cregit-Linux how code gets into the kernel

Release 4.17 security/selinux/hooks.c

Directory: security/selinux
/*
 *  NSA Security-Enhanced Linux (SELinux) security module
 *
 *  This file contains the SELinux hook function implementations.
 *
 *  Authors:  Stephen Smalley, <sds@tycho.nsa.gov>
 *            Chris Vance, <cvance@nai.com>
 *            Wayne Salamon, <wsalamon@nai.com>
 *            James Morris <jmorris@redhat.com>
 *
 *  Copyright (C) 2001,2002 Networks Associates Technology, Inc.
 *  Copyright (C) 2003-2008 Red Hat, Inc., James Morris <jmorris@redhat.com>
 *                                         Eric Paris <eparis@redhat.com>
 *  Copyright (C) 2004-2005 Trusted Computer Solutions, Inc.
 *                          <dgoeddel@trustedcs.com>
 *  Copyright (C) 2006, 2007, 2009 Hewlett-Packard Development Company, L.P.
 *      Paul Moore <paul@paul-moore.com>
 *  Copyright (C) 2007 Hitachi Software Engineering Co., Ltd.
 *                     Yuichi Nakamura <ynakam@hitachisoft.jp>
 *  Copyright (C) 2016 Mellanox Technologies
 *
 *      This program is free software; you can redistribute it and/or modify
 *      it under the terms of the GNU General Public License version 2,
 *      as published by the Free Software Foundation.
 */

#include <linux/init.h>
#include <linux/kd.h>
#include <linux/kernel.h>
#include <linux/tracehook.h>
#include <linux/errno.h>
#include <linux/sched/signal.h>
#include <linux/sched/task.h>
#include <linux/lsm_hooks.h>
#include <linux/xattr.h>
#include <linux/capability.h>
#include <linux/unistd.h>
#include <linux/mm.h>
#include <linux/mman.h>
#include <linux/slab.h>
#include <linux/pagemap.h>
#include <linux/proc_fs.h>
#include <linux/swap.h>
#include <linux/spinlock.h>
#include <linux/syscalls.h>
#include <linux/dcache.h>
#include <linux/file.h>
#include <linux/fdtable.h>
#include <linux/namei.h>
#include <linux/mount.h>
#include <linux/netfilter_ipv4.h>
#include <linux/netfilter_ipv6.h>
#include <linux/tty.h>
#include <net/icmp.h>
#include <net/ip.h>		/* for local_port_range[] */
#include <net/tcp.h>		/* struct or_callable used in sock_rcv_skb */
#include <net/inet_connection_sock.h>
#include <net/net_namespace.h>
#include <net/netlabel.h>
#include <linux/uaccess.h>
#include <asm/ioctls.h>
#include <linux/atomic.h>
#include <linux/bitops.h>
#include <linux/interrupt.h>
#include <linux/netdevice.h>	/* for network interface checks */
#include <net/netlink.h>
#include <linux/tcp.h>
#include <linux/udp.h>
#include <linux/dccp.h>
#include <linux/sctp.h>
#include <net/sctp/structs.h>
#include <linux/quota.h>
#include <linux/un.h>		/* for Unix socket types */
#include <net/af_unix.h>	/* for Unix socket types */
#include <linux/parser.h>
#include <linux/nfs_mount.h>
#include <net/ipv6.h>
#include <linux/hugetlb.h>
#include <linux/personality.h>
#include <linux/audit.h>
#include <linux/string.h>
#include <linux/selinux.h>
#include <linux/mutex.h>
#include <linux/posix-timers.h>
#include <linux/syslog.h>
#include <linux/user_namespace.h>
#include <linux/export.h>
#include <linux/msg.h>
#include <linux/shm.h>
#include <linux/bpf.h>

