ret
=
memset_s
(
&
serverAddr
,
sizeof
(
serverAddr
),
0
,
sizeof
(
serverAddr
));
ret
=
memset_s
(
&
serverAddr
,
sizeof
(
serverAddr
),
0
,
sizeof
(
serverAddr
));
LE_CHECK
(
ret
==
0
,
close
(
fd
);
LE_CHECK
(
ret
==
0
,
close
(
fd
);
return
ret
,
"Failed to memset_s serverAddr"
);
return
ret
,
"Failed to memset_s serverAddr"
);
serverAddr
.
sun_family
=
AF_UNIX
;
serverAddr
.
sun_family
=
AF_UNIX
;
...
@@ -118,9 +122,13 @@ static int CreateTcpSocket_(const char *server)
...
@@ -118,9 +122,13 @@ static int CreateTcpSocket_(const char *server)
LE_CHECK
(
fd
>
0
,
return
fd
,
"Failed to create socket"
);
LE_CHECK
(
fd
>
0
,
return
fd
,
"Failed to create socket"
);
SetNoBlock
(
fd
);
SetNoBlock
(
fd
);
int
on
=
1
;
int
ret
=
setsockopt
(
fd
,
SOL_SOCKET
,
SO_PASSCRED
,
&
on
,
sizeof
(
on
));
LE_CHECK
(
ret
==
0
,
return
ret
,
"Failed to set socket option"
);
struct
sockaddr_in
serverAddr
;
struct
sockaddr_in
serverAddr
;
GetSockaddrFromServer_
(
server
,
&
serverAddr
);
GetSockaddrFromServer_
(
server
,
&
serverAddr
);
int
ret
=
connect
(
fd
,
(
struct
sockaddr
*
)
&
serverAddr
,
sizeof
(
serverAddr
));
ret
=
connect
(
fd
,
(
struct
sockaddr
*
)
&
serverAddr
,
sizeof
(
serverAddr
));
LE_CHECK
(
ret
>=
0
,
close
(
fd
);
LE_CHECK
(
ret
>=
0
,
close
(
fd
);
return
ret
,
"Failed to connect socket errno:%d"
,
errno
);
return
ret
,
"Failed to connect socket errno:%d"
,
errno
);
return
fd
;
return
fd
;
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录