1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * Security-Enhanced Linux (SELinux) security module 4 * 5 * This file contains the SELinux hook function implementations. 6 * 7 * Authors: Stephen Smalley, <stephen.smalley.work@gmail.com> 8 * Chris Vance, <cvance@nai.com> 9 * Wayne Salamon, <wsalamon@nai.com> 10 * James Morris <jmorris@redhat.com> 11 * 12 * Copyright (C) 2001,2002 Networks Associates Technology, Inc. 13 * Copyright (C) 2003-2008 Red Hat, Inc., James Morris <jmorris@redhat.com> 14 * Eric Paris <eparis@redhat.com> 15 * Copyright (C) 2004-2005 Trusted Computer Solutions, Inc. 16 * <dgoeddel@trustedcs.com> 17 * Copyright (C) 2006, 2007, 2009 Hewlett-Packard Development Company, L.P. 18 * Paul Moore <paul@paul-moore.com> 19 * Copyright (C) 2007 Hitachi Software Engineering Co., Ltd. 20 * Yuichi Nakamura <ynakam@hitachisoft.jp> 21 * Copyright (C) 2016 Mellanox Technologies 22 */ 23 24 #include <linux/init.h> 25 #include <linux/kd.h> 26 #include <linux/kernel.h> 27 #include <linux/kernel_read_file.h> 28 #include <linux/errno.h> 29 #include <linux/sched/signal.h> 30 #include <linux/sched/task.h> 31 #include <linux/lsm_hooks.h> 32 #include <linux/xattr.h> 33 #include <linux/capability.h> 34 #include <linux/unistd.h> 35 #include <linux/mm.h> 36 #include <linux/mman.h> 37 #include <linux/slab.h> 38 #include <linux/pagemap.h> 39 #include <linux/proc_fs.h> 40 #include <linux/swap.h> 41 #include <linux/spinlock.h> 42 #include <linux/syscalls.h> 43 #include <linux/dcache.h> 44 #include <linux/file.h> 45 #include <linux/fdtable.h> 46 #include <linux/namei.h> 47 #include <linux/mount.h> 48 #include <linux/fs_context.h> 49 #include <linux/fs_parser.h> 50 #include <linux/netfilter_ipv4.h> 51 #include <linux/netfilter_ipv6.h> 52 #include <linux/tty.h> 53 #include <net/icmp.h> 54 #include <net/ip.h> /* for local_port_range[] */ 55 #include <net/tcp.h> /* struct or_callable used in sock_rcv_skb */ 56 #include <net/inet_connection_sock.h> 57 #include <net/net_namespace.h> 58 #include <net/netlabel.h> 59 #include <linux/uaccess.h> 60 #include <asm/ioctls.h> 61 #include <linux/atomic.h> 62 #include <linux/bitops.h> 63 #include <linux/interrupt.h> 64 #include <linux/netdevice.h> /* for network interface checks */ 65 #include <net/netlink.h> 66 #include <linux/tcp.h> 67 #include <linux/udp.h> 68 #include <linux/sctp.h> 69 #include <net/sctp/structs.h> 70 #include <linux/quota.h> 71 #include <linux/un.h> /* for Unix socket types */ 72 #include <net/af_unix.h> /* for Unix socket types */ 73 #include <linux/parser.h> 74 #include <linux/nfs_mount.h> 75 #include <net/ipv6.h> 76 #include <linux/hugetlb.h> 77 #include <linux/personality.h> 78 #include <linux/audit.h> 79 #include <linux/string.h> 80 #include <linux/mutex.h> 81 #include <linux/posix-timers.h> 82 #include <linux/syslog.h> 83 #include <linux/user_namespace.h> 84 #include <linux/export.h> 85 #include <linux/msg.h> 86 #include <linux/shm.h> 87 #include <uapi/linux/shm.h> 88 #include <linux/bpf.h> 89 #include <linux/kernfs.h> 90 #include <linux/stringhash.h> /* for hashlen_string() */ 91 #include <uapi/linux/mount.h> 92 #include <linux/fsnotify.h> 93 #include <linux/fanotify.h> 94 #include <linux/io_uring/cmd.h> 95 #include <uapi/linux/lsm.h> 96 #include <linux/memfd.h> 97 #include <uapi/linux/inet_diag.h> 98 99 #include "initcalls.h" 100 #include "avc.h" 101 #include "objsec.h" 102 #include "netif.h" 103 #include "netnode.h" 104 #include "netport.h" 105 #include "ibpkey.h" 106 #include "xfrm.h" 107 #include "netlabel.h" 108 #include "audit.h" 109 #include "avc_ss.h" 110 #include "ima.h" 111 112 #define SELINUX_INODE_INIT_XATTRS 1 113 114 struct selinux_state selinux_state; 115 116 /* SECMARK reference count */ 117 static atomic_t selinux_secmark_refcount = ATOMIC_INIT(0); 118 119 #ifdef CONFIG_SECURITY_SELINUX_DEVELOP 120 static int selinux_enforcing_boot __initdata; 121 122 static int __init enforcing_setup(char *str) 123 { 124 unsigned long enforcing; 125 if (!kstrtoul(str, 0, &enforcing)) 126 selinux_enforcing_boot = enforcing ? 1 : 0; 127 return 1; 128 } 129 __setup("enforcing=", enforcing_setup); 130 #else 131 #define selinux_enforcing_boot 1 132 #endif 133 134 int selinux_enabled_boot __initdata = 1; 135 #ifdef CONFIG_SECURITY_SELINUX_BOOTPARAM 136 static int __init selinux_enabled_setup(char *str) 137 { 138 unsigned long enabled; 139 if (!kstrtoul(str, 0, &enabled)) 140 selinux_enabled_boot = enabled ? 1 : 0; 141 return 1; 142 } 143 __setup("selinux=", selinux_enabled_setup); 144 #endif 145 146 static int __init checkreqprot_setup(char *str) 147 { 148 unsigned long checkreqprot; 149 150 if (!kstrtoul(str, 0, &checkreqprot)) { 151 if (checkreqprot) 152 pr_err("SELinux: checkreqprot set to 1 via kernel parameter. This is no longer supported.\n"); 153 } 154 return 1; 155 } 156 __setup("checkreqprot=", checkreqprot_setup); 157 158 /** 159 * selinux_secmark_enabled - Check to see if SECMARK is currently enabled 160 * 161 * Description: 162 * This function checks the SECMARK reference counter to see if any SECMARK 163 * targets are currently configured, if the reference counter is greater than 164 * zero SECMARK is considered to be enabled. Returns true (1) if SECMARK is 165 * enabled, false (0) if SECMARK is disabled. If the always_check_network 166 * policy capability is enabled, SECMARK is always considered enabled. 167 * 168 */ 169 static int selinux_secmark_enabled(void) 170 { 171 return (selinux_policycap_alwaysnetwork() || 172 atomic_read(&selinux_secmark_refcount)); 173 } 174 175 /** 176 * selinux_peerlbl_enabled - Check to see if peer labeling is currently enabled 177 * 178 * Description: 179 * This function checks if NetLabel or labeled IPSEC is enabled. Returns true 180 * (1) if any are enabled or false (0) if neither are enabled. If the 181 * always_check_network policy capability is enabled, peer labeling 182 * is always considered enabled. 183 * 184 */ 185 static int selinux_peerlbl_enabled(void) 186 { 187 return (selinux_policycap_alwaysnetwork() || 188 netlbl_enabled() || selinux_xfrm_enabled()); 189 } 190 191 static int selinux_netcache_avc_callback(u32 event) 192 { 193 if (event == AVC_CALLBACK_RESET) { 194 sel_netif_flush(); 195 sel_netnode_flush(); 196 sel_netport_flush(); 197 synchronize_net(); 198 } 199 return 0; 200 } 201 202 static int selinux_lsm_notifier_avc_callback(u32 event) 203 { 204 if (event == AVC_CALLBACK_RESET) { 205 sel_ib_pkey_flush(); 206 call_blocking_lsm_notifier(LSM_POLICY_CHANGE, NULL); 207 } 208 209 return 0; 210 } 211 212 /* 213 * initialise the security for the init task 214 */ 215 static void cred_init_security(void) 216 { 217 struct cred_security_struct *crsec; 218 219 /* NOTE: the lsm framework zeros out the buffer on allocation */ 220 221 crsec = selinux_cred(unrcu_pointer(current->real_cred)); 222 crsec->osid = crsec->sid = SECINITSID_KERNEL; 223 } 224 225 /* 226 * get the security ID of a set of credentials 227 */ 228 static inline u32 cred_sid(const struct cred *cred) 229 { 230 const struct cred_security_struct *crsec; 231 232 crsec = selinux_cred(cred); 233 return crsec->sid; 234 } 235 236 static void __ad_net_init(struct common_audit_data *ad, 237 struct lsm_network_audit *net, 238 int ifindex, struct sock *sk, u16 family) 239 { 240 ad->type = LSM_AUDIT_DATA_NET; 241 ad->u.net = net; 242 net->netif = ifindex; 243 net->sk = sk; 244 net->family = family; 245 } 246 247 static void ad_net_init_from_sk(struct common_audit_data *ad, 248 struct lsm_network_audit *net, 249 struct sock *sk) 250 { 251 __ad_net_init(ad, net, 0, sk, 0); 252 } 253 254 static void ad_net_init_from_iif(struct common_audit_data *ad, 255 struct lsm_network_audit *net, 256 int ifindex, u16 family) 257 { 258 __ad_net_init(ad, net, ifindex, NULL, family); 259 } 260 261 /* 262 * get the objective security ID of a task 263 */ 264 static inline u32 task_sid_obj(const struct task_struct *task) 265 { 266 u32 sid; 267 268 rcu_read_lock(); 269 sid = cred_sid(__task_cred(task)); 270 rcu_read_unlock(); 271 return sid; 272 } 273 274 static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry); 275 276 /* 277 * Try reloading inode security labels that have been marked as invalid. The 278 * @may_sleep parameter indicates when sleeping and thus reloading labels is 279 * allowed; when set to false, returns -ECHILD when the label is 280 * invalid. The @dentry parameter should be set to a dentry of the inode. 281 */ 282 static int __inode_security_revalidate(struct inode *inode, 283 struct dentry *dentry, 284 bool may_sleep) 285 { 286 if (!selinux_initialized()) 287 return 0; 288 289 if (may_sleep) 290 might_sleep(); 291 else 292 return -ECHILD; 293 294 /* 295 * Check to ensure that an inode's SELinux state is valid and try 296 * reloading the inode security label if necessary. This will fail if 297 * @dentry is NULL and no dentry for this inode can be found; in that 298 * case, continue using the old label. 299 */ 300 inode_doinit_with_dentry(inode, dentry); 301 return 0; 302 } 303 304 static struct inode_security_struct *inode_security_novalidate(struct inode *inode) 305 { 306 return selinux_inode(inode); 307 } 308 309 static inline struct inode_security_struct *inode_security_rcu(struct inode *inode, 310 bool rcu) 311 { 312 int rc; 313 struct inode_security_struct *isec = selinux_inode(inode); 314 315 /* check below is racy, but revalidate will recheck with lock held */ 316 if (data_race(likely(isec->initialized == LABEL_INITIALIZED))) 317 return isec; 318 rc = __inode_security_revalidate(inode, NULL, !rcu); 319 if (rc) 320 return ERR_PTR(rc); 321 return isec; 322 } 323 324 /* 325 * Get the security label of an inode. 326 */ 327 static inline struct inode_security_struct *inode_security(struct inode *inode) 328 { 329 struct inode_security_struct *isec = selinux_inode(inode); 330 331 /* check below is racy, but revalidate will recheck with lock held */ 332 if (data_race(likely(isec->initialized == LABEL_INITIALIZED))) 333 return isec; 334 __inode_security_revalidate(inode, NULL, true); 335 return isec; 336 } 337 338 static inline struct inode_security_struct *backing_inode_security_novalidate(struct dentry *dentry) 339 { 340 return selinux_inode(d_backing_inode(dentry)); 341 } 342 343 /* 344 * Get the security label of a dentry's backing inode. 345 */ 346 static inline struct inode_security_struct *backing_inode_security(struct dentry *dentry) 347 { 348 struct inode *inode = d_backing_inode(dentry); 349 struct inode_security_struct *isec = selinux_inode(inode); 350 351 /* check below is racy, but revalidate will recheck with lock held */ 352 if (data_race(likely(isec->initialized == LABEL_INITIALIZED))) 353 return isec; 354 __inode_security_revalidate(inode, dentry, true); 355 return isec; 356 } 357 358 static void inode_free_security(struct inode *inode) 359 { 360 struct inode_security_struct *isec = selinux_inode(inode); 361 struct superblock_security_struct *sbsec; 362 363 if (!isec) 364 return; 365 sbsec = selinux_superblock(inode->i_sb); 366 /* 367 * As not all inode security structures are in a list, we check for 368 * empty list outside of the lock to make sure that we won't waste 369 * time taking a lock doing nothing. 370 * 371 * The list_del_init() function can be safely called more than once. 372 * It should not be possible for this function to be called with 373 * concurrent list_add(), but for better safety against future changes 374 * in the code, we use list_empty_careful() here. 375 */ 376 if (!list_empty_careful(&isec->list)) { 377 spin_lock(&sbsec->isec_lock); 378 list_del_init(&isec->list); 379 spin_unlock(&sbsec->isec_lock); 380 } 381 } 382 383 struct selinux_mnt_opts { 384 u32 fscontext_sid; 385 u32 context_sid; 386 u32 rootcontext_sid; 387 u32 defcontext_sid; 388 }; 389 390 static void selinux_free_mnt_opts(void *mnt_opts) 391 { 392 kfree(mnt_opts); 393 } 394 395 enum { 396 Opt_error = -1, 397 Opt_context = 0, 398 Opt_defcontext = 1, 399 Opt_fscontext = 2, 400 Opt_rootcontext = 3, 401 Opt_seclabel = 4, 402 }; 403 404 #define A(s, has_arg) {#s, sizeof(#s) - 1, Opt_##s, has_arg} 405 static const struct { 406 const char *name; 407 int len; 408 int opt; 409 bool has_arg; 410 } tokens[] = { 411 A(context, true), 412 A(fscontext, true), 413 A(defcontext, true), 414 A(rootcontext, true), 415 A(seclabel, false), 416 }; 417 #undef A 418 419 static int match_opt_prefix(char *s, int l, char **arg) 420 { 421 unsigned int i; 422 423 for (i = 0; i < ARRAY_SIZE(tokens); i++) { 424 size_t len = tokens[i].len; 425 if (len > l || memcmp(s, tokens[i].name, len)) 426 continue; 427 if (tokens[i].has_arg) { 428 if (len == l || s[len] != '=') 429 continue; 430 *arg = s + len + 1; 431 } else if (len != l) 432 continue; 433 return tokens[i].opt; 434 } 435 return Opt_error; 436 } 437 438 #define SEL_MOUNT_FAIL_MSG "SELinux: duplicate or incompatible mount options\n" 439 440 static int may_context_mount_sb_relabel(u32 sid, 441 struct superblock_security_struct *sbsec, 442 const struct cred *cred) 443 { 444 const struct cred_security_struct *crsec = selinux_cred(cred); 445 int rc; 446 447 rc = avc_has_perm(crsec->sid, sbsec->sid, SECCLASS_FILESYSTEM, 448 FILESYSTEM__RELABELFROM, NULL); 449 if (rc) 450 return rc; 451 452 rc = avc_has_perm(crsec->sid, sid, SECCLASS_FILESYSTEM, 453 FILESYSTEM__RELABELTO, NULL); 454 return rc; 455 } 456 457 static int may_context_mount_inode_relabel(u32 sid, 458 struct superblock_security_struct *sbsec, 459 const struct cred *cred) 460 { 461 const struct cred_security_struct *crsec = selinux_cred(cred); 462 int rc; 463 rc = avc_has_perm(crsec->sid, sbsec->sid, SECCLASS_FILESYSTEM, 464 FILESYSTEM__RELABELFROM, NULL); 465 if (rc) 466 return rc; 467 468 rc = avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM, 469 FILESYSTEM__ASSOCIATE, NULL); 470 return rc; 471 } 472 473 static int selinux_is_genfs_special_handling(struct super_block *sb) 474 { 475 /* Special handling. Genfs but also in-core setxattr handler */ 476 return !strcmp(sb->s_type->name, "sysfs") || 477 !strcmp(sb->s_type->name, "pstore") || 478 !strcmp(sb->s_type->name, "debugfs") || 479 !strcmp(sb->s_type->name, "tracefs") || 480 !strcmp(sb->s_type->name, "rootfs") || 481 (selinux_policycap_cgroupseclabel() && 482 (!strcmp(sb->s_type->name, "cgroup") || 483 !strcmp(sb->s_type->name, "cgroup2"))) || 484 (selinux_policycap_functionfs_seclabel() && 485 !strcmp(sb->s_type->name, "functionfs")); 486 } 487 488 static int selinux_is_sblabel_mnt(struct super_block *sb) 489 { 490 struct superblock_security_struct *sbsec = selinux_superblock(sb); 491 492 /* 493 * IMPORTANT: Double-check logic in this function when adding a new 494 * SECURITY_FS_USE_* definition! 495 */ 496 BUILD_BUG_ON(SECURITY_FS_USE_MAX != 7); 497 498 switch (sbsec->behavior) { 499 case SECURITY_FS_USE_XATTR: 500 case SECURITY_FS_USE_TRANS: 501 case SECURITY_FS_USE_TASK: 502 case SECURITY_FS_USE_NATIVE: 503 return 1; 504 505 case SECURITY_FS_USE_GENFS: 506 return selinux_is_genfs_special_handling(sb); 507 508 /* Never allow relabeling on context mounts */ 509 case SECURITY_FS_USE_MNTPOINT: 510 case SECURITY_FS_USE_NONE: 511 default: 512 return 0; 513 } 514 } 515 516 static int sb_check_xattr_support(struct super_block *sb) 517 { 518 struct superblock_security_struct *sbsec = selinux_superblock(sb); 519 struct dentry *root = sb->s_root; 520 struct inode *root_inode = d_backing_inode(root); 521 u32 sid; 522 int rc; 523 524 /* 525 * Make sure that the xattr handler exists and that no 526 * error other than -ENODATA is returned by getxattr on 527 * the root directory. -ENODATA is ok, as this may be 528 * the first boot of the SELinux kernel before we have 529 * assigned xattr values to the filesystem. 530 */ 531 if (!(root_inode->i_opflags & IOP_XATTR)) { 532 pr_warn("SELinux: (dev %s, type %s) has no xattr support\n", 533 sb->s_id, sb->s_type->name); 534 goto fallback; 535 } 536 537 rc = __vfs_getxattr(root, root_inode, XATTR_NAME_SELINUX, NULL, 0); 538 if (rc < 0 && rc != -ENODATA) { 539 if (rc == -EOPNOTSUPP) { 540 pr_warn("SELinux: (dev %s, type %s) has no security xattr handler\n", 541 sb->s_id, sb->s_type->name); 542 goto fallback; 543 } else { 544 pr_warn("SELinux: (dev %s, type %s) getxattr errno %d\n", 545 sb->s_id, sb->s_type->name, -rc); 546 return rc; 547 } 548 } 549 return 0; 550 551 fallback: 552 /* No xattr support - try to fallback to genfs if possible. */ 553 rc = security_genfs_sid(sb->s_type->name, "/", 554 SECCLASS_DIR, &sid); 555 if (rc) 556 return -EOPNOTSUPP; 557 558 pr_warn("SELinux: (dev %s, type %s) falling back to genfs\n", 559 sb->s_id, sb->s_type->name); 560 sbsec->behavior = SECURITY_FS_USE_GENFS; 561 sbsec->sid = sid; 562 return 0; 563 } 564 565 static int sb_finish_set_opts(struct super_block *sb) 566 { 567 struct superblock_security_struct *sbsec = selinux_superblock(sb); 568 struct dentry *root = sb->s_root; 569 struct inode *root_inode = d_backing_inode(root); 570 int rc = 0; 571 572 if (sbsec->behavior == SECURITY_FS_USE_XATTR) { 573 rc = sb_check_xattr_support(sb); 574 if (rc) 575 return rc; 576 } 577 578 sbsec->flags |= SE_SBINITIALIZED; 579 580 /* 581 * Explicitly set or clear SBLABEL_MNT. It's not sufficient to simply 582 * leave the flag untouched because sb_clone_mnt_opts might be handing 583 * us a superblock that needs the flag to be cleared. 584 */ 585 if (selinux_is_sblabel_mnt(sb)) 586 sbsec->flags |= SBLABEL_MNT; 587 else 588 sbsec->flags &= ~SBLABEL_MNT; 589 590 /* Initialize the root inode. */ 591 rc = inode_doinit_with_dentry(root_inode, root); 592 593 /* Initialize any other inodes associated with the superblock, e.g. 594 inodes created prior to initial policy load or inodes created 595 during get_sb by a pseudo filesystem that directly 596 populates itself. */ 597 spin_lock(&sbsec->isec_lock); 598 while (!list_empty(&sbsec->isec_head)) { 599 struct inode_security_struct *isec = 600 list_first_entry(&sbsec->isec_head, 601 struct inode_security_struct, list); 602 struct inode *inode = isec->inode; 603 list_del_init(&isec->list); 604 spin_unlock(&sbsec->isec_lock); 605 inode = igrab(inode); 606 if (inode) { 607 if (!IS_PRIVATE(inode)) 608 inode_doinit_with_dentry(inode, NULL); 609 iput(inode); 610 } 611 spin_lock(&sbsec->isec_lock); 612 } 613 spin_unlock(&sbsec->isec_lock); 614 return rc; 615 } 616 617 static int bad_option(struct superblock_security_struct *sbsec, char flag, 618 u32 old_sid, u32 new_sid) 619 { 620 char mnt_flags = sbsec->flags & SE_MNTMASK; 621 622 /* check if the old mount command had the same options */ 623 if (sbsec->flags & SE_SBINITIALIZED) 624 if (!(sbsec->flags & flag) || 625 (old_sid != new_sid)) 626 return 1; 627 628 /* check if we were passed the same options twice, 629 * aka someone passed context=a,context=b 630 */ 631 if (!(sbsec->flags & SE_SBINITIALIZED)) 632 if (mnt_flags & flag) 633 return 1; 634 return 0; 635 } 636 637 /* 638 * Allow filesystems with binary mount data to explicitly set mount point 639 * labeling information. 640 */ 641 static int selinux_set_mnt_opts(struct super_block *sb, 642 void *mnt_opts, 643 unsigned long kern_flags, 644 unsigned long *set_kern_flags) 645 { 646 const struct cred *cred = current_cred(); 647 struct superblock_security_struct *sbsec = selinux_superblock(sb); 648 struct dentry *root = sb->s_root; 649 struct selinux_mnt_opts *opts = mnt_opts; 650 struct inode_security_struct *root_isec; 651 u32 fscontext_sid = 0, context_sid = 0, rootcontext_sid = 0; 652 u32 defcontext_sid = 0; 653 int rc = 0; 654 655 /* 656 * Specifying internal flags without providing a place to 657 * place the results is not allowed 658 */ 659 if (kern_flags && !set_kern_flags) 660 return -EINVAL; 661 662 mutex_lock(&sbsec->lock); 663 664 if (!selinux_initialized()) { 665 if (!opts) { 666 /* Defer initialization until selinux_complete_init, 667 after the initial policy is loaded and the security 668 server is ready to handle calls. */ 669 if (kern_flags & SECURITY_LSM_NATIVE_LABELS) { 670 sbsec->flags |= SE_SBNATIVE; 671 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 672 } 673 goto out; 674 } 675 rc = -EINVAL; 676 pr_warn("SELinux: Unable to set superblock options " 677 "before the security server is initialized\n"); 678 goto out; 679 } 680 681 /* 682 * Binary mount data FS will come through this function twice. Once 683 * from an explicit call and once from the generic calls from the vfs. 684 * Since the generic VFS calls will not contain any security mount data 685 * we need to skip the double mount verification. 686 * 687 * This does open a hole in which we will not notice if the first 688 * mount using this sb set explicit options and a second mount using 689 * this sb does not set any security options. (The first options 690 * will be used for both mounts) 691 */ 692 if ((sbsec->flags & SE_SBINITIALIZED) && (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA) 693 && !opts) { 694 if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) && 695 sbsec->behavior == SECURITY_FS_USE_NATIVE) 696 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 697 goto out; 698 } 699 700 root_isec = backing_inode_security_novalidate(root); 701 702 /* 703 * parse the mount options, check if they are valid sids. 704 * also check if someone is trying to mount the same sb more 705 * than once with different security options. 706 */ 707 if (opts) { 708 if (opts->fscontext_sid) { 709 fscontext_sid = opts->fscontext_sid; 710 if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, 711 fscontext_sid)) 712 goto out_double_mount; 713 sbsec->flags |= FSCONTEXT_MNT; 714 } 715 if (opts->context_sid) { 716 context_sid = opts->context_sid; 717 if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, 718 context_sid)) 719 goto out_double_mount; 720 sbsec->flags |= CONTEXT_MNT; 721 } 722 if (opts->rootcontext_sid) { 723 rootcontext_sid = opts->rootcontext_sid; 724 if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, 725 rootcontext_sid)) 726 goto out_double_mount; 727 sbsec->flags |= ROOTCONTEXT_MNT; 728 } 729 if (opts->defcontext_sid) { 730 defcontext_sid = opts->defcontext_sid; 731 if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, 732 defcontext_sid)) 733 goto out_double_mount; 734 sbsec->flags |= DEFCONTEXT_MNT; 735 } 736 } 737 738 if (sbsec->flags & SE_SBINITIALIZED) { 739 /* previously mounted with options, but not on this attempt? */ 740 if ((sbsec->flags & SE_MNTMASK) && !opts) 741 goto out_double_mount; 742 if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) && 743 sbsec->behavior == SECURITY_FS_USE_NATIVE) 744 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 745 rc = 0; 746 goto out; 747 } 748 749 sbsec->creator_sid = current_sid(); 750 751 if (strcmp(sb->s_type->name, "proc") == 0) 752 sbsec->flags |= SE_SBPROC | SE_SBGENFS; 753 754 if (!strcmp(sb->s_type->name, "debugfs") || 755 !strcmp(sb->s_type->name, "tracefs") || 756 !strcmp(sb->s_type->name, "binder") || 757 !strcmp(sb->s_type->name, "bpf") || 758 !strcmp(sb->s_type->name, "pstore") || 759 !strcmp(sb->s_type->name, "securityfs") || 760 (selinux_policycap_functionfs_seclabel() && 761 !strcmp(sb->s_type->name, "functionfs"))) 762 sbsec->flags |= SE_SBGENFS; 763 764 if (!strcmp(sb->s_type->name, "sysfs") || 765 !strcmp(sb->s_type->name, "cgroup") || 766 !strcmp(sb->s_type->name, "cgroup2")) 767 sbsec->flags |= SE_SBGENFS | SE_SBGENFS_XATTR; 768 769 if (!sbsec->behavior) { 770 /* 771 * Determine the labeling behavior to use for this 772 * filesystem type. 773 */ 774 rc = security_fs_use(sb); 775 if (rc) { 776 pr_warn("%s: security_fs_use(%s) returned %d\n", 777 __func__, sb->s_type->name, rc); 778 goto out; 779 } 780 } 781 782 /* 783 * If this is a user namespace mount and the filesystem type is not 784 * explicitly whitelisted, then no contexts are allowed on the command 785 * line and security labels must be ignored. 786 */ 787 if (sb->s_user_ns != &init_user_ns && 788 strcmp(sb->s_type->name, "tmpfs") && 789 strcmp(sb->s_type->name, "ramfs") && 790 strcmp(sb->s_type->name, "devpts") && 791 strcmp(sb->s_type->name, "overlay")) { 792 if (context_sid || fscontext_sid || rootcontext_sid || 793 defcontext_sid) { 794 rc = -EACCES; 795 goto out; 796 } 797 if (sbsec->behavior == SECURITY_FS_USE_XATTR) { 798 sbsec->behavior = SECURITY_FS_USE_MNTPOINT; 799 rc = security_transition_sid(current_sid(), 800 current_sid(), 801 SECCLASS_FILE, NULL, 802 &sbsec->mntpoint_sid); 803 if (rc) 804 goto out; 805 } 806 goto out_set_opts; 807 } 808 809 /* sets the context of the superblock for the fs being mounted. */ 810 if (fscontext_sid) { 811 rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred); 812 if (rc) 813 goto out; 814 815 sbsec->sid = fscontext_sid; 816 } 817 818 /* 819 * Switch to using mount point labeling behavior. 820 * sets the label used on all file below the mountpoint, and will set 821 * the superblock context if not already set. 822 */ 823 if (sbsec->flags & SE_SBNATIVE) { 824 /* 825 * This means we are initializing a superblock that has been 826 * mounted before the SELinux was initialized and the 827 * filesystem requested native labeling. We had already 828 * returned SECURITY_LSM_NATIVE_LABELS in *set_kern_flags 829 * in the original mount attempt, so now we just need to set 830 * the SECURITY_FS_USE_NATIVE behavior. 831 */ 832 sbsec->behavior = SECURITY_FS_USE_NATIVE; 833 } else if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !context_sid) { 834 sbsec->behavior = SECURITY_FS_USE_NATIVE; 835 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 836 } 837 838 if (context_sid) { 839 if (!fscontext_sid) { 840 rc = may_context_mount_sb_relabel(context_sid, sbsec, 841 cred); 842 if (rc) 843 goto out; 844 sbsec->sid = context_sid; 845 } else { 846 rc = may_context_mount_inode_relabel(context_sid, sbsec, 847 cred); 848 if (rc) 849 goto out; 850 } 851 if (!rootcontext_sid) 852 rootcontext_sid = context_sid; 853 854 sbsec->mntpoint_sid = context_sid; 855 sbsec->behavior = SECURITY_FS_USE_MNTPOINT; 856 } 857 858 if (rootcontext_sid) { 859 rc = may_context_mount_inode_relabel(rootcontext_sid, sbsec, 860 cred); 861 if (rc) 862 goto out; 863 864 root_isec->sid = rootcontext_sid; 865 root_isec->initialized = LABEL_INITIALIZED; 866 } 867 868 if (defcontext_sid) { 869 if (sbsec->behavior != SECURITY_FS_USE_XATTR && 870 sbsec->behavior != SECURITY_FS_USE_NATIVE) { 871 rc = -EINVAL; 872 pr_warn("SELinux: defcontext option is " 873 "invalid for this filesystem type\n"); 874 goto out; 875 } 876 877 if (defcontext_sid != sbsec->def_sid) { 878 rc = may_context_mount_inode_relabel(defcontext_sid, 879 sbsec, cred); 880 if (rc) 881 goto out; 882 } 883 884 sbsec->def_sid = defcontext_sid; 885 } 886 887 out_set_opts: 888 rc = sb_finish_set_opts(sb); 889 out: 890 mutex_unlock(&sbsec->lock); 891 return rc; 892 out_double_mount: 893 rc = -EINVAL; 894 pr_warn("SELinux: mount invalid. Same superblock, different " 895 "security settings for (dev %s, type %s)\n", sb->s_id, 896 sb->s_type->name); 897 goto out; 898 } 899 900 static int selinux_cmp_sb_context(const struct super_block *oldsb, 901 const struct super_block *newsb) 902 { 903 struct superblock_security_struct *old = selinux_superblock(oldsb); 904 struct superblock_security_struct *new = selinux_superblock(newsb); 905 char oldflags = old->flags & SE_MNTMASK; 906 char newflags = new->flags & SE_MNTMASK; 907 908 if (oldflags != newflags) 909 goto mismatch; 910 if ((oldflags & FSCONTEXT_MNT) && old->sid != new->sid) 911 goto mismatch; 912 if ((oldflags & CONTEXT_MNT) && old->mntpoint_sid != new->mntpoint_sid) 913 goto mismatch; 914 if ((oldflags & DEFCONTEXT_MNT) && old->def_sid != new->def_sid) 915 goto mismatch; 916 if (oldflags & ROOTCONTEXT_MNT) { 917 struct inode_security_struct *oldroot = backing_inode_security(oldsb->s_root); 918 struct inode_security_struct *newroot = backing_inode_security(newsb->s_root); 919 if (oldroot->sid != newroot->sid) 920 goto mismatch; 921 } 922 if (old->creator_sid != new->creator_sid) 923 goto mismatch; 924 return 0; 925 mismatch: 926 pr_warn("SELinux: mount invalid. Same superblock, " 927 "different security settings for (dev %s, " 928 "type %s)\n", newsb->s_id, newsb->s_type->name); 929 return -EBUSY; 930 } 931 932 static int selinux_sb_clone_mnt_opts(const struct super_block *oldsb, 933 struct super_block *newsb, 934 unsigned long kern_flags, 935 unsigned long *set_kern_flags) 936 { 937 int rc = 0; 938 const struct superblock_security_struct *oldsbsec = 939 selinux_superblock(oldsb); 940 struct superblock_security_struct *newsbsec = selinux_superblock(newsb); 941 942 int set_fscontext = (oldsbsec->flags & FSCONTEXT_MNT); 943 int set_context = (oldsbsec->flags & CONTEXT_MNT); 944 int set_rootcontext = (oldsbsec->flags & ROOTCONTEXT_MNT); 945 946 /* 947 * Specifying internal flags without providing a place to 948 * place the results is not allowed. 949 */ 950 if (kern_flags && !set_kern_flags) 951 return -EINVAL; 952 953 mutex_lock(&newsbsec->lock); 954 955 /* 956 * if the parent was able to be mounted it clearly had no special lsm 957 * mount options. thus we can safely deal with this superblock later 958 */ 959 if (!selinux_initialized()) { 960 if (kern_flags & SECURITY_LSM_NATIVE_LABELS) { 961 newsbsec->flags |= SE_SBNATIVE; 962 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 963 } 964 goto out; 965 } 966 967 /* how can we clone if the old one wasn't set up?? */ 968 BUG_ON(!(oldsbsec->flags & SE_SBINITIALIZED)); 969 970 /* if fs is reusing a sb, make sure that the contexts match */ 971 if (newsbsec->flags & SE_SBINITIALIZED) { 972 mutex_unlock(&newsbsec->lock); 973 if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) && !set_context) 974 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 975 return selinux_cmp_sb_context(oldsb, newsb); 976 } 977 978 newsbsec->flags = oldsbsec->flags; 979 980 newsbsec->sid = oldsbsec->sid; 981 newsbsec->def_sid = oldsbsec->def_sid; 982 newsbsec->behavior = oldsbsec->behavior; 983 newsbsec->creator_sid = oldsbsec->creator_sid; 984 985 if (newsbsec->behavior == SECURITY_FS_USE_NATIVE && 986 !