#include "avc.h"
#include "objsec.h"
#include "netif.h"
#include "netnode.h"
#include "netport.h"
#include "ibpkey.h"
#include "xfrm.h"
#include "netlabel.h"
#include "audit.h"
#include "avc_ss.h"


struct selinux_state selinux_state;

/* SECMARK reference count */

static atomic_t selinux_secmark_refcount = ATOMIC_INIT(0);

#ifdef CONFIG_SECURITY_SELINUX_DEVELOP

static int selinux_enforcing_boot;


static int __init enforcing_setup(char *str) { unsigned long enforcing; if (!kstrtoul(str, 0, &enforcing)) selinux_enforcing_boot = enforcing ? 1 : 0; return 1; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2051.28%125.00%
Eric Paris1743.59%125.00%
Jingoo Han12.56%125.00%
Stephen D. Smalley12.56%125.00%
Total39100.00%4100.00%

__setup("enforcing=", enforcing_setup); #else #define selinux_enforcing_boot 1 #endif #ifdef CONFIG_SECURITY_SELINUX_BOOTPARAM int selinux_enabled = CONFIG_SECURITY_SELINUX_BOOTPARAM_VALUE;
static int __init selinux_enabled_setup(char *str) { unsigned long enabled; if (!kstrtoul(str, 0, &enabled)) selinux_enabled = enabled ? 1 : 0; return 1; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2051.28%133.33%
Eric Paris1846.15%133.33%
Jingoo Han12.56%133.33%
Total39100.00%3100.00%

__setup("selinux=", selinux_enabled_setup); #else int selinux_enabled = 1; #endif static unsigned int selinux_checkreqprot_boot = CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE;
static int __init checkreqprot_setup(char *str) { unsigned long checkreqprot; if (!kstrtoul(str, 0, &checkreqprot)) selinux_checkreqprot_boot = checkreqprot ? 1 : 0; return 1; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley39100.00%1100.00%
Total39100.00%1100.00%

__setup("checkreqprot=", checkreqprot_setup); static struct kmem_cache *sel_inode_cache; static struct kmem_cache *file_security_cache; /** * selinux_secmark_enabled - Check to see if SECMARK is currently enabled * * Description: * This function checks the SECMARK reference counter to see if any SECMARK * targets are currently configured, if the reference counter is greater than * zero SECMARK is considered to be enabled. Returns true (1) if SECMARK is * enabled, false (0) if SECMARK is disabled. If the always_check_network * policy capability is enabled, SECMARK is always considered enabled. * */
static int selinux_secmark_enabled(void) { return (selinux_policycap_alwaysnetwork() || atomic_read(&selinux_secmark_refcount)); }

Contributors

PersonTokensPropCommitsCommitProp
Paul Moore1470.00%133.33%
Christopher J. PeBenito525.00%133.33%
Stephen D. Smalley15.00%133.33%
Total20100.00%3100.00%

/** * selinux_peerlbl_enabled - Check to see if peer labeling is currently enabled * * Description: * This function checks if NetLabel or labeled IPSEC is enabled. Returns true * (1) if any are enabled or false (0) if neither are enabled. If the * always_check_network policy capability is enabled, peer labeling * is always considered enabled. * */
static int selinux_peerlbl_enabled(void) { return (selinux_policycap_alwaysnetwork() || netlbl_enabled() || selinux_xfrm_enabled()); }

Contributors

PersonTokensPropCommitsCommitProp
Christopher J. PeBenito1680.00%133.33%
Paul Moore315.00%133.33%
Stephen D. Smalley15.00%133.33%
Total20100.00%3100.00%


static int selinux_netcache_avc_callback(u32 event) { if (event == AVC_CALLBACK_RESET) { sel_netif_flush(); sel_netnode_flush(); sel_netport_flush(); synchronize_net(); } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Paul Moore32100.00%1100.00%
Total32100.00%1100.00%


static int selinux_lsm_notifier_avc_callback(u32 event) { if (event == AVC_CALLBACK_RESET) { sel_ib_pkey_flush(); call_lsm_notifier(LSM_POLICY_CHANGE, NULL); } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Daniel Jurgens30100.00%2100.00%
Total30100.00%2100.00%

