xref: /freebsd/sbin/veriexec/veriexec.c (revision 1554ba03b651319ab0e1cde8492ea4516afc648b)
1eb12b8eaSSimon J. Gerraty /*-
288a3358eSStephen J. Kiernan  * SPDX-License-Identifier: BSD-2-Clause
388a3358eSStephen J. Kiernan  *
4*1554ba03SSimon J. Gerraty  * Copyright (c) 2018-2023, Juniper Networks, Inc.
5eb12b8eaSSimon J. Gerraty  *
6eb12b8eaSSimon J. Gerraty  * Redistribution and use in source and binary forms, with or without
7eb12b8eaSSimon J. Gerraty  * modification, are permitted provided that the following conditions
8eb12b8eaSSimon J. Gerraty  * are met:
9eb12b8eaSSimon J. Gerraty  * 1. Redistributions of source code must retain the above copyright
10eb12b8eaSSimon J. Gerraty  *    notice, this list of conditions and the following disclaimer.
11eb12b8eaSSimon J. Gerraty  * 2. Redistributions in binary form must reproduce the above copyright
12eb12b8eaSSimon J. Gerraty  *    notice, this list of conditions and the following disclaimer in the
13eb12b8eaSSimon J. Gerraty  *    documentation and/or other materials provided with the distribution.
14eb12b8eaSSimon J. Gerraty  *
15eb12b8eaSSimon J. Gerraty  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16eb12b8eaSSimon J. Gerraty  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17eb12b8eaSSimon J. Gerraty  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
18eb12b8eaSSimon J. Gerraty  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
19eb12b8eaSSimon J. Gerraty  * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
20eb12b8eaSSimon J. Gerraty  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
21eb12b8eaSSimon J. Gerraty  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22eb12b8eaSSimon J. Gerraty  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23eb12b8eaSSimon J. Gerraty  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24eb12b8eaSSimon J. Gerraty  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
25eb12b8eaSSimon J. Gerraty  * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26eb12b8eaSSimon J. Gerraty  */
27eb12b8eaSSimon J. Gerraty #include <sys/cdefs.h>
28eb12b8eaSSimon J. Gerraty #include <stdlib.h>
29eb12b8eaSSimon J. Gerraty #include <sysexits.h>
30eb12b8eaSSimon J. Gerraty #include <unistd.h>
31eb12b8eaSSimon J. Gerraty #include <paths.h>
32eb12b8eaSSimon J. Gerraty #include <err.h>
33eb12b8eaSSimon J. Gerraty #include <syslog.h>
34eb12b8eaSSimon J. Gerraty #include <libsecureboot.h>
35eb12b8eaSSimon J. Gerraty #include <libveriexec.h>
36b439f64aSHubert Mazur #include <sys/types.h>
37eb12b8eaSSimon J. Gerraty 
38eb12b8eaSSimon J. Gerraty #include "veriexec.h"
39eb12b8eaSSimon J. Gerraty 
40b439f64aSHubert Mazur /* Globals that are shared with manifest_parser.c */
41eb12b8eaSSimon J. Gerraty int dev_fd = -1;
42eb12b8eaSSimon J. Gerraty int ForceFlags = 0;
43eb12b8eaSSimon J. Gerraty int Verbose = 0;
44eb12b8eaSSimon J. Gerraty int VeriexecVersion = 0;
45eb12b8eaSSimon J. Gerraty const char *Cdir = NULL;
46eb12b8eaSSimon J. Gerraty 
47b439f64aSHubert Mazur /*!
48b439f64aSHubert Mazur  * @brief Print help message describing program's usage
49b439f64aSHubert Mazur  * @param void
50b439f64aSHubert Mazur  * @return always returns code 0
51b439f64aSHubert Mazur  */
52b439f64aSHubert Mazur static int
veriexec_usage(void)537e2af4f9SMina Galić veriexec_usage(void)
54b439f64aSHubert Mazur {
55b439f64aSHubert Mazur 	printf("%s",
56*1554ba03SSimon J. Gerraty 	    "Usage:\tveriexec [-C path] [-hlxv] [-[iz] state] [path]\n");
57b439f64aSHubert Mazur 
58b439f64aSHubert Mazur 	return (0);
59b439f64aSHubert Mazur }
60b439f64aSHubert Mazur 
61b439f64aSHubert Mazur /*!