(kern_flags & SECURITY_LSM_NATIVE_LABELS) && !set_context) { 987 rc = security_fs_use(newsb); 988 if (rc) 989 goto out; 990 } 991 992 if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !set_context) { 993 newsbsec->behavior = SECURITY_FS_USE_NATIVE; 994 *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; 995 } 996 997 if (set_context) { 998 u32 sid = oldsbsec->mntpoint_sid; 999 1000 if (!set_fscontext) 1001 newsbsec->sid = sid; 1002 if (!set_rootcontext) { 1003 struct inode_security_struct *newisec = backing_inode_security(newsb->s_root); 1004 newisec->sid = sid; 1005 } 1006 newsbsec->mntpoint_sid = sid; 1007 } 1008 if (set_rootcontext) { 1009 const struct inode_security_struct *oldisec = backing_inode_security(oldsb->s_root); 1010 struct inode_security_struct *newisec = backing_inode_security(newsb->s_root); 1011 1012 newisec->sid = oldisec->sid; 1013 } 1014 1015 sb_finish_set_opts(newsb); 1016 out: 1017 mutex_unlock(&newsbsec->lock); 1018 return rc; 1019 } 1020 1021 /* 1022 * NOTE: the caller is responsible for freeing the memory even if on error. 1023 */ 1024 static int selinux_add_opt(int token, const char *s, void **mnt_opts) 1025 { 1026 struct selinux_mnt_opts *opts = *mnt_opts; 1027 u32 *dst_sid; 1028 int rc; 1029 1030 if (token == Opt_seclabel) 1031 /* eaten and completely ignored */ 1032 return 0; 1033 if (!s) 1034 return -EINVAL; 1035 1036 if (!selinux_initialized()) { 1037 pr_warn("SELinux: Unable to set superblock options before the security server is initialized\n"); 1038 return -EINVAL; 1039 } 1040 1041 if (!opts) { 1042 opts = kzalloc_obj(*opts); 1043 if (!opts) 1044 return -ENOMEM; 1045 *mnt_opts = opts; 1046 } 1047 1048 switch (token) { 1049 case Opt_context: 1050 if (opts->context_sid || opts->defcontext_sid) 1051 goto err; 1052 dst_sid = &opts->context_sid; 1053 break; 1054 case Opt_fscontext: 1055 if (opts->fscontext_sid) 1056 goto err; 1057 dst_sid = &opts->fscontext_sid; 1058 break; 1059 case Opt_rootcontext: 1060 if (opts->rootcontext_sid) 1061 goto err; 1062 dst_sid = &opts->rootcontext_sid; 1063 break; 1064 case Opt_defcontext: 1065 if (opts->context_sid || opts->defcontext_sid) 1066 goto err; 1067 dst_sid = &opts->defcontext_sid; 1068 break; 1069 default: 1070 WARN_ON(1); 1071 return -EINVAL; 1072 } 1073 rc = security_context_str_to_sid(s, dst_sid, GFP_KERNEL); 1074 if (rc) 1075 pr_warn("SELinux: security_context_str_to_sid (%s) failed with errno=%d\n", 1076 s, rc); 1077 return rc; 1078 1079 err: 1080 pr_warn(SEL_MOUNT_FAIL_MSG); 1081 return -EINVAL; 1082 } 1083 1084 static int show_sid(struct seq_file *m, u32 sid) 1085 { 1086 char *context = NULL; 1087 u32 len; 1088 int rc; 1089 1090 rc = security_sid_to_context(sid, &context, &len); 1091 if (!rc) { 1092 bool has_comma = strchr(context, ','); 1093 1094 seq_putc(m, '='); 1095 if (has_comma) 1096 seq_putc(m, '\"'); 1097 seq_escape(m, context, "\"\n\\"); 1098 if (has_comma) 1099 seq_putc(m, '\"'); 1100 } 1101 kfree(context); 1102 return rc; 1103 } 1104 1105 static int selinux_sb_show_options(struct seq_file *m, struct super_block *sb) 1106 { 1107 struct superblock_security_struct *sbsec = selinux_superblock(sb); 1108 int rc; 1109 1110 if (!(sbsec->flags & SE_SBINITIALIZED)) 1111 return 0; 1112 1113 if (!selinux_initialized()) 1114 return 0; 1115 1116 if (sbsec->flags & FSCONTEXT_MNT) { 1117 seq_putc(m, ','); 1118 seq_puts(m, FSCONTEXT_STR); 1119 rc = show_sid(m, sbsec->sid); 1120 if (rc) 1121 return rc; 1122 } 1123 if (sbsec->flags & CONTEXT_MNT) { 1124 seq_putc(m, ','); 1125 seq_puts(m, CONTEXT_STR); 1126 rc = show_sid(m, sbsec->mntpoint_sid); 1127 if (rc) 1128 return rc; 1129 } 1130 if (sbsec->flags & DEFCONTEXT_MNT) { 1131 seq_putc(m, ','); 1132 seq_puts(m, DEFCONTEXT_STR); 1133 rc = show_sid(m, sbsec->def_sid); 1134 if (rc) 1135 return rc; 1136 } 1137 if (sbsec->flags & ROOTCONTEXT_MNT) { 1138 struct dentry *root = sb->s_root; 1139 struct inode_security_struct *isec = backing_inode_security(root); 1140 seq_putc(m, ','); 1141 seq_puts(m, ROOTCONTEXT_STR); 1142 rc = show_sid(m, isec->sid); 1143 if (rc) 1144 return rc; 1145 } 1146 if (sbsec->flags & SBLABEL_MNT) { 1147 seq_putc(m, ','); 1148 seq_puts(m, SECLABEL_STR); 1149 } 1150 return 0; 1151 } 1152 1153 static inline u16 inode_mode_to_security_class(umode_t mode) 1154 { 1155 switch (mode & S_IFMT) { 1156 case S_IFSOCK: 1157 return SECCLASS_SOCK_FILE; 1158 case S_IFLNK: 1159 return SECCLASS_LNK_FILE; 1160 case S_IFREG: 1161 return SECCLASS_FILE; 1162 case S_IFBLK: 1163 return SECCLASS_BLK_FILE; 1164 case S_IFDIR: 1165 return SECCLASS_DIR; 1166 case S_IFCHR: 1167 return SECCLASS_CHR_FILE; 1168 case S_IFIFO: 1169 return SECCLASS_FIFO_FILE; 1170 1171 } 1172 1173 return SECCLASS_FILE; 1174 } 1175 1176 static inline int default_protocol_stream(int protocol) 1177 { 1178 return (protocol == IPPROTO_IP || protocol == IPPROTO_TCP || 1179 protocol == IPPROTO_MPTCP); 1180 } 1181 1182 static inline int default_protocol_dgram(int protocol) 1183 { 1184 return (protocol == IPPROTO_IP || protocol == IPPROTO_UDP); 1185 } 1186 1187 static inline u16 socket_type_to_security_class(int family, int type, int protocol) 1188 { 1189 bool extsockclass = selinux_policycap_extsockclass(); 1190 1191 switch (family) { 1192 case PF_UNIX: 1193 switch (type) { 1194 case SOCK_STREAM: 1195 case SOCK_SEQPACKET: 1196 return SECCLASS_UNIX_STREAM_SOCKET; 1197 case SOCK_DGRAM: 1198 case SOCK_RAW: 1199 return SECCLASS_UNIX_DGRAM_SOCKET; 1200 } 1201 break; 1202 case PF_INET: 1203 case PF_INET6: 1204 switch (type) { 1205 case SOCK_STREAM: 1206 case SOCK_SEQPACKET: 1207 if (default_protocol_stream(protocol)) 1208 return SECCLASS_TCP_SOCKET; 1209 else if (extsockclass && protocol == IPPROTO_SCTP) 1210 return SECCLASS_SCTP_SOCKET; 1211 else 1212 return SECCLASS_RAWIP_SOCKET; 1213 case SOCK_DGRAM: 1214 if (default_protocol_dgram(protocol)) 1215 return SECCLASS_UDP_SOCKET; 1216 else if (extsockclass && (protocol == IPPROTO_ICMP || 1217 protocol == IPPROTO_ICMPV6)) 1218 return SECCLASS_ICMP_SOCKET; 1219 else 1220 return SECCLASS_RAWIP_SOCKET; 1221 default: 1222 return SECCLASS_RAWIP_SOCKET; 1223 } 1224 break; 1225 case PF_NETLINK: 1226 switch (protocol) { 1227 case NETLINK_ROUTE: 1228 return SECCLASS_NETLINK_ROUTE_SOCKET; 1229 case NETLINK_SOCK_DIAG: 1230 return SECCLASS_NETLINK_TCPDIAG_SOCKET; 1231 case NETLINK_NFLOG: 1232 return SECCLASS_NETLINK_NFLOG_SOCKET; 1233 case NETLINK_XFRM: 1234 return SECCLASS_NETLINK_XFRM_SOCKET; 1235 case NETLINK_SELINUX: 1236 return SECCLASS_NETLINK_SELINUX_SOCKET; 1237 case NETLINK_ISCSI: 1238 return SECCLASS_NETLINK_ISCSI_SOCKET; 1239 case NETLINK_AUDIT: 1240 return SECCLASS_NETLINK_AUDIT_SOCKET; 1241 case NETLINK_FIB_LOOKUP: 1242 return SECCLASS_NETLINK_FIB_LOOKUP_SOCKET; 1243 case NETLINK_CONNECTOR: 1244 return SECCLASS_NETLINK_CONNECTOR_SOCKET; 1245 case NETLINK_NETFILTER: 1246 return SECCLASS_NETLINK_NETFILTER_SOCKET; 1247 case NETLINK_DNRTMSG: 1248 return SECCLASS_NETLINK_DNRT_SOCKET; 1249 case NETLINK_KOBJECT_UEVENT: 1250 return SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET; 1251 case NETLINK_GENERIC: 1252 return SECCLASS_NETLINK_GENERIC_SOCKET; 1253 case NETLINK_SCSITRANSPORT: 1254 return SECCLASS_NETLINK_SCSITRANSPORT_SOCKET; 1255 case NETLINK_RDMA: 1256 return SECCLASS_NETLINK_RDMA_SOCKET; 1257 case NETLINK_CRYPTO: 1258 return SECCLASS_NETLINK_CRYPTO_SOCKET; 1259 default: 1260 return SECCLASS_NETLINK_SOCKET; 1261 } 1262 case PF_PACKET: 1263 return SECCLASS_PACKET_SOCKET; 1264 case PF_KEY: 1265 return SECCLASS_KEY_SOCKET; 1266 case PF_APPLETALK: 1267 return SECCLASS_APPLETALK_SOCKET; 1268 } 1269 1270 if (extsockclass) { 1271 switch (family) { 1272 case PF_AX25: 1273 return SECCLASS_AX25_SOCKET; 1274 case PF_IPX: 1275 return SECCLASS_IPX_SOCKET; 1276 case PF_NETROM: 1277 return SECCLASS_NETROM_SOCKET; 1278 case PF_ATMPVC: 1279 return SECCLASS_ATMPVC_SOCKET; 1280 case PF_X25: 1281 return SECCLASS_X25_SOCKET; 1282 case PF_ROSE: 1283 return SECCLASS_ROSE_SOCKET; 1284 case PF_DECnet: 1285 return SECCLASS_DECNET_SOCKET; 1286 case PF_ATMSVC: 1287 return SECCLASS_ATMSVC_SOCKET; 1288 case PF_RDS: 1289 return SECCLASS_RDS_SOCKET; 1290 case PF_IRDA: 1291 return SECCLASS_IRDA_SOCKET; 1292 case PF_PPPOX: 1293 return SECCLASS_PPPOX_SOCKET; 1294 case PF_LLC: 1295 return SECCLASS_LLC_SOCKET; 1296 case PF_CAN: 1297 return SECCLASS_CAN_SOCKET; 1298 case PF_TIPC: 1299 return SECCLASS_TIPC_SOCKET; 1300 case PF_BLUETOOTH: 1301 return SECCLASS_BLUETOOTH_SOCKET; 1302 case PF_IUCV: 1303 return SECCLASS_IUCV_SOCKET; 1304 case PF_RXRPC: 1305 return SECCLASS_RXRPC_SOCKET; 1306 case PF_ISDN: 1307 return SECCLASS_ISDN_SOCKET; 1308 case PF_PHONET: 1309 return SECCLASS_PHONET_SOCKET; 1310 case PF_IEEE802154: 1311 return SECCLASS_IEEE802154_SOCKET; 1312 case PF_CAIF: 1313 return SECCLASS_CAIF_SOCKET; 1314 case PF_ALG: 1315 return SECCLASS_ALG_SOCKET; 1316 case PF_NFC: 1317 return SECCLASS_NFC_SOCKET; 1318 case PF_VSOCK: 1319 return SECCLASS_VSOCK_SOCKET; 1320 case PF_KCM: 1321 return SECCLASS_KCM_SOCKET; 1322 case PF_QIPCRTR: 1323 return SECCLASS_QIPCRTR_SOCKET; 1324 case PF_SMC: 1325 return SECCLASS_SMC_SOCKET; 1326 case PF_XDP: 1327 return SECCLASS_XDP_SOCKET; 1328 case PF_MCTP: 1329 return SECCLASS_MCTP_SOCKET; 1330 #if PF_MAX > 46 1331 #error New address family defined, please update this function. 1332 #endif 1333 } 1334 } 1335 1336 return SECCLASS_SOCKET; 1337 } 1338 1339 static int selinux_genfs_get_sid(struct dentry *dentry, 1340 u16 tclass, 1341 u16 flags, 1342 u32 *sid) 1343 { 1344 int rc; 1345 struct super_block *sb = dentry->d_sb; 1346 char *buffer, *path; 1347 1348 buffer = kmalloc(PATH_MAX, GFP_KERNEL); 1349 if (!buffer) 1350 return -ENOMEM; 1351 1352 path = dentry_path_raw(dentry, buffer, PATH_MAX); 1353 if (IS_ERR(path)) 1354 rc = PTR_ERR(path); 1355 else { 1356 if (flags & SE_SBPROC) { 1357 /* each process gets a /proc/PID/ entry. Strip off the 1358 * PID part to get a valid selinux labeling. 1359 * e.g. /proc/1/net/rpc/nfs -> /net/rpc/nfs */ 1360 while (path[1] >= '0' && path[1] <= '9') { 1361 path[1] = '/'; 1362 path++; 1363 } 1364 } 1365 rc = security_genfs_sid(sb->s_type->name, 1366 path, tclass, sid); 1367 if (rc == -ENOENT) { 1368 /* No match in policy, mark as unlabeled. */ 1369 *sid = SECINITSID_UNLABELED; 1370 rc = 0; 1371 } 1372 } 1373 kfree(buffer); 1374 return rc; 1375 } 1376 1377 static int inode_doinit_use_xattr(struct inode *inode, struct dentry *dentry, 1378 u32 def_sid, u32 *sid) 1379 { 1380 #define INITCONTEXTLEN 255 1381 char *context; 1382 unsigned int len; 1383 int rc; 1384 1385 len = INITCONTEXTLEN; 1386 context = kmalloc(len + 1, GFP_NOFS); 1387 if (!context) 1388 return -ENOMEM; 1389 1390 context[len] = '\0'; 1391 rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, context, len); 1392 if (rc == -ERANGE) { 1393 kfree(context); 1394 1395 /* Need a larger buffer. Query for the right size. */ 1396 rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, NULL, 0); 1397 if (rc < 0) 1398 return rc; 1399 1400 len = rc; 1401 context = kmalloc(len + 1, GFP_NOFS); 1402 if (!context) 1403 return -ENOMEM; 1404 1405 context[len] = '\0'; 1406 rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, 1407 context, len); 1408 } 1409 if (rc < 0) { 1410 kfree(context); 1411 if (rc != -ENODATA) { 1412 pr_warn("SELinux: %s: getxattr returned %d for dev=%s ino=%llu\n", 1413 __func__, -rc, inode->i_sb->s_id, inode->i_ino); 1414 return rc; 1415 } 1416 *sid = def_sid; 1417 return 0; 1418 } 1419 1420 rc = security_context_to_sid_default(context, rc, sid, 1421 def_sid, GFP_NOFS); 1422 if (rc) { 1423 char *dev = inode->i_sb->s_id; 1424 u64 ino = inode->i_ino; 1425 1426 if (rc == -EINVAL) { 1427 pr_notice_ratelimited("SELinux: inode=%llu on dev=%s was found to have an invalid context=%s. This indicates you may need to relabel the inode or the filesystem in question.\n", 1428 ino, dev, context); 1429 } else { 1430 pr_warn("SELinux: %s: context_to_sid(%s) returned %d for dev=%s ino=%llu\n", 1431 __func__, context, -rc, dev, ino); 1432 } 1433 } 1434 kfree(context); 1435 return 0; 1436 } 1437 1438 /* The inode's security attributes must be initialized before first use. */ 1439 static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry) 1440 { 1441 struct superblock_security_struct *sbsec = NULL; 1442 struct inode_security_struct *isec = selinux_inode(inode); 1443 u32 task_sid, sid = 0; 1444 u16 sclass; 1445 struct dentry *dentry; 1446 int rc = 0; 1447 1448 /* check below is racy, but we will recheck with lock held */ 1449 if (data_race(isec->initialized == LABEL_INITIALIZED)) 1450 return 0; 1451 1452 spin_lock(&isec->lock); 1453 if (isec->initialized == LABEL_INITIALIZED) 1454 goto out_unlock; 1455 1456 if (isec->sclass == SECCLASS_FILE) 1457 isec->sclass = inode_mode_to_security_class(inode->i_mode); 1458 1459 sbsec = selinux_superblock(inode->i_sb); 1460 if (!(sbsec->flags & SE_SBINITIALIZED)) { 1461 /* Defer initialization until selinux_complete_init, 1462 after the initial policy is loaded and the security 1463 server is ready to handle calls. */ 1464 spin_lock(&sbsec->isec_lock); 1465 if (list_empty(&isec->list)) 1466 list_add(&isec->list, &sbsec->isec_head); 1467 spin_unlock(&sbsec->isec_lock); 1468 goto out_unlock; 1469 } 1470 1471 sclass = isec->sclass; 1472 task_sid = isec->task_sid; 1473 sid = isec->sid; 1474 isec->initialized = LABEL_PENDING; 1475 spin_unlock(&isec->lock); 1476 1477 switch (sbsec->behavior) { 1478 /* 1479 * In case of SECURITY_FS_USE_NATIVE we need to re-fetch the labels 1480 * via xattr when called from delayed_superblock_init(). 1481 */ 1482 case SECURITY_FS_USE_NATIVE: 1483 case SECURITY_FS_USE_XATTR: 1484 if (!(inode->i_opflags & IOP_XATTR)) { 1485 sid = sbsec->def_sid; 1486 break; 1487 } 1488 /* Need a dentry, since the xattr API requires one. 1489 Life would be simpler if we could just pass the inode. */ 1490 if (opt_dentry) { 1491 /* Called from d_instantiate or d_splice_alias. */ 1492 dentry = dget(opt_dentry); 1493 } else { 1494 /* 1495 * Called from selinux_complete_init, try to find a dentry. 1496 * Some filesystems really want a connected one, so try 1497 * that first. We could split SECURITY_FS_USE_XATTR in 1498 * two, depending upon that... 1499 */ 1500 dentry = d_find_alias(inode); 1501 if (!dentry) 1502 dentry = d_find_any_alias(inode); 1503 } 1504 if (!dentry) { 1505 /* 1506 * this is can be hit on boot when a file is accessed 1507 * before the policy is loaded. When we load policy we 1508 * may find inodes that have no dentry on the 1509 * sbsec->isec_head list. No reason to complain as these 1510 * will get fixed up the next time we go through 1511 * inode_doinit with a dentry, before these inodes could 1512 * be used again by userspace. 1513 */ 1514 goto out_invalid; 1515 } 1516 1517 rc = inode_doinit_use_xattr(inode, dentry, sbsec->def_sid, 1518 &sid); 1519 dput(dentry); 1520 if (rc) 1521 goto out; 1522 break; 1523 case SECURITY_FS_USE_TASK: 1524 sid = task_sid; 1525 break; 1526 case SECURITY_FS_USE_TRANS: 1527 /* Default to the fs SID. */ 1528 sid = sbsec->sid; 1529 1530 /* Try to obtain a transition SID. */ 1531 rc = security_transition_sid(task_sid, sid, 1532 sclass, NULL, &sid); 1533 if (rc) 1534 goto out; 1535 break; 1536 case SECURITY_FS_USE_MNTPOINT: 1537 sid = sbsec->mntpoint_sid; 1538 break; 1539 default: 1540 /* Default to the fs superblock SID. */ 1541 sid = sbsec->sid; 1542 1543 if ((sbsec->flags & SE_SBGENFS) && 1544 (!S_ISLNK(inode->i_mode) || 1545 selinux_policycap_genfs_seclabel_symlinks())) { 1546 /* We must have a dentry to determine the label on 1547 * procfs inodes */ 1548 if (opt_dentry) { 1549 /* Called from d_instantiate or 1550 * d_splice_alias. */ 1551 dentry = dget(opt_dentry); 1552 } else { 1553 /* Called from selinux_complete_init, try to 1554 * find a dentry. Some filesystems really want 1555 * a connected one, so try that first. 1556 */ 1557 dentry = d_find_alias(inode); 1558 if (!dentry) 1559 dentry = d_find_any_alias(inode); 1560 } 1561 /* 1562 * This can be hit on boot when a file is accessed 1563 * before the policy is loaded. When we load policy we 1564 * may find inodes that have no dentry on the 1565 * sbsec->isec_head list. No reason to complain as 1566 * these will get fixed up the next time we go through 1567 * inode_doinit() with a dentry, before these inodes 1568 * could be used again by userspace. 1569 */ 1570 if (!dentry) 1571 goto out_invalid; 1572 rc = selinux_genfs_get_sid(dentry, sclass, 1573 sbsec->flags, &sid); 1574 if (rc) { 1575 dput(dentry); 1576 goto out; 1577 } 1578 1579 if ((sbsec->flags & SE_SBGENFS_XATTR) && 1580 (inode->i_opflags & IOP_XATTR)) { 1581 rc = inode_doinit_use_xattr(inode, dentry, 1582 sid, &sid); 1583 if (rc) { 1584 dput(dentry); 1585 goto out; 1586 } 1587 } 1588 dput(dentry); 1589 } 1590 break; 1591 } 1592 1593 out: 1594 spin_lock(&isec->lock); 1595 if (isec->initialized == LABEL_PENDING) { 1596 if (rc) { 1597 isec->initialized = LABEL_INVALID; 1598 goto out_unlock; 1599 } 1600 isec->initialized = LABEL_INITIALIZED; 1601 isec->sid = sid; 1602 } 1603 1604 out_unlock: 1605 spin_unlock(&isec->lock); 1606 return rc; 1607 1608 out_invalid: 1609 spin_lock(&isec->lock); 1610 if (isec->initialized == LABEL_PENDING) { 1611 isec->initialized = LABEL_INVALID; 1612 isec->sid = sid; 1613 } 1614 spin_unlock(&isec->lock); 1615 return 0; 1616 } 1617 1618 /* Convert a Linux signal to an access vector. */ 1619 static inline u32 signal_to_av(int sig) 1620 { 1621 u32 perm = 0; 1622 1623 switch (sig) { 1624 case SIGCHLD: 1625 /* Commonly granted from child to parent. */ 1626 perm = PROCESS__SIGCHLD; 1627 break; 1628 case SIGKILL: 1629 /* Cannot be caught or ignored */ 1630 perm = PROCESS__SIGKILL; 1631 break; 1632 case SIGSTOP: 1633 /* Cannot be caught or ignored */ 1634 perm = PROCESS__SIGSTOP; 1635 break; 1636 default: 1637 /* All other signals. */ 1638 perm = PROCESS__SIGNAL; 1639 break; 1640 } 1641 1642 return perm; 1643 } 1644 1645 #if CAP_LAST_CAP > 63 1646 #error Fix SELinux to handle capabilities > 63. 1647 #endif 1648 1649 /* Check whether a task is allowed to use a capability. */ 1650 static int cred_has_capability(const struct cred *cred, 1651 int cap, unsigned int opts, bool initns) 1652 { 1653 struct common_audit_data ad; 1654 struct av_decision avd; 1655 u16 sclass; 1656 u32 sid = cred_sid(cred); 1657 u32 av = CAP_TO_MASK(cap); 1658 int rc; 1659 1660 ad.type = LSM_AUDIT_DATA_CAP; 1661 ad.u.cap = cap; 1662 1663 switch (CAP_TO_INDEX(cap)) { 1664 case 0: 1665 sclass = initns ? SECCLASS_CAPABILITY : SECCLASS_CAP_USERNS; 1666 break; 1667 case 1: 1668 sclass = initns ? SECCLASS_CAPABILITY2 : SECCLASS_CAP2_USERNS; 1669 break; 1670 default: 1671 pr_err("SELinux: out of range capability %d\n", cap); 1672 return -EINVAL; 1673 } 1674 1675 rc = avc_has_perm_noaudit(sid, sid, sclass, av, 0, &avd); 1676 if (!(opts & CAP_OPT_NOAUDIT)) { 1677 int rc2 = avc_audit(sid, sid, sclass, av, &avd, rc, &ad); 1678 if (rc2) 1679 return rc2; 1680 } 1681 return rc; 1682 } 1683 1684 /* 1685 * Check whether a SID has a particular permission to an inode. The 'adp' 1686 * parameter is optional and allows other audit data to be passed (e.g. the 1687 * dentry). 1688 */ 1689 static int inode_sid_has_perm(u32 sid, struct inode *inode, u32 perms, 1690 struct common_audit_data *adp) 1691 { 1692 struct inode_security_struct *isec; 1693 1694 if (unlikely(IS_PRIVATE(inode))) 1695 return 0; 1696 1697 isec = selinux_inode(inode); 1698 1699 return avc_has_perm(sid, isec->sid, isec->sclass, perms, adp); 1700 } 1701 1702 static int inode_has_perm(const struct cred *cred, 1703 struct inode *inode, 1704 u32 perms, 1705 struct common_audit_data *adp) 1706 { 1707 return inode_sid_has_perm(cred_sid(cred), inode, perms, adp); 1708 } 1709 1710 /* Same as inode_has_perm, but pass explicit audit data containing 1711 the dentry to help the auditing code to more easily generate the 1712 pathname if needed. */ 1713 static inline int dentry_has_perm(const struct cred *cred, 1714 struct dentry *dentry, 1715 u32 av) 1716 { 1717 struct common_audit_data ad; 1718 struct inode *inode = d_backing_inode(dentry); 1719 struct inode_security_struct *isec = selinux_inode(inode); 1720 1721 ad.type = LSM_AUDIT_DATA_DENTRY; 1722 ad.u.dentry = dentry; 1723 /* check below is racy, but revalidate will recheck with lock held */ 1724 if (data_race(unlikely(isec->initialized != LABEL_INITIALIZED))) 1725 __inode_security_revalidate(inode, dentry, true); 1726 return inode_has_perm(cred, inode, av, &ad); 1727 } 1728 1729 /* Same as inode_has_perm, but pass explicit audit data containing 1730 the path to help the auditing code to more easily generate the 1731 pathname if needed. */ 1732 static inline int path_has_perm(const struct cred *cred, 1733 const struct path *path, 1734 u32 av) 1735 { 1736 struct common_audit_data ad; 1737 struct inode *inode = d_backing_inode(path->dentry); 1738 struct inode_security_struct *isec = selinux_inode(inode); 1739 1740 ad.type = LSM_AUDIT_DATA_PATH; 1741 ad.u.path = *path; 1742 /* check below is racy, but revalidate will recheck with lock held */ 1743 if (data_race(unlikely(isec->initialized != LABEL_INITIALIZED))) 1744 __inode_security_revalidate(inode, path->dentry, true); 1745 return inode_has_perm(cred, inode, av, &ad); 1746 } 1747 1748 /* Same as path_has_perm, but uses the inode from the file struct. */ 1749 static inline int file_path_has_perm(const struct cred *cred, 1750 struct file *file, 1751 u32 av) 1752 { 1753 struct common_audit_data ad; 1754 1755 ad.type = LSM_AUDIT_DATA_FILE; 1756 ad.u.file = file; 1757 return inode_has_perm(cred, file_inode(file), av, &ad); 1758 } 1759 1760 #ifdef CONFIG_BPF_SYSCALL 1761 static int bpf_fd_pass(const struct file *file, u32 sid); 1762 #endif 1763 1764 static int __file_has_perm(const struct cred *cred, const struct file *file, 1765 u32 av, bool bf_user_file) 1766 1767 { 1768 struct common_audit_data ad; 1769 struct inode *inode; 1770 u32 ssid = cred_sid(cred); 1771 u32 tsid_fd; 1772 int rc; 1773 1774 if (bf_user_file) { 1775 struct backing_file_security_struct *bfsec; 1776 const struct path *path; 1777 1778 if (WARN_ON(!(file->f_mode & FMODE_BACKING))) 1779 return -EIO; 1780 1781 bfsec = selinux_backing_file(file); 1782 path = backing_file_user_path(file); 1783 tsid_fd = bfsec->uf_sid; 1784 inode = d_inode(path->dentry); 1785 1786 ad.type = LSM_AUDIT_DATA_PATH; 1787 ad.u.path = *path; 1788 } else { 1789 struct file_security_struct *fsec = selinux_file(file); 1790 1791 tsid_fd = fsec->sid; 1792 inode = file_inode(file); 1793 1794 ad.type = LSM_AUDIT_DATA_FILE; 1795 ad.u.file = file; 1796 } 1797 1798 if (ssid != tsid_fd) { 1799 rc = avc_has_perm(ssid, tsid_fd, SECCLASS_FD, FD__USE, &ad); 1800 if (rc) 1801 return rc; 1802 } 1803 1804 #ifdef CONFIG_BPF_SYSCALL 1805 /* regardless of backing vs user file, use the underlying file here */ 1806 rc = bpf_fd_pass(file, ssid); 1807 if (rc) 1808 return rc; 1809 #endif 1810 1811 /* av is zero if only checking access to the descriptor. */ 1812 if (av) 1813 return inode_has_perm(cred, inode, av, &ad); 1814 1815 return 0; 1816 } 1817 1818 /* Check whether a task can use an open file descriptor to 1819 access an inode in a given way. Check access to the 1820 descriptor itself, and then use dentry_has_perm to 1821 check a particular permission to the file. 1822 Access to the descriptor is implicitly granted if it 1823 has the same SID as the process. If av is zero, then 1824 access to the file is not checked, e.g. for cases 1825 where only the descriptor is affected like seek. */ 1826 static inline int file_has_perm(const struct cred *cred, 1827 const struct file *file, u32 av) 1828 { 1829 return __file_has_perm(cred, file, av, false); 1830 } 1831 1832 /* 1833 * Determine the label for an inode that might be unioned. 1834 */ 1835 static int 1836 selinux_determine_inode_label(const struct cred_security_struct *crsec, 1837 struct inode *dir, 1838 const struct qstr *name, u16 tclass, 1839 u32 *_new_isid) 1840 { 1841 const struct superblock_security_struct *sbsec = 1842 selinux_superblock(dir->i_sb); 1843 1844 if ((sbsec->flags & SE_SBINITIALIZED) && 1845 (sbsec->behavior == SECURITY_FS_USE_MNTPOINT)) { 1846 *_new_isid = sbsec->mntpoint_sid; 1847 } else if ((sbsec->flags & SBLABEL_MNT) && 1848 crsec->create_sid) { 1849 *_new_isid = crsec->create_sid; 1850 } else { 1851 const struct inode_security_struct *dsec = inode_security(dir); 1852 return security_transition_sid(crsec->sid, 1853 dsec->sid, tclass, 1854 name, _new_isid); 1855 } 1856 1857 return 0; 1858 } 1859 1860 /* Check whether a task can create a file. */ 1861 static int may_create(struct inode *dir, 1862 struct dentry *dentry, 1863 u16 tclass) 1864 { 1865 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 1866 struct inode_security_struct *dsec; 1867 struct superblock_security_struct *sbsec; 1868 u32 sid, newsid; 1869 struct common_audit_data ad; 1870 int rc; 1871 1872 dsec = inode_security(dir); 1873 sbsec = selinux_superblock(dir->i_sb); 1874 1875 sid = crsec->sid; 1876 1877 ad.type = LSM_AUDIT_DATA_DENTRY; 1878 ad.u.dentry = dentry; 1879 1880 rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, 1881 DIR__ADD_NAME | DIR__SEARCH, 1882 &ad); 1883 if (rc) 1884 return rc; 1885 1886 rc = selinux_determine_inode_label(crsec, dir, &dentry->d_name, tclass, 1887 &newsid); 1888 if (rc) 1889 return rc; 1890 1891 rc = avc_has_perm(sid, newsid, tclass, FILE__CREATE, &ad); 1892 if (rc) 1893 return rc; 1894 1895 return avc_has_perm(newsid, sbsec->sid, 1896 SECCLASS_FILESYSTEM, 1897 FILESYSTEM__ASSOCIATE, &ad); 1898 } 1899 1900 #define MAY_LINK 0 1901 #define MAY_UNLINK 1 1902 #define MAY_RMDIR 2 1903 1904 /* Check whether a task can link, unlink, or rmdir a file/directory. */ 1905 static int may_link(struct inode *dir, 1906 struct dentry *dentry, 1907 int kind) 1908 1909 { 1910 struct inode_security_struct *dsec, *isec; 1911 struct common_audit_data ad; 1912 u32 sid = current_sid(); 1913 u32 av; 1914 int rc; 1915 1916 dsec = inode_security(dir); 1917 isec = backing_inode_security(dentry); 1918 1919 ad.type = LSM_AUDIT_DATA_DENTRY; 1920 ad.u.dentry = dentry; 1921 1922 av = DIR__SEARCH; 1923 av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME); 1924 rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, av, &ad); 1925 if (rc) 1926 return rc; 1927 1928 switch (kind) { 1929 case MAY_LINK: 1930 av = FILE__LINK; 1931 break; 1932 case MAY_UNLINK: 1933 av = FILE__UNLINK; 1934 break; 1935 case MAY_RMDIR: 1936 av = DIR__RMDIR; 1937 break; 1938 default: 1939 pr_warn("SELinux: %s: unrecognized kind %d\n", 1940 __func__, kind); 1941 return 0; 1942 } 1943 1944 rc = avc_has_perm(sid, isec->sid, isec->sclass, av, &ad); 1945 return rc; 1946 } 1947 1948 static inline int may_rename(struct inode *old_dir, 1949 struct dentry *old_dentry, 1950 struct inode *new_dir, 1951 struct dentry *new_dentry) 1952 { 1953 struct inode_security_struct *old_dsec, *new_dsec, *old_isec, *new_isec; 1954 struct common_audit_data ad; 1955 u32 sid = current_sid(); 1956 u32 av; 1957 int old_is_dir, new_is_dir; 1958 int rc; 1959 1960 old_dsec = inode_security(old_dir); 1961 old_isec = backing_inode_security(old_dentry); 1962 old_is_dir = d_is_dir(old_dentry); 1963 new_dsec = inode_security(new_dir); 1964 1965 ad.type = LSM_AUDIT_DATA_DENTRY; 1966 1967 ad.u.dentry = old_dentry; 1968 rc = avc_has_perm(sid, old_dsec->sid, SECCLASS_DIR, 1969 DIR__REMOVE_NAME | DIR__SEARCH, &ad); 1970 if (rc) 1971 return rc; 1972 rc = avc_has_perm(sid, old_isec->sid, 1973 old_isec->sclass, FILE__RENAME, &ad); 1974 if (rc) 1975 return rc; 1976 if (old_is_dir && new_dir != old_dir) { 1977 rc = avc_has_perm(sid, old_isec->sid, 1978 old_isec->sclass, DIR__REPARENT, &ad); 1979 if (rc) 1980 return rc; 1981 } 1982 1983 ad.u.dentry = new_dentry; 1984 av = DIR__ADD_NAME | DIR__SEARCH; 1985 if (d_is_positive(new_dentry)) 1986 av |= DIR__REMOVE_NAME; 1987 rc = avc_has_perm(sid, new_dsec->sid, SECCLASS_DIR, av, &ad); 1988 if (rc) 1989 return rc; 1990 if (d_is_positive(new_dentry)) { 1991 new_isec = backing_inode_security(new_dentry); 1992 new_is_dir = d_is_dir(new_dentry); 1993 rc = avc_has_perm(sid, new_isec->sid, 1994 new_isec->sclass, 1995 (new_is_dir ? DIR__RMDIR : FILE__UNLINK), &ad); 1996 if (rc) 1997 return rc; 1998 } 1999 2000 return 0; 2001 } 2002 2003 /* Check whether a task can perform a filesystem operation. */ 2004 static int superblock_has_perm(const struct cred *cred, 2005 const struct super_block *sb, 2006 u32 perms, 2007 struct common_audit_data *ad) 2008 { 2009 struct superblock_security_struct *sbsec; 2010 u32 sid = cred_sid(cred); 2011 2012 sbsec = selinux_superblock(sb); 2013 return avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM, perms, ad); 2014 } 2015 2016 /* Convert a Linux mode and permission mask to an access vector. */ 2017 static inline u32 file_mask_to_av(int mode, int mask) 2018 { 2019 u32 av = 0; 2020 2021 if (!S_ISDIR(mode)) { 2022 if (mask & MAY_EXEC) 2023 av |= FILE__EXECUTE; 2024 if (mask & MAY_READ) 2025 av |= FILE__READ; 2026 2027 if (mask & MAY_APPEND) 2028 av |= FILE__APPEND; 2029 else if (mask & MAY_WRITE) 2030 av |= FILE__WRITE; 2031 2032 } else { 2033 if (mask & MAY_EXEC) 2034 av |= DIR__SEARCH; 2035 if (mask & MAY_WRITE) 2036 av |= DIR__WRITE; 2037 if (mask & MAY_READ) 2038 av |= DIR__READ; 2039 } 2040 2041 return av; 2042 } 2043 2044 /* Convert a Linux file to an access vector. */ 2045 static inline u32 file_to_av(const struct file *file) 2046 { 2047 u32 av = 0; 2048 2049 if (file->f_mode & FMODE_READ) 2050 av |= FILE__READ; 2051 if (file->f_mode & FMODE_WRITE) { 2052 if (file->f_flags & O_APPEND) 2053 av |= FILE__APPEND; 2054 else 2055 av |= FILE__WRITE; 2056 } 2057 if (!av) { 2058 /* 2059 * Special file opened with flags 3 for ioctl-only use. 2060 */ 2061 av = FILE__IOCTL; 2062 } 2063 2064 return av; 2065 } 2066 2067 /* 2068 * Convert a file to an access vector and include the correct 2069 * open permission. 