/* * initialise the security for the init task */
static void cred_init_security(void) { struct cred *cred = (struct cred *) current->real_cred; struct task_security_struct *tsec; tsec = kzalloc(sizeof(struct task_security_struct), GFP_KERNEL); if (!tsec) panic("SELinux: Failed to initialize initial task.\n"); tsec->osid = tsec->sid = SECINITSID_KERNEL; cred->security = tsec; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton4060.61%116.67%
David Howells2537.88%466.67%
James Morris11.52%116.67%
Total66100.00%6100.00%

/* * get the security ID of a set of credentials */
static inline u32 cred_sid(const struct cred *cred) { const struct task_security_struct *tsec; tsec = cred->security; return tsec->sid; }

Contributors

PersonTokensPropCommitsCommitProp
David Howells2066.67%266.67%
Andrew Morton1033.33%133.33%
Total30100.00%3100.00%

/* * get the objective security ID of a task */
static inline u32 task_sid(const struct task_struct *task) { u32 sid; rcu_read_lock(); sid = cred_sid(__task_cred(task)); rcu_read_unlock(); return sid; }

Contributors

PersonTokensPropCommitsCommitProp
David Howells35100.00%2100.00%
Total35100.00%2100.00%

/* Allocate and free functions for each kind of security blob. */
static int inode_alloc_security(struct inode *inode) { struct inode_security_struct *isec; u32 sid = current_sid(); isec = kmem_cache_zalloc(sel_inode_cache, GFP_NOFS); if (!isec) return -ENOMEM; spin_lock_init(&isec->lock); INIT_LIST_HEAD(&isec->list); isec->inode = inode; isec->sid = SECINITSID_UNLABELED; isec->sclass = SECCLASS_FILE; isec->task_sid = sid; isec->initialized = LABEL_INVALID; inode->i_security = isec; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton6871.58%112.50%
David Howells1616.84%112.50%
Andreas Gruenbacher77.37%225.00%
Eric Paris11.05%112.50%
Josef Bacik11.05%112.50%
Robert P. J. Day11.05%112.50%
James Morris11.05%112.50%
Total95100.00%8100.00%

static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry); /* * Try reloading inode security labels that have been marked as invalid. The * @may_sleep parameter indicates when sleeping and thus reloading labels is * allowed; when set to false, returns -ECHILD when the label is * invalid. The @opt_dentry parameter should be set to a dentry of the inode; * when no dentry is available, set it to NULL instead. */
static int __inode_security_revalidate(struct inode *inode, struct dentry *opt_dentry, bool may_sleep) { struct inode_security_struct *isec = inode->i_security; might_sleep_if(may_sleep); if (selinux_state.initialized && isec->initialized != LABEL_INITIALIZED) { if (!may_sleep) return -ECHILD; /* * Try reloading the inode security label. This will fail if * @opt_dentry is NULL and no dentry for this inode can be * found; in that case, continue using the old label. */ inode_doinit_with_dentry(inode, opt_dentry); } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andreas Gruenbacher6191.04%125.00%
Stephen D. Smalley34.48%125.00%
Paul Moore34.48%250.00%
Total67100.00%4100.00%


static struct inode_security_struct *inode_security_novalidate(struct inode *inode) { return inode->i_security; }

Contributors

PersonTokensPropCommitsCommitProp
Andreas Gruenbacher18100.00%1100.00%
Total18100.00%1100.00%


static struct inode_security_struct *inode_security_rcu(struct inode *inode, bool rcu) { int error; error = __inode_security_revalidate(inode, NULL, !rcu); if (error) return ERR_PTR(error); return inode->i_security; }

Contributors

PersonTokensPropCommitsCommitProp
Andreas Gruenbacher46100.00%1100.00%
Total46100.00%1100.00%