62b439f64aSHubert Mazur  * @brief Load a veriexec manifest
63b439f64aSHubert Mazur  * @param manifest Pointer to the location of the manifest file
64b439f64aSHubert Mazur  * @retval the error code returned from the parser
65b439f64aSHubert Mazur  */
66eb12b8eaSSimon J. Gerraty static int
veriexec_load(const char * manifest)67eb12b8eaSSimon J. Gerraty veriexec_load(const char *manifest)
68eb12b8eaSSimon J. Gerraty {
69eb12b8eaSSimon J. Gerraty 	unsigned char *content;
70eb12b8eaSSimon J. Gerraty 	int rc;
71eb12b8eaSSimon J. Gerraty 
72eb12b8eaSSimon J. Gerraty 	content = verify_signed(manifest, VEF_VERBOSE);
73eb12b8eaSSimon J. Gerraty 	if (!content)
74eb12b8eaSSimon J. Gerraty 		errx(EX_USAGE, "cannot verify %s", manifest);
75b439f64aSHubert Mazur 	if (manifest_open(manifest, (const char *)content)) {
76eb12b8eaSSimon J. Gerraty 		rc = yyparse();
77eb12b8eaSSimon J. Gerraty 	} else {
78eb12b8eaSSimon J. Gerraty 		err(EX_NOINPUT, "cannot load %s", manifest);
79eb12b8eaSSimon J. Gerraty 	}
80eb12b8eaSSimon J. Gerraty 	free(content);
81eb12b8eaSSimon J. Gerraty 	return (rc);
82eb12b8eaSSimon J. Gerraty }
83eb12b8eaSSimon J. Gerraty 
84b439f64aSHubert Mazur /*!
85b439f64aSHubert Mazur  * @brief Get the veriexec state for the supplied argument
86b439f64aSHubert Mazur  * @param arg_text String containing the argument to be processed
87b439f64aSHubert Mazur  * @retval The veriexec state number for the specified argument
88b439f64aSHubert Mazur  */
89b439f64aSHubert Mazur static uint32_t
veriexec_state_query(const char * arg_text)90b439f64aSHubert Mazur veriexec_state_query(const char *arg_text)
91b439f64aSHubert Mazur {
92b439f64aSHubert Mazur 	uint32_t state = 0;
93b439f64aSHubert Mazur 	unsigned long len;
94b439f64aSHubert Mazur 
95b439f64aSHubert Mazur 	len = strlen(arg_text);
96b439f64aSHubert Mazur 
97b439f64aSHubert Mazur 	if (strncmp(arg_text, "active", len) == 0)
98b439f64aSHubert Mazur 		state |= VERIEXEC_STATE_ACTIVE;
99b439f64aSHubert Mazur 	else if (strncmp(arg_text, "enforce", len) == 0)
100b439f64aSHubert Mazur 		state |= VERIEXEC_STATE_ENFORCE;
101b439f64aSHubert Mazur 	if (strncmp(arg_text, "loaded", len) == 0)
102b439f64aSHubert Mazur 		state |= VERIEXEC_STATE_LOADED;
103b439f64aSHubert Mazur 	if (strncmp(arg_text, "locked", len) == 0)
104b439f64aSHubert Mazur 		state |= VERIEXEC_STATE_LOCKED;
105b439f64aSHubert Mazur 	if (state == 0 || __bitcount(state) > 1)
106b439f64aSHubert Mazur 		errx(EX_USAGE, "Unknown state \'%s\'", arg_text);
107b439f64aSHubert Mazur 
108b439f64aSHubert Mazur 	return (state);
109b439f64aSHubert Mazur }
110b439f64aSHubert Mazur 
111b439f64aSHubert Mazur /*!