2070 */ 2071 static inline u32 open_file_to_av(struct file *file) 2072 { 2073 u32 av = file_to_av(file); 2074 struct inode *inode = file_inode(file); 2075 2076 if (selinux_policycap_openperm() && 2077 inode->i_sb->s_magic != SOCKFS_MAGIC) 2078 av |= FILE__OPEN; 2079 2080 return av; 2081 } 2082 2083 /* Hook functions begin here. */ 2084 2085 static int selinux_binder_set_context_mgr(const struct cred *mgr) 2086 { 2087 return avc_has_perm(current_sid(), cred_sid(mgr), SECCLASS_BINDER, 2088 BINDER__SET_CONTEXT_MGR, NULL); 2089 } 2090 2091 static int selinux_binder_transaction(const struct cred *from, 2092 const struct cred *to) 2093 { 2094 u32 mysid = current_sid(); 2095 u32 fromsid = cred_sid(from); 2096 u32 tosid = cred_sid(to); 2097 int rc; 2098 2099 if (mysid != fromsid) { 2100 rc = avc_has_perm(mysid, fromsid, SECCLASS_BINDER, 2101 BINDER__IMPERSONATE, NULL); 2102 if (rc) 2103 return rc; 2104 } 2105 2106 return avc_has_perm(fromsid, tosid, 2107 SECCLASS_BINDER, BINDER__CALL, NULL); 2108 } 2109 2110 static int selinux_binder_transfer_binder(const struct cred *from, 2111 const struct cred *to) 2112 { 2113 return avc_has_perm(cred_sid(from), cred_sid(to), 2114 SECCLASS_BINDER, BINDER__TRANSFER, 2115 NULL); 2116 } 2117 2118 static int selinux_binder_transfer_file(const struct cred *from, 2119 const struct cred *to, 2120 const struct file *file) 2121 { 2122 u32 sid = cred_sid(to); 2123 struct file_security_struct *fsec = selinux_file(file); 2124 struct dentry *dentry = file->f_path.dentry; 2125 struct inode_security_struct *isec; 2126 struct common_audit_data ad; 2127 int rc; 2128 2129 ad.type = LSM_AUDIT_DATA_PATH; 2130 ad.u.path = file->f_path; 2131 2132 if (sid != fsec->sid) { 2133 rc = avc_has_perm(sid, fsec->sid, 2134 SECCLASS_FD, 2135 FD__USE, 2136 &ad); 2137 if (rc) 2138 return rc; 2139 } 2140 2141 #ifdef CONFIG_BPF_SYSCALL 2142 rc = bpf_fd_pass(file, sid); 2143 if (rc) 2144 return rc; 2145 #endif 2146 2147 if (unlikely(IS_PRIVATE(d_backing_inode(dentry)))) 2148 return 0; 2149 2150 isec = backing_inode_security(dentry); 2151 return avc_has_perm(sid, isec->sid, isec->sclass, file_to_av(file), 2152 &ad); 2153 } 2154 2155 static int selinux_ptrace_access_check(struct task_struct *child, 2156 unsigned int mode) 2157 { 2158 u32 sid = current_sid(); 2159 u32 csid = task_sid_obj(child); 2160 2161 if (mode & PTRACE_MODE_READ) 2162 return avc_has_perm(sid, csid, SECCLASS_FILE, FILE__READ, 2163 NULL); 2164 2165 return avc_has_perm(sid, csid, SECCLASS_PROCESS, PROCESS__PTRACE, 2166 NULL); 2167 } 2168 2169 static int selinux_ptrace_traceme(struct task_struct *parent) 2170 { 2171 return avc_has_perm(task_sid_obj(parent), task_sid_obj(current), 2172 SECCLASS_PROCESS, PROCESS__PTRACE, NULL); 2173 } 2174 2175 static int selinux_capget(const struct task_struct *target, kernel_cap_t *effective, 2176 kernel_cap_t *inheritable, kernel_cap_t *permitted) 2177 { 2178 return avc_has_perm(current_sid(), task_sid_obj(target), 2179 SECCLASS_PROCESS, PROCESS__GETCAP, NULL); 2180 } 2181 2182 static int selinux_capset(struct cred *new, const struct cred *old, 2183 const kernel_cap_t *effective, 2184 const kernel_cap_t *inheritable, 2185 const kernel_cap_t *permitted) 2186 { 2187 return avc_has_perm(cred_sid(old), cred_sid(new), SECCLASS_PROCESS, 2188 PROCESS__SETCAP, NULL); 2189 } 2190 2191 /* 2192 * (This comment used to live with the selinux_task_setuid hook, 2193 * which was removed). 2194 * 2195 * Since setuid only affects the current process, and since the SELinux 2196 * controls are not based on the Linux identity attributes, SELinux does not 2197 * need to control this operation. However, SELinux does control the use of 2198 * the CAP_SETUID and CAP_SETGID capabilities using the capable hook. 2199 */ 2200 2201 static int selinux_capable(const struct cred *cred, struct user_namespace *ns, 2202 int cap, unsigned int opts) 2203 { 2204 return cred_has_capability(cred, cap, opts, ns == &init_user_ns); 2205 } 2206 2207 static int selinux_quotactl(int cmds, int type, int id, const struct super_block *sb) 2208 { 2209 const struct cred *cred = current_cred(); 2210 int rc = 0; 2211 2212 if (!sb) 2213 return 0; 2214 2215 switch (cmds) { 2216 case Q_SYNC: 2217 case Q_QUOTAON: 2218 case Q_QUOTAOFF: 2219 case Q_SETINFO: 2220 case Q_SETQUOTA: 2221 case Q_XQUOTAOFF: 2222 case Q_XQUOTAON: 2223 case Q_XSETQLIM: 2224 rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAMOD, NULL); 2225 break; 2226 case Q_GETFMT: 2227 case Q_GETINFO: 2228 case Q_GETQUOTA: 2229 case Q_XGETQUOTA: 2230 case Q_XGETQSTAT: 2231 case Q_XGETQSTATV: 2232 case Q_XGETNEXTQUOTA: 2233 rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAGET, NULL); 2234 break; 2235 default: 2236 rc = 0; /* let the kernel handle invalid cmds */ 2237 break; 2238 } 2239 return rc; 2240 } 2241 2242 static int selinux_quota_on(struct dentry *dentry) 2243 { 2244 const struct cred *cred = current_cred(); 2245 2246 return dentry_has_perm(cred, dentry, FILE__QUOTAON); 2247 } 2248 2249 static int selinux_syslog(int type) 2250 { 2251 switch (type) { 2252 case SYSLOG_ACTION_READ_ALL: /* Read last kernel messages */ 2253 case SYSLOG_ACTION_SIZE_BUFFER: /* Return size of the log buffer */ 2254 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 2255 SECCLASS_SYSTEM, SYSTEM__SYSLOG_READ, NULL); 2256 case SYSLOG_ACTION_CONSOLE_OFF: /* Disable logging to console */ 2257 case SYSLOG_ACTION_CONSOLE_ON: /* Enable logging to console */ 2258 /* Set level of messages printed to console */ 2259 case SYSLOG_ACTION_CONSOLE_LEVEL: 2260 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 2261 SECCLASS_SYSTEM, SYSTEM__SYSLOG_CONSOLE, 2262 NULL); 2263 } 2264 /* All other syslog types */ 2265 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 2266 SECCLASS_SYSTEM, SYSTEM__SYSLOG_MOD, NULL); 2267 } 2268 2269 /* 2270 * Check permission for allocating a new virtual mapping. Returns 2271 * 0 if permission is granted, negative error code if not. 2272 * 2273 * Do not audit the selinux permission check, as this is applied to all 2274 * processes that allocate mappings. 2275 */ 2276 static int selinux_vm_enough_memory(struct mm_struct *mm, long pages) 2277 { 2278 return cred_has_capability(current_cred(), CAP_SYS_ADMIN, 2279 CAP_OPT_NOAUDIT, true); 2280 } 2281 2282 /* binprm security operations */ 2283 2284 static u32 ptrace_parent_sid(void) 2285 { 2286 u32 sid = 0; 2287 struct task_struct *tracer; 2288 2289 rcu_read_lock(); 2290 tracer = ptrace_parent(current); 2291 if (tracer) 2292 sid = task_sid_obj(tracer); 2293 rcu_read_unlock(); 2294 2295 return sid; 2296 } 2297 2298 static int check_nnp_nosuid(const struct linux_binprm *bprm, 2299 const struct cred_security_struct *old_crsec, 2300 const struct cred_security_struct *new_crsec) 2301 { 2302 int nnp = (bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS); 2303 int nosuid = !mnt_may_suid(bprm->file->f_path.mnt); 2304 int rc; 2305 u32 av; 2306 2307 if (!nnp && !nosuid) 2308 return 0; /* neither NNP nor nosuid */ 2309 2310 if (new_crsec->sid == old_crsec->sid) 2311 return 0; /* No change in credentials */ 2312 2313 /* 2314 * If the policy enables the nnp_nosuid_transition policy capability, 2315 * then we permit transitions under NNP or nosuid if the 2316 * policy allows the corresponding permission between 2317 * the old and new contexts. 2318 */ 2319 if (selinux_policycap_nnp_nosuid_transition()) { 2320 av = 0; 2321 if (nnp) 2322 av |= PROCESS2__NNP_TRANSITION; 2323 if (nosuid) 2324 av |= PROCESS2__NOSUID_TRANSITION; 2325 rc = avc_has_perm(old_crsec->sid, new_crsec->sid, 2326 SECCLASS_PROCESS2, av, NULL); 2327 if (!rc) 2328 return 0; 2329 } 2330 2331 /* 2332 * We also permit NNP or nosuid transitions to bounded SIDs, 2333 * i.e. SIDs that are guaranteed to only be allowed a subset 2334 * of the permissions of the current SID. 2335 */ 2336 rc = security_bounded_transition(old_crsec->sid, 2337 new_crsec->sid); 2338 if (!rc) 2339 return 0; 2340 2341 /* 2342 * On failure, preserve the errno values for NNP vs nosuid. 2343 * NNP: Operation not permitted for caller. 2344 * nosuid: Permission denied to file. 2345 */ 2346 if (nnp) 2347 return -EPERM; 2348 return -EACCES; 2349 } 2350 2351 static int selinux_bprm_creds_for_exec(struct linux_binprm *bprm) 2352 { 2353 const struct cred_security_struct *old_crsec; 2354 struct cred_security_struct *new_crsec; 2355 struct inode_security_struct *isec; 2356 struct common_audit_data ad; 2357 struct inode *inode = file_inode(bprm->file); 2358 int rc; 2359 2360 /* SELinux context only depends on initial program or script and not 2361 * the script interpreter */ 2362 2363 old_crsec = selinux_cred(current_cred()); 2364 new_crsec = selinux_cred(bprm->cred); 2365 isec = inode_security(inode); 2366 2367 if (WARN_ON(isec->sclass != SECCLASS_FILE && 2368 isec->sclass != SECCLASS_MEMFD_FILE)) 2369 return -EACCES; 2370 2371 /* Default to the current task SID. */ 2372 new_crsec->sid = old_crsec->sid; 2373 new_crsec->osid = old_crsec->sid; 2374 2375 /* Reset fs, key, and sock SIDs on execve. */ 2376 new_crsec->create_sid = 0; 2377 new_crsec->keycreate_sid = 0; 2378 new_crsec->sockcreate_sid = 0; 2379 2380 /* 2381 * Before policy is loaded, label any task outside kernel space 2382 * as SECINITSID_INIT, so that any userspace tasks surviving from 2383 * early boot end up with a label different from SECINITSID_KERNEL 2384 * (if the policy chooses to set SECINITSID_INIT != SECINITSID_KERNEL). 2385 */ 2386 if (!selinux_initialized()) { 2387 new_crsec->sid = SECINITSID_INIT; 2388 /* also clear the exec_sid just in case */ 2389 new_crsec->exec_sid = 0; 2390 return 0; 2391 } 2392 2393 if (old_crsec->exec_sid) { 2394 new_crsec->sid = old_crsec->exec_sid; 2395 /* Reset exec SID on execve. */ 2396 new_crsec->exec_sid = 0; 2397 2398 /* Fail on NNP or nosuid if not an allowed transition. */ 2399 rc = check_nnp_nosuid(bprm, old_crsec, new_crsec); 2400 if (rc) 2401 return rc; 2402 } else { 2403 /* Check for a default transition on this program. */ 2404 rc = security_transition_sid(old_crsec->sid, 2405 isec->sid, SECCLASS_PROCESS, NULL, 2406 &new_crsec->sid); 2407 if (rc) 2408 return rc; 2409 2410 /* 2411 * Fallback to old SID on NNP or nosuid if not an allowed 2412 * transition. 2413 */ 2414 rc = check_nnp_nosuid(bprm, old_crsec, new_crsec); 2415 if (rc) 2416 new_crsec->sid = old_crsec->sid; 2417 } 2418 2419 ad.type = LSM_AUDIT_DATA_FILE; 2420 ad.u.file = bprm->file; 2421 2422 if (new_crsec->sid == old_crsec->sid) { 2423 rc = avc_has_perm(old_crsec->sid, isec->sid, isec->sclass, 2424 FILE__EXECUTE_NO_TRANS, &ad); 2425 if (rc) 2426 return rc; 2427 } else { 2428 /* Check permissions for the transition. */ 2429 rc = avc_has_perm(old_crsec->sid, new_crsec->sid, 2430 SECCLASS_PROCESS, PROCESS__TRANSITION, &ad); 2431 if (rc) 2432 return rc; 2433 2434 rc = avc_has_perm(new_crsec->sid, isec->sid, isec->sclass, 2435 FILE__ENTRYPOINT, &ad); 2436 if (rc) 2437 return rc; 2438 2439 /* Check for shared state */ 2440 if (bprm->unsafe & LSM_UNSAFE_SHARE) { 2441 rc = avc_has_perm(old_crsec->sid, new_crsec->sid, 2442 SECCLASS_PROCESS, PROCESS__SHARE, 2443 NULL); 2444 if (rc) 2445 return -EPERM; 2446 } 2447 2448 /* Make sure that anyone attempting to ptrace over a task that 2449 * changes its SID has the appropriate permit */ 2450 if (bprm->unsafe & LSM_UNSAFE_PTRACE) { 2451 u32 ptsid = ptrace_parent_sid(); 2452 if (ptsid != 0) { 2453 rc = avc_has_perm(ptsid, new_crsec->sid, 2454 SECCLASS_PROCESS, 2455 PROCESS__PTRACE, NULL); 2456 if (rc) 2457 return -EPERM; 2458 } 2459 } 2460 2461 /* Clear any possibly unsafe personality bits on exec: */ 2462 bprm->per_clear |= PER_CLEAR_ON_SETID; 2463 2464 /* Enable secure mode for SIDs transitions unless 2465 the noatsecure permission is granted between 2466 the two SIDs, i.e. ahp returns 0. */ 2467 rc = avc_has_perm(old_crsec->sid, new_crsec->sid, 2468 SECCLASS_PROCESS, PROCESS__NOATSECURE, 2469 NULL); 2470 bprm->secureexec |= !!rc; 2471 } 2472 2473 return 0; 2474 } 2475 2476 static int match_file(const void *p, struct file *file, unsigned fd) 2477 { 2478 return file_has_perm(p, file, file_to_av(file)) ? fd + 1 : 0; 2479 } 2480 2481 /* Derived from fs/exec.c:flush_old_files. */ 2482 static inline void flush_unauthorized_files(const struct cred *cred, 2483 struct files_struct *files) 2484 { 2485 struct file *file, *devnull = NULL; 2486 struct tty_struct *tty; 2487 int drop_tty = 0; 2488 unsigned n; 2489 2490 tty = get_current_tty(); 2491 if (tty) { 2492 spin_lock(&tty->files_lock); 2493 if (!list_empty(&tty->tty_files)) { 2494 struct tty_file_private *file_priv; 2495 2496 /* Revalidate access to controlling tty. 2497 Use file_path_has_perm on the tty path directly 2498 rather than using file_has_perm, as this particular 2499 open file may belong to another process and we are 2500 only interested in the inode-based check here. */ 2501 file_priv = list_first_entry(&tty->tty_files, 2502 struct tty_file_private, list); 2503 file = file_priv->file; 2504 if (file_path_has_perm(cred, file, FILE__READ | FILE__WRITE)) 2505 drop_tty = 1; 2506 } 2507 spin_unlock(&tty->files_lock); 2508 tty_kref_put(tty); 2509 } 2510 /* Reset controlling tty. */ 2511 if (drop_tty) 2512 no_tty(); 2513 2514 /* Revalidate access to inherited open files. */ 2515 n = iterate_fd(files, 0, match_file, cred); 2516 if (!n) /* none found? */ 2517 return; 2518 2519 devnull = dentry_open(&selinux_null, O_RDWR, cred); 2520 if (IS_ERR(devnull)) 2521 devnull = NULL; 2522 /* replace all the matching ones with this */ 2523 do { 2524 replace_fd(n - 1, devnull, 0); 2525 } while ((n = iterate_fd(files, n, match_file, cred)) != 0); 2526 if (devnull) 2527 fput(devnull); 2528 } 2529 2530 /* 2531 * Prepare a process for imminent new credential changes due to exec 2532 */ 2533 static void selinux_bprm_committing_creds(const struct linux_binprm *bprm) 2534 { 2535 struct cred_security_struct *new_crsec; 2536 struct rlimit *rlim, *initrlim; 2537 int rc, i; 2538 2539 new_crsec = selinux_cred(bprm->cred); 2540 if (new_crsec->sid == new_crsec->osid) 2541 return; 2542 2543 /* Close files for which the new task SID is not authorized. */ 2544 flush_unauthorized_files(bprm->cred, current->files); 2545 2546 /* Always clear parent death signal on SID transitions. */ 2547 current->pdeath_signal = 0; 2548 2549 /* Check whether the new SID can inherit resource limits from the old 2550 * SID. If not, reset all soft limits to the lower of the current 2551 * task's hard limit and the init task's soft limit. 2552 * 2553 * Note that the setting of hard limits (even to lower them) can be 2554 * controlled by the setrlimit check. The inclusion of the init task's 2555 * soft limit into the computation is to avoid resetting soft limits 2556 * higher than the default soft limit for cases where the default is 2557 * lower than the hard limit, e.g. RLIMIT_CORE or RLIMIT_STACK. 2558 */ 2559 rc = avc_has_perm(new_crsec->osid, new_crsec->sid, SECCLASS_PROCESS, 2560 PROCESS__RLIMITINH, NULL); 2561 if (rc) { 2562 /* protect against do_prlimit() */ 2563 task_lock(current); 2564 for (i = 0; i < RLIM_NLIMITS; i++) { 2565 rlim = current->signal->rlim + i; 2566 initrlim = init_task.signal->rlim + i; 2567 rlim->rlim_cur = min(rlim->rlim_max, initrlim->rlim_cur); 2568 } 2569 task_unlock(current); 2570 if (IS_ENABLED(CONFIG_POSIX_TIMERS)) 2571 update_rlimit_cpu(current, rlimit(RLIMIT_CPU)); 2572 } 2573 } 2574 2575 /* 2576 * Clean up the process immediately after the installation of new credentials 2577 * due to exec 2578 */ 2579 static void selinux_bprm_committed_creds(const struct linux_binprm *bprm) 2580 { 2581 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 2582 u32 osid, sid; 2583 int rc; 2584 2585 osid = crsec->osid; 2586 sid = crsec->sid; 2587 2588 if (sid == osid) 2589 return; 2590 2591 /* Check whether the new SID can inherit signal state from the old SID. 2592 * If not, clear itimers to avoid subsequent signal generation and 2593 * flush and unblock signals. 2594 * 2595 * This must occur _after_ the task SID has been updated so that any 2596 * kill done after the flush will be checked against the new SID. 2597 */ 2598 rc = avc_has_perm(osid, sid, SECCLASS_PROCESS, PROCESS__SIGINH, NULL); 2599 if (rc) { 2600 clear_itimer(); 2601 2602 spin_lock_irq(&unrcu_pointer(current->sighand)->siglock); 2603 if (!fatal_signal_pending(current)) { 2604 flush_sigqueue(¤t->pending); 2605 flush_sigqueue(¤t->signal->shared_pending); 2606 flush_signal_handlers(current, 1); 2607 sigemptyset(¤t->blocked); 2608 recalc_sigpending(); 2609 } 2610 spin_unlock_irq(&unrcu_pointer(current->sighand)->siglock); 2611 } 2612 2613 /* Wake up the parent if it is waiting so that it can recheck 2614 * wait permission to the new task SID. */ 2615 read_lock(&tasklist_lock); 2616 __wake_up_parent(current, unrcu_pointer(current->real_parent)); 2617 read_unlock(&tasklist_lock); 2618 } 2619 2620 /* superblock security operations */ 2621 2622 static int selinux_sb_alloc_security(struct super_block *sb) 2623 { 2624 struct superblock_security_struct *sbsec = selinux_superblock(sb); 2625 2626 mutex_init(&sbsec->lock); 2627 INIT_LIST_HEAD(&sbsec->isec_head); 2628 spin_lock_init(&sbsec->isec_lock); 2629 sbsec->sid = SECINITSID_UNLABELED; 2630 sbsec->def_sid = SECINITSID_FILE; 2631 sbsec->mntpoint_sid = SECINITSID_UNLABELED; 2632 sbsec->creator_sid = SECINITSID_UNLABELED; 2633 2634 return 0; 2635 } 2636 2637 static inline int opt_len(const char *s) 2638 { 2639 bool open_quote = false; 2640 int len; 2641 char c; 2642 2643 for (len = 0; (c = s[len]) != '\0'; len++) { 2644 if (c == '"') 2645 open_quote = !open_quote; 2646 if (c == ',' && !open_quote) 2647 break; 2648 } 2649 return len; 2650 } 2651 2652 static int selinux_sb_eat_lsm_opts(char *options, void **mnt_opts) 2653 { 2654 char *from = options; 2655 char *to = options; 2656 bool first = true; 2657 int rc; 2658 2659 while (1) { 2660 int len = opt_len(from); 2661 int token; 2662 char *arg = NULL; 2663 2664 token = match_opt_prefix(from, len, &arg); 2665 2666 if (token != Opt_error) { 2667 char *p, *q; 2668 2669 /* strip quotes */ 2670 if (arg) { 2671 for (p = q = arg; p < from + len; p++) { 2672 char c = *p; 2673 if (c != '"') 2674 *q++ = c; 2675 } 2676 arg = kmemdup_nul(arg, q - arg, GFP_KERNEL); 2677 if (!arg) { 2678 rc = -ENOMEM; 2679 goto free_opt; 2680 } 2681 } 2682 rc = selinux_add_opt(token, arg, mnt_opts); 2683 kfree(arg); 2684 arg = NULL; 2685 if (unlikely(rc)) { 2686 goto free_opt; 2687 } 2688 } else { 2689 if (!first) { // copy with preceding comma 2690 from--; 2691 len++; 2692 } 2693 if (to != from) 2694 memmove(to, from, len); 2695 to += len; 2696 first = false; 2697 } 2698 if (!from[len]) 2699 break; 2700 from += len + 1; 2701 } 2702 *to = '\0'; 2703 return 0; 2704 2705 free_opt: 2706 if (*mnt_opts) { 2707 selinux_free_mnt_opts(*mnt_opts); 2708 *mnt_opts = NULL; 2709 } 2710 return rc; 2711 } 2712 2713 static int selinux_sb_mnt_opts_compat(struct super_block *sb, void *mnt_opts) 2714 { 2715 struct selinux_mnt_opts *opts = mnt_opts; 2716 struct superblock_security_struct *sbsec = selinux_superblock(sb); 2717 2718 /* 2719 * Superblock not initialized (i.e. no options) - reject if any 2720 * options specified, otherwise accept. 2721 */ 2722 if (!(sbsec->flags & SE_SBINITIALIZED)) 2723 return opts ? 1 : 0; 2724 2725 /* 2726 * Superblock initialized and no options specified - reject if 2727 * superblock has any options set, otherwise accept. 2728 */ 2729 if (!opts) 2730 return (sbsec->flags & SE_MNTMASK) ? 1 : 0; 2731 2732 if (opts->fscontext_sid) { 2733 if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, 2734 opts->fscontext_sid)) 2735 return 1; 2736 } 2737 if (opts->context_sid) { 2738 if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, 2739 opts->context_sid)) 2740 return 1; 2741 } 2742 if (opts->rootcontext_sid) { 2743 struct inode_security_struct *root_isec; 2744 2745 root_isec = backing_inode_security(sb->s_root); 2746 if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, 2747 opts->rootcontext_sid)) 2748 return 1; 2749 } 2750 if (opts->defcontext_sid) { 2751 if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, 2752 opts->defcontext_sid)) 2753 return 1; 2754 } 2755 return 0; 2756 } 2757 2758 static int selinux_sb_remount(struct super_block *sb, void *mnt_opts) 2759 { 2760 struct selinux_mnt_opts *opts = mnt_opts; 2761 struct superblock_security_struct *sbsec = selinux_superblock(sb); 2762 2763 if (!(sbsec->flags & SE_SBINITIALIZED)) 2764 return 0; 2765 2766 if (!opts) 2767 return 0; 2768 2769 if (opts->fscontext_sid) { 2770 if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, 2771 opts->fscontext_sid)) 2772 goto out_bad_option; 2773 } 2774 if (opts->context_sid) { 2775 if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, 2776 opts->context_sid)) 2777 goto out_bad_option; 2778 } 2779 if (opts->rootcontext_sid) { 2780 struct inode_security_struct *root_isec; 2781 root_isec = backing_inode_security(sb->s_root); 2782 if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, 2783 opts->rootcontext_sid)) 2784 goto out_bad_option; 2785 } 2786 if (opts->defcontext_sid) { 2787 if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, 2788 opts->defcontext_sid)) 2789 goto out_bad_option; 2790 } 2791 return 0; 2792 2793 out_bad_option: 2794 pr_warn("SELinux: unable to change security options " 2795 "during remount (dev %s, type=%s)\n", sb->s_id, 2796 sb->s_type->name); 2797 return -EINVAL; 2798 } 2799 2800 static int selinux_sb_kern_mount(const struct super_block *sb) 2801 { 2802 const struct cred *cred = current_cred(); 2803 struct common_audit_data ad; 2804 2805 ad.type = LSM_AUDIT_DATA_DENTRY; 2806 ad.u.dentry = sb->s_root; 2807 return superblock_has_perm(cred, sb, FILESYSTEM__MOUNT, &ad); 2808 } 2809 2810 static int selinux_sb_statfs(struct dentry *dentry) 2811 { 2812 const struct cred *cred = current_cred(); 2813 struct common_audit_data ad; 2814 2815 ad.type = LSM_AUDIT_DATA_DENTRY; 2816 ad.u.dentry = dentry->d_sb->s_root; 2817 return superblock_has_perm(cred, dentry->d_sb, FILESYSTEM__GETATTR, &ad); 2818 } 2819 2820 static int selinux_mount(const char *dev_name, 2821 const struct path *path, 2822 const char *type, 2823 unsigned long flags, 2824 void *data) 2825 { 2826 const struct cred *cred = current_cred(); 2827 2828 if (flags & MS_REMOUNT) 2829 return superblock_has_perm(cred, path->dentry->d_sb, 2830 FILESYSTEM__REMOUNT, NULL); 2831 else 2832 return path_has_perm(cred, path, FILE__MOUNTON); 2833 } 2834 2835 static int selinux_move_mount(const struct path *from_path, 2836 const struct path *to_path) 2837 { 2838 const struct cred *cred = current_cred(); 2839 2840 return path_has_perm(cred, to_path, FILE__MOUNTON); 2841 } 2842 2843 static int selinux_umount(struct vfsmount *mnt, int flags) 2844 { 2845 const struct cred *cred = current_cred(); 2846 2847 return superblock_has_perm(cred, mnt->mnt_sb, 2848 FILESYSTEM__UNMOUNT, NULL); 2849 } 2850 2851 static int selinux_fs_context_submount(struct fs_context *fc, 2852 struct super_block *reference) 2853 { 2854 const struct superblock_security_struct *sbsec = selinux_superblock(reference); 2855 struct selinux_mnt_opts *opts; 2856 2857 /* 2858 * Ensure that fc->security remains NULL when no options are set 2859 * as expected by selinux_set_mnt_opts(). 2860 */ 2861 if (!(sbsec->flags & (FSCONTEXT_MNT|CONTEXT_MNT|DEFCONTEXT_MNT))) 2862 return 0; 2863 2864 opts = kzalloc_obj(*opts); 2865 if (!opts) 2866 return -ENOMEM; 2867 2868 if (sbsec->flags & FSCONTEXT_MNT) 2869 opts->fscontext_sid = sbsec->sid; 2870 if (sbsec->flags & CONTEXT_MNT) 2871 opts->context_sid = sbsec->mntpoint_sid; 2872 if (sbsec->flags & DEFCONTEXT_MNT) 2873 opts->defcontext_sid = sbsec->def_sid; 2874 fc->security = opts; 2875 return 0; 2876 } 2877 2878 static int selinux_fs_context_dup(struct fs_context *fc, 2879 struct fs_context *src_fc) 2880 { 2881 const struct selinux_mnt_opts *src = src_fc->security; 2882 2883 if (!src) 2884 return 0; 2885 2886 fc->security = kmemdup(src, sizeof(*src), GFP_KERNEL); 2887 return fc->security ? 0 : -ENOMEM; 2888 } 2889 2890 static const struct fs_parameter_spec selinux_fs_parameters[] = { 2891 fsparam_string(CONTEXT_STR, Opt_context), 2892 fsparam_string(DEFCONTEXT_STR, Opt_defcontext), 2893 fsparam_string(FSCONTEXT_STR, Opt_fscontext), 2894 fsparam_string(ROOTCONTEXT_STR, Opt_rootcontext), 2895 fsparam_flag (SECLABEL_STR, Opt_seclabel), 2896 {} 2897 }; 2898 2899 static int selinux_fs_context_parse_param(struct fs_context *fc, 2900 struct fs_parameter *param) 2901 { 2902 struct fs_parse_result result; 2903 int opt; 2904 2905 opt = fs_parse(fc, selinux_fs_parameters, param, &result); 2906 if (opt < 0) 2907 return opt; 2908 2909 return selinux_add_opt(opt, param->string, &fc->security); 2910 } 2911 2912 /* inode security operations */ 2913 2914 static int selinux_inode_alloc_security(struct inode *inode) 2915 { 2916 struct inode_security_struct *isec = selinux_inode(inode); 2917 u32 sid = current_sid(); 2918 2919 spin_lock_init(&isec->lock); 2920 INIT_LIST_HEAD(&isec->list); 2921 isec->inode = inode; 2922 isec->sid = SECINITSID_UNLABELED; 2923 isec->sclass = SECCLASS_FILE; 2924 isec->task_sid = sid; 2925 isec->initialized = LABEL_INVALID; 2926 2927 return 0; 2928 } 2929 2930 static void selinux_inode_free_security(struct inode *inode) 2931 { 2932 inode_free_security(inode); 2933 } 2934 2935 static int selinux_dentry_init_security(struct dentry *dentry, int mode, 2936 const struct qstr *name, 2937 const char **xattr_name, 2938 struct lsm_context *cp) 2939 { 2940 u32 newsid; 2941 int rc; 2942 2943 rc = selinux_determine_inode_label(selinux_cred(current_cred()), 2944 d_inode(dentry->d_parent), name, 2945 inode_mode_to_security_class(mode), 2946 &newsid); 2947 if (rc) 2948 return rc; 2949 2950 if (xattr_name) 2951 *xattr_name = XATTR_NAME_SELINUX; 2952 2953 cp->id = LSM_ID_SELINUX; 2954 return security_sid_to_context(newsid, &cp->context, &cp->len); 2955 } 2956 2957 static int selinux_dentry_create_files_as(struct dentry *dentry, int mode, 2958 const struct qstr *name, 2959 const struct cred *old, 2960 struct cred *new) 2961 { 2962 u32 newsid; 2963 int rc; 2964 struct cred_security_struct *crsec; 2965 2966 rc = selinux_determine_inode_label(selinux_cred(old), 2967 d_inode(dentry->d_parent), name, 2968 inode_mode_to_security_class(mode), 2969 &newsid); 2970 if (rc) 2971 return rc; 2972 2973 crsec = selinux_cred(new); 2974 crsec->create_sid = newsid; 2975 return 0; 2976 } 2977 2978 static int selinux_inode_init_security(struct inode *inode, struct inode *dir, 2979 const struct qstr *qstr, 2980 struct xattr *xattrs, int *xattr_count) 2981 { 2982 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 2983 struct superblock_security_struct *sbsec; 2984 struct xattr *xattr; 2985 u32 newsid, clen; 2986 u16 newsclass; 2987 int rc; 2988 char *context; 2989 2990 sbsec = selinux_superblock(dir->i_sb); 2991 2992 if (!selinux_initialized() || 2993 !(sbsec->flags & SBLABEL_MNT)) 2994 return -EOPNOTSUPP; 2995 2996 newsid = crsec->create_sid; 2997 newsclass = inode_mode_to_security_class(inode->i_mode); 2998 rc = selinux_determine_inode_label(crsec, dir, qstr, newsclass, &newsid); 2999 if (rc) 3000 return rc; 3001 3002 /* Possibly defer initialization to selinux_complete_init. */ 3003 if (sbsec->flags & SE_SBINITIALIZED) { 3004 struct inode_security_struct *isec = selinux_inode(inode); 3005 isec->sclass = newsclass; 3006 isec->sid = newsid; 3007 isec->initialized = LABEL_INITIALIZED; 3008 } 3009 3010 xattr = lsm_get_xattr_slot(xattrs, xattr_count); 3011 if (xattr) { 3012 rc = security_sid_to_context_force(newsid, 3013 &context, &clen); 3014 if (rc) 3015 return rc; 3016 xattr->value = context; 3017 xattr->value_len = clen; 3018 xattr->name = XATTR_SELINUX_SUFFIX; 3019 } 3020 3021 return 0; 3022 } 3023 3024 static int selinux_inode_init_security_anon(struct inode *inode, 3025 const struct qstr *name, 3026 const struct inode *context_inode) 3027 { 3028 u32 sid = current_sid(); 3029 struct common_audit_data ad; 3030 struct inode_security_struct *isec; 3031 int rc; 3032 bool is_memfd = false; 3033 3034 if (unlikely(!selinux_initialized())) 3035 return 0; 3036 3037 if (name != NULL && name->name != NULL && 3038 !strcmp(name->name, MEMFD_ANON_NAME)) { 3039 if (!selinux_policycap_memfd_class()) 3040 return 0; 3041 is_memfd = true; 3042 } 3043 3044 isec = selinux_inode(inode); 3045 3046 /* 3047 * We only get here once per ephemeral inode. The inode has 3048 * been initialized via inode_alloc_security but is otherwise 3049 * untouched. 3050 */ 3051 3052 if (context_inode) { 3053 struct inode_security_struct *context_isec = 3054 selinux_inode(context_inode); 3055 if (context_isec->initialized != LABEL_INITIALIZED) { 3056 pr_err("SELinux: context_inode is not initialized\n"); 3057 return -EACCES; 3058 } 3059 3060 isec->sclass = context_isec->sclass; 3061 isec->sid = context_isec->sid; 3062 } else { 3063 if (is_memfd) 3064 isec->sclass = SECCLASS_MEMFD_FILE; 3065 else 3066 isec->sclass = SECCLASS_ANON_INODE; 3067 rc = security_transition_sid( 3068 sid, sid, 3069 isec->sclass, name, &isec->sid); 3070 if (rc) 3071 return rc; 3072 } 3073 3074 isec->initialized = LABEL_INITIALIZED; 3075 /* 3076 * Now that we've initialized security, check whether we're 3077 * allowed to actually create this type of anonymous inode. 