/* * Get the security label of an inode. */
static struct inode_security_struct *inode_security(struct inode *inode) { __inode_security_revalidate(inode, NULL, true); return inode->i_security; }

Contributors

PersonTokensPropCommitsCommitProp
Andreas Gruenbacher27100.00%2100.00%
Total27100.00%2100.00%


static struct inode_security_struct *backing_inode_security_novalidate(struct dentry *dentry) { struct inode *inode = d_backing_inode(dentry); return inode->i_security; }

Contributors

PersonTokensPropCommitsCommitProp
Paul Moore28100.00%1100.00%
Total28100.00%1100.00%

/* * Get the security label of a dentry's backing inode. */
static struct inode_security_struct *backing_inode_security(struct dentry *dentry) { struct inode *inode = d_backing_inode(dentry); __inode_security_revalidate(inode, dentry, true); return inode->i_security; }

Contributors

PersonTokensPropCommitsCommitProp
Andreas Gruenbacher37100.00%2100.00%
Total37100.00%2100.00%


static void inode_free_rcu(struct rcu_head *head) { struct inode_security_struct *isec; isec = container_of(head, struct inode_security_struct, rcu); kmem_cache_free(sel_inode_cache, isec); }

Contributors

PersonTokensPropCommitsCommitProp
Steven Rostedt35100.00%1100.00%
Total35100.00%1100.00%


static void inode_free_security(struct inode *inode) { struct inode_security_struct *isec = inode->i_security; struct superblock_security_struct *sbsec = inode->i_sb->s_security; /* * As not all inode security structures are in a list, we check for * empty list outside of the lock to make sure that we won't waste * time taking a lock doing nothing. * * The list_del_init() function can be safely called more than once. * It should not be possible for this function to be called with * concurrent list_add(), but for better safety against future changes * in the code, we use list_empty_careful() here. */ if (!list_empty_careful(&isec->list)) { spin_lock(&sbsec->isec_lock); list_del_init(&isec->list); spin_unlock(&sbsec->isec_lock); } /* * The inode may still be referenced in a path walk and * a call to selinux_inode_permission() can be made * after inode_free_security() is called. Ideally, the VFS * wouldn't do this, but fixing that is a much harder * job. For now, simply free the i_security via RCU, and * leave the current inode->i_security pointer intact. * The inode will be freed after the RCU grace period too. */ call_rcu(&isec->rcu, inode_free_rcu); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton6176.25%250.00%
Waiman Long1215.00%125.00%
Steven Rostedt78.75%125.00%
Total80100.00%4100.00%


static int file_alloc_security(struct file *file) { struct file_security_struct *fsec; u32 sid = current_sid(); fsec = kmem_cache_zalloc(file_security_cache, GFP_KERNEL); if (!fsec) return -ENOMEM; fsec->sid = sid; fsec->fown_sid = sid; file->f_security = fsec; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton5285.25%125.00%
David Howells69.84%125.00%
Sangwoo23.28%125.00%
Stephen D. Smalley11.64%125.00%
Total61100.00%4100.00%


static void file_free_security(struct file *file) { struct file_security_struct *fsec = file->f_security; file->f_security = NULL; kmem_cache_free(file_security_cache, fsec); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3090.91%150.00%
Sangwoo39.09%150.00%
Total33100.00%2100.00%


static int superblock_alloc_security(struct super_block *sb) { struct superblock_security_struct *sbsec; sbsec = kzalloc(sizeof(struct superblock_security_struct), GFP_KERNEL); if (!sbsec) return -ENOMEM; mutex_init(&sbsec->lock); INIT_LIST_HEAD(&sbsec->isec_head); spin_lock_init(&sbsec->isec_lock); sbsec->sb = sb; sbsec->sid = SECINITSID_UNLABELED; sbsec->def_sid = SECINITSID_FILE; sbsec->mntpoint_sid = SECINITSID_UNLABELED; sb->s_security = sbsec; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton8690.53%350.00%
Eric Paris88.42%233.33%
James Morris11.05%116.67%
Total95100.00%6100.00%