112b439f64aSHubert Mazur  * @brief Get the veriexec command state for the supplied argument
113b439f64aSHubert Mazur  * @param arg_text String containing the argument to be processed
114b439f64aSHubert Mazur  * @retval The veriexec command state for the specified argument
115b439f64aSHubert Mazur  */
116b439f64aSHubert Mazur static uint32_t
veriexec_state_modify(const char * arg_text)117b439f64aSHubert Mazur veriexec_state_modify(const char *arg_text)
118b439f64aSHubert Mazur {
119b439f64aSHubert Mazur 	uint32_t state = 0;
120b439f64aSHubert Mazur 	unsigned long len;
121b439f64aSHubert Mazur 
122b439f64aSHubert Mazur 	len = strlen(arg_text);
123b439f64aSHubert Mazur 
124b439f64aSHubert Mazur 	if (strncmp(arg_text, "active", len) == 0)
125b439f64aSHubert Mazur 		state = VERIEXEC_ACTIVE;
126b439f64aSHubert Mazur 	else if (strncmp(arg_text, "enforce", len) == 0)
127b439f64aSHubert Mazur 		state = VERIEXEC_ENFORCE;
128b439f64aSHubert Mazur 	else if (strncmp(arg_text, "getstate", len) == 0)
129b439f64aSHubert Mazur 		state = VERIEXEC_GETSTATE;
130b439f64aSHubert Mazur 	else if (strncmp(arg_text, "lock", len) == 0)
131b439f64aSHubert Mazur 		state = VERIEXEC_LOCK;
132b439f64aSHubert Mazur 	else
133b439f64aSHubert Mazur 		errx(EX_USAGE, "Unknown command \'%s\'", arg_text);
134b439f64aSHubert Mazur 
135b439f64aSHubert Mazur 	return (state);
136b439f64aSHubert Mazur }
137b439f64aSHubert Mazur 
138*1554ba03SSimon J. Gerraty #ifdef HAVE_VERIEXEC_GET_PATH_LABEL
139*1554ba03SSimon J. Gerraty static void
veriexec_check_labels(int argc,char * argv[])140*1554ba03SSimon J. Gerraty veriexec_check_labels(int argc, char *argv[])
141*1554ba03SSimon J. Gerraty {
142*1554ba03SSimon J. Gerraty 	char buf[BUFSIZ];
143*1554ba03SSimon J. Gerraty 	char *cp;
144*1554ba03SSimon J. Gerraty 	int n;
145*1554ba03SSimon J. Gerraty 
146*1554ba03SSimon J. Gerraty 	n = (argc - optind);
147*1554ba03SSimon J. Gerraty 	for (; optind < argc; optind++) {
148*1554ba03SSimon J. Gerraty 		cp = veriexec_get_path_label(argv[optind], buf, sizeof(buf));
149*1554ba03SSimon J. Gerraty 		if (cp) {
150*1554ba03SSimon J. Gerraty 			if (n > 1)
151*1554ba03SSimon J. Gerraty 				printf("%s: %s\n", argv[optind], cp);
152*1554ba03SSimon J. Gerraty 			else
153*1554ba03SSimon J. Gerraty 				printf("%s\n", cp);
154*1554ba03SSimon J. Gerraty 			if (cp != buf)
155*1554ba03SSimon J. Gerraty 				free(cp);
156*1554ba03SSimon J. Gerraty 		}
157*1554ba03SSimon J. Gerraty 	}
158*1554ba03SSimon J. Gerraty 	exit(EX_OK);
159*1554ba03SSimon J. Gerraty }
160*1554ba03SSimon J. Gerraty #endif
161*1554ba03SSimon J. Gerraty 
162*1554ba03SSimon J. Gerraty static void
veriexec_check_paths(int argc,char * argv[])163*1554ba03SSimon J. Gerraty veriexec_check_paths(int argc, char *argv[])
164*1554ba03SSimon J. Gerraty {
165*1554ba03SSimon J. Gerraty 	int x;
166*1554ba03SSimon J. Gerraty 
167*1554ba03SSimon J. Gerraty 	x = EX_OK;
168*1554ba03SSimon J. Gerraty 	for (; optind < argc; optind++) {
169*1554ba03SSimon J. Gerraty 		if (veriexec_check_path(argv[optind])) {