3078 */ 3079 3080 ad.type = LSM_AUDIT_DATA_ANONINODE; 3081 ad.u.anonclass = name ? (const char *)name->name : "?"; 3082 3083 return avc_has_perm(sid, 3084 isec->sid, 3085 isec->sclass, 3086 FILE__CREATE, 3087 &ad); 3088 } 3089 3090 static int selinux_inode_create(struct inode *dir, struct dentry *dentry, umode_t mode) 3091 { 3092 return may_create(dir, dentry, SECCLASS_FILE); 3093 } 3094 3095 static int selinux_inode_link(struct dentry *old_dentry, struct inode *dir, struct dentry *new_dentry) 3096 { 3097 return may_link(dir, old_dentry, MAY_LINK); 3098 } 3099 3100 static int selinux_inode_unlink(struct inode *dir, struct dentry *dentry) 3101 { 3102 return may_link(dir, dentry, MAY_UNLINK); 3103 } 3104 3105 static int selinux_inode_symlink(struct inode *dir, struct dentry *dentry, const char *name) 3106 { 3107 return may_create(dir, dentry, SECCLASS_LNK_FILE); 3108 } 3109 3110 static int selinux_inode_mkdir(struct inode *dir, struct dentry *dentry, umode_t mask) 3111 { 3112 return may_create(dir, dentry, SECCLASS_DIR); 3113 } 3114 3115 static int selinux_inode_rmdir(struct inode *dir, struct dentry *dentry) 3116 { 3117 return may_link(dir, dentry, MAY_RMDIR); 3118 } 3119 3120 static int selinux_inode_mknod(struct inode *dir, struct dentry *dentry, umode_t mode, dev_t dev) 3121 { 3122 return may_create(dir, dentry, inode_mode_to_security_class(mode)); 3123 } 3124 3125 static int selinux_inode_rename(struct inode *old_inode, struct dentry *old_dentry, 3126 struct inode *new_inode, struct dentry *new_dentry) 3127 { 3128 return may_rename(old_inode, old_dentry, new_inode, new_dentry); 3129 } 3130 3131 static int selinux_inode_readlink(struct dentry *dentry) 3132 { 3133 const struct cred *cred = current_cred(); 3134 3135 return dentry_has_perm(cred, dentry, FILE__READ); 3136 } 3137 3138 static int selinux_inode_follow_link(struct dentry *dentry, struct inode *inode, 3139 bool rcu) 3140 { 3141 struct common_audit_data ad; 3142 struct inode_security_struct *isec; 3143 u32 sid = current_sid(); 3144 3145 ad.type = LSM_AUDIT_DATA_DENTRY; 3146 ad.u.dentry = dentry; 3147 isec = inode_security_rcu(inode, rcu); 3148 if (IS_ERR(isec)) 3149 return PTR_ERR(isec); 3150 3151 return avc_has_perm(sid, isec->sid, isec->sclass, FILE__READ, &ad); 3152 } 3153 3154 static noinline int audit_inode_permission(struct inode *inode, 3155 u32 perms, u32 audited, u32 denied, 3156 int result) 3157 { 3158 struct common_audit_data ad; 3159 struct inode_security_struct *isec = selinux_inode(inode); 3160 3161 ad.type = LSM_AUDIT_DATA_INODE; 3162 ad.u.inode = inode; 3163 3164 return slow_avc_audit(current_sid(), isec->sid, isec->sclass, perms, 3165 audited, denied, result, &ad); 3166 } 3167 3168 /** 3169 * task_avdcache_reset - Reset the task's AVD cache 3170 * @tsec: the task's security state 3171 * 3172 * Clear the task's AVD cache in @tsec and reset it to the current policy's 3173 * and task's info. 3174 */ 3175 static inline void task_avdcache_reset(struct task_security_struct *tsec) 3176 { 3177 memset(&tsec->avdcache.dir, 0, sizeof(tsec->avdcache.dir)); 3178 tsec->avdcache.sid = current_sid(); 3179 tsec->avdcache.seqno = avc_policy_seqno(); 3180 tsec->avdcache.dir_spot = TSEC_AVDC_DIR_SIZE - 1; 3181 } 3182 3183 /** 3184 * task_avdcache_search - Search the task's AVD cache 3185 * @tsec: the task's security state 3186 * @isec: the inode to search for in the cache 3187 * @avdc: matching avd cache entry returned to the caller 3188 * 3189 * Search @tsec for a AVD cache entry that matches @isec and return it to the 3190 * caller via @avdc. Returns 0 if a match is found, negative values otherwise. 3191 */ 3192 static inline int task_avdcache_search(struct task_security_struct *tsec, 3193 struct inode_security_struct *isec, 3194 struct avdc_entry **avdc) 3195 { 3196 int orig, iter; 3197 3198 /* focused on path walk optimization, only cache directories */ 3199 if (isec->sclass != SECCLASS_DIR) 3200 return -ENOENT; 3201 3202 if (unlikely(current_sid() != tsec->avdcache.sid || 3203 tsec->avdcache.seqno != avc_policy_seqno())) { 3204 task_avdcache_reset(tsec); 3205 return -ENOENT; 3206 } 3207 3208 orig = iter = tsec->avdcache.dir_spot; 3209 do { 3210 if (tsec->avdcache.dir[iter].isid == isec->sid) { 3211 /* cache hit */ 3212 tsec->avdcache.dir_spot = iter; 3213 *avdc = &tsec->avdcache.dir[iter]; 3214 return 0; 3215 } 3216 iter = (iter - 1) & (TSEC_AVDC_DIR_SIZE - 1); 3217 } while (iter != orig); 3218 3219 return -ENOENT; 3220 } 3221 3222 /** 3223 * task_avdcache_update - Update the task's AVD cache 3224 * @tsec: the task's security state 3225 * @isec: the inode associated with the cache entry 3226 * @avd: the AVD to cache 3227 * 3228 * Update the AVD cache in @tsec with the @avd info associated 3229 * with @isec. 3230 */ 3231 static inline void task_avdcache_update(struct task_security_struct *tsec, 3232 struct inode_security_struct *isec, 3233 struct av_decision *avd) 3234 { 3235 int spot; 3236 3237 /* focused on path walk optimization, only cache directories */ 3238 if (isec->sclass != SECCLASS_DIR) 3239 return; 3240 3241 /* update cache */ 3242 spot = (tsec->avdcache.dir_spot + 1) & (TSEC_AVDC_DIR_SIZE - 1); 3243 tsec->avdcache.dir_spot = spot; 3244 tsec->avdcache.dir[spot].isid = isec->sid; 3245 tsec->avdcache.dir[spot].avd = *avd; 3246 tsec->avdcache.permissive_neveraudit = 3247 (avd->flags == (AVD_FLAGS_PERMISSIVE|AVD_FLAGS_NEVERAUDIT)); 3248 } 3249 3250 /** 3251 * selinux_inode_permission - Check if the current task can access an inode 3252 * @inode: the inode that is being accessed 3253 * @requested: the accesses being requested 3254 * 3255 * Check if the current task is allowed to access @inode according to 3256 * @requested. Returns 0 if allowed, negative values otherwise. 3257 */ 3258 static int selinux_inode_permission(struct inode *inode, int requested) 3259 { 3260 int mask; 3261 u32 perms; 3262 u32 sid = current_sid(); 3263 struct task_security_struct *tsec; 3264 struct inode_security_struct *isec; 3265 struct avdc_entry *avdc; 3266 struct av_decision avd, *avdp = &avd; 3267 int rc, rc2; 3268 u32 audited, denied; 3269 3270 mask = requested & (MAY_READ|MAY_WRITE|MAY_EXEC|MAY_APPEND); 3271 3272 /* No permission to check. Existence test. */ 3273 if (!mask) 3274 return 0; 3275 3276 tsec = selinux_task(current); 3277 if (task_avdcache_permnoaudit(tsec, sid)) 3278 return 0; 3279 3280 isec = inode_security_rcu(inode, requested & MAY_NOT_BLOCK); 3281 if (IS_ERR(isec)) 3282 return PTR_ERR(isec); 3283 perms = file_mask_to_av(inode->i_mode, mask); 3284 3285 rc = task_avdcache_search(tsec, isec, &avdc); 3286 if (likely(!rc)) { 3287 /* Cache hit. */ 3288 avdp = &avdc->avd; 3289 denied = perms & ~avdp->allowed; 3290 if (unlikely(denied) && enforcing_enabled() && 3291 !(avdp->flags & AVD_FLAGS_PERMISSIVE)) 3292 rc = -EACCES; 3293 } else { 3294 /* Cache miss. */ 3295 rc = avc_has_perm_noaudit(sid, isec->sid, isec->sclass, 3296 perms, 0, avdp); 3297 task_avdcache_update(tsec, isec, avdp); 3298 } 3299 3300 audited = avc_audit_required(perms, avdp, rc, 3301 (requested & MAY_ACCESS) ? 3302 FILE__AUDIT_ACCESS : 0, &denied); 3303 if (likely(!audited)) 3304 return rc; 3305 3306 rc2 = audit_inode_permission(inode, perms, audited, denied, rc); 3307 if (rc2) 3308 return rc2; 3309 3310 return rc; 3311 } 3312 3313 static int selinux_inode_setattr(struct mnt_idmap *idmap, struct dentry *dentry, 3314 struct iattr *iattr) 3315 { 3316 const struct cred *cred = current_cred(); 3317 struct inode *inode = d_backing_inode(dentry); 3318 unsigned int ia_valid = iattr->ia_valid; 3319 u32 av = FILE__WRITE; 3320 3321 /* ATTR_FORCE is just used for ATTR_KILL_S[UG]ID. */ 3322 if (ia_valid & ATTR_FORCE) { 3323 ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID | ATTR_MODE | 3324 ATTR_FORCE); 3325 if (!ia_valid) 3326 return 0; 3327 } 3328 3329 if (ia_valid & (ATTR_MODE | ATTR_UID | ATTR_GID | 3330 ATTR_ATIME_SET | ATTR_MTIME_SET | ATTR_TIMES_SET)) 3331 return dentry_has_perm(cred, dentry, FILE__SETATTR); 3332 3333 if (selinux_policycap_openperm() && 3334 inode->i_sb->s_magic != SOCKFS_MAGIC && 3335 (ia_valid & ATTR_SIZE) && 3336 !(ia_valid & ATTR_FILE)) 3337 av |= FILE__OPEN; 3338 3339 return dentry_has_perm(cred, dentry, av); 3340 } 3341 3342 static int selinux_inode_getattr(const struct path *path) 3343 { 3344 struct task_security_struct *tsec; 3345 3346 tsec = selinux_task(current); 3347 3348 if (task_avdcache_permnoaudit(tsec, current_sid())) 3349 return 0; 3350 3351 return path_has_perm(current_cred(), path, FILE__GETATTR); 3352 } 3353 3354 static bool has_cap_mac_admin(bool audit) 3355 { 3356 const struct cred *cred = current_cred(); 3357 unsigned int opts = audit ? CAP_OPT_NONE : CAP_OPT_NOAUDIT; 3358 3359 if (cap_capable(cred, &init_user_ns, CAP_MAC_ADMIN, opts)) 3360 return false; 3361 if (cred_has_capability(cred, CAP_MAC_ADMIN, opts, true)) 3362 return false; 3363 return true; 3364 } 3365 3366 /** 3367 * selinux_inode_xattr_skipcap - Skip the xattr capability checks? 3368 * @name: name of the xattr 3369 * 3370 * Returns 1 to indicate that SELinux "owns" the access control rights to xattrs 3371 * named @name; the LSM layer should avoid enforcing any traditional 3372 * capability based access controls on this xattr. Returns 0 to indicate that 3373 * SELinux does not "own" the access control rights to xattrs named @name and is 3374 * deferring to the LSM layer for further access controls, including capability 3375 * based controls. 3376 */ 3377 static int selinux_inode_xattr_skipcap(const char *name) 3378 { 3379 /* require capability check if not a selinux xattr */ 3380 return !strcmp(name, XATTR_NAME_SELINUX); 3381 } 3382 3383 static int selinux_inode_setxattr(struct mnt_idmap *idmap, 3384 struct dentry *dentry, const char *name, 3385 const void *value, size_t size, int flags) 3386 { 3387 struct inode *inode = d_backing_inode(dentry); 3388 struct inode_security_struct *isec; 3389 struct superblock_security_struct *sbsec; 3390 struct common_audit_data ad; 3391 u32 newsid, sid = current_sid(); 3392 int rc = 0; 3393 3394 /* if not a selinux xattr, only check the ordinary setattr perm */ 3395 if (strcmp(name, XATTR_NAME_SELINUX)) 3396 return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); 3397 3398 if (!selinux_initialized()) 3399 return (inode_owner_or_capable(idmap, inode) ? 0 : -EPERM); 3400 3401 sbsec = selinux_superblock(inode->i_sb); 3402 if (!(sbsec->flags & SBLABEL_MNT)) 3403 return -EOPNOTSUPP; 3404 3405 if (!inode_owner_or_capable(idmap, inode)) 3406 return -EPERM; 3407 3408 ad.type = LSM_AUDIT_DATA_DENTRY; 3409 ad.u.dentry = dentry; 3410 3411 isec = backing_inode_security(dentry); 3412 rc = avc_has_perm(sid, isec->sid, isec->sclass, 3413 FILE__RELABELFROM, &ad); 3414 if (rc) 3415 return rc; 3416 3417 rc = security_context_to_sid(value, size, &newsid, 3418 GFP_KERNEL); 3419 if (rc == -EINVAL) { 3420 if (!has_cap_mac_admin(true)) { 3421 struct audit_buffer *ab; 3422 size_t audit_size; 3423 3424 /* We strip a nul only if it is at the end, otherwise the 3425 * context contains a nul and we should audit that */ 3426 if (value) { 3427 const char *str = value; 3428 3429 if (str[size - 1] == '\0') 3430 audit_size = size - 1; 3431 else 3432 audit_size = size; 3433 } else { 3434 audit_size = 0; 3435 } 3436 ab = audit_log_start(audit_context(), 3437 GFP_ATOMIC, AUDIT_SELINUX_ERR); 3438 if (!ab) 3439 return rc; 3440 audit_log_format(ab, "op=setxattr invalid_context="); 3441 audit_log_n_untrustedstring(ab, value, audit_size); 3442 audit_log_end(ab); 3443 3444 return rc; 3445 } 3446 rc = security_context_to_sid_force(value, 3447 size, &newsid); 3448 } 3449 if (rc) 3450 return rc; 3451 3452 rc = avc_has_perm(sid, newsid, isec->sclass, 3453 FILE__RELABELTO, &ad); 3454 if (rc) 3455 return rc; 3456 3457 rc = security_validate_transition(isec->sid, newsid, 3458 sid, isec->sclass); 3459 if (rc) 3460 return rc; 3461 3462 return avc_has_perm(newsid, 3463 sbsec->sid, 3464 SECCLASS_FILESYSTEM, 3465 FILESYSTEM__ASSOCIATE, 3466 &ad); 3467 } 3468 3469 static int selinux_inode_set_acl(struct mnt_idmap *idmap, 3470 struct dentry *dentry, const char *acl_name, 3471 struct posix_acl *kacl) 3472 { 3473 return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); 3474 } 3475 3476 static int selinux_inode_get_acl(struct mnt_idmap *idmap, 3477 struct dentry *dentry, const char *acl_name) 3478 { 3479 return dentry_has_perm(current_cred(), dentry, FILE__GETATTR); 3480 } 3481 3482 static int selinux_inode_remove_acl(struct mnt_idmap *idmap, 3483 struct dentry *dentry, const char *acl_name) 3484 { 3485 return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); 3486 } 3487 3488 static void selinux_inode_post_setxattr(struct dentry *dentry, const char *name, 3489 const void *value, size_t size, 3490 int flags) 3491 { 3492 struct inode *inode = d_backing_inode(dentry); 3493 struct inode_security_struct *isec; 3494 u32 newsid; 3495 int rc; 3496 3497 if (strcmp(name, XATTR_NAME_SELINUX)) { 3498 /* Not an attribute we recognize, so nothing to do. */ 3499 return; 3500 } 3501 3502 if (!selinux_initialized()) { 3503 /* If we haven't even been initialized, then we can't validate 3504 * against a policy, so leave the label as invalid. It may 3505 * resolve to a valid label on the next revalidation try if 3506 * we've since initialized. 3507 */ 3508 return; 3509 } 3510 3511 rc = security_context_to_sid_force(value, size, 3512 &newsid); 3513 if (rc) { 3514 pr_err("SELinux: unable to map context to SID" 3515 "for (%s, %llu), rc=%d\n", 3516 inode->i_sb->s_id, inode->i_ino, -rc); 3517 return; 3518 } 3519 3520 isec = backing_inode_security(dentry); 3521 spin_lock(&isec->lock); 3522 isec->sclass = inode_mode_to_security_class(inode->i_mode); 3523 isec->sid = newsid; 3524 isec->initialized = LABEL_INITIALIZED; 3525 spin_unlock(&isec->lock); 3526 } 3527 3528 static int selinux_inode_getxattr(struct dentry *dentry, const char *name) 3529 { 3530 const struct cred *cred = current_cred(); 3531 3532 return dentry_has_perm(cred, dentry, FILE__GETATTR); 3533 } 3534 3535 static int selinux_inode_listxattr(struct dentry *dentry) 3536 { 3537 const struct cred *cred = current_cred(); 3538 3539 return dentry_has_perm(cred, dentry, FILE__GETATTR); 3540 } 3541 3542 static int selinux_inode_removexattr(struct mnt_idmap *idmap, 3543 struct dentry *dentry, const char *name) 3544 { 3545 /* if not a selinux xattr, only check the ordinary setattr perm */ 3546 if (strcmp(name, XATTR_NAME_SELINUX)) 3547 return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); 3548 3549 if (!selinux_initialized()) 3550 return 0; 3551 3552 /* No one is allowed to remove a SELinux security label. 3553 You can change the label, but all data must be labeled. */ 3554 return -EACCES; 3555 } 3556 3557 static int selinux_inode_file_setattr(struct dentry *dentry, 3558 struct file_kattr *fa) 3559 { 3560 return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); 3561 } 3562 3563 static int selinux_inode_file_getattr(struct dentry *dentry, 3564 struct file_kattr *fa) 3565 { 3566 return dentry_has_perm(current_cred(), dentry, FILE__GETATTR); 3567 } 3568 3569 static int selinux_path_notify(const struct path *path, u64 mask, 3570 unsigned int obj_type) 3571 { 3572 int ret; 3573 u32 perm; 3574 3575 struct common_audit_data ad; 3576 3577 ad.type = LSM_AUDIT_DATA_PATH; 3578 ad.u.path = *path; 3579 3580 /* 3581 * Set permission needed based on the type of mark being set. 3582 * Performs an additional check for sb watches. 3583 */ 3584 switch (obj_type) { 3585 case FSNOTIFY_OBJ_TYPE_VFSMOUNT: 3586 perm = FILE__WATCH_MOUNT; 3587 break; 3588 case FSNOTIFY_OBJ_TYPE_SB: 3589 perm = FILE__WATCH_SB; 3590 ret = superblock_has_perm(current_cred(), path->dentry->d_sb, 3591 FILESYSTEM__WATCH, &ad); 3592 if (ret) 3593 return ret; 3594 break; 3595 case FSNOTIFY_OBJ_TYPE_INODE: 3596 perm = FILE__WATCH; 3597 break; 3598 case FSNOTIFY_OBJ_TYPE_MNTNS: 3599 perm = FILE__WATCH_MOUNTNS; 3600 break; 3601 default: 3602 return -EINVAL; 3603 } 3604 3605 /* blocking watches require the file:watch_with_perm permission */ 3606 if (mask & (ALL_FSNOTIFY_PERM_EVENTS)) 3607 perm |= FILE__WATCH_WITH_PERM; 3608 3609 /* watches on read-like events need the file:watch_reads permission */ 3610 if (mask & (FS_ACCESS | FS_ACCESS_PERM | FS_PRE_ACCESS | 3611 FS_CLOSE_NOWRITE)) 3612 perm |= FILE__WATCH_READS; 3613 3614 return path_has_perm(current_cred(), path, perm); 3615 } 3616 3617 /* 3618 * Copy the inode security context value to the user. 3619 * 3620 * Permission check is handled by selinux_inode_getxattr hook. 3621 */ 3622 static int selinux_inode_getsecurity(struct mnt_idmap *idmap, 3623 struct inode *inode, const char *name, 3624 void **buffer, bool alloc) 3625 { 3626 u32 size; 3627 int error; 3628 char *context = NULL; 3629 struct inode_security_struct *isec; 3630 3631 /* 3632 * If we're not initialized yet, then we can't validate contexts, so 3633 * just let vfs_getxattr fall back to using the on-disk xattr. 3634 */ 3635 if (!selinux_initialized() || 3636 strcmp(name, XATTR_SELINUX_SUFFIX)) 3637 return -EOPNOTSUPP; 3638 3639 /* 3640 * If the caller has CAP_MAC_ADMIN, then get the raw context 3641 * value even if it is not defined by current policy; otherwise, 3642 * use the in-core value under current policy. 3643 * Use the non-auditing forms of the permission checks since 3644 * getxattr may be called by unprivileged processes commonly 3645 * and lack of permission just means that we fall back to the 3646 * in-core context value, not a denial. 3647 */ 3648 isec = inode_security(inode); 3649 if (has_cap_mac_admin(false)) 3650 error = security_sid_to_context_force(isec->sid, &context, 3651 &size); 3652 else 3653 error = security_sid_to_context(isec->sid, 3654 &context, &size); 3655 if (error) 3656 return error; 3657 error = size; 3658 if (alloc) { 3659 *buffer = context; 3660 goto out_nofree; 3661 } 3662 kfree(context); 3663 out_nofree: 3664 return error; 3665 } 3666 3667 static int selinux_inode_setsecurity(struct inode *inode, const char *name, 3668 const void *value, size_t size, int flags) 3669 { 3670 struct inode_security_struct *isec = inode_security_novalidate(inode); 3671 struct superblock_security_struct *sbsec; 3672 u32 newsid; 3673 int rc; 3674 3675 if (strcmp(name, XATTR_SELINUX_SUFFIX)) 3676 return -EOPNOTSUPP; 3677 3678 sbsec = selinux_superblock(inode->i_sb); 3679 if (!(sbsec->flags & SBLABEL_MNT)) 3680 return -EOPNOTSUPP; 3681 3682 if (!value || !size) 3683 return -EACCES; 3684 3685 rc = security_context_to_sid(value, size, &newsid, 3686 GFP_KERNEL); 3687 if (rc) 3688 return rc; 3689 3690 spin_lock(&isec->lock); 3691 isec->sclass = inode_mode_to_security_class(inode->i_mode); 3692 isec->sid = newsid; 3693 isec->initialized = LABEL_INITIALIZED; 3694 spin_unlock(&isec->lock); 3695 return 0; 3696 } 3697 3698 static int selinux_inode_listsecurity(struct inode *inode, char **buffer, 3699 ssize_t *remaining_size) 3700 { 3701 if (!selinux_initialized()) 3702 return 0; 3703 return xattr_list_one(buffer, remaining_size, XATTR_NAME_SELINUX); 3704 } 3705 3706 static void selinux_inode_getlsmprop(struct inode *inode, struct lsm_prop *prop) 3707 { 3708 struct inode_security_struct *isec = inode_security_novalidate(inode); 3709 3710 prop->selinux.secid = isec->sid; 3711 } 3712 3713 static int selinux_inode_copy_up(struct dentry *src, struct cred **new) 3714 { 3715 struct lsm_prop prop; 3716 struct cred_security_struct *crsec; 3717 struct cred *new_creds = *new; 3718 3719 if (new_creds == NULL) { 3720 new_creds = prepare_creds(); 3721 if (!new_creds) 3722 return -ENOMEM; 3723 } 3724 3725 crsec = selinux_cred(new_creds); 3726 /* Get label from overlay inode and set it in create_sid */ 3727 selinux_inode_getlsmprop(d_inode(src), &prop); 3728 crsec->create_sid = prop.selinux.secid; 3729 *new = new_creds; 3730 return 0; 3731 } 3732 3733 static int selinux_inode_copy_up_xattr(struct dentry *dentry, const char *name) 3734 { 3735 /* The copy_up hook above sets the initial context on an inode, but we 3736 * don't then want to overwrite it by blindly copying all the lower 3737 * xattrs up. Instead, filter out SELinux-related xattrs following 3738 * policy load. 3739 */ 3740 if (selinux_initialized() && !strcmp(name, XATTR_NAME_SELINUX)) 3741 return -ECANCELED; /* Discard */ 3742 /* 3743 * Any other attribute apart from SELINUX is not claimed, supported 3744 * by selinux. 3745 */ 3746 return -EOPNOTSUPP; 3747 } 3748 3749 /* kernfs node operations */ 3750 3751 static int selinux_kernfs_init_security(struct kernfs_node *kn_dir, 3752 struct kernfs_node *kn) 3753 { 3754 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 3755 u32 parent_sid, newsid, clen; 3756 int rc; 3757 char *context; 3758 3759 rc = kernfs_xattr_get(kn_dir, XATTR_NAME_SELINUX, NULL, 0); 3760 if (rc == -ENODATA) 3761 return 0; 3762 else if (rc < 0) 3763 return rc; 3764 3765 clen = (u32)rc; 3766 context = kmalloc(clen, GFP_KERNEL); 3767 if (!context) 3768 return -ENOMEM; 3769 3770 rc = kernfs_xattr_get(kn_dir, XATTR_NAME_SELINUX, context, clen); 3771 if (rc < 0) { 3772 kfree(context); 3773 return rc; 3774 } 3775 3776 rc = security_context_to_sid(context, clen, &parent_sid, 3777 GFP_KERNEL); 3778 kfree(context); 3779 if (rc) 3780 return rc; 3781 3782 if (crsec->create_sid) { 3783 newsid = crsec->create_sid; 3784 } else { 3785 u16 secclass = inode_mode_to_security_class(kn->mode); 3786 const char *kn_name; 3787 struct qstr q; 3788 3789 /* kn is fresh, can't be renamed, name goes not away */ 3790 kn_name = rcu_dereference_check(kn->name, true); 3791 q.name = kn_name; 3792 q.hash_len = hashlen_string(kn_dir, kn_name); 3793 3794 rc = security_transition_sid(crsec->sid, 3795 parent_sid, secclass, &q, 3796 &newsid); 3797 if (rc) 3798 return rc; 3799 } 3800 3801 rc = security_sid_to_context_force(newsid, 3802 &context, &clen); 3803 if (rc) 3804 return rc; 3805 3806 rc = kernfs_xattr_set(kn, XATTR_NAME_SELINUX, context, clen, 3807 XATTR_CREATE); 3808 kfree(context); 3809 return rc; 3810 } 3811 3812 3813 /* file security operations */ 3814 3815 static int selinux_revalidate_file_permission(struct file *file, int mask) 3816 { 3817 const struct cred *cred = current_cred(); 3818 struct inode *inode = file_inode(file); 3819 3820 /* file_mask_to_av won't add FILE__WRITE if MAY_APPEND is set */ 3821 if ((file->f_flags & O_APPEND) && (mask & MAY_WRITE)) 3822 mask |= MAY_APPEND; 3823 3824 return file_has_perm(cred, file, 3825 file_mask_to_av(inode->i_mode, mask)); 3826 } 3827 3828 static int selinux_file_permission(struct file *file, int mask) 3829 { 3830 struct inode *inode = file_inode(file); 3831 struct file_security_struct *fsec = selinux_file(file); 3832 struct inode_security_struct *isec; 3833 u32 sid = current_sid(); 3834 3835 if (!mask) 3836 /* No permission to check. Existence test. */ 3837 return 0; 3838 3839 isec = inode_security(inode); 3840 if (sid == fsec->sid && fsec->isid == isec->sid && 3841 fsec->pseqno == avc_policy_seqno()) 3842 /* No change since file_open check. */ 3843 return 0; 3844 3845 return selinux_revalidate_file_permission(file, mask); 3846 } 3847 3848 static int selinux_file_alloc_security(struct file *file) 3849 { 3850 struct file_security_struct *fsec = selinux_file(file); 3851 u32 sid = current_sid(); 3852 3853 fsec->sid = sid; 3854 fsec->fown_sid = sid; 3855 3856 return 0; 3857 } 3858 3859 static inline u32 selinux_file_user_sid(const struct file *file) 3860 { 3861 if (unlikely(file->f_mode & FMODE_BACKING)) 3862 return selinux_backing_file(file)->uf_sid; 3863 return selinux_file(file)->sid; 3864 } 3865 3866 static int selinux_backing_file_alloc(struct file *backing_file, 3867 const struct file *user_file) 3868 { 3869 struct backing_file_security_struct *bfsec; 3870 const struct backing_file_security_struct *ubfsec; 3871 struct backing_file_security_layer *layer; 3872 u32 i; 3873 3874 bfsec = selinux_backing_file(backing_file); 3875 bfsec->uf_sid = selinux_file_user_sid(user_file); 3876 if (!(user_file->f_mode & FMODE_BACKING)) 3877 return 0; 3878 3879 ubfsec = selinux_backing_file(user_file); 3880 /* a wrapped count would make kmalloc_array() return ZERO_SIZE_PTR */ 3881 if (unlikely(ubfsec->layer_count == U32_MAX)) 3882 return -EOVERFLOW; 3883 3884 /* 3885 * The final VMA only retains the lowest backing file, so record the 3886 * whole chain here rather than in the mmap hook, where concurrent 3887 * mappings would have to be serialized. Size it dynamically: erofs 3888 * inode sharing adds a backing file without bumping s_stack_depth. 3889 */ 3890 bfsec->layers = kmalloc_array(ubfsec->layer_count + 1, 3891 sizeof(*bfsec->layers), GFP_KERNEL); 3892 if (!bfsec->layers) 3893 return -ENOMEM; 3894 3895 for (i = 0; i < ubfsec->layer_count; i++) { 3896 layer = &bfsec->layers[i]; 3897 *layer = ubfsec->layers[i]; 3898 path_get(&layer->path); 3899 } 3900 3901 /* f_path, not file_user_path(): this layer, not the top-level file */ 3902 layer = &bfsec->layers[i]; 3903 layer->path = user_file->f_path; 3904 layer->mounter_sid = cred_sid(user_file->f_cred); 3905 layer->fd_sid = selinux_file(user_file)->sid; 3906 path_get(&layer->path); 3907 bfsec->layer_count = ubfsec->layer_count + 1; 3908 3909 return 0; 3910 } 3911 3912 static void selinux_backing_file_free(struct file *backing_file) 3913 { 3914 struct backing_file_security_struct *bfsec; 3915 3916 /* security_backing_file_free() may be called twice after an error */ 3917 if (!backing_file_security(backing_file)) 3918 return; 3919 3920 bfsec = selinux_backing_file(backing_file); 3921 while (bfsec->layer_count) 3922 path_put(&bfsec->layers[--bfsec->layer_count].path); 3923 kfree(bfsec->layers); 3924 bfsec->layers = NULL; 3925 } 3926 3927 /* 3928 * Check whether a task has the ioctl permission and cmd 3929 * operation to an inode. 3930 */ 3931 static int ioctl_has_perm(const struct cred *cred, struct file *file, 3932 u32 requested, u16 cmd) 3933 { 3934 struct common_audit_data ad; 3935 struct file_security_struct *fsec = selinux_file(file); 3936 struct inode *inode = file_inode(file); 3937 struct inode_security_struct *isec; 3938 struct lsm_ioctlop_audit ioctl; 3939 u32 ssid = cred_sid(cred); 3940 int rc; 3941 u8 driver = cmd >> 8; 3942 u8 xperm = cmd & 0xff; 3943 3944 ad.type = LSM_AUDIT_DATA_IOCTL_OP; 3945 ad.u.op = &ioctl; 3946 ad.u.op->cmd = cmd; 3947 ad.u.op->path = file->f_path; 3948 3949 if (ssid != fsec->sid) { 3950 rc = avc_has_perm(ssid, fsec->sid, 3951 SECCLASS_FD, 3952 FD__USE, 3953 &ad); 3954 if (rc) 3955 goto out; 3956 } 3957 3958 if (unlikely(IS_PRIVATE(inode))) 3959 return 0; 3960 3961 isec = inode_security(inode); 3962 rc = avc_has_extended_perms(ssid, isec->sid, isec->sclass, requested, 3963 driver, AVC_EXT_IOCTL, xperm, &ad); 3964 out: 3965 return rc; 3966 } 3967 3968 static int selinux_file_ioctl(struct file *file, unsigned int cmd, 3969 unsigned long arg) 3970 { 3971 const struct cred *cred = current_cred(); 3972 int error = 0; 3973 3974 switch (cmd) { 3975 case FIONREAD: 3976 case FIBMAP: 3977 case FIGETBSZ: 3978 case FS_IOC_GETFLAGS: 3979 case FS_IOC_GETVERSION: 3980 error = file_has_perm(cred, file, FILE__GETATTR); 3981 break; 3982 3983 case FS_IOC_SETFLAGS: 3984 case FS_IOC_SETVERSION: 3985 error = file_has_perm(cred, file, FILE__SETATTR); 3986 break; 3987 3988 /* sys_ioctl() checks */ 3989 case FIONBIO: 3990 case FIOASYNC: 3991 error = file_has_perm(cred, file, 0); 3992 break; 3993 3994 case KDSKBENT: 3995 case KDSKBSENT: 3996 error = cred_has_capability(cred, CAP_SYS_TTY_CONFIG, 3997 CAP_OPT_NONE, true); 3998 break; 3999 4000 case FIOCLEX: 4001 case FIONCLEX: 4002 if (!selinux_policycap_ioctl_skip_cloexec()) 4003 error = ioctl_has_perm(cred, file, FILE__IOCTL, (u16) cmd); 4004 break; 4005 4006 /* default case assumes that the command will go 4007 * to the file's ioctl() function. 4008 */ 4009 default: 4010 error = ioctl_has_perm(cred, file, FILE__IOCTL, (u16) cmd); 4011 } 4012 return error; 4013 } 4014 4015 static int selinux_file_ioctl_compat(struct file *file, unsigned int cmd, 4016 unsigned long arg) 4017 { 4018 /* 4019 * If we are in a 64-bit kernel running 32-bit userspace, we need to 4020 * make sure we don't compare 32-bit flags to 64-bit flags. 4021 */ 4022 switch (cmd) { 4023 case FS_IOC32_GETFLAGS: 4024 cmd = FS_IOC_GETFLAGS; 4025 break; 4026 case FS_IOC32_SETFLAGS: 4027 cmd = FS_IOC_SETFLAGS; 4028 break; 4029 case FS_IOC32_GETVERSION: 4030 cmd = FS_IOC_GETVERSION; 4031 break; 4032 case FS_IOC32_SETVERSION: 4033 cmd = FS_IOC_SETVERSION; 4034 break; 4035 default: 4036 break; 4037 } 4038 4039 return selinux_file_ioctl(file, cmd, arg); 4040 } 4041 4042 static int default_noexec __ro_after_init; 4043 4044 static u32 file_map_prot_to_av(unsigned long prot, bool shared) 4045 { 4046 u32 av = FILE__READ; 4047 4048 if (shared && (prot & PROT_WRITE)) 4049 av |= FILE__WRITE; 4050 if (prot & PROT_EXEC) 4051 av |= FILE__EXECUTE; 4052 4053 return av; 4054 } 4055 4056 static int backing_mounters_has_perm(const struct file *file, u32 av) 4057 { 4058 const struct backing_file_security_struct *bfsec; 4059 const struct backing_file_security_layer *layer; 4060 struct common_audit_data ad; 4061 struct inode *inode; 4062 u32 i; 4063 int rc; 4064 4065 if (WARN_ON_ONCE(!(file->f_mode & FMODE_BACKING))) 4066 return -EIO; 4067 4068 bfsec = selinux_backing_file(file); 4069 for (i = 0; i < bfsec->layer_count; i++) { 4070 layer = &bfsec->layers[i]; 4071 inode = d_inode(layer->path.dentry); 4072 4073 ad.type = LSM_AUDIT_DATA_PATH; 4074 ad.u.path = layer->path; 4075 4076 if (layer->mounter_sid != layer->fd_sid) { 4077 rc = avc_has_perm(layer->mounter_sid, layer->fd_sid, 4078 SECCLASS_FD, FD__USE, &ad); 4079 if (rc) 4080 return rc; 4081 } 4082 4083 rc = inode_sid_has_perm(layer->mounter_sid, inode, av, &ad); 4084 if (rc) 4085 return rc; 4086 } 4087 4088 return 0; 4089 } 4090 4091 static int __file_map_prot_check(const struct file *file, unsigned long prot, 4092 bool shared, bool mounter_check, 4093 bool bf_user_file) 4094 { 4095 struct inode *inode = NULL; 4096 bool prot_exec = prot & PROT_EXEC; 4097 bool prot_write = prot & PROT_WRITE; 4098 4099 if (file) { 4100 if (bf_user_file) 4101 inode = d_inode(backing_file_user_path(file)->dentry); 4102 else 4103 inode = file_inode(file); 4104 } 4105 4106 if (!mounter_check && default_noexec && prot_exec && 4107 (!file || IS_PRIVATE(inode) || (!shared && prot_write))) { 4108 int rc; 4109 u32 sid = current_sid(); 4110 4111 /* 4112 * We are making executable an anonymous mapping or a private 4113 * file mapping that will also be writable. 4114 */ 4115 rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__EXECMEM, 4116 NULL); 4117 if (rc) 4118 return rc; 4119 } 4120 4121 if (file) { 4122 const struct cred *cred = mounter_check ? 4123 file->f_cred : current_cred(); 4124 4125 return __file_has_perm(cred, file, 4126 file_map_prot_to_av(prot, shared), 4127 bf_user_file); 4128 } 4129 4130 return 0; 4131 } 4132 4133 static inline int file_map_prot_check(const struct file *file, 4134 unsigned long prot, bool shared, 4135 bool mounter_check) 4136 { 4137 return __file_map_prot_check(file, prot, shared, mounter_check, false); 4138 } 4139 4140 static int selinux_mmap_addr(unsigned long addr) 4141 { 4142 int rc = 0; 4143 4144 if (addr < CONFIG_LSM_MMAP_MIN_ADDR) { 4145 u32 sid = current_sid(); 4146 rc = avc_has_perm(sid, sid, SECCLASS_MEMPROTECT, 4147 MEMPROTECT__MMAP_ZERO, NULL); 4148 } 4149 4150 return rc; 4151 } 4152 4153 static int selinux_mmap_file_common(struct file *file, unsigned long prot, 4154 bool shared, bool mounter_check) 4155 { 4156 if (file) { 4157 int rc; 4158 struct common_audit_data ad; 4159 const struct cred *cred = mounter_check ? 