-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
TOMOYO: Add environment variable name restriction support.
This patch adds support for checking environment variable's names. Although TOMOYO already provides ability to check argv[]/envp[] passed to execve() requests, file execute /bin/sh exec.envp["LD_LIBRARY_PATH"]="bar" will reject execution of /bin/sh if environment variable LD_LIBRARY_PATH is not defined. To grant execution of /bin/sh if LD_LIBRARY_PATH is not defined, administrators have to specify like file execute /bin/sh exec.envp["LD_LIBRARY_PATH"]="/system/lib" file execute /bin/sh exec.envp["LD_LIBRARY_PATH"]=NULL . Since there are many environment variables whereas conditional checks are applied as "&&", it is difficult to cover all combinations. Therefore, this patch supports conditional checks that are applied as "||", by specifying like file execute /bin/sh misc env LD_LIBRARY_PATH exec.envp["LD_LIBRARY_PATH"]="/system/lib" which means "grant execution of /bin/sh if environment variable is not defined or is defined and its value is /system/lib". Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp> Signed-off-by: James Morris <jmorris@namei.org>
- Loading branch information
Tetsuo Handa
authored and
James Morris
committed
Sep 13, 2011
1 parent
5dbe304
commit d58e0da
Showing
7 changed files
with
266 additions
and
10 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,122 @@ | ||
/* | ||
* security/tomoyo/environ.c | ||
* | ||
* Copyright (C) 2005-2011 NTT DATA CORPORATION | ||
*/ | ||
|
||
#include "common.h" | ||
|
||
/** | ||
* tomoyo_check_env_acl - Check permission for environment variable's name. | ||
* | ||
* @r: Pointer to "struct tomoyo_request_info". | ||
* @ptr: Pointer to "struct tomoyo_acl_info". | ||
* | ||
* Returns true if granted, false otherwise. | ||
*/ | ||
static bool tomoyo_check_env_acl(struct tomoyo_request_info *r, | ||
const struct tomoyo_acl_info *ptr) | ||
{ | ||
const struct tomoyo_env_acl *acl = | ||
container_of(ptr, typeof(*acl), head); | ||
|
||
return tomoyo_path_matches_pattern(r->param.environ.name, acl->env); | ||
} | ||
|
||
/** | ||
* tomoyo_audit_env_log - Audit environment variable name log. | ||
* | ||
* @r: Pointer to "struct tomoyo_request_info". | ||
* | ||
* Returns 0 on success, negative value otherwise. | ||
*/ | ||
static int tomoyo_audit_env_log(struct tomoyo_request_info *r) | ||
{ | ||
return tomoyo_supervisor(r, "misc env %s\n", | ||
r->param.environ.name->name); | ||
} | ||
|
||
/** | ||
* tomoyo_env_perm - Check permission for environment variable's name. | ||
* | ||
* @r: Pointer to "struct tomoyo_request_info". | ||
* @env: The name of environment variable. | ||
* | ||
* Returns 0 on success, negative value otherwise. | ||
* | ||
* Caller holds tomoyo_read_lock(). | ||
*/ | ||
int tomoyo_env_perm(struct tomoyo_request_info *r, const char *env) | ||
{ | ||
struct tomoyo_path_info environ; | ||
int error; | ||
|
||
if (!env || !*env) | ||
return 0; | ||
environ.name = env; | ||
tomoyo_fill_path_info(&environ); | ||
r->param_type = TOMOYO_TYPE_ENV_ACL; | ||
r->param.environ.name = &environ; | ||
do { | ||
tomoyo_check_acl(r, tomoyo_check_env_acl); | ||
error = tomoyo_audit_env_log(r); | ||
} while (error == TOMOYO_RETRY_REQUEST); | ||
return error; | ||
} | ||
|
||
/** | ||
* tomoyo_same_env_acl - Check for duplicated "struct tomoyo_env_acl" entry. | ||
* | ||
* @a: Pointer to "struct tomoyo_acl_info". | ||
* @b: Pointer to "struct tomoyo_acl_info". | ||
* | ||
* Returns true if @a == @b, false otherwise. | ||
*/ | ||
static bool tomoyo_same_env_acl(const struct tomoyo_acl_info *a, | ||
const struct tomoyo_acl_info *b) | ||
{ | ||
const struct tomoyo_env_acl *p1 = container_of(a, typeof(*p1), head); | ||
const struct tomoyo_env_acl *p2 = container_of(b, typeof(*p2), head); | ||
|
||
return p1->env == p2->env; | ||
} | ||
|
||
/** | ||
* tomoyo_write_env - Write "struct tomoyo_env_acl" list. | ||
* | ||
* @param: Pointer to "struct tomoyo_acl_param". | ||
* | ||
* Returns 0 on success, negative value otherwise. | ||
* | ||
* Caller holds tomoyo_read_lock(). | ||
*/ | ||
static int tomoyo_write_env(struct tomoyo_acl_param *param) | ||
{ | ||
struct tomoyo_env_acl e = { .head.type = TOMOYO_TYPE_ENV_ACL }; | ||
int error = -ENOMEM; | ||
const char *data = tomoyo_read_token(param); | ||
|
||
if (!tomoyo_correct_word(data) || strchr(data, '=')) | ||
return -EINVAL; | ||
e.env = tomoyo_get_name(data); | ||
if (!e.env) | ||
return error; | ||
error = tomoyo_update_domain(&e.head, sizeof(e), param, | ||
tomoyo_same_env_acl, NULL); | ||
tomoyo_put_name(e.env); | ||
return error; | ||
} | ||
|
||
/** | ||
* tomoyo_write_misc - Update environment variable list. | ||
* | ||
* @param: Pointer to "struct tomoyo_acl_param". | ||
* | ||
* Returns 0 on success, negative value otherwise. | ||
*/ | ||
int tomoyo_write_misc(struct tomoyo_acl_param *param) | ||
{ | ||
if (tomoyo_str_starts(¶m->data, "env ")) | ||
return tomoyo_write_env(param); | ||
return -EINVAL; | ||
} |
Oops, something went wrong.