170*1554ba03SSimon J. Gerraty 			warn("%s", argv[optind]);
171*1554ba03SSimon J. Gerraty 			x = 2;
172*1554ba03SSimon J. Gerraty 		}
173*1554ba03SSimon J. Gerraty 	}
174*1554ba03SSimon J. Gerraty 	exit(x);
175*1554ba03SSimon J. Gerraty }
176*1554ba03SSimon J. Gerraty 
177eb12b8eaSSimon J. Gerraty int
main(int argc,char * argv[])178eb12b8eaSSimon J. Gerraty main(int argc, char *argv[])
179eb12b8eaSSimon J. Gerraty {
180b439f64aSHubert Mazur 	long long converted_int;
181b439f64aSHubert Mazur 	uint32_t state;
1821c7ac0c2SStephen J. Kiernan 	int c, x;
183eb12b8eaSSimon J. Gerraty 
184b439f64aSHubert Mazur 	if (argc < 2)
185b439f64aSHubert Mazur 		return (veriexec_usage());
186b439f64aSHubert Mazur 
187eb12b8eaSSimon J. Gerraty 	dev_fd = open(_PATH_DEV_VERIEXEC, O_WRONLY, 0);
188eb12b8eaSSimon J. Gerraty 
189*1554ba03SSimon J. Gerraty 	while ((c = getopt(argc, argv, "C:hi:lSxvz:")) != -1) {
190eb12b8eaSSimon J. Gerraty 		switch (c) {
191b439f64aSHubert Mazur 		case 'h':
192b439f64aSHubert Mazur 			/* Print usage info */
193b439f64aSHubert Mazur 
194b439f64aSHubert Mazur 			return (veriexec_usage());
195eb12b8eaSSimon J. Gerraty 		case 'C':
196b439f64aSHubert Mazur 			/* Get the provided directory argument */
197b439f64aSHubert Mazur 
198eb12b8eaSSimon J. Gerraty 			Cdir = optarg;
199eb12b8eaSSimon J. Gerraty 			break;
200eb12b8eaSSimon J. Gerraty 		case 'i':
201b439f64aSHubert Mazur 			/* Query the current state */
202b439f64aSHubert Mazur 
203eb12b8eaSSimon J. Gerraty 			if (dev_fd < 0) {
204eb12b8eaSSimon J. Gerraty 				err(EX_UNAVAILABLE, "cannot open veriexec");
205eb12b8eaSSimon J. Gerraty 			}
206eb12b8eaSSimon J. Gerraty 			if (ioctl(dev_fd, VERIEXEC_GETSTATE, &x)) {
207eb12b8eaSSimon J. Gerraty 				err(EX_UNAVAILABLE,
208eb12b8eaSSimon J. Gerraty 				    "Cannot get veriexec state");
209eb12b8eaSSimon J. Gerraty 			}
210b439f64aSHubert Mazur 
211b439f64aSHubert Mazur 			state = veriexec_state_query(optarg);
212b439f64aSHubert Mazur 
213b439f64aSHubert Mazur 			exit((x & state) == 0);
214eb12b8eaSSimon J. Gerraty 			break;
215*1554ba03SSimon J. Gerraty #ifdef HAVE_VERIEXEC_GET_PATH_LABEL
216*1554ba03SSimon J. Gerraty 		case 'l':
217*1554ba03SSimon J. Gerraty 			veriexec_check_labels(argc, argv);
218*1554ba03SSimon J. Gerraty 			break;
219*1554ba03SSimon J. Gerraty #endif
220ab4f0a15SSimon J. Gerraty 		case 'S':
221ab4f0a15SSimon J. Gerraty 			/* Strictly enforce certificate validity */
222ab4f0a15SSimon J. Gerraty 			ve_enforce_validity_set(1);
223ab4f0a15SSimon J. Gerraty 			break;
224eb12b8eaSSimon J. Gerraty 		case 'v':
225b439f64aSHubert Mazur 			/* Increase the verbosity */
226b439f64aSHubert Mazur 
227eb12b8eaSSimon J. Gerraty 			Verbose++;
228eb12b8eaSSimon J. Gerraty 			break;
229eb12b8eaSSimon J. Gerraty 		case 'x':
230b439f64aSHubert Mazur 			/* Check veriexec paths */
231b439f64aSHubert Mazur 
232eb12b8eaSSimon J. Gerraty 			/*
233eb12b8eaSSimon J. Gerraty 			 * -x says all other args are paths to check.