4160 file->f_cred : current_cred(); 4161 4162 ad.type = LSM_AUDIT_DATA_FILE; 4163 ad.u.file = file; 4164 rc = inode_has_perm(cred, file_inode(file), FILE__MAP, &ad); 4165 if (rc) 4166 return rc; 4167 } 4168 4169 return file_map_prot_check(file, prot, shared, mounter_check); 4170 } 4171 4172 static int selinux_mmap_file(struct file *file, 4173 unsigned long reqprot __always_unused, 4174 unsigned long prot, unsigned long flags) 4175 { 4176 return selinux_mmap_file_common(file, prot, 4177 (flags & MAP_TYPE) == MAP_SHARED, 4178 false); 4179 } 4180 4181 /** 4182 * selinux_mmap_backing_file - Check mmap permissions on a backing file 4183 * @vma: memory region 4184 * @backing_file: stacked filesystem backing file 4185 * @user_file: user visible file 4186 * 4187 * This is called after selinux_mmap_file() on stacked filesystems, and it 4188 * is this function's responsibility to verify access to @backing_file and 4189 * setup the SELinux state for possible later use in the mprotect() code path. 4190 * 4191 * By the time this function is called, mmap() access to @user_file has already 4192 * been authorized and @vma->vm_file has been set to point to @backing_file. 4193 * 4194 * Return zero on success, negative values otherwise. 4195 */ 4196 static int selinux_mmap_backing_file(struct vm_area_struct *vma, 4197 struct file *backing_file, 4198 struct file *user_file __always_unused) 4199 { 4200 unsigned long prot = 0; 4201 4202 /* translate vma->vm_flags perms into PROT perms */ 4203 if (vma->vm_flags & VM_READ) 4204 prot |= PROT_READ; 4205 if (vma->vm_flags & VM_WRITE) 4206 prot |= PROT_WRITE; 4207 if (vma->vm_flags & VM_EXEC) 4208 prot |= PROT_EXEC; 4209 4210 return selinux_mmap_file_common(backing_file, prot, 4211 vma->vm_flags & VM_SHARED, 4212 true); 4213 } 4214 4215 static int selinux_file_mprotect(struct vm_area_struct *vma, 4216 unsigned long reqprot __always_unused, 4217 unsigned long prot) 4218 { 4219 int rc; 4220 const struct cred *cred = current_cred(); 4221 u32 sid = cred_sid(cred); 4222 u32 av; 4223 const struct file *file = vma->vm_file; 4224 bool backing_file; 4225 bool shared = vma->vm_flags & VM_SHARED; 4226 4227 /* check if we need to trigger the "backing files are awful" mode */ 4228 backing_file = file && (file->f_mode & FMODE_BACKING); 4229 4230 if (default_noexec && 4231 (prot & PROT_EXEC) && !(vma->vm_flags & VM_EXEC)) { 4232 /* 4233 * We don't use the vma_is_initial_heap() helper as it has 4234 * a history of problems and is currently broken on systems 4235 * where there is no heap, e.g. brk == start_brk. Before 4236 * replacing the conditional below with vma_is_initial_heap(), 4237 * or something similar, please ensure that the logic is the 4238 * same as what we have below or you have tested every possible 4239 * corner case you can think to test. 4240 */ 4241 if (vma->vm_start >= vma->vm_mm->start_brk && 4242 vma->vm_end <= vma->vm_mm->brk) { 4243 rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, 4244 PROCESS__EXECHEAP, NULL); 4245 if (rc) 4246 return rc; 4247 } else if (!file && (vma_is_initial_stack(vma) || 4248 vma_is_stack_for_current(vma))) { 4249 rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, 4250 PROCESS__EXECSTACK, NULL); 4251 if (rc) 4252 return rc; 4253 } else if (file && vma->anon_vma) { 4254 /* 4255 * We are making executable a file mapping that has 4256 * had some COW done. Since pages might have been 4257 * written, check ability to execute the possibly 4258 * modified content. This typically should only 4259 * occur for text relocations. 4260 */ 4261 rc = __file_has_perm(cred, file, FILE__EXECMOD, 4262 backing_file); 4263 if (rc) 4264 return rc; 4265 if (backing_file) { 4266 rc = backing_mounters_has_perm(file, 4267 FILE__EXECMOD); 4268 if (rc) 4269 return rc; 4270 rc = file_has_perm(file->f_cred, file, 4271 FILE__EXECMOD); 4272 if (rc) 4273 return rc; 4274 } 4275 } 4276 } 4277 4278 rc = __file_map_prot_check(file, prot, shared, false, backing_file); 4279 if (rc) 4280 return rc; 4281 if (backing_file) { 4282 av = file_map_prot_to_av(prot, shared); 4283 rc = backing_mounters_has_perm(file, av); 4284 if (rc) 4285 return rc; 4286 rc = file_map_prot_check(file, prot, shared, true); 4287 if (rc) 4288 return rc; 4289 } 4290 4291 return 0; 4292 } 4293 4294 static int selinux_file_lock(struct file *file, unsigned int cmd) 4295 { 4296 const struct cred *cred = current_cred(); 4297 4298 return file_has_perm(cred, file, FILE__LOCK); 4299 } 4300 4301 static int selinux_file_fcntl(struct file *file, unsigned int cmd, 4302 unsigned long arg) 4303 { 4304 const struct cred *cred = current_cred(); 4305 int err = 0; 4306 4307 switch (cmd) { 4308 case F_SETFL: 4309 if ((file->f_flags & O_APPEND) && !(arg & O_APPEND)) { 4310 err = file_has_perm(cred, file, FILE__WRITE); 4311 break; 4312 } 4313 fallthrough; 4314 case F_SETOWN: 4315 case F_SETSIG: 4316 case F_GETFL: 4317 case F_GETOWN: 4318 case F_GETSIG: 4319 case F_GETOWNER_UIDS: 4320 /* Just check FD__USE permission */ 4321 err = file_has_perm(cred, file, 0); 4322 break; 4323 case F_GETLK: 4324 case F_SETLK: 4325 case F_SETLKW: 4326 case F_OFD_GETLK: 4327 case F_OFD_SETLK: 4328 case F_OFD_SETLKW: 4329 #if BITS_PER_LONG == 32 4330 case F_GETLK64: 4331 case F_SETLK64: 4332 case F_SETLKW64: 4333 #endif 4334 err = file_has_perm(cred, file, FILE__LOCK); 4335 break; 4336 } 4337 4338 return err; 4339 } 4340 4341 static void selinux_file_set_fowner(struct file *file) 4342 { 4343 struct file_security_struct *fsec; 4344 4345 fsec = selinux_file(file); 4346 fsec->fown_sid = current_sid(); 4347 } 4348 4349 static int selinux_file_send_sigiotask(struct task_struct *tsk, 4350 struct fown_struct *fown, int signum) 4351 { 4352 struct file *file; 4353 u32 sid = task_sid_obj(tsk); 4354 u32 perm; 4355 struct file_security_struct *fsec; 4356 4357 /* struct fown_struct is never outside the context of a struct file */ 4358 file = fown->file; 4359 4360 fsec = selinux_file(file); 4361 4362 if (!signum) 4363 perm = signal_to_av(SIGIO); /* as per send_sigio_to_task */ 4364 else 4365 perm = signal_to_av(signum); 4366 4367 return avc_has_perm(fsec->fown_sid, sid, 4368 SECCLASS_PROCESS, perm, NULL); 4369 } 4370 4371 static int selinux_file_receive(struct file *file) 4372 { 4373 const struct cred *cred = current_cred(); 4374 4375 return file_has_perm(cred, file, file_to_av(file)); 4376 } 4377 4378 static int selinux_file_open(struct file *file) 4379 { 4380 struct file_security_struct *fsec; 4381 struct inode_security_struct *isec; 4382 4383 fsec = selinux_file(file); 4384 isec = inode_security(file_inode(file)); 4385 /* 4386 * Save inode label and policy sequence number 4387 * at open-time so that selinux_file_permission 4388 * can determine whether revalidation is necessary. 4389 * Task label is already saved in the file security 4390 * struct as its SID. 4391 */ 4392 fsec->isid = isec->sid; 4393 fsec->pseqno = avc_policy_seqno(); 4394 /* 4395 * Since the inode label or policy seqno may have changed 4396 * between the selinux_inode_permission check and the saving 4397 * of state above, recheck that access is still permitted. 4398 * Otherwise, access might never be revalidated against the 4399 * new inode label or new policy. 4400 * This check is not redundant - do not remove. 4401 */ 4402 return file_path_has_perm(file->f_cred, file, open_file_to_av(file)); 4403 } 4404 4405 /* task security operations */ 4406 4407 static int selinux_task_alloc(struct task_struct *task, 4408 u64 clone_flags) 4409 { 4410 u32 sid = current_sid(); 4411 struct task_security_struct *old_tsec = selinux_task(current); 4412 struct task_security_struct *new_tsec = selinux_task(task); 4413 4414 *new_tsec = *old_tsec; 4415 return avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__FORK, NULL); 4416 } 4417 4418 /* 4419 * prepare a new set of credentials for modification 4420 */ 4421 static int selinux_cred_prepare(struct cred *new, const struct cred *old, 4422 gfp_t gfp) 4423 { 4424 const struct cred_security_struct *old_crsec = selinux_cred(old); 4425 struct cred_security_struct *crsec = selinux_cred(new); 4426 4427 *crsec = *old_crsec; 4428 return 0; 4429 } 4430 4431 /* 4432 * transfer the SELinux data to a blank set of creds 4433 */ 4434 static void selinux_cred_transfer(struct cred *new, const struct cred *old) 4435 { 4436 const struct cred_security_struct *old_crsec = selinux_cred(old); 4437 struct cred_security_struct *crsec = selinux_cred(new); 4438 4439 *crsec = *old_crsec; 4440 } 4441 4442 static void selinux_cred_getsecid(const struct cred *c, u32 *secid) 4443 { 4444 *secid = cred_sid(c); 4445 } 4446 4447 static void selinux_cred_getlsmprop(const struct cred *c, struct lsm_prop *prop) 4448 { 4449 prop->selinux.secid = cred_sid(c); 4450 } 4451 4452 /* 4453 * set the security data for a kernel service 4454 * - all the creation contexts are set to unlabelled 4455 */ 4456 static int selinux_kernel_act_as(struct cred *new, u32 secid) 4457 { 4458 struct cred_security_struct *crsec = selinux_cred(new); 4459 u32 sid = current_sid(); 4460 int ret; 4461 4462 ret = avc_has_perm(sid, secid, 4463 SECCLASS_KERNEL_SERVICE, 4464 KERNEL_SERVICE__USE_AS_OVERRIDE, 4465 NULL); 4466 if (ret == 0) { 4467 crsec->sid = secid; 4468 crsec->create_sid = 0; 4469 crsec->keycreate_sid = 0; 4470 crsec->sockcreate_sid = 0; 4471 } 4472 return ret; 4473 } 4474 4475 /* 4476 * set the file creation context in a security record to the same as the 4477 * objective context of the specified inode 4478 */ 4479 static int selinux_kernel_create_files_as(struct cred *new, struct inode *inode) 4480 { 4481 struct inode_security_struct *isec = inode_security(inode); 4482 struct cred_security_struct *crsec = selinux_cred(new); 4483 u32 sid = current_sid(); 4484 int ret; 4485 4486 ret = avc_has_perm(sid, isec->sid, 4487 SECCLASS_KERNEL_SERVICE, 4488 KERNEL_SERVICE__CREATE_FILES_AS, 4489 NULL); 4490 4491 if (ret == 0) 4492 crsec->create_sid = isec->sid; 4493 return ret; 4494 } 4495 4496 static int selinux_kernel_module_request(char *kmod_name) 4497 { 4498 struct common_audit_data ad; 4499 4500 ad.type = LSM_AUDIT_DATA_KMOD; 4501 ad.u.kmod_name = kmod_name; 4502 4503 return avc_has_perm(current_sid(), SECINITSID_KERNEL, SECCLASS_SYSTEM, 4504 SYSTEM__MODULE_REQUEST, &ad); 4505 } 4506 4507 static int selinux_kernel_load_from_file(struct file *file, u32 requested) 4508 { 4509 struct common_audit_data ad; 4510 struct inode_security_struct *isec; 4511 struct file_security_struct *fsec; 4512 u32 sid = current_sid(); 4513 int rc; 4514 4515 if (file == NULL) 4516 return avc_has_perm(sid, sid, SECCLASS_SYSTEM, requested, NULL); 4517 4518 ad.type = LSM_AUDIT_DATA_FILE; 4519 ad.u.file = file; 4520 4521 fsec = selinux_file(file); 4522 if (sid != fsec->sid) { 4523 rc = avc_has_perm(sid, fsec->sid, SECCLASS_FD, FD__USE, &ad); 4524 if (rc) 4525 return rc; 4526 } 4527 4528 isec = inode_security(file_inode(file)); 4529 return avc_has_perm(sid, isec->sid, SECCLASS_SYSTEM, requested, &ad); 4530 } 4531 4532 static int selinux_kernel_read_file(struct file *file, 4533 enum kernel_read_file_id id, 4534 bool contents) 4535 { 4536 int rc = 0; 4537 4538 BUILD_BUG_ON_MSG(READING_MAX_ID > 8, 4539 "New kernel_read_file_id introduced; update SELinux!"); 4540 4541 switch (id) { 4542 case READING_FIRMWARE: 4543 rc = selinux_kernel_load_from_file(file, SYSTEM__FIRMWARE_LOAD); 4544 break; 4545 case READING_MODULE: 4546 case READING_MODULE_COMPRESSED: 4547 rc = selinux_kernel_load_from_file(file, SYSTEM__MODULE_LOAD); 4548 break; 4549 case READING_KEXEC_IMAGE: 4550 rc = selinux_kernel_load_from_file(file, 4551 SYSTEM__KEXEC_IMAGE_LOAD); 4552 break; 4553 case READING_KEXEC_INITRAMFS: 4554 rc = selinux_kernel_load_from_file(file, 4555 SYSTEM__KEXEC_INITRAMFS_LOAD); 4556 break; 4557 case READING_POLICY: 4558 rc = selinux_kernel_load_from_file(file, SYSTEM__POLICY_LOAD); 4559 break; 4560 case READING_X509_CERTIFICATE: 4561 rc = selinux_kernel_load_from_file(file, 4562 SYSTEM__X509_CERTIFICATE_LOAD); 4563 break; 4564 default: 4565 break; 4566 } 4567 4568 return rc; 4569 } 4570 4571 static int selinux_kernel_load_data(enum kernel_load_data_id id, bool contents) 4572 { 4573 int rc = 0; 4574 4575 BUILD_BUG_ON_MSG(LOADING_MAX_ID > 8, 4576 "New kernel_load_data_id introduced; update SELinux!"); 4577 4578 switch (id) { 4579 case LOADING_FIRMWARE: 4580 rc = selinux_kernel_load_from_file(NULL, SYSTEM__FIRMWARE_LOAD); 4581 break; 4582 case LOADING_MODULE: 4583 rc = selinux_kernel_load_from_file(NULL, SYSTEM__MODULE_LOAD); 4584 break; 4585 case LOADING_KEXEC_IMAGE: 4586 rc = selinux_kernel_load_from_file(NULL, 4587 SYSTEM__KEXEC_IMAGE_LOAD); 4588 break; 4589 case LOADING_KEXEC_INITRAMFS: 4590 rc = selinux_kernel_load_from_file(NULL, 4591 SYSTEM__KEXEC_INITRAMFS_LOAD); 4592 break; 4593 case LOADING_POLICY: 4594 rc = selinux_kernel_load_from_file(NULL, 4595 SYSTEM__POLICY_LOAD); 4596 break; 4597 case LOADING_X509_CERTIFICATE: 4598 rc = selinux_kernel_load_from_file(NULL, 4599 SYSTEM__X509_CERTIFICATE_LOAD); 4600 break; 4601 default: 4602 break; 4603 } 4604 4605 return rc; 4606 } 4607 4608 static int selinux_task_setpgid(struct task_struct *p, pid_t pgid) 4609 { 4610 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4611 PROCESS__SETPGID, NULL); 4612 } 4613 4614 static int selinux_task_getpgid(struct task_struct *p) 4615 { 4616 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4617 PROCESS__GETPGID, NULL); 4618 } 4619 4620 static int selinux_task_getsid(struct task_struct *p) 4621 { 4622 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4623 PROCESS__GETSESSION, NULL); 4624 } 4625 4626 static void selinux_current_getlsmprop_subj(struct lsm_prop *prop) 4627 { 4628 prop->selinux.secid = current_sid(); 4629 } 4630 4631 static void selinux_task_getlsmprop_obj(struct task_struct *p, 4632 struct lsm_prop *prop) 4633 { 4634 prop->selinux.secid = task_sid_obj(p); 4635 } 4636 4637 static int selinux_task_setnice(struct task_struct *p, int nice) 4638 { 4639 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4640 PROCESS__SETSCHED, NULL); 4641 } 4642 4643 static int selinux_task_setioprio(struct task_struct *p, int ioprio) 4644 { 4645 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4646 PROCESS__SETSCHED, NULL); 4647 } 4648 4649 static int selinux_task_getioprio(struct task_struct *p) 4650 { 4651 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4652 PROCESS__GETSCHED, NULL); 4653 } 4654 4655 static int selinux_task_prlimit(const struct cred *cred, const struct cred *tcred, 4656 unsigned int flags) 4657 { 4658 u32 av = 0; 4659 4660 if (!flags) 4661 return 0; 4662 if (flags & LSM_PRLIMIT_WRITE) 4663 av |= PROCESS__SETRLIMIT; 4664 if (flags & LSM_PRLIMIT_READ) 4665 av |= PROCESS__GETRLIMIT; 4666 return avc_has_perm(cred_sid(cred), cred_sid(tcred), 4667 SECCLASS_PROCESS, av, NULL); 4668 } 4669 4670 static int selinux_task_setrlimit(struct task_struct *p, unsigned int resource, 4671 struct rlimit *new_rlim) 4672 { 4673 struct rlimit *old_rlim = p->signal->rlim + resource; 4674 4675 /* Control the ability to change the hard limit (whether 4676 lowering or raising it), so that the hard limit can 4677 later be used as a safe reset point for the soft limit 4678 upon context transitions. See selinux_bprm_committing_creds. */ 4679 if (old_rlim->rlim_max != new_rlim->rlim_max) 4680 return avc_has_perm(current_sid(), task_sid_obj(p), 4681 SECCLASS_PROCESS, PROCESS__SETRLIMIT, NULL); 4682 4683 return 0; 4684 } 4685 4686 static int selinux_task_setscheduler(struct task_struct *p) 4687 { 4688 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4689 PROCESS__SETSCHED, NULL); 4690 } 4691 4692 static int selinux_task_getscheduler(struct task_struct *p) 4693 { 4694 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4695 PROCESS__GETSCHED, NULL); 4696 } 4697 4698 static int selinux_task_movememory(struct task_struct *p) 4699 { 4700 return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS, 4701 PROCESS__SETSCHED, NULL); 4702 } 4703 4704 static int selinux_task_kill(struct task_struct *p, struct kernel_siginfo *info, 4705 int sig, const struct cred *cred) 4706 { 4707 u32 secid; 4708 u32 perm; 4709 4710 if (!sig) 4711 perm = PROCESS__SIGNULL; /* null signal; existence test */ 4712 else 4713 perm = signal_to_av(sig); 4714 if (!cred) 4715 secid = current_sid(); 4716 else 4717 secid = cred_sid(cred); 4718 return avc_has_perm(secid, task_sid_obj(p), SECCLASS_PROCESS, perm, NULL); 4719 } 4720 4721 static void selinux_task_to_inode(struct task_struct *p, 4722 struct inode *inode) 4723 { 4724 struct inode_security_struct *isec = selinux_inode(inode); 4725 u32 sid = task_sid_obj(p); 4726 4727 spin_lock(&isec->lock); 4728 isec->sclass = inode_mode_to_security_class(inode->i_mode); 4729 isec->sid = sid; 4730 isec->initialized = LABEL_INITIALIZED; 4731 spin_unlock(&isec->lock); 4732 } 4733 4734 static int selinux_userns_create(const struct cred *cred) 4735 { 4736 u32 sid = current_sid(); 4737 4738 return avc_has_perm(sid, sid, SECCLASS_USER_NAMESPACE, 4739 USER_NAMESPACE__CREATE, NULL); 4740 } 4741 4742 /* Returns error only if unable to parse addresses */ 4743 static int selinux_parse_skb_ipv4(struct sk_buff *skb, 4744 struct common_audit_data *ad, u8 *proto) 4745 { 4746 int offset, ihlen, ret = -EINVAL; 4747 struct iphdr _iph, *ih; 4748 4749 offset = skb_network_offset(skb); 4750 ih = skb_header_pointer(skb, offset, sizeof(_iph), &_iph); 4751 if (ih == NULL) 4752 goto out; 4753 4754 ihlen = ih->ihl * 4; 4755 if (ihlen < sizeof(_iph)) 4756 goto out; 4757 4758 ad->u.net->v4info.saddr = ih->saddr; 4759 ad->u.net->v4info.daddr = ih->daddr; 4760 ret = 0; 4761 4762 if (proto) 4763 *proto = ih->protocol; 4764 4765 switch (ih->protocol) { 4766 case IPPROTO_TCP: { 4767 struct tcphdr _tcph, *th; 4768 4769 if (ntohs(ih->frag_off) & IP_OFFSET) 4770 break; 4771 4772 offset += ihlen; 4773 th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph); 4774 if (th == NULL) 4775 break; 4776 4777 ad->u.net->sport = th->source; 4778 ad->u.net->dport = th->dest; 4779 break; 4780 } 4781 4782 case IPPROTO_UDP: { 4783 struct udphdr _udph, *uh; 4784 4785 if (ntohs(ih->frag_off) & IP_OFFSET) 4786 break; 4787 4788 offset += ihlen; 4789 uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph); 4790 if (uh == NULL) 4791 break; 4792 4793 ad->u.net->sport = uh->source; 4794 ad->u.net->dport = uh->dest; 4795 break; 4796 } 4797 4798 #if IS_ENABLED(CONFIG_IP_SCTP) 4799 case IPPROTO_SCTP: { 4800 struct sctphdr _sctph, *sh; 4801 4802 if (ntohs(ih->frag_off) & IP_OFFSET) 4803 break; 4804 4805 offset += ihlen; 4806 sh = skb_header_pointer(skb, offset, sizeof(_sctph), &_sctph); 4807 if (sh == NULL) 4808 break; 4809 4810 ad->u.net->sport = sh->source; 4811 ad->u.net->dport = sh->dest; 4812 break; 4813 } 4814 #endif 4815 default: 4816 break; 4817 } 4818 out: 4819 return ret; 4820 } 4821 4822 #if IS_ENABLED(CONFIG_IPV6) 4823 4824 /* Returns error only if unable to parse addresses */ 4825 static int selinux_parse_skb_ipv6(struct sk_buff *skb, 4826 struct common_audit_data *ad, u8 *proto) 4827 { 4828 u8 nexthdr; 4829 int ret = -EINVAL, offset; 4830 struct ipv6hdr _ipv6h, *ip6; 4831 __be16 frag_off; 4832 4833 offset = skb_network_offset(skb); 4834 ip6 = skb_header_pointer(skb, offset, sizeof(_ipv6h), &_ipv6h); 4835 if (ip6 == NULL) 4836 goto out; 4837 4838 ad->u.net->v6info.saddr = ip6->saddr; 4839 ad->u.net->v6info.daddr = ip6->daddr; 4840 ret = 0; 4841 4842 nexthdr = ip6->nexthdr; 4843 offset += sizeof(_ipv6h); 4844 offset = ipv6_skip_exthdr(skb, offset, &nexthdr, &frag_off); 4845 if (offset < 0) 4846 goto out; 4847 4848 if (proto) 4849 *proto = nexthdr; 4850 4851 switch (nexthdr) { 4852 case IPPROTO_TCP: { 4853 struct tcphdr _tcph, *th; 4854 4855 th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph); 4856 if (th == NULL) 4857 break; 4858 4859 ad->u.net->sport = th->source; 4860 ad->u.net->dport = th->dest; 4861 break; 4862 } 4863 4864 case IPPROTO_UDP: { 4865 struct udphdr _udph, *uh; 4866 4867 uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph); 4868 if (uh == NULL) 4869 break; 4870 4871 ad->u.net->sport = uh->source; 4872 ad->u.net->dport = uh->dest; 4873 break; 4874 } 4875 4876 #if IS_ENABLED(CONFIG_IP_SCTP) 4877 case IPPROTO_SCTP: { 4878 struct sctphdr _sctph, *sh; 4879 4880 sh = skb_header_pointer(skb, offset, sizeof(_sctph), &_sctph); 4881 if (sh == NULL) 4882 break; 4883 4884 ad->u.net->sport = sh->source; 4885 ad->u.net->dport = sh->dest; 4886 break; 4887 } 4888 #endif 4889 /* includes fragments */ 4890 default: 4891 break; 4892 } 4893 out: 4894 return ret; 4895 } 4896 4897 #endif /* IPV6 */ 4898 4899 static int selinux_parse_skb(struct sk_buff *skb, struct common_audit_data *ad, 4900 char **_addrp, int src, u8 *proto) 4901 { 4902 char *addrp; 4903 int ret; 4904 4905 switch (ad->u.net->family) { 4906 case PF_INET: 4907 ret = selinux_parse_skb_ipv4(skb, ad, proto); 4908 if (ret) 4909 goto parse_error; 4910 addrp = (char *)(src ? &ad->u.net->v4info.saddr : 4911 &ad->u.net->v4info.daddr); 4912 goto okay; 4913 4914 #if IS_ENABLED(CONFIG_IPV6) 4915 case PF_INET6: 4916 ret = selinux_parse_skb_ipv6(skb, ad, proto); 4917 if (ret) 4918 goto parse_error; 4919 addrp = (char *)(src ? &ad->u.net->v6info.saddr : 4920 &ad->u.net->v6info.daddr); 4921 goto okay; 4922 #endif /* IPV6 */ 4923 default: 4924 addrp = NULL; 4925 goto okay; 4926 } 4927 4928 parse_error: 4929 pr_warn( 4930 "SELinux: failure in selinux_parse_skb()," 4931 " unable to parse packet\n"); 4932 return ret; 4933 4934 okay: 4935 if (_addrp) 4936 *_addrp = addrp; 4937 return 0; 4938 } 4939 4940 /** 4941 * selinux_skb_peerlbl_sid - Determine the peer label of a packet 4942 * @skb: the packet 4943 * @family: protocol family 4944 * @sid: the packet's peer label SID 4945 * 4946 * Description: 4947 * Check the various different forms of network peer labeling and determine 4948 * the peer label/SID for the packet; most of the magic actually occurs in 4949 * the security server function security_net_peersid_cmp(). The function 4950 * returns zero if the value in @sid is valid (although it may be SECSID_NULL) 4951 * or -EACCES if @sid is invalid due to inconsistencies with the different 4952 * peer labels. 4953 * 4954 */ 4955 static int selinux_skb_peerlbl_sid(struct sk_buff *skb, u16 family, u32 *sid) 4956 { 4957 int err; 4958 u32 xfrm_sid; 4959 u32 nlbl_sid; 4960 u32 nlbl_type; 4961 4962 err = selinux_xfrm_skb_sid(skb, &xfrm_sid); 4963 if (unlikely(err)) 4964 return -EACCES; 4965 err = selinux_netlbl_skbuff_getsid(skb, family, &nlbl_type, &nlbl_sid); 4966 if (unlikely(err)) 4967 return -EACCES; 4968 4969 err = security_net_peersid_resolve(nlbl_sid, 4970 nlbl_type, xfrm_sid, sid); 4971 if (unlikely(err)) { 4972 pr_warn( 4973 "SELinux: failure in selinux_skb_peerlbl_sid()," 4974 " unable to determine packet's peer label\n"); 4975 return -EACCES; 4976 } 4977 4978 return 0; 4979 } 4980 4981 /** 4982 * selinux_conn_sid - Determine the child socket label for a connection 4983 * @sk_sid: the parent socket's SID 4984 * @skb_sid: the packet's SID 4985 * @conn_sid: the resulting connection SID 4986 * 4987 * If @skb_sid is valid then the user:role:type information from @sk_sid is 4988 * combined with the MLS information from @skb_sid in order to create 4989 * @conn_sid. If @skb_sid is not valid then @conn_sid is simply a copy 4990 * of @sk_sid. Returns zero on success, negative values on failure. 4991 * 4992 */ 4993 static int selinux_conn_sid(u32 sk_sid, u32 skb_sid, u32 *conn_sid) 4994 { 4995 int err = 0; 4996 4997 if (skb_sid != SECSID_NULL) 4998 err = security_sid_mls_copy(sk_sid, skb_sid, 4999 conn_sid); 5000 else 5001 *conn_sid = sk_sid; 5002 5003 return err; 5004 } 5005 5006 /* socket security operations */ 5007 5008 static int socket_sockcreate_sid(const struct cred_security_struct *crsec, 5009 u16 secclass, u32 *socksid) 5010 { 5011 if (crsec->sockcreate_sid > SECSID_NULL) { 5012 *socksid = crsec->sockcreate_sid; 5013 return 0; 5014 } 5015 5016 return security_transition_sid(crsec->sid, crsec->sid, 5017 secclass, NULL, socksid); 5018 } 5019 5020 static bool sock_skip_has_perm(u32 sid) 5021 { 5022 if (sid == SECINITSID_KERNEL) 5023 return true; 5024 5025 /* 5026 * Before POLICYDB_CAP_USERSPACE_INITIAL_CONTEXT, sockets that 5027 * inherited the kernel context from early boot used to be skipped 5028 * here, so preserve that behavior unless the capability is set. 5029 * 5030 * By setting the capability the policy signals that it is ready 5031 * for this quirk to be fixed. Note that sockets created by a kernel 5032 * thread or a usermode helper executed without a transition will 5033 * still be skipped in this check regardless of the policycap 5034 * setting. 5035 */ 5036 if (!selinux_policycap_userspace_initial_context() && 5037 sid == SECINITSID_INIT) 5038 return true; 5039 return false; 5040 } 5041 5042 5043 static int sock_has_perm(struct sock *sk, u32 perms) 5044 { 5045 struct sk_security_struct *sksec = selinux_sock(sk); 5046 struct common_audit_data ad; 5047 struct lsm_network_audit net; 5048 5049 if (sock_skip_has_perm(sksec->sid)) 5050 return 0; 5051 5052 ad_net_init_from_sk(&ad, &net, sk); 5053 5054 return avc_has_perm(current_sid(), sksec->sid, sksec->sclass, perms, 5055 &ad); 5056 } 5057 5058 static int selinux_socket_create(int family, int type, 5059 int protocol, int kern) 5060 { 5061 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 5062 u32 newsid; 5063 u16 secclass; 5064 int rc; 5065 5066 if (kern) 5067 return 0; 5068 5069 secclass = socket_type_to_security_class(family, type, protocol); 5070 rc = socket_sockcreate_sid(crsec, secclass, &newsid); 5071 if (rc) 5072 return rc; 5073 5074 return avc_has_perm(crsec->sid, newsid, secclass, SOCKET__CREATE, NULL); 5075 } 5076 5077 static int selinux_socket_post_create(struct socket *sock, int family, 5078 int type, int protocol, int kern) 5079 { 5080 const struct cred_security_struct *crsec = selinux_cred(current_cred()); 5081 struct inode_security_struct *isec = inode_security_novalidate(SOCK_INODE(sock)); 5082 struct sk_security_struct *sksec; 5083 u16 sclass = socket_type_to_security_class(family, type, protocol); 5084 u32 sid = SECINITSID_KERNEL; 5085 int err = 0; 5086 5087 if (!kern) { 5088 err = socket_sockcreate_sid(crsec, sclass, &sid); 5089 if (err) 5090 return err; 5091 } 5092 5093 isec->sclass = sclass; 5094 isec->sid = sid; 5095 isec->initialized = LABEL_INITIALIZED; 5096 5097 if (sock->sk) { 5098 sksec = selinux_sock(sock->sk); 5099 sksec->sclass = sclass; 5100 sksec->sid = sid; 5101 /* Allows detection of the first association on this socket */ 5102 if (sksec->sclass == SECCLASS_SCTP_SOCKET) 5103 sksec->sctp_assoc_state = SCTP_ASSOC_UNSET; 5104 5105 err = selinux_netlbl_socket_post_create(sock->sk, family); 5106 } 5107 5108 return err; 5109 } 5110 5111 static int selinux_socket_socketpair(struct socket *socka, 5112 struct socket *sockb) 5113 { 5114 struct sk_security_struct *sksec_a = selinux_sock(socka->sk); 5115 struct sk_security_struct *sksec_b = selinux_sock(sockb->sk); 5116 5117 sksec_a->peer_sid = sksec_b->sid; 5118 sksec_b->peer_sid = sksec_a->sid; 5119 5120 return 0; 5121 } 5122 5123 /* Range of port numbers used to automatically bind. 5124 Need to determine whether we should perform a name_bind 5125 permission check between the socket and the port number. */ 5126 5127 static int __selinux_socket_bind(struct sock *sk, struct sockaddr *address, int addrlen) 5128 { 5129 struct sk_security_struct *sksec = selinux_sock(sk); 5130 u16 family; 5131 int err; 5132 5133 err = sock_has_perm(sk, SOCKET__BIND); 5134 if (err) 5135 goto out; 5136 5137 /* If PF_INET or PF_INET6, check name_bind permission for the port. */ 5138 family = sk->sk_family; 5139 if (family == PF_INET || family == PF_INET6) { 5140 char *addrp; 5141 struct common_audit_data ad; 5142 struct lsm_network_audit net = {0,}; 5143 struct sockaddr_in *addr4 = NULL; 5144 struct sockaddr_in6 *addr6 = NULL; 5145 u16 family_sa; 5146 unsigned short snum; 5147 u32 sid, node_perm; 5148 5149 /* 5150 * sctp_bindx(3) calls via selinux_sctp_bind_connect() 5151 * that validates multiple binding addresses. Because of this 5152 * need to check address->sa_family as it is possible to have 5153 * sk->sk_family = PF_INET6 with addr->sa_family = AF_INET. 5154 */ 5155 if (addrlen < offsetofend(struct sockaddr, sa_family)) 5156 return -EINVAL; 5157 family_sa = address->sa_family; 5158 switch (family_sa) { 5159 case AF_UNSPEC: 5160 case AF_INET: 5161 if (addrlen < sizeof(struct sockaddr_in)) 5162 return -EINVAL; 5163 addr4 = (struct sockaddr_in *)address; 5164 if (family_sa == AF_UNSPEC) { 5165 if (family == PF_INET6) { 5166 /* Length check from inet6_bind_sk() */ 5167 if (addrlen < SIN6_LEN_RFC2133) 5168 return -EINVAL; 5169 /* Family check from __inet6_bind() */ 5170 goto err_af; 5171 } 5172 /* see __inet_bind(), we only want to allow 5173 * AF_UNSPEC if the address is INADDR_ANY 5174 */ 5175 if (addr4->sin_addr.s_addr != htonl(INADDR_ANY)) 5176 goto err_af; 5177 family_sa = AF_INET; 5178 } 5179 snum = ntohs(addr4->sin_port); 5180 addrp = (char *)&addr4->sin_addr.s_addr; 5181 break; 5182 case AF_INET6: 5183 if (addrlen < SIN6_LEN_RFC2133) 5184 return -EINVAL; 5185 addr6 = (struct sockaddr_in6 *)address; 5186 snum = ntohs(addr6->sin6_port); 5187 addrp = (char *)&addr6->sin6_addr.s6_addr; 5188 break; 5189 default: 5190 goto err_af; 5191 } 5192 5193 ad.type = LSM_AUDIT_DATA_NET; 5194 ad.u.net = &net; 5195 ad.u.net->sport = htons(snum); 5196 ad.u.net->family = family_sa; 5197 5198 if (snum) { 5199 int low, high; 5200 5201 inet_get_local_port_range(sock_net(sk), &low, &high); 5202 5203 if (inet_port_requires_bind_service(sock_net(sk), snum) || 5204 snum < low || snum > high) { 5205 err = sel_netport_sid(sk->sk_protocol, 5206 snum, &sid); 5207 if (err) 5208 goto out; 5209 err = avc_has_perm(sksec->sid, sid, 5210 sksec->sclass, 5211 SOCKET__NAME_BIND, &ad); 5212 if (err) 5213 goto out; 5214 } 5215 } 5216 5217 switch (sksec->sclass) { 5218 case SECCLASS_TCP_SOCKET: 5219 node_perm = TCP_SOCKET__NODE_BIND; 5220 break; 5221 5222 case SECCLASS_UDP_SOCKET: 5223 node_perm = UDP_SOCKET__NODE_BIND; 5224 break; 5225 5226 case SECCLASS_SCTP_SOCKET: 5227 node_perm = SCTP_SOCKET__NODE_BIND; 5228 break; 5229 5230 default: 5231 node_perm = RAWIP_SOCKET__NODE_BIND; 5232 break; 5233 } 5234 5235 err = sel_netnode_sid(addrp, family_sa, &sid); 5236 if (err) 5237 goto out; 5238 5239 if (family_sa == AF_INET) 5240 ad.u.net->v4info.saddr = addr4->sin_addr.s_addr; 5241 else 5242 ad.u.net->v6info.saddr = addr6->sin6_addr; 5243 5244 err = avc_has_perm(sksec->sid, sid, 5245 sksec->sclass, node_perm, &ad); 5246 if (err) 5247 goto out; 5248 } 5249 out: 5250 return err; 5251 err_af: 5252 /* Note that SCTP services expect -EINVAL, others -EAFNOSUPPORT. */ 5253 if (sk->sk_protocol == IPPROTO_SCTP) 5254 return -EINVAL; 5255 return -EAFNOSUPPORT; 5256 } 5257 5258 static int selinux_socket_bind(struct socket *sock, struct sockaddr *address, int addrlen) 5259 { 5260 return __selinux_socket_bind(sock->sk, address, addrlen); 5261 } 5262 5263 /* This supports connect(2) and SCTP connect services such as sctp_connectx(3) 5264 * and sctp_sendmsg(3) as described in Documentation/security/SCTP.rst 5265 */ 5266 static int selinux_socket_connect_helper(struct sock *sk, 5267 struct sockaddr *address, int addrlen) 5268 { 5269 struct sk_security_struct *sksec = selinux_sock(sk); 5270 int err; 5271 5272 err = sock_has_perm(sk, SOCKET__CONNECT); 5273 if (err) 5274 return err; 5275 if (addrlen < offsetofend(struct sockaddr, sa_family)) 5276 return -EINVAL; 5277 5278 /* connect(AF_UNSPEC) has special handling, as it is a documented 5279 * way to disconnect the socket 5280 */ 5281 if (address->sa_family == AF_UNSPEC) 5282 return 0; 5283 5284 /* 5285 * If a TCP or SCTP socket, check name_connect permission 5286 * for the port. 5287 */ 5288 if (sksec->sclass == SECCLASS_TCP_SOCKET || 5289 sksec->sclass == SECCLASS_SCTP_SOCKET) { 5290 struct common_audit_data ad; 5291 struct lsm_network_audit net = {0,}; 5292 struct sockaddr_in *addr4 = NULL; 5293 struct sockaddr_in6 *addr6 = NULL; 5294 unsigned short snum; 5295 u32 sid, perm; 5296 5297 /* sctp_connectx(3) calls via selinux_sctp_bind_connect() 5298 * that validates multiple connect addresses. Because of this 5299 * need to check address->sa_family as it is possible to have 5300 * sk->sk_family = PF_INET6 with addr->sa_family = AF_INET. 5301 */ 5302 switch (address->sa_family) { 5303 case AF_INET: 5304 addr4 = (struct sockaddr_in *)address; 5305 if (addrlen < sizeof(struct sockaddr_in)) 5306 return -EINVAL; 5307 snum = ntohs(addr4->sin_port); 5308 break; 5309 case AF_INET6: 5310 addr6 = (struct sockaddr_in6 *)address; 5311 if (addrlen < SIN6_LEN_RFC2133) 5312 return -EINVAL; 5313 snum = ntohs(addr6->sin6_port); 5314 break; 5315 default: 5316 /* Note that SCTP services expect -EINVAL, whereas 5317 * others expect -EAFNOSUPPORT. 5318 */ 5319 if (sksec->sclass == SECCLASS_SCTP_SOCKET) 5320 return -EINVAL; 5321 else 5322 return -EAFNOSUPPORT; 5323 } 5324 5325 err = sel_netport_sid(sk->sk_protocol, snum, &sid); 5326 if (err) 5327 return err; 5328 5329 switch (sksec->sclass) { 5330 case SECCLASS_TCP_SOCKET: 5331 perm = TCP_SOCKET__NAME_CONNECT; 5332 break; 5333 case SECCLASS_SCTP_SOCKET: 5334 perm = SCTP_SOCKET__NAME_CONNECT; 5335 break; 5336 } 5337 5338 ad.type = LSM_AUDIT_DATA_NET; 5339 ad.u.net = &net; 5340 ad.u.net->dport = htons(snum); 5341 ad.u.net->family = address->sa_family; 5342 err = avc_has_perm(sksec->sid, sid, sksec->sclass, perm, &ad); 5343 if (err) 5344 return err; 5345 } 5346 5347 return 0; 5348 } 5349 5350 /* Supports connect(2), see comments in selinux_socket_connect_helper() */ 5351 static int selinux_socket_connect(struct socket *sock, 5352 struct sockaddr *address, int addrlen) 5353 { 5354 int err; 5355 struct sock *sk = sock->sk; 5356 5357 err = selinux_socket_connect_helper(sk, address, addrlen); 5358 if (err) 5359 return err; 5360 5361 return selinux_netlbl_socket_connect(sk, address); 5362 } 5363 5364 static int selinux_socket_listen(struct socket *sock, int backlog) 5365 { 5366 return sock_has_perm(sock->sk, SOCKET__LISTEN); 5367 } 5368 5369 static int selinux_socket_accept(struct socket *sock, struct socket *newsock) 5370 { 5371 int err; 5372 struct inode_security_struct *isec; 5373 struct inode_security_struct *newisec; 5374 u16 sclass; 5375 u32 sid; 5376 5377 err = sock_has_perm(sock->sk, SOCKET__ACCEPT); 5378 if (err) 5379 return err; 5380 5381 isec = inode_security_novalidate(SOCK_INODE(sock)); 5382 spin_lock(&isec->lock); 5383 sclass = isec->sclass; 5384 sid = isec->sid; 5385 spin_unlock(&isec->lock); 5386 5387 newisec = inode_security_novalidate(SOCK_INODE(newsock)); 5388 newisec->sclass = sclass; 5389 newisec->sid = sid; 5390 newisec->initialized = LABEL_INITIALIZED; 5391 5392 return 0; 5393 } 5394 5395 static int selinux_socket_sendmsg(struct socket *sock, struct msghdr *msg, 5396 int size) 5397 { 5398 int rc; 5399 struct sockaddr *const addr = msg->msg_name; 5400 const int addrlen = msg->msg_namelen; 5401 5402 rc = sock_has_perm(sock->sk, SOCKET__WRITE); 5403 if (rc) 5404 return rc; 5405 5406 if (addr && (msg->msg_flags & MSG_FASTOPEN) && 5407 (sk_is_tcp(sock->sk) || 5408 (sk_is_inet(sock->sk) && sock->sk->sk_type == SOCK_STREAM && 5409 sock->sk->sk_protocol == IPPROTO_MPTCP))) { 5410 rc = selinux_socket_connect(sock, addr, addrlen); 5411 if (rc) 5412 return rc; 5413 } 5414 5415 return 0; 5416 } 5417 5418 static int selinux_socket_recvmsg(struct socket *sock, struct msghdr *msg, 5419 int size, int flags) 5420 { 5421 return sock_has_perm(sock->sk, SOCKET__READ); 5422 } 5423 5424 static int selinux_socket_getsockname(struct socket *sock) 5425 { 5426 return sock_has_perm(sock->sk, SOCKET__GETATTR); 5427 } 5428 5429 static int selinux_socket_getpeername(struct socket *sock) 5430 { 5431 return sock_has_perm(sock->sk, SOCKET__GETATTR); 5432 } 5433 5434 static int selinux_socket_setsockopt(struct socket *sock, int level, int optname) 5435 { 5436 int err; 5437 5438 err = sock_has_perm(sock->sk, SOCKET__SETOPT); 5439 if (err) 5440 return err; 5441 5442 return selinux_netlbl_socket_setsockopt(sock, level, optname); 5443 } 5444 5445 static int selinux_socket_getsockopt(struct socket *sock, int level, 5446 int optname) 5447 { 5448 return sock_has_perm(sock->sk, SOCKET__GETOPT); 5449 } 5450 5451 static int selinux_socket_shutdown(struct socket *sock, int how) 5452 { 5453 return sock_has_perm(sock->sk, SOCKET__SHUTDOWN); 5454 } 5455 5456 static int selinux_socket_unix_stream_connect(struct sock *sock, 5457 struct sock *other, 5458 struct sock *newsk) 5459 { 5460 struct sk_security_struct *sksec_sock = selinux_sock(sock); 5461 struct sk_security_struct *sksec_other = selinux_sock(other); 5462 struct sk_security_struct *sksec_new = selinux_sock(newsk); 5463 struct common_audit_data ad; 5464 struct lsm_network_audit net; 5465 int err; 5466 5467 ad_net_init_from_sk(&ad, &net, other); 5468 5469 err = avc_has_perm(sksec_sock->sid, sksec_other->sid, 5470 sksec_other->sclass, 5471 UNIX_STREAM_SOCKET__CONNECTTO, &ad); 5472 if (err) 5473 return err; 5474 5475 /* server child socket */ 5476 sksec_new->peer_sid = sksec_sock->sid; 5477 err = security_sid_mls_copy(sksec_other->sid, 5478 sksec_sock->sid, &sksec_new->sid); 5479 if (err) 5480 return err; 5481 5482 /* connecting socket */ 5483 sksec_sock->peer_sid = sksec_new->sid; 5484 5485 return 0; 5486 } 5487 5488 static int selinux_socket_unix_may_send(struct socket *sock, 5489 struct socket *other) 5490 { 5491 struct sk_security_struct *ssec = selinux_sock(sock->sk); 5492 struct sk_security_struct *osec = selinux_sock(other->sk); 5493 struct common_audit_data ad; 5494 struct lsm_network_audit net; 5495 5496 ad_net_init_from_sk(&ad, &net, other->sk); 5497 5498 return avc_has_perm(ssec->sid, osec->sid, osec->sclass, SOCKET__SENDTO, 5499 &ad); 5500 } 5501 5502 static int selinux_inet_sys_rcv_skb(struct net *ns, int ifindex, 5503 char *addrp, u16 family, u32 peer_sid, 5504 struct common_audit_data *ad) 5505 { 5506 int err; 5507 u32 if_sid; 5508 u32 node_sid; 5509 5510 err = sel_netif_sid(ns, ifindex, &if_sid); 5511 if (err) 5512 return err; 5513 err = avc_has_perm(peer_sid, if_sid, 5514 SECCLASS_NETIF, NETIF__INGRESS, ad); 5515 if (err) 5516 return err; 5517 5518 err = sel_netnode_sid(addrp, family, &node_sid); 5519 if (err) 5520 return err; 5521 return avc_has_perm(peer_sid, node_sid, 5522 SECCLASS_NODE, NODE__RECVFROM, ad); 5523 } 5524 5525 static int selinux_sock_rcv_skb_compat(struct sock *sk, struct sk_buff *skb, 5526 u16 family) 5527 { 5528 int err = 0; 5529 struct sk_security_struct *sksec = selinux_sock(sk); 5530 u32 sk_sid = sksec->sid; 5531 struct common_audit_data ad; 5532 struct lsm_network_audit net; 5533 char *addrp; 5534 5535 ad_net_init_from_iif(&ad, &net, skb->skb_iif, family); 5536 err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL); 5537 if (err) 5538 return err; 5539 5540 if (selinux_secmark_enabled()) { 5541 err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET, 5542 PACKET__RECV, &ad); 5543 if (err) 5544 return err; 5545 } 5546 5547 err = selinux_netlbl_sock_rcv_skb(sksec, skb, family, &ad); 5548 if (err) 5549 return err; 5550 err = selinux_xfrm_sock_rcv_skb(sksec->sid, skb, &ad); 5551 5552 return err; 5553 } 5554 5555 static int selinux_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb) 5556 { 5557 int err, peerlbl_active, secmark_active; 5558 struct sk_security_struct *sksec = selinux_sock(sk); 5559 u16 family = sk->sk_family; 5560 u32 sk_sid = sksec->sid; 5561 struct common_audit_data ad; 5562 struct lsm_network_audit net; 5563 char *addrp; 5564 5565 if (family != PF_INET && family != PF_INET6) 5566 return 0; 5567 5568 /* Handle mapped IPv4 packets arriving via IPv6 sockets */ 5569 if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP)) 5570 family = PF_INET; 5571 5572 /* If any sort of compatibility mode is enabled then handoff processing 5573 * to the selinux_sock_rcv_skb_compat() function to deal with the 5574 * special handling. We do this in an attempt to keep this function 5575 * as fast and as clean as possible. */ 5576 if (!selinux_policycap_netpeer()) 5577 return selinux_sock_rcv_skb_compat(sk, skb, family); 5578 5579 secmark_active = selinux_secmark_enabled(); 5580 peerlbl_active = selinux_peerlbl_enabled(); 5581 if (!secmark_active && !peerlbl_active) 5582 return 0; 5583 5584 ad_net_init_from_iif(&ad, &net, skb->skb_iif, family); 5585 err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL); 5586 if (err) 5587 return err; 5588 5589 if (peerlbl_active) { 5590 u32 peer_sid; 5591 5592 err = selinux_skb_peerlbl_sid(skb, family, &peer_sid); 5593 if (err) 5594 return err; 5595 err = selinux_inet_sys_rcv_skb(sock_net(sk), skb->skb_iif, 5596 addrp, family, peer_sid, &ad); 5597 if (err) { 5598 selinux_netlbl_err(skb, family, err, 0); 5599 return err; 5600 } 5601 err = avc_has_perm(sk_sid, peer_sid, SECCLASS_PEER, 5602 PEER__RECV, &ad); 5603 if (err) { 5604 selinux_netlbl_err(skb, family, err, 0); 5605 return err; 5606 } 5607 } 5608 5609 if (secmark_active) { 5610 err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET, 5611 PACKET__RECV, &ad); 5612 if (err) 5613 return err; 5614 } 5615 5616 return err; 5617 } 5618 5619 static int selinux_socket_getpeersec_stream(struct socket *sock, 5620 sockptr_t optval, sockptr_t optlen, 5621 unsigned int len) 5622 { 5623 int err = 0; 5624 char *scontext = NULL; 5625 u32 scontext_len; 5626 struct sk_security_struct *sksec = selinux_sock(sock->sk); 5627 u32 peer_sid = SECSID_NULL; 5628 5629 if (sksec->sclass == SECCLASS_UNIX_STREAM_SOCKET || 5630 sksec->sclass == SECCLASS_TCP_SOCKET || 5631 sksec->sclass == SECCLASS_SCTP_SOCKET) 5632 peer_sid = sksec->peer_sid; 5633 if (peer_sid == SECSID_NULL) 5634 return -ENOPROTOOPT; 5635 5636 err = security_sid_to_context(peer_sid, &scontext, 5637 &scontext_len); 5638 if (err) 5639 return err; 5640 if (scontext_len > len) { 5641 err = -ERANGE; 5642 goto out_len; 5643 } 5644 5645 if (copy_to_sockptr(optval, scontext, scontext_len)) 5646 err = -EFAULT; 5647 out_len: 5648 if (copy_to_sockptr(optlen, &scontext_len, sizeof(scontext_len))) 5649 err = -EFAULT; 5650 kfree(scontext); 5651 return err; 5652 } 5653 5654 static int selinux_socket_getpeersec_dgram(struct socket *sock, 5655 struct sk_buff *skb, u32 *secid) 5656 { 5657 u32 peer_secid = SECSID_NULL; 5658 u16 family; 5659 5660 if (skb && skb->protocol == htons(ETH_P_IP)) 5661 family = PF_INET; 5662 else if (skb && skb->protocol == htons(ETH_P_IPV6)) 5663 family = PF_INET6; 5664 else if (sock) 5665 family = sock->sk->sk_family; 5666 else { 5667 *secid = SECSID_NULL; 5668 return -EINVAL; 5669 } 5670 5671 if (sock && family == PF_UNIX) { 5672 struct inode_security_struct *isec; 5673 isec = inode_security_novalidate(SOCK_INODE(sock)); 5674 peer_secid = isec->sid; 5675 } else if (skb) 5676 selinux_skb_peerlbl_sid(skb, family, &peer_secid); 5677 5678 *secid = peer_secid; 5679 if (peer_secid == SECSID_NULL) 5680 return -ENOPROTOOPT; 5681 return 0; 5682 } 5683 5684 static int selinux_sk_alloc_security(struct sock *sk, int family, gfp_t priority) 5685 { 5686 struct sk_security_struct *sksec = selinux_sock(sk); 5687 5688 sksec->peer_sid = SECINITSID_UNLABELED; 5689 sksec->sid = SECINITSID_UNLABELED; 5690 sksec->sclass = SECCLASS_SOCKET; 5691 selinux_netlbl_sk_security_reset(sksec); 5692 5693 return 0; 5694 } 5695 5696 static void selinux_sk_free_security(struct sock *sk) 5697 { 5698 struct sk_security_struct *sksec = selinux_sock(sk); 5699 5700 selinux_netlbl_sk_security_free(sksec); 5701 } 5702 5703 static void selinux_sk_clone_security(const struct sock *sk, struct sock *newsk) 5704 { 5705 struct sk_security_struct *sksec = selinux_sock(sk); 5706 struct sk_security_struct *newsksec = selinux_sock(newsk); 5707 5708 newsksec->sid = sksec->sid; 5709 newsksec->peer_sid = sksec->peer_sid; 5710 newsksec->sclass = sksec->sclass; 5711 5712 selinux_netlbl_sk_security_reset(newsksec); 5713 } 5714 5715 static void selinux_sk_getsecid(const struct sock *sk, u32 *secid) 5716 { 5717 if (!sk) 5718 *secid = SECINITSID_ANY_SOCKET; 5719 else { 5720 const struct sk_security_struct *sksec = selinux_sock(sk); 5721 5722 *secid = sksec->sid; 5723 } 5724 } 5725 5726 static void selinux_sock_graft(struct sock *sk, struct socket *parent) 5727 { 5728 struct inode_security_struct *isec = 5729 inode_security_novalidate(SOCK_INODE(parent)); 5730 struct sk_security_struct *sksec = selinux_sock(sk); 5731 5732 if (sk->sk_family == PF_INET || sk->sk_family == PF_INET6 || 5733 sk->sk_family == PF_UNIX) 5734 isec->sid = sksec->sid; 5735 sksec->sclass = isec->sclass; 5736 } 5737 5738 /* 5739 * Determines peer_secid for the asoc and updates socket's peer label 5740 * if it's the first association on the socket. 5741 */ 5742 static int selinux_sctp_process_new_assoc(struct sctp_association *asoc, 5743 struct sk_buff *skb) 5744 { 5745 struct sock *sk = asoc->base.sk; 5746 u16 family = sk->sk_family; 5747 struct sk_security_struct *sksec = selinux_sock(sk); 5748 struct common_audit_data ad; 5749 struct lsm_network_audit net; 5750 int err; 5751 5752 /* handle mapped IPv4 packets arriving via IPv6 sockets */ 5753 if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP)) 5754 family = PF_INET; 5755 5756 if (selinux_peerlbl_enabled()) { 5757 asoc->peer_secid = SECSID_NULL; 5758 5759 /* This will return peer_sid = SECSID_NULL if there are 5760 * no peer labels, see security_net_peersid_resolve(). 5761 */ 5762 err = selinux_skb_peerlbl_sid(skb, family, &asoc->peer_secid); 5763 if (err) 5764 return err; 5765 5766 if (asoc->peer_secid == SECSID_NULL) 5767 asoc->peer_secid = SECINITSID_UNLABELED; 5768 } else { 5769 asoc->peer_secid = SECINITSID_UNLABELED; 5770 } 5771 5772 if (sksec->sctp_assoc_state == SCTP_ASSOC_UNSET) { 5773 sksec->sctp_assoc_state = SCTP_ASSOC_SET; 5774 5775 /* Here as first association on socket. As the peer SID 5776 * was allowed by peer recv (and the netif/node checks), 5777 * then it is approved by policy and used as the primary 5778 * peer SID for getpeercon(3). 5779 */ 5780 sksec->peer_sid = asoc->peer_secid; 5781 } else if (sksec->peer_sid != asoc->peer_secid) { 5782 /* Other association peer SIDs are checked to enforce 5783 * consistency among the peer SIDs. 5784 */ 5785 ad_net_init_from_sk(&ad, &net, asoc->base.sk); 5786 err = avc_has_perm(sksec->peer_sid, asoc->peer_secid, 5787 sksec->sclass, SCTP_SOCKET__ASSOCIATION, 5788 &ad); 5789 if (err) 5790 return err; 5791 } 5792 return 0; 5793 } 5794 5795 /* Called whenever SCTP receives an INIT or COOKIE ECHO chunk. This 5796 * happens on an incoming connect(2), sctp_connectx(3) or 5797 * sctp_sendmsg(3) (with no association already present). 5798 */ 5799 static int selinux_sctp_assoc_request(struct sctp_association *asoc, 5800 struct sk_buff *skb) 5801 { 5802 struct sk_security_struct *sksec = selinux_sock(asoc->base.sk); 5803 u32 conn_sid; 5804 int err; 5805 5806 if (!selinux_policycap_extsockclass()) 5807 return 0; 5808 5809 err = selinux_sctp_process_new_assoc(asoc, skb); 5810 if (err) 5811 return err; 5812 5813 /* Compute the MLS component for the connection and store 5814 * the information in asoc. This will be used by SCTP TCP type 5815 * sockets and peeled off connections as they cause a new 5816 * socket to be generated. selinux_sctp_sk_clone() will then 5817 * plug this into the new socket. 5818 */ 5819 err = selinux_conn_sid(sksec->sid, asoc->peer_secid, &conn_sid); 5820 if (err) 5821 return err; 5822 5823 asoc->secid = conn_sid; 5824 5825 /* Set any NetLabel labels including CIPSO/CALIPSO options. */ 5826 return selinux_netlbl_sctp_assoc_request(asoc, skb); 5827 } 5828 5829 /* Called when SCTP receives a COOKIE ACK chunk as the final 5830 * response to an association request (initited by us). 5831 */ 5832 static int selinux_sctp_assoc_established(struct sctp_association *asoc, 5833 struct sk_buff *skb) 5834 { 5835 struct sk_security_struct *sksec = selinux_sock(asoc->base.sk); 5836 5837 if (!selinux_policycap_extsockclass()) 5838 return 0; 5839 5840 /* Inherit secid from the parent socket - this will be picked up 5841 * by selinux_sctp_sk_clone() if the association gets peeled off 5842 * into a new socket. 5843 */ 5844 asoc->secid = sksec->sid; 5845 5846 return selinux_sctp_process_new_assoc(asoc, skb); 5847 } 5848 5849 /* Check if sctp IPv4/IPv6 addresses are valid for binding or connecting 5850 * based on their @optname. 5851 */ 5852 static int selinux_sctp_bind_connect(struct sock *sk, int optname, 5853 struct sockaddr *address, 5854 int addrlen) 5855 { 5856 int len, err = 0, walk_size = 0; 5857 void *addr_buf; 5858 struct sockaddr *addr; 5859 5860 if (!selinux_policycap_extsockclass()) 5861 return 0; 5862 5863 /* Process one or more addresses that may be IPv4 or IPv6 */ 5864 addr_buf = address; 5865 5866 while (walk_size < addrlen) { 5867 if (walk_size + sizeof(sa_family_t) > addrlen) 5868 return -EINVAL; 5869 5870 addr = addr_buf; 5871 switch (addr->sa_family) { 5872 case AF_UNSPEC: 5873 case AF_INET: 5874 len = sizeof(struct sockaddr_in); 5875 break; 5876 case AF_INET6: 5877 len = sizeof(struct sockaddr_in6); 5878 break; 5879 default: 5880 return -EINVAL; 5881 } 5882 5883 if (walk_size + len > addrlen) 5884 return -EINVAL; 5885 5886 err = -EINVAL; 5887 switch (optname) { 5888 /* Bind checks */ 5889 case SCTP_PRIMARY_ADDR: 5890 case SCTP_SET_PEER_PRIMARY_ADDR: 5891 case SCTP_SOCKOPT_BINDX_ADD: 5892 err = __selinux_socket_bind(sk, addr, len); 5893 break; 5894 /* Connect checks */ 5895 case SCTP_SOCKOPT_CONNECTX: 5896 case SCTP_PARAM_SET_PRIMARY: 5897 case SCTP_PARAM_ADD_IP: 5898 case SCTP_SENDMSG_CONNECT: 5899 err = selinux_socket_connect_helper(sk, addr, len); 5900 if (err) 5901 return err; 5902 5903 /* As selinux_sctp_bind_connect() is called by the 5904 * SCTP protocol layer, the socket is already locked, 5905 * therefore selinux_netlbl_socket_connect_locked() 5906 * is called here. The situations handled are: 5907 * sctp_connectx(3), sctp_sendmsg(3), sendmsg(2), 5908 * whenever a new IP address is added or when a new 5909 * primary address is selected. 5910 * Note that an SCTP connect(2) call happens before 5911 * the SCTP protocol layer and is handled via 5912 * selinux_socket_connect(). 5913 */ 5914 err = selinux_netlbl_socket_connect_locked(sk, addr); 5915 break; 5916 } 5917 5918 if (err) 5919 return err; 5920 5921 addr_buf += len; 5922 walk_size += len; 5923 } 5924 5925 return 0; 5926 } 5927 5928 /* Called whenever a new socket is created by accept(2) or sctp_peeloff(3). */ 5929 static void selinux_sctp_sk_clone(struct sctp_association *asoc, struct sock *sk, 5930 struct sock *newsk) 5931 { 5932 struct sk_security_struct *sksec = selinux_sock(sk); 5933 struct sk_security_struct *newsksec = selinux_sock(newsk); 5934 5935 /* If policy does not support SECCLASS_SCTP_SOCKET then call 5936 * the non-sctp clone version. 5937 */ 5938 if (!selinux_policycap_extsockclass()) 5939 return selinux_sk_clone_security(sk, newsk); 5940 5941 newsksec->sid = asoc->secid; 5942 newsksec->peer_sid = asoc->peer_secid; 5943 newsksec->sclass = sksec->sclass; 5944 selinux_netlbl_sctp_sk_clone(sk, newsk); 5945 } 5946 5947 static int selinux_mptcp_add_subflow(struct sock *sk, struct sock *ssk) 5948 { 5949 struct sk_security_struct *ssksec = selinux_sock(ssk); 5950 struct sk_security_struct *sksec = selinux_sock(sk); 5951 5952 ssksec->sclass = sksec->sclass; 5953 ssksec->sid = sksec->sid; 5954 5955 /* replace the existing subflow label deleting the existing one 5956 * and re-recreating a new label using the updated context 5957 */ 5958 selinux_netlbl_sk_security_free(ssksec); 5959 return selinux_netlbl_socket_post_create(ssk, ssk->sk_family); 5960 } 5961 5962 static int selinux_inet_conn_request(const struct sock *sk, struct sk_buff *skb, 5963 struct request_sock *req) 5964 { 5965 struct sk_security_struct *sksec = selinux_sock(sk); 5966 int err; 5967 u16 family = req->rsk_ops->family; 5968 u32 connsid; 5969 u32 peersid; 5970 5971 err = selinux_skb_peerlbl_sid(skb, family, &peersid); 5972 if (err) 5973 return err; 5974 err = selinux_conn_sid(sksec->sid, peersid, &connsid); 5975 if (err) 5976 return err; 5977 req->secid = connsid; 5978 req->peer_secid = peersid; 5979 5980 return selinux_netlbl_inet_conn_request(req, family); 5981 } 5982 5983 static void selinux_inet_csk_clone(struct sock *newsk, 5984 const struct request_sock *req) 5985 { 5986 struct sk_security_struct *newsksec = selinux_sock(newsk); 5987 5988 newsksec->sid = req->secid; 5989 newsksec->peer_sid = req->peer_secid; 5990 /* NOTE: Ideally, we should also get the isec->sid for the 5991 new socket in sync, but we don't have the isec available yet. 5992 So we will wait until sock_graft to do it, by which 5993 time it will have been created and available. */ 5994 5995 /* We don't need to take any sort of lock here as we are the only 5996 * thread with access to newsksec */ 5997 selinux_netlbl_inet_csk_clone(newsk, req->rsk_ops->family); 5998 } 5999 6000 static void selinux_inet_conn_established(struct sock *sk, struct sk_buff *skb) 6001 { 6002 u16 family = sk->sk_family; 6003 struct sk_security_struct *sksec = selinux_sock(sk); 6004 6005 /* handle mapped IPv4 packets arriving via IPv6 sockets */ 6006 if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP)) 6007 family = PF_INET; 6008 6009 selinux_skb_peerlbl_sid(skb, family, &sksec->peer_sid); 6010 } 6011 6012 static int selinux_secmark_relabel_packet(u32 sid) 6013 { 6014 return avc_has_perm(current_sid(), sid, SECCLASS_PACKET, PACKET__RELABELTO, 6015 NULL); 6016 } 6017 6018 static void selinux_secmark_refcount_inc(void) 6019 { 6020 atomic_inc(&selinux_secmark_refcount); 6021 } 6022 6023 static void selinux_secmark_refcount_dec(void) 6024 { 6025 atomic_dec(&selinux_secmark_refcount); 6026 } 6027 6028 static void selinux_req_classify_flow(const struct request_sock *req, 6029 struct flowi_common *flic) 6030 { 6031 flic->flowic_secid = req->secid; 6032 } 6033 6034 static int selinux_tun_dev_alloc_security(void *security) 6035 { 6036 struct tun_security_struct *tunsec = selinux_tun_dev(security); 6037 6038 tunsec->sid = current_sid(); 6039 return 0; 6040 } 6041 6042 static int selinux_tun_dev_create(void) 6043 { 6044 u32 sid = current_sid(); 6045 6046 /* we aren't taking into account the "sockcreate" SID since the socket 6047 * that is being created here is not a socket in the traditional sense, 6048 * instead it is a private sock, accessible only to the kernel, and 6049 * representing a wide range of network traffic spanning multiple 6050 * connections unlike traditional sockets - check the TUN driver to 6051 * get a better understanding of why this socket is special */ 6052 6053 return avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET, TUN_SOCKET__CREATE, 6054 NULL); 6055 } 6056 6057 static int selinux_tun_dev_attach_queue(void *security) 6058 { 6059 struct tun_security_struct *tunsec = selinux_tun_dev(security); 6060 6061 return avc_has_perm(current_sid(), tunsec->sid, SECCLASS_TUN_SOCKET, 6062 TUN_SOCKET__ATTACH_QUEUE, NULL); 6063 } 6064 6065 static int selinux_tun_dev_attach(struct sock *sk, void *security) 6066 { 6067 struct tun_security_struct *tunsec = selinux_tun_dev(security); 6068 struct sk_security_struct *sksec = selinux_sock(sk); 6069 6070 /* we don't currently perform any NetLabel based labeling here and it 6071 * isn't clear that we would want to do so anyway; while we could apply 6072 * labeling without the support of the TUN user the resulting labeled 6073 * traffic from the other end of the connection would almost certainly 6074 * cause confusion to the TUN user that had no idea network labeling 6075 * protocols were being used */ 6076 6077 sksec->sid = tunsec->sid; 6078 sksec->sclass = SECCLASS_TUN_SOCKET; 6079 6080 return 0; 6081 } 6082 6083 static int selinux_tun_dev_open(void *security) 6084 { 6085 struct tun_security_struct *tunsec = selinux_tun_dev(security); 6086 u32 sid = current_sid(); 6087 int err; 6088 6089 err = avc_has_perm(sid, tunsec->sid, SECCLASS_TUN_SOCKET, 6090 TUN_SOCKET__RELABELFROM, NULL); 6091 if (err) 6092 return err; 6093 err = avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET, 6094 TUN_SOCKET__RELABELTO, NULL); 6095 if (err) 6096 return err; 6097 tunsec->sid = sid; 6098 6099 return 0; 6100 } 6101 6102 #ifdef CONFIG_NETFILTER 6103 6104 static unsigned int selinux_ip_forward(void *priv, struct sk_buff *skb, 6105 const struct nf_hook_state *state) 6106 { 6107 int ifindex; 6108 u16 family; 6109 char *addrp; 6110 u32 peer_sid; 6111 struct common_audit_data ad; 6112 struct lsm_network_audit net; 6113 int secmark_active, peerlbl_active; 6114 6115 if (!selinux_policycap_netpeer()) 6116 return NF_ACCEPT; 6117 6118 secmark_active = selinux_secmark_enabled(); 6119 peerlbl_active = selinux_peerlbl_enabled(); 6120 if (!secmark_active && !peerlbl_active) 6121 return NF_ACCEPT; 6122 6123 family = state->pf; 6124 if (selinux_skb_peerlbl_sid(skb, family, &peer_sid) != 0) 6125 return NF_DROP; 6126 6127 ifindex = state->in->ifindex; 6128 ad_net_init_from_iif(&ad, &net, ifindex, family); 6129 if (selinux_parse_skb(skb, &ad, &addrp, 1, NULL) != 0) 6130 return NF_DROP; 6131 6132 if (peerlbl_active) { 6133 int err; 6134 6135 err = selinux_inet_sys_rcv_skb(state->net, ifindex, 6136 addrp, family, peer_sid, &ad); 6137 if (err) { 6138 selinux_netlbl_err(skb, family, err, 1); 6139 return NF_DROP; 6140 } 6141 } 6142 6143 if (secmark_active) 6144 if (avc_has_perm(peer_sid, skb->secmark, 6145 SECCLASS_PACKET, PACKET__FORWARD_IN, &ad)) 6146 return NF_DROP; 6147 6148 if (netlbl_enabled()) 6149 /* we do this in the FORWARD path and not the POST_ROUTING 6150 * path because we want to make sure we apply the necessary 6151 * labeling before IPsec is applied so we can leverage AH 6152 * protection */ 6153 if (selinux_netlbl_skbuff_setsid(skb, family, peer_sid) != 0) 6154 return NF_DROP; 6155 6156 return NF_ACCEPT; 6157 } 6158 6159 static unsigned int selinux_ip_output(void *priv, struct sk_buff *skb, 6160 const struct nf_hook_state *state) 6161 { 6162 struct sock *sk; 6163 u32 sid; 6164 6165 if (!netlbl_enabled()) 6166 return NF_ACCEPT; 6167 6168 /* we do this in the LOCAL_OUT path and not the POST_ROUTING path 6169 * because we want to make sure we apply the necessary labeling 6170 * before IPsec is applied so we can leverage AH protection */ 6171 sk = skb_to_full_sk(skb); 6172 if (sk) { 6173 struct sk_security_struct *sksec; 6174 6175 if (sk_listener(sk)) 6176 /* if the socket is the listening state then this 6177 * packet is a SYN-ACK packet which means it needs to 6178 * be labeled based on the connection/request_sock and 6179 * not the parent socket. unfortunately, we can't 6180 * lookup the request_sock yet as it isn't queued on 6181 * the parent socket until after the SYN-ACK is sent. 6182 * the "solution" is to simply pass the packet as-is 6183 * as any IP option based labeling should be copied 6184 * from the initial connection request (in the IP 6185 * layer). it is far from ideal, but until we get a 6186 * security label in the packet itself this is the 6187 * best we can do. */ 6188 return NF_ACCEPT; 6189 6190 /* standard practice, label using the parent socket */ 6191 sksec = selinux_sock(sk); 6192 sid = sksec->sid; 6193 } else 6194 sid = SECINITSID_KERNEL; 6195 if (selinux_netlbl_skbuff_setsid(skb, state->pf, sid) != 0) 6196 return NF_DROP; 6197 6198 return NF_ACCEPT; 6199 } 6200 6201 6202 static unsigned int selinux_ip_postroute_compat(struct sk_buff *skb, 6203 const struct nf_hook_state *state) 6204 { 6205 struct sock *sk; 6206 struct sk_security_struct *sksec; 6207 struct common_audit_data ad; 6208 struct lsm_network_audit net; 6209 u8 proto = 0; 6210 6211 sk = skb_to_full_sk(skb); 6212 if (sk == NULL) 6213 return NF_ACCEPT; 6214 sksec = selinux_sock(sk); 6215 6216 ad_net_init_from_iif(&ad, &net, state->out->ifindex, state->pf); 6217 if (selinux_parse_skb(skb, &ad, NULL, 0, &proto)) 6218 return NF_DROP; 6219 6220 if (selinux_secmark_enabled()) 6221 if (avc_has_perm(sksec->sid, skb->secmark, 6222 SECCLASS_PACKET, PACKET__SEND, &ad)) 6223 return NF_DROP_ERR(-ECONNREFUSED); 6224 6225 if (selinux_xfrm_postroute_last(sksec->sid, skb, &ad, proto)) 6226 return NF_DROP_ERR(-ECONNREFUSED); 6227 6228 return NF_ACCEPT; 6229 } 6230 6231 static unsigned int selinux_ip_postroute(void *priv, 6232 struct sk_buff *skb, 6233 const struct nf_hook_state *state) 6234 { 6235 u16 family; 6236 u32 secmark_perm; 6237 u32 peer_sid; 6238 int ifindex; 6239 struct sock *sk; 6240 struct common_audit_data ad; 6241 struct lsm_network_audit net; 6242 char *addrp; 6243 int secmark_active, peerlbl_active; 6244 6245 /* If any sort of compatibility mode is enabled then handoff processing 6246 * to the selinux_ip_postroute_compat() function to deal with the 6247 * special handling. We do this in an attempt to keep this function 6248 * as fast and as clean as possible. */ 6249 if (!selinux_policycap_netpeer()) 6250 return selinux_ip_postroute_compat(skb, state); 6251 6252 secmark_active = selinux_secmark_enabled(); 6253 peerlbl_active = selinux_peerlbl_enabled(); 6254 if (!secmark_active && !peerlbl_active) 6255 return NF_ACCEPT; 6256 6257 sk = skb_to_full_sk(skb); 6258 6259 #ifdef CONFIG_XFRM 6260 /* If skb->dst->xfrm is non-NULL then the packet is undergoing an IPsec 6261 * packet transformation so allow the packet to pass without any checks 6262 * since we'll have another chance to perform access control checks 6263 * when the packet is on it's final way out. 6264 * NOTE: there appear to be some IPv6 multicast cases where skb->dst 6265 * is NULL, in this case go ahead and apply access control. 