234eb12b8eaSSimon J. Gerraty 			 */
235*1554ba03SSimon J. Gerraty 			veriexec_check_paths(argc, argv);
236eb12b8eaSSimon J. Gerraty 			break;
237eb12b8eaSSimon J. Gerraty 		case 'z':
238b439f64aSHubert Mazur 			/* Modify the state */
239b439f64aSHubert Mazur 
240b439f64aSHubert Mazur 			if (strncmp(optarg, "debug", strlen(optarg)) == 0) {
241b439f64aSHubert Mazur 				const char *error;
242b439f64aSHubert Mazur 
243b439f64aSHubert Mazur 				if (optind >= argc)
244b439f64aSHubert Mazur 					errx(EX_USAGE,
245b439f64aSHubert Mazur 					    "Missing mac_veriexec verbosity level \'N\', veriexec -z debug N, where N is \'off\' or the value 0 or greater");
246b439f64aSHubert Mazur 
247b439f64aSHubert Mazur 				if (strncmp(argv[optind], "off", strlen(argv[optind])) == 0) {
248b439f64aSHubert Mazur 					state = VERIEXEC_DEBUG_OFF;
249b439f64aSHubert Mazur 					x = 0;
250b439f64aSHubert Mazur 				} else {
251b439f64aSHubert Mazur 					state = VERIEXEC_DEBUG_ON;
252b439f64aSHubert Mazur 
253b439f64aSHubert Mazur 					converted_int = strtonum(argv[optind], 0, INT_MAX, &error);
254b439f64aSHubert Mazur 
255b439f64aSHubert Mazur 					if (error != NULL)
256b439f64aSHubert Mazur 						errx(EX_USAGE, "Conversion error for argument \'%s\' : %s",
257b439f64aSHubert Mazur 						    argv[optind], error);
258b439f64aSHubert Mazur 
259b439f64aSHubert Mazur 					x = (int) converted_int;
260b439f64aSHubert Mazur 
261b439f64aSHubert Mazur 
262eb12b8eaSSimon J. Gerraty 					if (x == 0)
263b439f64aSHubert Mazur 						state = VERIEXEC_DEBUG_OFF;
264eb12b8eaSSimon J. Gerraty 				}
265b439f64aSHubert Mazur 			} else
266b439f64aSHubert Mazur 				state = veriexec_state_modify(optarg);
267b439f64aSHubert Mazur 
268b439f64aSHubert Mazur 			if (dev_fd < 0)
269b439f64aSHubert Mazur 				err(EX_UNAVAILABLE, "Cannot open veriexec");
270b439f64aSHubert Mazur 			if (ioctl(dev_fd, state, &x))
271b439f64aSHubert Mazur 				err(EX_UNAVAILABLE, "Cannot %s veriexec", optarg);
272b439f64aSHubert Mazur 
273b439f64aSHubert Mazur 			if (state == VERIEXEC_DEBUG_ON || state == VERIEXEC_DEBUG_OFF)
274b439f64aSHubert Mazur 				printf("mac_veriexec debug verbosity level: %d\n", x);
275b439f64aSHubert Mazur 			else if (state == VERIEXEC_GETSTATE)
276b439f64aSHubert Mazur 				printf("Veriexec state (octal) : %#o\n", x);
277b439f64aSHubert Mazur 
278eb12b8eaSSimon J. Gerraty 			exit(EX_OK);
279eb12b8eaSSimon J. Gerraty 			break;
280b439f64aSHubert Mazur 		default:
281b439f64aSHubert Mazur 
282b439f64aSHubert Mazur 			/* Missing argument, print usage info.*/
283b439f64aSHubert Mazur 			veriexec_usage();
284b439f64aSHubert Mazur 			exit(EX_USAGE);
285b439f64aSHubert Mazur 			break;
286eb12b8eaSSimon J. Gerraty 		}
287eb12b8eaSSimon J. Gerraty 	}
288b439f64aSHubert Mazur 
289b439f64aSHubert Mazur 	if (Verbose)
290b439f64aSHubert Mazur 		printf("Verbosity level : %d\n", Verbose);
291b439f64aSHubert Mazur 
292b439f64aSHubert Mazur 	if (dev_fd < 0)
293b439f64aSHubert Mazur 		err(EX_UNAVAILABLE, "Cannot open veriexec");
294b439f64aSHubert Mazur 
295eb12b8eaSSimon J. Gerraty 	openlog(getprogname(), LOG_PID, LOG_AUTH);
296eb12b8eaSSimon J. Gerraty 	if (ve_trust_init() < 1)
297eb12b8eaSSimon J. Gerraty 		errx(EX_OSFILE, "cannot initialize trust store");
298eb12b8eaSSimon J. Gerraty #ifdef VERIEXEC_GETVERSION
299eb12b8eaSSimon J. Gerraty 	if (ioctl(dev_fd, VERIEXEC_GETVERSION, &VeriexecVersion)) {
300eb12b8eaSSimon J. Gerraty 		VeriexecVersion = 0;	/* unknown */
301eb12b8eaSSimon J. Gerraty 	}
302eb12b8eaSSimon J. Gerraty #endif
303eb12b8eaSSimon J. Gerraty 
304eb12b8eaSSimon J. Gerraty 	for (; optind < argc; optind++) {
305eb12b8eaSSimon J. Gerraty 		if (veriexec_load(argv[optind])) {
306eb12b8eaSSimon J. Gerraty 			err(EX_DATAERR, "cannot load %s", argv[optind]);
307eb12b8eaSSimon J. Gerraty 		}
308eb12b8eaSSimon J. Gerraty 	}
309eb12b8eaSSimon J. Gerraty 	exit(EX_OK);
310eb12b8eaSSimon J. Gerraty }
311