6266 * NOTE: if this is a local socket (skb->sk != NULL) that is in the 6267 * TCP listening state we cannot wait until the XFRM processing 6268 * is done as we will miss out on the SA label if we do; 6269 * unfortunately, this means more work, but it is only once per 6270 * connection. */ 6271 if (skb_dst(skb) != NULL && skb_dst(skb)->xfrm != NULL && 6272 !(sk && sk_listener(sk))) 6273 return NF_ACCEPT; 6274 #endif 6275 6276 family = state->pf; 6277 if (sk == NULL) { 6278 /* Without an associated socket the packet is either coming 6279 * from the kernel or it is being forwarded; check the packet 6280 * to determine which and if the packet is being forwarded 6281 * query the packet directly to determine the security label. */ 6282 if (skb->skb_iif) { 6283 secmark_perm = PACKET__FORWARD_OUT; 6284 if (selinux_skb_peerlbl_sid(skb, family, &peer_sid)) 6285 return NF_DROP; 6286 } else { 6287 secmark_perm = PACKET__SEND; 6288 peer_sid = SECINITSID_KERNEL; 6289 } 6290 } else if (sk_listener(sk)) { 6291 /* Locally generated packet but the associated socket is in the 6292 * listening state which means this is a SYN-ACK packet. In 6293 * this particular case the correct security label is assigned 6294 * to the connection/request_sock but unfortunately we can't 6295 * query the request_sock as it isn't queued on the parent 6296 * socket until after the SYN-ACK packet is sent; the only 6297 * viable choice is to regenerate the label like we do in 6298 * selinux_inet_conn_request(). See also selinux_ip_output() 6299 * for similar problems. */ 6300 u32 skb_sid; 6301 struct sk_security_struct *sksec; 6302 6303 sksec = selinux_sock(sk); 6304 if (selinux_skb_peerlbl_sid(skb, family, &skb_sid)) 6305 return NF_DROP; 6306 /* At this point, if the returned skb peerlbl is SECSID_NULL 6307 * and the packet has been through at least one XFRM 6308 * transformation then we must be dealing with the "final" 6309 * form of labeled IPsec packet; since we've already applied 6310 * all of our access controls on this packet we can safely 6311 * pass the packet. */ 6312 if (skb_sid == SECSID_NULL) { 6313 switch (family) { 6314 case PF_INET: 6315 if (IPCB(skb)->flags & IPSKB_XFRM_TRANSFORMED) 6316 return NF_ACCEPT; 6317 break; 6318 case PF_INET6: 6319 if (IP6CB(skb)->flags & IP6SKB_XFRM_TRANSFORMED) 6320 return NF_ACCEPT; 6321 break; 6322 default: 6323 return NF_DROP_ERR(-ECONNREFUSED); 6324 } 6325 } 6326 if (selinux_conn_sid(sksec->sid, skb_sid, &peer_sid)) 6327 return NF_DROP; 6328 secmark_perm = PACKET__SEND; 6329 } else { 6330 /* Locally generated packet, fetch the security label from the 6331 * associated socket. */ 6332 struct sk_security_struct *sksec = selinux_sock(sk); 6333 peer_sid = sksec->sid; 6334 secmark_perm = PACKET__SEND; 6335 } 6336 6337 ifindex = state->out->ifindex; 6338 ad_net_init_from_iif(&ad, &net, ifindex, family); 6339 if (selinux_parse_skb(skb, &ad, &addrp, 0, NULL)) 6340 return NF_DROP; 6341 6342 if (secmark_active) 6343 if (avc_has_perm(peer_sid, skb->secmark, 6344 SECCLASS_PACKET, secmark_perm, &ad)) 6345 return NF_DROP_ERR(-ECONNREFUSED); 6346 6347 if (peerlbl_active) { 6348 u32 if_sid; 6349 u32 node_sid; 6350 6351 if (sel_netif_sid(state->net, ifindex, &if_sid)) 6352 return NF_DROP; 6353 if (avc_has_perm(peer_sid, if_sid, 6354 SECCLASS_NETIF, NETIF__EGRESS, &ad)) 6355 return NF_DROP_ERR(-ECONNREFUSED); 6356 6357 if (sel_netnode_sid(addrp, family, &node_sid)) 6358 return NF_DROP; 6359 if (avc_has_perm(peer_sid, node_sid, 6360 SECCLASS_NODE, NODE__SENDTO, &ad)) 6361 return NF_DROP_ERR(-ECONNREFUSED); 6362 } 6363 6364 return NF_ACCEPT; 6365 } 6366 #endif /* CONFIG_NETFILTER */ 6367 6368 static int nlmsg_sock_has_extended_perms(struct sock *sk, u32 perms, u16 nlmsg_type) 6369 { 6370 struct sk_security_struct *sksec = selinux_sock(sk); 6371 struct common_audit_data ad; 6372 u8 driver; 6373 u8 xperm; 6374 6375 if (sock_skip_has_perm(sksec->sid)) 6376 return 0; 6377 6378 ad.type = LSM_AUDIT_DATA_NLMSGTYPE; 6379 ad.u.nlmsg_type = nlmsg_type; 6380 6381 driver = nlmsg_type >> 8; 6382 xperm = nlmsg_type & 0xff; 6383 6384 return avc_has_extended_perms(current_sid(), sksec->sid, sksec->sclass, 6385 perms, driver, AVC_EXT_NLMSG, xperm, &ad); 6386 } 6387 6388 static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb) 6389 { 6390 int rc = 0; 6391 unsigned int msg_len; 6392 unsigned int data_len = skb->len; 6393 unsigned char *data = skb->data; 6394 struct nlmsghdr *nlh; 6395 struct sk_security_struct *sksec = selinux_sock(sk); 6396 u16 sclass = sksec->sclass; 6397 u32 perm; 6398 6399 while (data_len >= nlmsg_total_size(0)) { 6400 nlh = (struct nlmsghdr *)data; 6401 6402 /* NOTE: the nlmsg_len field isn't reliably set by some netlink 6403 * users which means we can't reject skb's with bogus 6404 * length fields; our solution is to follow what 6405 * netlink_rcv_skb() does and simply skip processing at 6406 * messages with length fields that are clearly junk 6407 */ 6408 if (nlh->nlmsg_len < NLMSG_HDRLEN || nlh->nlmsg_len > data_len) 6409 return 0; 6410 6411 rc = selinux_nlmsg_lookup(sclass, nlh->nlmsg_type, &perm); 6412 if (rc == 0) { 6413 if (selinux_policycap_netlink_xperm()) { 6414 rc = nlmsg_sock_has_extended_perms( 6415 sk, perm, nlh->nlmsg_type); 6416 } else { 6417 rc = sock_has_perm(sk, perm); 6418 } 6419 if (rc) 6420 return rc; 6421 } else if (rc == -EINVAL) { 6422 /* -EINVAL is a missing msg/perm mapping */ 6423 if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET && 6424 nlh->nlmsg_type == DCCPDIAG_GETSOCK) 6425 pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n", 6426 task_pid_nr(current), current->comm); 6427 else 6428 pr_warn_ratelimited("SELinux: unrecognized netlink" 6429 " message: protocol=%hu nlmsg_type=%hu sclass=%s" 6430 " pid=%d comm=%s\n", 6431 sk->sk_protocol, nlh->nlmsg_type, 6432 secclass_map[sclass - 1].name, 6433 task_pid_nr(current), current->comm); 6434 if (enforcing_enabled() && 6435 !security_get_allow_unknown()) 6436 return rc; 6437 rc = 0; 6438 } else if (rc == -ENOENT) { 6439 /* -ENOENT is a missing socket/class mapping, ignore */ 6440 rc = 0; 6441 } else { 6442 return rc; 6443 } 6444 6445 /* move to the next message after applying netlink padding */ 6446 msg_len = NLMSG_ALIGN(nlh->nlmsg_len); 6447 if (msg_len >= data_len) 6448 return 0; 6449 data_len -= msg_len; 6450 data += msg_len; 6451 } 6452 6453 return rc; 6454 } 6455 6456 static void ipc_init_security(struct ipc_security_struct *isec, u16 sclass) 6457 { 6458 isec->sclass = sclass; 6459 isec->sid = current_sid(); 6460 } 6461 6462 static int ipc_has_perm(struct kern_ipc_perm *ipc_perms, 6463 u32 perms) 6464 { 6465 struct ipc_security_struct *isec; 6466 struct common_audit_data ad; 6467 u32 sid = current_sid(); 6468 6469 isec = selinux_ipc(ipc_perms); 6470 6471 ad.type = LSM_AUDIT_DATA_IPC; 6472 ad.u.ipc_id = ipc_perms->key; 6473 6474 return avc_has_perm(sid, isec->sid, isec->sclass, perms, &ad); 6475 } 6476 6477 static int selinux_msg_msg_alloc_security(struct msg_msg *msg) 6478 { 6479 struct msg_security_struct *msec; 6480 6481 msec = selinux_msg_msg(msg); 6482 msec->sid = SECINITSID_UNLABELED; 6483 6484 return 0; 6485 } 6486 6487 /* message queue security operations */ 6488 static int selinux_msg_queue_alloc_security(struct kern_ipc_perm *msq) 6489 { 6490 struct ipc_security_struct *isec; 6491 struct common_audit_data ad; 6492 u32 sid = current_sid(); 6493 6494 isec = selinux_ipc(msq); 6495 ipc_init_security(isec, SECCLASS_MSGQ); 6496 6497 ad.type = LSM_AUDIT_DATA_IPC; 6498 ad.u.ipc_id = msq->key; 6499 6500 return avc_has_perm(sid, isec->sid, SECCLASS_MSGQ, 6501 MSGQ__CREATE, &ad); 6502 } 6503 6504 static int selinux_msg_queue_associate(struct kern_ipc_perm *msq, int msqflg) 6505 { 6506 struct ipc_security_struct *isec; 6507 struct common_audit_data ad; 6508 u32 sid = current_sid(); 6509 6510 isec = selinux_ipc(msq); 6511 6512 ad.type = LSM_AUDIT_DATA_IPC; 6513 ad.u.ipc_id = msq->key; 6514 6515 return avc_has_perm(sid, isec->sid, SECCLASS_MSGQ, 6516 MSGQ__ASSOCIATE, &ad); 6517 } 6518 6519 static int selinux_msg_queue_msgctl(struct kern_ipc_perm *msq, int cmd) 6520 { 6521 u32 perms; 6522 6523 switch (cmd) { 6524 case IPC_INFO: 6525 case MSG_INFO: 6526 /* No specific object, just general system-wide information. */ 6527 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 6528 SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL); 6529 case IPC_STAT: 6530 case MSG_STAT: 6531 case MSG_STAT_ANY: 6532 perms = MSGQ__GETATTR | MSGQ__ASSOCIATE; 6533 break; 6534 case IPC_SET: 6535 perms = MSGQ__SETATTR; 6536 break; 6537 case IPC_RMID: 6538 perms = MSGQ__DESTROY; 6539 break; 6540 default: 6541 return 0; 6542 } 6543 6544 return ipc_has_perm(msq, perms); 6545 } 6546 6547 static int selinux_msg_queue_msgsnd(struct kern_ipc_perm *msq, struct msg_msg *msg, int msqflg) 6548 { 6549 struct ipc_security_struct *isec; 6550 struct msg_security_struct *msec; 6551 struct common_audit_data ad; 6552 u32 sid = current_sid(); 6553 int rc; 6554 6555 isec = selinux_ipc(msq); 6556 msec = selinux_msg_msg(msg); 6557 6558 /* 6559 * First time through, need to assign label to the message 6560 */ 6561 if (msec->sid == SECINITSID_UNLABELED) { 6562 /* 6563 * Compute new sid based on current process and 6564 * message queue this message will be stored in 6565 */ 6566 rc = security_transition_sid(sid, isec->sid, 6567 SECCLASS_MSG, NULL, &msec->sid); 6568 if (rc) 6569 return rc; 6570 } 6571 6572 ad.type = LSM_AUDIT_DATA_IPC; 6573 ad.u.ipc_id = msq->key; 6574 6575 /* Can this process write to the queue? */ 6576 rc = avc_has_perm(sid, isec->sid, SECCLASS_MSGQ, 6577 MSGQ__WRITE, &ad); 6578 if (!rc) 6579 /* Can this process send the message */ 6580 rc = avc_has_perm(sid, msec->sid, SECCLASS_MSG, 6581 MSG__SEND, &ad); 6582 if (!rc) 6583 /* Can the message be put in the queue? */ 6584 rc = avc_has_perm(msec->sid, isec->sid, SECCLASS_MSGQ, 6585 MSGQ__ENQUEUE, &ad); 6586 6587 return rc; 6588 } 6589 6590 static int selinux_msg_queue_msgrcv(struct kern_ipc_perm *msq, struct msg_msg *msg, 6591 struct task_struct *target, 6592 long type, int mode) 6593 { 6594 struct ipc_security_struct *isec; 6595 struct msg_security_struct *msec; 6596 struct common_audit_data ad; 6597 u32 sid = task_sid_obj(target); 6598 int rc; 6599 6600 isec = selinux_ipc(msq); 6601 msec = selinux_msg_msg(msg); 6602 6603 ad.type = LSM_AUDIT_DATA_IPC; 6604 ad.u.ipc_id = msq->key; 6605 6606 rc = avc_has_perm(sid, isec->sid, 6607 SECCLASS_MSGQ, MSGQ__READ, &ad); 6608 if (!rc) 6609 rc = avc_has_perm(sid, msec->sid, 6610 SECCLASS_MSG, MSG__RECEIVE, &ad); 6611 return rc; 6612 } 6613 6614 /* Shared Memory security operations */ 6615 static int selinux_shm_alloc_security(struct kern_ipc_perm *shp) 6616 { 6617 struct ipc_security_struct *isec; 6618 struct common_audit_data ad; 6619 u32 sid = current_sid(); 6620 6621 isec = selinux_ipc(shp); 6622 ipc_init_security(isec, SECCLASS_SHM); 6623 6624 ad.type = LSM_AUDIT_DATA_IPC; 6625 ad.u.ipc_id = shp->key; 6626 6627 return avc_has_perm(sid, isec->sid, SECCLASS_SHM, 6628 SHM__CREATE, &ad); 6629 } 6630 6631 static int selinux_shm_associate(struct kern_ipc_perm *shp, int shmflg) 6632 { 6633 struct ipc_security_struct *isec; 6634 struct common_audit_data ad; 6635 u32 sid = current_sid(); 6636 6637 isec = selinux_ipc(shp); 6638 6639 ad.type = LSM_AUDIT_DATA_IPC; 6640 ad.u.ipc_id = shp->key; 6641 6642 return avc_has_perm(sid, isec->sid, SECCLASS_SHM, 6643 SHM__ASSOCIATE, &ad); 6644 } 6645 6646 /* Note, at this point, shp is locked down */ 6647 static int selinux_shm_shmctl(struct kern_ipc_perm *shp, int cmd) 6648 { 6649 u32 perms; 6650 6651 switch (cmd) { 6652 case IPC_INFO: 6653 case SHM_INFO: 6654 /* No specific object, just general system-wide information. */ 6655 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 6656 SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL); 6657 case IPC_STAT: 6658 case SHM_STAT: 6659 case SHM_STAT_ANY: 6660 perms = SHM__GETATTR | SHM__ASSOCIATE; 6661 break; 6662 case IPC_SET: 6663 perms = SHM__SETATTR; 6664 break; 6665 case SHM_LOCK: 6666 case SHM_UNLOCK: 6667 perms = SHM__LOCK; 6668 break; 6669 case IPC_RMID: 6670 perms = SHM__DESTROY; 6671 break; 6672 default: 6673 return 0; 6674 } 6675 6676 return ipc_has_perm(shp, perms); 6677 } 6678 6679 static int selinux_shm_shmat(struct kern_ipc_perm *shp, 6680 char __user *shmaddr, int shmflg) 6681 { 6682 u32 perms; 6683 6684 if (shmflg & SHM_RDONLY) 6685 perms = SHM__READ; 6686 else 6687 perms = SHM__READ | SHM__WRITE; 6688 6689 return ipc_has_perm(shp, perms); 6690 } 6691 6692 /* Semaphore security operations */ 6693 static int selinux_sem_alloc_security(struct kern_ipc_perm *sma) 6694 { 6695 struct ipc_security_struct *isec; 6696 struct common_audit_data ad; 6697 u32 sid = current_sid(); 6698 6699 isec = selinux_ipc(sma); 6700 ipc_init_security(isec, SECCLASS_SEM); 6701 6702 ad.type = LSM_AUDIT_DATA_IPC; 6703 ad.u.ipc_id = sma->key; 6704 6705 return avc_has_perm(sid, isec->sid, SECCLASS_SEM, 6706 SEM__CREATE, &ad); 6707 } 6708 6709 static int selinux_sem_associate(struct kern_ipc_perm *sma, int semflg) 6710 { 6711 struct ipc_security_struct *isec; 6712 struct common_audit_data ad; 6713 u32 sid = current_sid(); 6714 6715 isec = selinux_ipc(sma); 6716 6717 ad.type = LSM_AUDIT_DATA_IPC; 6718 ad.u.ipc_id = sma->key; 6719 6720 return avc_has_perm(sid, isec->sid, SECCLASS_SEM, 6721 SEM__ASSOCIATE, &ad); 6722 } 6723 6724 /* Note, at this point, sma is locked down */ 6725 static int selinux_sem_semctl(struct kern_ipc_perm *sma, int cmd) 6726 { 6727 int err; 6728 u32 perms; 6729 6730 switch (cmd) { 6731 case IPC_INFO: 6732 case SEM_INFO: 6733 /* No specific object, just general system-wide information. */ 6734 return avc_has_perm(current_sid(), SECINITSID_KERNEL, 6735 SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL); 6736 case GETPID: 6737 case GETNCNT: 6738 case GETZCNT: 6739 perms = SEM__GETATTR; 6740 break; 6741 case GETVAL: 6742 case GETALL: 6743 perms = SEM__READ; 6744 break; 6745 case SETVAL: 6746 case SETALL: 6747 perms = SEM__WRITE; 6748 break; 6749 case IPC_RMID: 6750 perms = SEM__DESTROY; 6751 break; 6752 case IPC_SET: 6753 perms = SEM__SETATTR; 6754 break; 6755 case IPC_STAT: 6756 case SEM_STAT: 6757 case SEM_STAT_ANY: 6758 perms = SEM__GETATTR | SEM__ASSOCIATE; 6759 break; 6760 default: 6761 return 0; 6762 } 6763 6764 err = ipc_has_perm(sma, perms); 6765 return err; 6766 } 6767 6768 static int selinux_sem_semop(struct kern_ipc_perm *sma, 6769 struct sembuf *sops, unsigned nsops, int alter) 6770 { 6771 u32 perms; 6772 6773 if (alter) 6774 perms = SEM__READ | SEM__WRITE; 6775 else 6776 perms = SEM__READ; 6777 6778 return ipc_has_perm(sma, perms); 6779 } 6780 6781 static int selinux_ipc_permission(struct kern_ipc_perm *ipcp, short flag) 6782 { 6783 u32 av = 0; 6784 6785 av = 0; 6786 if (flag & S_IRUGO) 6787 av |= IPC__UNIX_READ; 6788 if (flag & S_IWUGO) 6789 av |= IPC__UNIX_WRITE; 6790 6791 if (av == 0) 6792 return 0; 6793 6794 return ipc_has_perm(ipcp, av); 6795 } 6796 6797 static void selinux_ipc_getlsmprop(struct kern_ipc_perm *ipcp, 6798 struct lsm_prop *prop) 6799 { 6800 struct ipc_security_struct *isec = selinux_ipc(ipcp); 6801 prop->selinux.secid = isec->sid; 6802 } 6803 6804 static void selinux_d_instantiate(struct dentry *dentry, struct inode *inode) 6805 { 6806 if (inode) 6807 inode_doinit_with_dentry(inode, dentry); 6808 } 6809 6810 static int selinux_lsm_getattr(unsigned int attr, struct task_struct *p, 6811 char **value) 6812 { 6813 const struct cred_security_struct *crsec; 6814 int error; 6815 u32 sid; 6816 u32 len; 6817 6818 rcu_read_lock(); 6819 crsec = selinux_cred(__task_cred(p)); 6820 if (p != current) { 6821 error = avc_has_perm(current_sid(), crsec->sid, 6822 SECCLASS_PROCESS, PROCESS__GETATTR, NULL); 6823 if (error) 6824 goto err_unlock; 6825 } 6826 switch (attr) { 6827 case LSM_ATTR_CURRENT: 6828 sid = crsec->sid; 6829 break; 6830 case LSM_ATTR_PREV: 6831 sid = crsec->osid; 6832 break; 6833 case LSM_ATTR_EXEC: 6834 sid = crsec->exec_sid; 6835 break; 6836 case LSM_ATTR_FSCREATE: 6837 sid = crsec->create_sid; 6838 break; 6839 case LSM_ATTR_KEYCREATE: 6840 sid = crsec->keycreate_sid; 6841 break; 6842 case LSM_ATTR_SOCKCREATE: 6843 sid = crsec->sockcreate_sid; 6844 break; 6845 default: 6846 error = -EOPNOTSUPP; 6847 goto err_unlock; 6848 } 6849 rcu_read_unlock(); 6850 6851 if (sid == SECSID_NULL) { 6852 *value = NULL; 6853 return 0; 6854 } 6855 6856 error = security_sid_to_context(sid, value, &len); 6857 if (error) 6858 return error; 6859 return len; 6860 6861 err_unlock: 6862 rcu_read_unlock(); 6863 return error; 6864 } 6865 6866 static int selinux_lsm_setattr(u64 attr, void *value, size_t size) 6867 { 6868 struct cred_security_struct *crsec; 6869 struct cred *new; 6870 u32 mysid = current_sid(), sid = 0, ptsid; 6871 int error; 6872 char *str = value; 6873 6874 /* 6875 * Basic control over ability to set these attributes at all. 6876 */ 6877 switch (attr) { 6878 case LSM_ATTR_EXEC: 6879 error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS, 6880 PROCESS__SETEXEC, NULL); 6881 break; 6882 case LSM_ATTR_FSCREATE: 6883 error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS, 6884 PROCESS__SETFSCREATE, NULL); 6885 break; 6886 case LSM_ATTR_KEYCREATE: 6887 error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS, 6888 PROCESS__SETKEYCREATE, NULL); 6889 break; 6890 case LSM_ATTR_SOCKCREATE: 6891 error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS, 6892 PROCESS__SETSOCKCREATE, NULL); 6893 break; 6894 case LSM_ATTR_CURRENT: 6895 error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS, 6896 PROCESS__SETCURRENT, NULL); 6897 break; 6898 default: 6899 error = -EOPNOTSUPP; 6900 break; 6901 } 6902 if (error) 6903 return error; 6904 6905 /* Obtain a SID for the context, if one was specified. */ 6906 if (size && str[0] && str[0] != '\n') { 6907 if (str[size-1] == '\n') { 6908 str[size-1] = 0; 6909 size--; 6910 } 6911 error = security_context_to_sid(value, size, 6912 &sid, GFP_KERNEL); 6913 if (error == -EINVAL && attr == LSM_ATTR_FSCREATE) { 6914 if (!has_cap_mac_admin(true)) { 6915 struct audit_buffer *ab; 6916 size_t audit_size; 6917 6918 /* We strip a nul only if it is at the end, 6919 * otherwise the context contains a nul and 6920 * we should audit that */ 6921 if (str[size - 1] == '\0') 6922 audit_size = size - 1; 6923 else 6924 audit_size = size; 6925 ab = audit_log_start(audit_context(), 6926 GFP_ATOMIC, 6927 AUDIT_SELINUX_ERR); 6928 if (!ab) 6929 return error; 6930 audit_log_format(ab, "op=fscreate invalid_context="); 6931 audit_log_n_untrustedstring(ab, value, 6932 audit_size); 6933 audit_log_end(ab); 6934 6935 return error; 6936 } 6937 error = security_context_to_sid_force(value, size, 6938 &sid); 6939 } 6940 if (error) 6941 return error; 6942 } 6943 6944 new = prepare_creds(); 6945 if (!new) 6946 return -ENOMEM; 6947 6948 /* Permission checking based on the specified context is 6949 performed during the actual operation (execve, 6950 open/mkdir/...), when we know the full context of the 6951 operation. See selinux_bprm_creds_for_exec for the execve 6952 checks and may_create for the file creation checks. The 6953 operation will then fail if the context is not permitted. */ 6954 crsec = selinux_cred(new); 6955 if (attr == LSM_ATTR_EXEC) { 6956 crsec->exec_sid = sid; 6957 } else if (attr == LSM_ATTR_FSCREATE) { 6958 crsec->create_sid = sid; 6959 } else if (attr == LSM_ATTR_KEYCREATE) { 6960 if (sid) { 6961 error = avc_has_perm(mysid, sid, 6962 SECCLASS_KEY, KEY__CREATE, NULL); 6963 if (error) 6964 goto abort_change; 6965 } 6966 crsec->keycreate_sid = sid; 6967 } else if (attr == LSM_ATTR_SOCKCREATE) { 6968 crsec->sockcreate_sid = sid; 6969 } else if (attr == LSM_ATTR_CURRENT) { 6970 error = -EINVAL; 6971 if (sid == 0) 6972 goto abort_change; 6973 6974 if (!current_is_single_threaded()) { 6975 error = security_bounded_transition(crsec->sid, sid); 6976 if (error) 6977 goto abort_change; 6978 } 6979 6980 /* Check permissions for the transition. */ 6981 error = avc_has_perm(crsec->sid, sid, SECCLASS_PROCESS, 6982 PROCESS__DYNTRANSITION, NULL); 6983 if (error) 6984 goto abort_change; 6985 6986 /* Check for ptracing, and update the task SID if ok. 6987 Otherwise, leave SID unchanged and fail. */ 6988 ptsid = ptrace_parent_sid(); 6989 if (ptsid != 0) { 6990 error = avc_has_perm(ptsid, sid, SECCLASS_PROCESS, 6991 PROCESS__PTRACE, NULL); 6992 if (error) 6993 goto abort_change; 6994 } 6995 6996 crsec->sid = sid; 6997 } else { 6998 error = -EINVAL; 6999 goto abort_change; 7000 } 7001 7002 commit_creds(new); 7003 return size; 7004 7005 abort_change: 7006 abort_creds(new); 7007 return error; 7008 } 7009 7010 /** 7011 * selinux_getselfattr - Get SELinux current task attributes 7012 * @attr: the requested attribute 7013 * @ctx: buffer to receive the result 7014 * @size: buffer size (input), buffer size used (output) 7015 * @flags: unused 7016 * 7017 * Fill the passed user space @ctx with the details of the requested 7018 * attribute. 7019 * 7020 * Returns the number of attributes on success, an error code otherwise. 7021 * There will only ever be one attribute. 7022 */ 7023 static int selinux_getselfattr(unsigned int attr, struct lsm_ctx __user *ctx, 7024 u32 *size, u32 flags) 7025 { 7026 int rc; 7027 char *val = NULL; 7028 int val_len; 7029 7030 val_len = selinux_lsm_getattr(attr, current, &val); 7031 if (val_len < 0) 7032 return val_len; 7033 rc = lsm_fill_user_ctx(ctx, size, val, val_len, LSM_ID_SELINUX, 0); 7034 kfree(val); 7035 return (!rc ? 1 : rc); 7036 } 7037 7038 static int selinux_setselfattr(unsigned int attr, struct lsm_ctx *ctx, 7039 u32 size, u32 flags) 7040 { 7041 int rc; 7042 7043 rc = selinux_lsm_setattr(attr, ctx->ctx, ctx->ctx_len); 7044 if (rc > 0) 7045 return 0; 7046 return rc; 7047 } 7048 7049 static int selinux_getprocattr(struct task_struct *p, 7050 const char *name, char **value) 7051 { 7052 unsigned int attr = lsm_name_to_attr(name); 7053 int rc; 7054 7055 if (attr) { 7056 rc = selinux_lsm_getattr(attr, p, value); 7057 if (rc != -EOPNOTSUPP) 7058 return rc; 7059 } 7060 7061 return -EINVAL; 7062 } 7063 7064 static int selinux_setprocattr(const char *name, void *value, size_t size) 7065 { 7066 int attr = lsm_name_to_attr(name); 7067 7068 if (attr) 7069 return selinux_lsm_setattr(attr, value, size); 7070 return -EINVAL; 7071 } 7072 7073 static int selinux_ismaclabel(const char *name) 7074 { 7075 return (strcmp(name, XATTR_SELINUX_SUFFIX) == 0); 7076 } 7077 7078 static int selinux_secid_to_secctx(u32 secid, struct lsm_context *cp) 7079 { 7080 u32 seclen; 7081 int ret; 7082 7083 if (cp) { 7084 cp->id = LSM_ID_SELINUX; 7085 ret = security_sid_to_context(secid, &cp->context, &cp->len); 7086 if (ret < 0) 7087 return ret; 7088 return cp->len; 7089 } 7090 ret = security_sid_to_context(secid, NULL, &seclen); 7091 if (ret < 0) 7092 return ret; 7093 return seclen; 7094 } 7095 7096 static int selinux_lsmprop_to_secctx(struct lsm_prop *prop, 7097 struct lsm_context *cp) 7098 { 7099 return selinux_secid_to_secctx(prop->selinux.secid, cp); 7100 } 7101 7102 static int selinux_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid) 7103 { 7104 return security_context_to_sid(secdata, seclen, 7105 secid, GFP_KERNEL); 7106 } 7107 7108 static void selinux_release_secctx(struct lsm_context *cp) 7109 { 7110 if (cp->id == LSM_ID_SELINUX) { 7111 kfree(cp->context); 7112 cp->context = NULL; 7113 cp->id = LSM_ID_UNDEF; 7114 } 7115 } 7116 7117 static void selinux_inode_invalidate_secctx(struct inode *inode) 7118 { 7119 struct inode_security_struct *isec = selinux_inode(inode); 7120 7121 spin_lock(&isec->lock); 7122 isec->initialized = LABEL_INVALID; 7123 spin_unlock(&isec->lock); 7124 } 7125 7126 /* 7127 * called with inode->i_mutex locked 7128 */ 7129 static int selinux_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen) 7130 { 7131 int rc = selinux_inode_setsecurity(inode, XATTR_SELINUX_SUFFIX, 7132 ctx, ctxlen, 0); 7133 /* Do not return error when suppressing label (SBLABEL_MNT not set). */ 7134 return rc == -EOPNOTSUPP ? 0 : rc; 7135 } 7136 7137 /* 7138 * called with inode->i_mutex locked 7139 */ 7140 static int selinux_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen) 7141 { 7142 return __vfs_setxattr_locked(&nop_mnt_idmap, dentry, XATTR_NAME_SELINUX, 7143 ctx, ctxlen, 0, NULL); 7144 } 7145 7146 static int selinux_inode_getsecctx(struct inode *inode, struct lsm_context *cp) 7147 { 7148 int len; 7149 len = selinux_inode_getsecurity(&nop_mnt_idmap, inode, 7150 XATTR_SELINUX_SUFFIX, 7151 (void **)&cp->context, true); 7152 if (len < 0) 7153 return len; 7154 cp->len = len; 7155 cp->id = LSM_ID_SELINUX; 7156 return 0; 7157 } 7158 #ifdef CONFIG_KEYS 7159 7160 static int selinux_key_alloc(struct key *k, const struct cred *cred, 7161 unsigned long flags) 7162 { 7163 const struct cred_security_struct *crsec; 7164 struct key_security_struct *ksec = selinux_key(k); 7165 7166 crsec = selinux_cred(cred); 7167 if (crsec->keycreate_sid) 7168 ksec->sid = crsec->keycreate_sid; 7169 else 7170 ksec->sid = crsec->sid; 7171 7172 return 0; 7173 } 7174 7175 static int selinux_key_permission(key_ref_t key_ref, 7176 const struct cred *cred, 7177 enum key_need_perm need_perm) 7178 { 7179 struct key *key; 7180 struct key_security_struct *ksec; 7181 u32 perm, sid; 7182 7183 switch (need_perm) { 7184 case KEY_NEED_VIEW: 7185 perm = KEY__VIEW; 7186 break; 7187 case KEY_NEED_READ: 7188 perm = KEY__READ; 7189 break; 7190 case KEY_NEED_WRITE: 7191 perm = KEY__WRITE; 7192 break; 7193 case KEY_NEED_SEARCH: 7194 perm = KEY__SEARCH; 7195 break; 7196 case KEY_NEED_LINK: 7197 perm = KEY__LINK; 7198 break; 7199 case KEY_NEED_SETATTR: 7200 perm = KEY__SETATTR; 7201 break; 7202 case KEY_NEED_UNLINK: 7203 case KEY_SYSADMIN_OVERRIDE: 7204 case KEY_AUTHTOKEN_OVERRIDE: 7205 case KEY_DEFER_PERM_CHECK: 7206 return 0; 7207 default: 7208 WARN_ON(1); 7209 return -EPERM; 7210 7211 } 7212 7213 sid = cred_sid(cred); 7214 key = key_ref_to_ptr(key_ref); 7215 ksec = selinux_key(key); 7216 7217 return avc_has_perm(sid, ksec->sid, SECCLASS_KEY, perm, NULL); 7218 } 7219 7220 static int selinux_key_getsecurity(struct key *key, char **_buffer) 7221 { 7222 struct key_security_struct *ksec = selinux_key(key); 7223 char *context = NULL; 7224 unsigned len; 7225 int rc; 7226 7227 rc = security_sid_to_context(ksec->sid, 7228 &context, &len); 7229 if (!rc) 7230 rc = len; 7231 *_buffer = context; 7232 return rc; 7233 } 7234 7235 #ifdef CONFIG_KEY_NOTIFICATIONS 7236 static int selinux_watch_key(struct key *key) 7237 { 7238 struct key_security_struct *ksec = selinux_key(key); 7239 u32 sid = current_sid(); 7240 7241 return avc_has_perm(sid, ksec->sid, SECCLASS_KEY, KEY__VIEW, NULL); 7242 } 7243 #endif 7244 #endif 7245 7246 #ifdef CONFIG_SECURITY_INFINIBAND 7247 static int selinux_ib_pkey_access(void *ib_sec, u64 subnet_prefix, u16 pkey_val) 7248 { 7249 struct common_audit_data ad; 7250 int err; 7251 u32 sid = 0; 7252 struct ib_security_struct *sec = ib_sec; 7253 struct lsm_ibpkey_audit ibpkey; 7254 7255 err = sel_ib_pkey_sid(subnet_prefix, pkey_val, &sid); 7256 if (err) 7257 return err; 7258 7259 ad.type = LSM_AUDIT_DATA_IBPKEY; 7260 ibpkey.subnet_prefix = subnet_prefix; 7261 ibpkey.pkey = pkey_val; 7262 ad.u.ibpkey = &ibpkey; 7263 return avc_has_perm(sec->sid, sid, 7264 SECCLASS_INFINIBAND_PKEY, 7265 INFINIBAND_PKEY__ACCESS, &ad); 7266 } 7267 7268 static int selinux_ib_endport_manage_subnet(void *ib_sec, const char *dev_name, 7269 u8 port_num) 7270 { 7271 struct common_audit_data ad; 7272 int err; 7273 u32 sid = 0; 7274 struct ib_security_struct *sec = ib_sec; 7275 struct lsm_ibendport_audit ibendport; 7276 7277 err = security_ib_endport_sid(dev_name, port_num, 7278 &sid); 7279 7280 if (err) 7281 return err; 7282 7283 ad.type = LSM_AUDIT_DATA_IBENDPORT; 7284 ibendport.dev_name = dev_name; 7285 ibendport.port = port_num; 7286 ad.u.ibendport = &ibendport; 7287 return avc_has_perm(sec->sid, sid, 7288 SECCLASS_INFINIBAND_ENDPORT, 7289 INFINIBAND_ENDPORT__MANAGE_SUBNET, &ad); 7290 } 7291 7292 static int selinux_ib_alloc_security(void *ib_sec) 7293 { 7294 struct ib_security_struct *sec = selinux_ib(ib_sec); 7295 7296 sec->sid = current_sid(); 7297 return 0; 7298 } 7299 #endif 7300 7301 #ifdef CONFIG_BPF_SYSCALL 7302 static int selinux_bpf(int cmd, union bpf_attr *attr, 7303 unsigned int size, bool kernel) 7304 { 7305 u32 sid = current_sid(); 7306 int ret; 7307 7308 if (selinux_policycap_bpf_token_perms()) 7309 return 0; 7310 7311 switch (cmd) { 7312 case BPF_MAP_CREATE: 7313 ret = avc_has_perm(sid, sid, SECCLASS_BPF, BPF__MAP_CREATE, 7314 NULL); 7315 break; 7316 case BPF_PROG_LOAD: 7317 ret = avc_has_perm(sid, sid, SECCLASS_BPF, BPF__PROG_LOAD, 7318 NULL); 7319 break; 7320 default: 7321 ret = 0; 7322 break; 7323 } 7324 7325 return ret; 7326 } 7327 7328 static u32 bpf_map_fmode_to_av(fmode_t fmode) 7329 { 7330 u32 av = 0; 7331 7332 if (fmode & FMODE_READ) 7333 av |= BPF__MAP_READ; 7334 if (fmode & FMODE_WRITE) 7335 av |= BPF__MAP_WRITE; 7336 return av; 7337 } 7338 7339 /* This function will check the file pass through unix socket or binder to see 7340 * if it is a bpf related object. And apply corresponding checks on the bpf 7341 * object based on the type. The bpf maps and programs, not like other files and 7342 * socket, are using a shared anonymous inode inside the kernel as their inode. 7343 * So checking that inode cannot identify if the process have privilege to 7344 * access the bpf object and that's why we have to add this additional check in 7345 * selinux_file_receive and selinux_binder_transfer_files. 7346 */ 7347 static int bpf_fd_pass(const struct file *file, u32 sid) 7348 { 7349 struct bpf_security_struct *bpfsec; 7350 struct bpf_prog *prog; 7351 struct bpf_map *map; 7352 int ret; 7353 7354 if (file->f_op == &bpf_map_fops) { 7355 map = file->private_data; 7356 bpfsec = selinux_bpf_map_security(map); 7357 ret = avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF, 7358 bpf_map_fmode_to_av(file->f_mode), NULL); 7359 if (ret) 7360 return ret; 7361 } else if (file->f_op == &bpf_prog_fops) { 7362 prog = file->private_data; 7363 bpfsec = selinux_bpf_prog_security(prog); 7364 ret = avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF, 7365 BPF__PROG_RUN, NULL); 7366 if (ret) 7367 return ret; 7368 } 7369 return 0; 7370 } 7371 7372 static int selinux_bpf_map(struct bpf_map *map, fmode_t fmode) 7373 { 7374 u32 sid = current_sid(); 7375 struct bpf_security_struct *bpfsec; 7376 7377 bpfsec = selinux_bpf_map_security(map); 7378 return avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF, 7379 bpf_map_fmode_to_av(fmode), NULL); 7380 } 7381 7382 static int selinux_bpf_prog(struct bpf_prog *prog) 7383 { 7384 u32 sid = current_sid(); 7385 struct bpf_security_struct *bpfsec; 7386 7387 bpfsec = selinux_bpf_prog_security(prog); 7388 return avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF, 7389 BPF__PROG_RUN, NULL); 7390 } 7391 7392 static int selinux_bpf_map_create(struct bpf_map *map, union bpf_attr *attr, 7393 struct bpf_token *token, bool kernel) 7394 { 7395 struct bpf_security_struct *bpfsec; 7396 u32 ssid; 7397 7398 bpfsec = selinux_bpf_map_security(map); 7399 bpfsec->sid = current_sid(); 7400 7401 if (!token) 7402 ssid = bpfsec->sid; 7403 else 7404 ssid = selinux_bpf_token_security(token)->grantor_sid; 7405 7406 return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__MAP_CREATE, 7407 NULL); 7408 } 7409 7410 static int selinux_bpf_prog_load(struct bpf_prog *prog, union bpf_attr *attr, 7411 struct bpf_token *token, bool kernel) 7412 { 7413 struct bpf_security_struct *bpfsec; 7414 u32 ssid; 7415 7416 bpfsec = selinux_bpf_prog_security(prog); 7417 bpfsec->sid = current_sid(); 7418 7419 if (!token) 7420 ssid = bpfsec->sid; 7421 else 7422 ssid = selinux_bpf_token_security(token)->grantor_sid; 7423 7424 return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__PROG_LOAD, 7425 NULL); 7426 } 7427 7428 #define bpf_token_cmd(T, C) \ 7429 ((T)->allowed_cmds & (1ULL << (C))) 7430 7431 static int selinux_bpf_token_create(struct bpf_token *token, 7432 union bpf_attr *attr, 7433 const struct path *path) 7434 { 7435 struct bpf_security_struct *bpfsec; 7436 struct superblock_security_struct *sbsec; 7437 int err; 7438 7439 sbsec = selinux_superblock(path->dentry->d_sb); 7440 7441 bpfsec = selinux_bpf_token_security(token); 7442 bpfsec->sid = current_sid(); 7443 bpfsec->grantor_sid = sbsec->creator_sid; 7444 7445 bpfsec->perms = 0; 7446 /** 7447 * 'token->allowed_cmds' is a bit mask of allowed commands 7448 * Convert the BPF command enum to a bitmask representing its position 7449 * in the allowed_cmds bitmap. 7450 */ 7451 if (bpf_token_cmd(token, BPF_MAP_CREATE)) { 7452 err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid, 7453 SECCLASS_BPF, BPF__MAP_CREATE_AS, NULL); 7454 if (err) 7455 return err; 7456 bpfsec->perms |= BPF__MAP_CREATE; 7457 } 7458 if (bpf_token_cmd(token, BPF_PROG_LOAD)) { 7459 err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid, 7460 SECCLASS_BPF, BPF__PROG_LOAD_AS, NULL); 7461 if (err) 7462 return err; 7463 bpfsec->perms |= BPF__PROG_LOAD; 7464 } 7465 7466 return 0; 7467 } 7468 7469 static int selinux_bpf_token_cmd(const struct bpf_token *token, 7470 enum bpf_cmd cmd) 7471 { 7472 struct bpf_security_struct *bpfsec; 7473 7474 bpfsec = token->security; 7475 switch (cmd) { 7476 case BPF_MAP_CREATE: 7477 if (!(bpfsec->perms & BPF__MAP_CREATE)) 7478 return -EACCES; 7479 break; 7480 case BPF_PROG_LOAD: 7481 if (!(bpfsec->perms & BPF__PROG_LOAD)) 7482 return -EACCES; 7483 break; 7484 default: 7485 break; 7486 } 7487 7488 return 0; 7489 } 7490 7491 static int selinux_bpf_token_capable(const struct bpf_token *token, int cap) 7492 { 7493 u16 sclass; 7494 struct bpf_security_struct *bpfsec = token->security; 7495 bool initns = (token->userns == &init_user_ns); 7496 u32 av = CAP_TO_MASK(cap); 7497 7498 switch (CAP_TO_INDEX(cap)) { 7499 case 0: 7500 sclass = initns ? SECCLASS_CAPABILITY : SECCLASS_CAP_USERNS; 7501 break; 7502 case 1: 7503 sclass = initns ? SECCLASS_CAPABILITY2 : SECCLASS_CAP2_USERNS; 7504 break; 7505 default: 7506 pr_err("SELinux: out of range capability %d\n", cap); 7507 return -EINVAL; 7508 } 7509 7510 return avc_has_perm(current_sid(), bpfsec->grantor_sid, sclass, av, 7511 NULL); 7512 } 7513 #endif 7514 7515 #ifdef CONFIG_PERF_EVENTS 7516 static int selinux_perf_event_open(int type) 7517 { 7518 u32 requested, sid = current_sid(); 7519 7520 if (type == PERF_SECURITY_OPEN) 7521 requested = PERF_EVENT__OPEN; 7522 else if (type == PERF_SECURITY_CPU) 7523 requested = PERF_EVENT__CPU; 7524 else if (type == PERF_SECURITY_KERNEL) 7525 requested = PERF_EVENT__KERNEL; 7526 else if (type == PERF_SECURITY_TRACEPOINT) 7527 requested = PERF_EVENT__TRACEPOINT; 7528 else 7529 return -EINVAL; 7530 7531 return avc_has_perm(sid, sid, SECCLASS_PERF_EVENT, 7532 requested, NULL); 7533 } 7534 7535 static int selinux_perf_event_alloc(struct perf_event *event) 7536 { 7537 struct perf_event_security_struct *perfsec; 7538 7539 perfsec = selinux_perf_event(event->security); 7540 perfsec->sid = current_sid(); 7541 7542 return 0; 7543 } 7544 7545 static int selinux_perf_event_read(struct perf_event *event) 7546 { 7547 struct perf_event_security_struct *perfsec = event->security; 7548 u32 sid = current_sid(); 7549 7550 return avc_has_perm(sid, perfsec->sid, 7551 SECCLASS_PERF_EVENT, PERF_EVENT__READ, NULL); 7552 } 7553 7554 static int selinux_perf_event_write(struct perf_event *event) 7555 { 7556 struct perf_event_security_struct *perfsec = event->security; 7557 u32 sid = current_sid(); 7558 7559 return avc_has_perm(sid, perfsec->sid, 7560 SECCLASS_PERF_EVENT, PERF_EVENT__WRITE, NULL); 7561 } 7562 #endif 7563 7564 #ifdef CONFIG_IO_URING 7565 /** 7566 * selinux_uring_override_creds - check the requested cred override 7567 * @new: the target creds 7568 * 7569 * Check to see if the current task is allowed to override it's credentials 7570 * to service an io_uring operation. 7571 */ 7572 static int selinux_uring_override_creds(const struct cred *new) 7573 { 7574 return avc_has_perm(current_sid(), cred_sid(new), 7575 SECCLASS_IO_URING, IO_URING__OVERRIDE_CREDS, NULL); 7576 } 7577 7578 /** 7579 * selinux_uring_sqpoll - check if a io_uring polling thread can be created 7580 * 7581 * Check to see if the current task is allowed to create a new io_uring 7582 * kernel polling thread. 7583 */ 7584 static int selinux_uring_sqpoll(void) 7585 { 7586 u32 sid = current_sid(); 7587 7588 return avc_has_perm(sid, sid, 7589 SECCLASS_IO_URING, IO_URING__SQPOLL, NULL); 7590 } 7591 7592 /** 7593 * selinux_uring_cmd - check if IORING_OP_URING_CMD is allowed 7594 * @ioucmd: the io_uring command structure 7595 * 7596 * Check to see if the current domain is allowed to execute an 7597 * IORING_OP_URING_CMD against the device/file specified in @ioucmd. 7598 * 7599 */ 7600 static int selinux_uring_cmd(struct io_uring_cmd *ioucmd) 7601 { 7602 struct file *file = ioucmd->file; 7603 struct inode *inode = file_inode(file); 7604 struct inode_security_struct *isec = selinux_inode(inode); 7605 struct common_audit_data ad; 7606 7607 ad.type = LSM_AUDIT_DATA_FILE; 7608 ad.u.file = file; 7609 7610 return avc_has_perm(current_sid(), isec->sid, 7611 SECCLASS_IO_URING, IO_URING__CMD, &ad); 7612 } 7613 7614 /** 7615 * selinux_uring_allowed - check if io_uring_setup() can be called 7616 * 7617 * Check to see if the current task is allowed to call io_uring_setup(). 7618 */ 7619 static int selinux_uring_allowed(void) 7620 { 7621 u32 sid = current_sid(); 7622 7623 return avc_has_perm(sid, sid, SECCLASS_IO_URING, IO_URING__ALLOWED, 7624 NULL); 7625 } 7626 #endif /* CONFIG_IO_URING */ 7627 7628 static const struct lsm_id selinux_lsmid = { 7629 .name = "selinux", 7630 .id = LSM_ID_SELINUX, 7631 }; 7632 7633 struct lsm_blob_sizes selinux_blob_sizes __ro_after_init = { 7634 .lbs_cred = sizeof(struct cred_security_struct), 7635 .lbs_task = sizeof(struct task_security_struct), 7636 .lbs_file = sizeof(struct file_security_struct), 7637 .lbs_backing_file = sizeof(struct backing_file_security_struct), 7638 .lbs_inode = sizeof(struct inode_security_struct), 7639 .lbs_ipc = sizeof(struct ipc_security_struct), 7640 .lbs_key = sizeof(struct key_security_struct), 7641 .lbs_msg_msg = sizeof(struct msg_security_struct), 7642 #ifdef CONFIG_PERF_EVENTS 7643 .lbs_perf_event = sizeof(struct perf_event_security_struct), 7644 #endif 7645 .lbs_sock = sizeof(struct sk_security_struct), 7646 .lbs_superblock = sizeof(struct superblock_security_struct), 7647 .lbs_xattr_count = SELINUX_INODE_INIT_XATTRS, 7648 .lbs_tun_dev = sizeof(struct tun_security_struct), 7649 .lbs_ib = sizeof(struct ib_security_struct), 7650 .lbs_bpf_map = sizeof(struct bpf_security_struct), 7651 .lbs_bpf_prog = sizeof(struct bpf_security_struct), 7652 .lbs_bpf_token = sizeof(struct bpf_security_struct), 7653 }; 7654 7655 /* 7656 * IMPORTANT NOTE: When adding new hooks, please be careful to keep this order: 7657 * 1. any hooks that don't belong to (2.) or (3.) below, 7658 * 2. hooks that both access structures allocated by other hooks, and allocate 7659 * structures that can be later accessed by other hooks (mostly "cloning" 7660 * hooks), 7661 * 3. hooks that only allocate structures that can be later accessed by other 7662 * hooks ("allocating" hooks). 7663 * 7664 * Please follow block comment delimiters in the list to keep this order. 7665 */ 7666 static struct security_hook_list selinux_hooks[] __ro_after_init = { 7667 LSM_HOOK_INIT(binder_set_context_mgr, selinux_binder_set_context_mgr), 7668 LSM_HOOK_INIT(binder_transaction, selinux_binder_transaction), 7669 LSM_HOOK_INIT(binder_transfer_binder, selinux_binder_transfer_binder), 7670 LSM_HOOK_INIT(binder_transfer_file, selinux_binder_transfer_file), 7671 7672 LSM_HOOK_INIT(ptrace_access_check, selinux_ptrace_access_check), 7673 LSM_HOOK_INIT(ptrace_traceme, selinux_ptrace_traceme), 7674 LSM_HOOK_INIT(capget, selinux_capget), 7675 LSM_HOOK_INIT(capset, selinux_capset), 7676 LSM_HOOK_INIT(capable, selinux_capable), 7677 LSM_HOOK_INIT(quotactl, selinux_quotactl), 7678 LSM_HOOK_INIT(quota_on, selinux_quota_on), 7679 LSM_HOOK_INIT(syslog, selinux_syslog), 7680 LSM_HOOK_INIT(vm_enough_memory, selinux_vm_enough_memory), 7681 7682 LSM_HOOK_INIT(netlink_send, selinux_netlink_send), 7683 7684 LSM_HOOK_INIT(bprm_creds_for_exec, selinux_bprm_creds_for_exec), 7685 LSM_HOOK_INIT(bprm_committing_creds, selinux_bprm_committing_creds), 7686 LSM_HOOK_INIT(bprm_committed_creds, selinux_bprm_committed_creds), 7687 7688 LSM_HOOK_INIT(sb_free_mnt_opts, selinux_free_mnt_opts), 7689 LSM_HOOK_INIT(sb_mnt_opts_compat, selinux_sb_mnt_opts_compat), 7690 LSM_HOOK_INIT(sb_remount, selinux_sb_remount), 7691 LSM_HOOK_INIT(sb_kern_mount, selinux_sb_kern_mount), 7692 LSM_HOOK_INIT(sb_show_options, selinux_sb_show_options), 7693 LSM_HOOK_INIT(sb_statfs, selinux_sb_statfs), 7694 LSM_HOOK_INIT(sb_mount, selinux_mount), 7695 LSM_HOOK_INIT(sb_umount, selinux_umount), 7696 LSM_HOOK_INIT(sb_set_mnt_opts, selinux_set_mnt_opts), 7697 LSM_HOOK_INIT(sb_clone_mnt_opts, selinux_sb_clone_mnt_opts), 7698 7699 LSM_HOOK_INIT(move_mount, selinux_move_mount), 7700 7701 LSM_HOOK_INIT(dentry_init_security, selinux_dentry_init_security), 7702 LSM_HOOK_INIT(dentry_create_files_as, selinux_dentry_create_files_as), 7703 7704 LSM_HOOK_INIT(inode_free_security, selinux_inode_free_security), 7705 LSM_HOOK_INIT(inode_init_security, selinux_inode_init_security), 7706 LSM_HOOK_INIT(inode_init_security_anon, selinux_inode_init_security_anon), 7707 LSM_HOOK_INIT(inode_create, selinux_inode_create), 7708 LSM_HOOK_INIT(inode_link, selinux_inode_link), 7709 LSM_HOOK_INIT(inode_unlink, selinux_inode_unlink), 7710 LSM_HOOK_INIT(inode_symlink, selinux_inode_symlink), 7711 LSM_HOOK_INIT(inode_mkdir, selinux_inode_mkdir), 7712 LSM_HOOK_INIT(inode_rmdir, selinux_inode_rmdir), 7713 LSM_HOOK_INIT(inode_mknod, selinux_inode_mknod), 7714 LSM_HOOK_INIT(inode_rename, selinux_inode_rename), 7715 LSM_HOOK_INIT(inode_readlink, selinux_inode_readlink), 7716 LSM_HOOK_INIT(inode_follow_link, selinux_inode_follow_link), 7717 LSM_HOOK_INIT(inode_permission, selinux_inode_permission), 7718 LSM_HOOK_INIT(inode_setattr, selinux_inode_setattr), 7719 LSM_HOOK_INIT(inode_getattr, selinux_inode_getattr), 7720 LSM_HOOK_INIT(inode_xattr_skipcap, selinux_inode_xattr_skipcap), 7721 LSM_HOOK_INIT(inode_setxattr, selinux_inode_setxattr), 7722 LSM_HOOK_INIT(inode_post_setxattr, selinux_inode_post_setxattr), 7723 LSM_HOOK_INIT(inode_getxattr, selinux_inode_getxattr), 7724 LSM_HOOK_INIT(inode_listxattr, selinux_inode_listxattr), 7725 LSM_HOOK_INIT(inode_removexattr, selinux_inode_removexattr), 7726 LSM_HOOK_INIT(inode_file_getattr, selinux_inode_file_getattr), 7727 LSM_HOOK_INIT(inode_file_setattr, selinux_inode_file_setattr), 7728 LSM_HOOK_INIT(inode_set_acl, selinux_inode_set_acl), 7729 LSM_HOOK_INIT(inode_get_acl, selinux_inode_get_acl), 7730 LSM_HOOK_INIT(inode_remove_acl, selinux_inode_remove_acl), 7731 LSM_HOOK_INIT(inode_getsecurity, selinux_inode_getsecurity), 7732 LSM_HOOK_INIT(inode_setsecurity, selinux_inode_setsecurity), 7733 LSM_HOOK_INIT(inode_listsecurity, selinux_inode_listsecurity), 7734 LSM_HOOK_INIT(inode_getlsmprop, selinux_inode_getlsmprop), 7735 LSM_HOOK_INIT(inode_copy_up, selinux_inode_copy_up), 7736 LSM_HOOK_INIT(inode_copy_up_xattr, selinux_inode_copy_up_xattr), 7737 LSM_HOOK_INIT(path_notify, selinux_path_notify), 7738 7739 LSM_HOOK_INIT(kernfs_init_security, selinux_kernfs_init_security), 7740 7741 LSM_HOOK_INIT(file_permission, selinux_file_permission), 7742 LSM_HOOK_INIT(file_alloc_security, selinux_file_alloc_security), 7743 LSM_HOOK_INIT(backing_file_alloc, selinux_backing_file_alloc), 7744 LSM_HOOK_INIT(backing_file_free, selinux_backing_file_free), 7745 LSM_HOOK_INIT(file_ioctl, selinux_file_ioctl), 7746 LSM_HOOK_INIT(file_ioctl_compat, selinux_file_ioctl_compat), 7747 LSM_HOOK_INIT(mmap_file, selinux_mmap_file), 7748 LSM_HOOK_INIT(mmap_backing_file, selinux_mmap_backing_file), 7749 LSM_HOOK_INIT(mmap_addr, selinux_mmap_addr), 7750 LSM_HOOK_INIT(file_mprotect, selinux_file_mprotect), 7751 LSM_HOOK_INIT(file_lock, selinux_file_lock), 7752 LSM_HOOK_INIT(file_fcntl, selinux_file_fcntl), 7753 LSM_HOOK_INIT(file_set_fowner, selinux_file_set_fowner), 7754 LSM_HOOK_INIT(file_send_sigiotask, selinux_file_send_sigiotask), 7755 LSM_HOOK_INIT(file_receive, selinux_file_receive), 7756 7757 LSM_HOOK_INIT(file_open, selinux_file_open), 7758 7759 LSM_HOOK_INIT(task_alloc, selinux_task_alloc), 7760 LSM_HOOK_INIT(cred_prepare, selinux_cred_prepare), 7761 LSM_HOOK_INIT(cred_transfer, selinux_cred_transfer), 7762 LSM_HOOK_INIT(cred_getsecid, selinux_cred_getsecid), 7763 LSM_HOOK_INIT(cred_getlsmprop, selinux_cred_getlsmprop), 7764 LSM_HOOK_INIT(kernel_act_as, selinux_kernel_act_as), 7765 LSM_HOOK_INIT(kernel_create_files_as, selinux_kernel_create_files_as), 7766 LSM_HOOK_INIT(kernel_module_request, selinux_kernel_module_request), 7767 LSM_HOOK_INIT(kernel_load_data, selinux_kernel_load_data), 7768 LSM_HOOK_INIT(kernel_read_file, selinux_kernel_read_file), 7769 LSM_HOOK_INIT(task_setpgid, selinux_task_setpgid), 7770 LSM_HOOK_INIT(task_getpgid, selinux_task_getpgid), 7771 LSM_HOOK_INIT(task_getsid, selinux_task_getsid), 7772 LSM_HOOK_INIT(current_getlsmprop_subj, selinux_current_getlsmprop_subj), 7773 LSM_HOOK_INIT(task_getlsmprop_obj, selinux_task_getlsmprop_obj), 7774 LSM_HOOK_INIT(task_setnice, selinux_task_setnice), 7775 LSM_HOOK_INIT(task_setioprio, selinux_task_setioprio), 7776 LSM_HOOK_INIT(task_getioprio, selinux_task_getioprio), 7777 LSM_HOOK_INIT(task_prlimit, selinux_task_prlimit), 7778 LSM_HOOK_INIT(task_setrlimit, selinux_task_setrlimit), 7779 LSM_HOOK_INIT(task_setscheduler, selinux_task_setscheduler), 7780 LSM_HOOK_INIT(task_getscheduler, selinux_task_getscheduler), 7781 LSM_HOOK_INIT(task_movememory, selinux_task_movememory), 7782 LSM_HOOK_INIT(task_kill, selinux_task_kill), 7783 LSM_HOOK_INIT(task_to_inode, selinux_task_to_inode), 7784 LSM_HOOK_INIT(userns_create, selinux_userns_create), 7785 7786 LSM_HOOK_INIT(ipc_permission, selinux_ipc_permission), 7787 LSM_HOOK_INIT(ipc_getlsmprop, selinux_ipc_getlsmprop), 7788 7789 LSM_HOOK_INIT(msg_queue_associate, selinux_msg_queue_associate), 7790 LSM_HOOK_INIT(msg_queue_msgctl, selinux_msg_queue_msgctl), 7791 LSM_HOOK_INIT(msg_queue_msgsnd, selinux_msg_queue_msgsnd), 7792 LSM_HOOK_INIT(msg_queue_msgrcv, selinux_msg_queue_msgrcv), 7793 7794 LSM_HOOK_INIT(shm_associate, selinux_shm_associate), 7795 LSM_HOOK_INIT(shm_shmctl, selinux_shm_shmctl), 7796 LSM_HOOK_INIT(shm_shmat, selinux_shm_shmat), 7797 7798 LSM_HOOK_INIT(sem_associate, selinux_sem_associate), 7799 LSM_HOOK_INIT(sem_semctl, selinux_sem_semctl), 7800 LSM_HOOK_INIT(sem_semop, selinux_sem_semop), 7801 7802 LSM_HOOK_INIT(d_instantiate, selinux_d_instantiate), 7803 7804 LSM_HOOK_INIT(getselfattr, selinux_getselfattr), 7805 LSM_HOOK_INIT(setselfattr, selinux_setselfattr), 7806 LSM_HOOK_INIT(getprocattr, selinux_getprocattr), 7807 LSM_HOOK_INIT(setprocattr, selinux_setprocattr), 7808 7809 LSM_HOOK_INIT(ismaclabel, selinux_ismaclabel), 7810 LSM_HOOK_INIT(secctx_to_secid, selinux_secctx_to_secid), 7811 LSM_HOOK_INIT(release_secctx, selinux_release_secctx), 7812 LSM_HOOK_INIT(inode_invalidate_secctx, selinux_inode_invalidate_secctx), 7813 LSM_HOOK_INIT(inode_notifysecctx, selinux_inode_notifysecctx), 7814 LSM_HOOK_INIT(inode_setsecctx, selinux_inode_setsecctx), 7815 7816 LSM_HOOK_INIT(unix_stream_connect, selinux_socket_unix_stream_connect), 7817 LSM_HOOK_INIT(unix_may_send, selinux_socket_unix_may_send), 7818 7819 LSM_HOOK_INIT(socket_create, selinux_socket_create), 7820 LSM_HOOK_INIT(socket_post_create, selinux_socket_post_create), 7821 LSM_HOOK_INIT(socket_socketpair, selinux_socket_socketpair), 7822 LSM_HOOK_INIT(socket_bind, selinux_socket_bind), 7823 LSM_HOOK_INIT(socket_connect, selinux_socket_connect), 7824 LSM_HOOK_INIT(socket_listen, selinux_socket_listen), 7825 LSM_HOOK_INIT(socket_accept, selinux_socket_accept), 7826 LSM_HOOK_INIT(socket_sendmsg, selinux_socket_sendmsg), 7827 LSM_HOOK_INIT(socket_recvmsg, selinux_socket_recvmsg), 7828 LSM_HOOK_INIT(socket_getsockname, selinux_socket_getsockname), 7829 LSM_HOOK_INIT(socket_getpeername, selinux_socket_getpeername), 7830 LSM_HOOK_INIT(socket_getsockopt, selinux_socket_getsockopt), 7831 LSM_HOOK_INIT(socket_setsockopt, selinux_socket_setsockopt), 7832 LSM_HOOK_INIT(socket_shutdown, selinux_socket_shutdown), 7833 LSM_HOOK_INIT(socket_sock_rcv_skb, selinux_socket_sock_rcv_skb), 7834 LSM_HOOK_INIT(socket_getpeersec_stream, 7835 selinux_socket_getpeersec_stream), 7836 LSM_HOOK_INIT(socket_getpeersec_dgram, selinux_socket_getpeersec_dgram), 7837 LSM_HOOK_INIT(sk_free_security, selinux_sk_free_security), 7838 LSM_HOOK_INIT(sk_clone_security, selinux_sk_clone_security), 7839 LSM_HOOK_INIT(sk_getsecid, selinux_sk_getsecid), 7840 LSM_HOOK_INIT(sock_graft, selinux_sock_graft), 7841 LSM_HOOK_INIT(sctp_assoc_request, selinux_sctp_assoc_request), 7842 LSM_HOOK_INIT(sctp_sk_clone, selinux_sctp_sk_clone), 7843 LSM_HOOK_INIT(sctp_bind_connect, selinux_sctp_bind_connect), 7844 LSM_HOOK_INIT(sctp_assoc_established, selinux_sctp_assoc_established), 7845 LSM_HOOK_INIT(mptcp_add_subflow, selinux_mptcp_add_subflow), 7846 LSM_HOOK_INIT(inet_conn_request, selinux_inet_conn_request), 7847 LSM_HOOK_INIT(inet_csk_clone, selinux_inet_csk_clone), 7848 LSM_HOOK_INIT(inet_conn_established, selinux_inet_conn_established), 7849 LSM_HOOK_INIT(secmark_relabel_packet, selinux_secmark_relabel_packet), 7850 LSM_HOOK_INIT(secmark_refcount_inc, selinux_secmark_refcount_inc), 7851 LSM_HOOK_INIT(secmark_refcount_dec, selinux_secmark_refcount_dec), 7852 LSM_HOOK_INIT(req_classify_flow, selinux_req_classify_flow), 7853 LSM_HOOK_INIT(tun_dev_create, selinux_tun_dev_create), 7854 LSM_HOOK_INIT(tun_dev_attach_queue, selinux_tun_dev_attach_queue), 7855 LSM_HOOK_INIT(tun_dev_attach, selinux_tun_dev_attach), 7856 LSM_HOOK_INIT(tun_dev_open, selinux_tun_dev_open), 7857 #ifdef CONFIG_SECURITY_INFINIBAND 7858 LSM_HOOK_INIT(ib_pkey_access, selinux_ib_pkey_access), 7859 LSM_HOOK_INIT(ib_endport_manage_subnet, 7860 selinux_ib_endport_manage_subnet), 7861 #endif 7862 #ifdef CONFIG_SECURITY_NETWORK_XFRM 7863 LSM_HOOK_INIT(xfrm_policy_free_security, selinux_xfrm_policy_free), 7864 LSM_HOOK_INIT(xfrm_policy_delete_security, selinux_xfrm_policy_delete), 7865 LSM_HOOK_INIT(xfrm_state_free_security, selinux_xfrm_state_free), 7866 LSM_HOOK_INIT(xfrm_state_delete_security, selinux_xfrm_state_delete), 7867 LSM_HOOK_INIT(xfrm_policy_lookup, selinux_xfrm_policy_lookup), 7868 LSM_HOOK_INIT(xfrm_state_pol_flow_match, 7869 selinux_xfrm_state_pol_flow_match), 7870 LSM_HOOK_INIT(xfrm_decode_session, selinux_xfrm_decode_session), 7871 #endif 7872 7873 #ifdef CONFIG_KEYS 7874 LSM_HOOK_INIT(key_permission, selinux_key_permission), 7875 LSM_HOOK_INIT(key_getsecurity, selinux_key_getsecurity), 7876 #ifdef CONFIG_KEY_NOTIFICATIONS 7877 LSM_HOOK_INIT(watch_key, selinux_watch_key), 7878 #endif 7879 #endif 7880 7881 #ifdef CONFIG_AUDIT 7882 LSM_HOOK_INIT(audit_rule_known, selinux_audit_rule_known), 7883 LSM_HOOK_INIT(audit_rule_match, selinux_audit_rule_match), 7884 LSM_HOOK_INIT(audit_rule_free, selinux_audit_rule_free), 7885 #endif 7886 7887 #ifdef CONFIG_BPF_SYSCALL 7888 LSM_HOOK_INIT(bpf, selinux_bpf), 7889 LSM_HOOK_INIT(bpf_map, selinux_bpf_map), 7890 LSM_HOOK_INIT(bpf_prog, selinux_bpf_prog), 7891 #endif 7892 7893 #ifdef CONFIG_PERF_EVENTS 7894 LSM_HOOK_INIT(perf_event_open, selinux_perf_event_open), 7895 LSM_HOOK_INIT(perf_event_read, selinux_perf_event_read), 7896 LSM_HOOK_INIT(perf_event_write, selinux_perf_event_write), 7897 #endif 7898 7899 #ifdef CONFIG_IO_URING 7900 LSM_HOOK_INIT(uring_override_creds, selinux_uring_override_creds), 7901 LSM_HOOK_INIT(uring_sqpoll, selinux_uring_sqpoll), 7902 LSM_HOOK_INIT(uring_cmd, selinux_uring_cmd), 7903 LSM_HOOK_INIT(uring_allowed, selinux_uring_allowed), 7904 #endif 7905 7906 /* 7907 * PUT "CLONING" (ACCESSING + ALLOCATING) HOOKS HERE 7908 */ 7909 LSM_HOOK_INIT(fs_context_submount, selinux_fs_context_submount), 7910 LSM_HOOK_INIT(fs_context_dup, selinux_fs_context_dup), 7911 LSM_HOOK_INIT(fs_context_parse_param, selinux_fs_context_parse_param), 7912 LSM_HOOK_INIT(sb_eat_lsm_opts, selinux_sb_eat_lsm_opts), 7913 #ifdef CONFIG_SECURITY_NETWORK_XFRM 7914 LSM_HOOK_INIT(xfrm_policy_clone_security, selinux_xfrm_policy_clone), 7915 #endif 7916 7917 /* 7918 * PUT "ALLOCATING" HOOKS HERE 7919 */ 7920 LSM_HOOK_INIT(msg_msg_alloc_security, selinux_msg_msg_alloc_security), 7921 LSM_HOOK_INIT(msg_queue_alloc_security, 7922 selinux_msg_queue_alloc_security), 7923 LSM_HOOK_INIT(shm_alloc_security, selinux_shm_alloc_security), 7924 LSM_HOOK_INIT(sb_alloc_security, selinux_sb_alloc_security), 7925 LSM_HOOK_INIT(inode_alloc_security, selinux_inode_alloc_security), 7926 LSM_HOOK_INIT(sem_alloc_security, selinux_sem_alloc_security), 7927 LSM_HOOK_INIT(secid_to_secctx, selinux_secid_to_secctx), 7928 LSM_HOOK_INIT(lsmprop_to_secctx, selinux_lsmprop_to_secctx), 7929 LSM_HOOK_INIT(inode_getsecctx, selinux_inode_getsecctx), 7930 LSM_HOOK_INIT(sk_alloc_security, selinux_sk_alloc_security), 7931 LSM_HOOK_INIT(tun_dev_alloc_security, selinux_tun_dev_alloc_security), 7932 #ifdef CONFIG_SECURITY_INFINIBAND 7933 LSM_HOOK_INIT(ib_alloc_security, selinux_ib_alloc_security), 7934 #endif 7935 #ifdef CONFIG_SECURITY_NETWORK_XFRM 7936 LSM_HOOK_INIT(xfrm_policy_alloc_security, selinux_xfrm_policy_alloc), 7937 LSM_HOOK_INIT(xfrm_state_alloc, selinux_xfrm_state_alloc), 7938 LSM_HOOK_INIT(xfrm_state_alloc_acquire, 7939 selinux_xfrm_state_alloc_acquire), 7940 #endif 7941 #ifdef CONFIG_KEYS 7942 LSM_HOOK_INIT(key_alloc, selinux_key_alloc), 7943 #endif 7944 #ifdef CONFIG_AUDIT 7945 LSM_HOOK_INIT(audit_rule_init, selinux_audit_rule_init), 7946 #endif 7947 #ifdef CONFIG_BPF_SYSCALL 7948 LSM_HOOK_INIT(bpf_map_create, selinux_bpf_map_create), 7949 LSM_HOOK_INIT(bpf_prog_load, selinux_bpf_prog_load), 7950 LSM_HOOK_INIT(bpf_token_create, selinux_bpf_token_create), 7951 LSM_HOOK_INIT(bpf_token_cmd, selinux_bpf_token_cmd), 7952 LSM_HOOK_INIT(bpf_token_capable, selinux_bpf_token_capable), 7953 #endif 7954 #ifdef CONFIG_PERF_EVENTS 7955 LSM_HOOK_INIT(perf_event_alloc, selinux_perf_event_alloc), 7956 #endif 7957 }; 7958 7959 static __init int selinux_init(void) 7960 { 7961 vma_flags_t data_default_flags = VMA_DATA_DEFAULT_FLAGS; 7962 7963 pr_info("SELinux: Initializing.\n"); 7964 7965 memset(&selinux_state, 0, sizeof(selinux_state)); 7966 enforcing_set(selinux_enforcing_boot); 7967 selinux_avc_init(); 7968 mutex_init(&selinux_state.status_lock); 7969 mutex_init(&selinux_state.policy_mutex); 7970 7971 /* Set the security state for the initial task. */ 7972 cred_init_security(); 7973 7974 /* Inform the audit system that secctx is used */ 7975 audit_cfg_lsm(&selinux_lsmid, 7976 AUDIT_CFG_LSM_SECCTX_SUBJECT | 7977 AUDIT_CFG_LSM_SECCTX_OBJECT); 7978 7979 default_noexec = !vma_flags_test(&data_default_flags, VMA_EXEC_BIT); 7980 if (!default_noexec) 7981 pr_notice("SELinux: virtual memory is executable by default\n"); 7982 7983 avc_init(); 7984 7985 avtab_cache_init(); 7986 7987 ebitmap_cache_init(); 7988 7989 hashtab_cache_init(); 7990 7991 selinux_ima_config_len_init(); 7992 7993 security_add_hooks(selinux_hooks, ARRAY_SIZE(selinux_hooks), 7994 &selinux_lsmid); 7995 7996 if (avc_add_callback(selinux_netcache_avc_callback, AVC_CALLBACK_RESET)) 7997 panic("SELinux: Unable to register AVC netcache callback\n"); 7998 7999 if (avc_add_callback(selinux_lsm_notifier_avc_callback, AVC_CALLBACK_RESET)) 8000 panic("SELinux: Unable to register AVC LSM notifier callback\n"); 8001 8002 if (avc_add_callback(selinux_audit_rule_avc_callback, 8003 AVC_CALLBACK_RESET)) 8004 panic("SELinux: Unable to register AVC audit callback\n"); 8005 8006 if (selinux_enforcing_boot) 8007 pr_debug("SELinux: Starting in enforcing mode\n"); 8008 else 8009 pr_debug("SELinux: Starting in permissive mode\n"); 8010 8011 fs_validate_description("selinux", selinux_fs_parameters); 8012 8013 return 0; 8014 } 8015 8016 static void delayed_superblock_init(struct super_block *sb, void *unused) 8017 { 8018 selinux_set_mnt_opts(sb, NULL, 0, NULL); 8019 } 8020 8021 void selinux_complete_init(void) 8022 { 8023 pr_debug("SELinux: Completing initialization.\n"); 8024 8025 /* Set up any superblocks initialized prior to the policy load. */ 8026 pr_debug("SELinux: Setting up existing superblocks.\n"); 8027 iterate_supers(delayed_superblock_init, NULL); 8028 } 8029 8030 /* SELinux requires early initialization in order to label 8031 all processes and objects when they are created. */ 8032 DEFINE_LSM(selinux) = { 8033 .id = &selinux_lsmid, 8034 .flags = LSM_FLAG_LEGACY_MAJOR | LSM_FLAG_EXCLUSIVE, 8035 .enabled = &selinux_enabled_boot, 8036 .blobs = &selinux_blob_sizes, 8037 .init = selinux_init, 8038 .initcall_device = selinux_initcall, 8039 }; 8040 8041 #if defined(CONFIG_NETFILTER) 8042 static const struct nf_hook_ops selinux_nf_ops[] = { 8043 { 8044 .hook = selinux_ip_postroute, 8045 .pf = NFPROTO_IPV4, 8046 .hooknum = NF_INET_POST_ROUTING, 8047 .priority = NF_IP_PRI_SELINUX_LAST, 8048 }, 8049 { 8050 .hook = selinux_ip_forward, 8051 .pf = NFPROTO_IPV4, 8052 .hooknum = NF_INET_FORWARD, 8053 .priority = NF_IP_PRI_SELINUX_FIRST, 8054 }, 8055 { 8056 .hook = selinux_ip_output, 8057 .pf = NFPROTO_IPV4, 8058 .hooknum = NF_INET_LOCAL_OUT, 8059 .priority = NF_IP_PRI_SELINUX_FIRST, 8060 }, 8061 #if IS_ENABLED(CONFIG_IPV6) 8062 { 8063 .hook = selinux_ip_postroute, 8064 .pf = NFPROTO_IPV6, 8065 .hooknum = NF_INET_POST_ROUTING, 8066 .priority = NF_IP6_PRI_SELINUX_LAST, 8067 }, 8068 { 8069 .hook = selinux_ip_forward, 8070 .pf = NFPROTO_IPV6, 8071 .hooknum = NF_INET_FORWARD, 8072 .priority = NF_IP6_PRI_SELINUX_FIRST, 8073 }, 8074 { 8075 .hook = selinux_ip_output, 8076 .pf = NFPROTO_IPV6, 8077 .hooknum = NF_INET_LOCAL_OUT, 8078 .priority = NF_IP6_PRI_SELINUX_FIRST, 8079 }, 8080 #endif /* IPV6 */ 8081 }; 8082 8083 static int __net_init selinux_nf_register(struct net *net) 8084 { 8085 return nf_register_net_hooks(net, selinux_nf_ops, 8086 ARRAY_SIZE(selinux_nf_ops)); 8087 } 8088 8089 static void __net_exit selinux_nf_unregister(struct net *net) 8090 { 8091 nf_unregister_net_hooks(net, selinux_nf_ops, 8092 ARRAY_SIZE(selinux_nf_ops)); 8093 } 8094 8095 static struct pernet_operations selinux_net_ops = { 8096 .init = selinux_nf_register, 8097 .exit = selinux_nf_unregister, 8098 }; 8099 8100 int __init selinux_nf_ip_init(void) 8101 { 8102 int err; 8103 8104 if (!selinux_enabled_boot) 8105 return 0; 8106 8107 pr_debug("SELinux: Registering netfilter hooks\n"); 8108 8109 err = register_pernet_subsys(&selinux_net_ops); 8110 if (err) 8111 panic("SELinux: register_pernet_subsys: error %d\n", err); 8112 8113 return 0; 8114 } 8115 #endif /* CONFIG_NETFILTER */ 8116