static void superblock_free_security(struct super_block *sb) { struct superblock_security_struct *sbsec = sb->s_security; sb->s_security = NULL; kfree(sbsec); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton31100.00%1100.00%
Total31100.00%1100.00%


static inline int inode_doinit(struct inode *inode) { return inode_doinit_with_dentry(inode, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton20100.00%1100.00%
Total20100.00%1100.00%

enum { Opt_error = -1, Opt_context = 1, Opt_fscontext = 2, Opt_defcontext = 3, Opt_rootcontext = 4, Opt_labelsupport = 5, Opt_nextmntopt = 6, }; #define NUM_SEL_MNT_OPTS (Opt_nextmntopt - 1) static const match_table_t tokens = { {Opt_context, CONTEXT_STR "%s"}, {Opt_fscontext, FSCONTEXT_STR "%s"}, {Opt_defcontext, DEFCONTEXT_STR "%s"}, {Opt_rootcontext, ROOTCONTEXT_STR "%s"}, {Opt_labelsupport, LABELSUPP_STR}, {Opt_error, NULL}, }; #define SEL_MOUNT_FAIL_MSG "SELinux: duplicate or incompatible mount options\n"
static int may_context_mount_sb_relabel(u32 sid, struct superblock_security_struct *sbsec, const struct cred *cred) { const struct task_security_struct *tsec = cred->security; int rc; rc = avc_has_perm(&selinux_state, tsec->sid, sbsec->sid, SECCLASS_FILESYSTEM, FILESYSTEM__RELABELFROM, NULL); if (rc) return rc; rc = avc_has_perm(&selinux_state, tsec->sid, sid, SECCLASS_FILESYSTEM, FILESYSTEM__RELABELTO, NULL); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris6677.65%133.33%
David Howells1315.29%133.33%
Stephen D. Smalley67.06%133.33%
Total85100.00%3100.00%


static int may_context_mount_inode_relabel(u32 sid, struct superblock_security_struct *sbsec, const struct cred *cred) { const struct task_security_struct *tsec = cred->security; int rc; rc = avc_has_perm(&selinux_state, tsec->sid, sbsec->sid, SECCLASS_FILESYSTEM, FILESYSTEM__RELABELFROM, NULL); if (rc) return rc; rc = avc_has_perm(&selinux_state, sid, sbsec->sid, SECCLASS_FILESYSTEM, FILESYSTEM__ASSOCIATE, NULL); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris6677.65%133.33%
David Howells1315.29%133.33%
Stephen D. Smalley67.06%133.33%
Total85100.00%3100.00%


static int selinux_is_sblabel_mnt(struct super_block *sb) { struct superblock_security_struct *sbsec = sb->s_security; return sbsec->behavior == SECURITY_FS_USE_XATTR || sbsec->behavior == SECURITY_FS_USE_TRANS || sbsec->behavior == SECURITY_FS_USE_TASK || sbsec->behavior == SECURITY_FS_USE_NATIVE || /* Special handling. Genfs but also in-core setxattr handler */ !strcmp(sb->s_type->name, "sysfs") || !strcmp(sb->s_type->name, "pstore") || !strcmp(sb->s_type->name, "debugfs") || !strcmp(sb->s_type->name, "tracefs") || !strcmp(sb->s_type->name, "rootfs") || (selinux_policycap_cgroupseclabel() && (!strcmp(sb->s_type->name, "cgroup") || !strcmp(sb->s_type->name, "cgroup2"))); }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris5741.61%114.29%
Mark Salyzyn2820.44%114.29%
Antonio Murdaca2216.06%114.29%
Stephen D. Smalley139.49%228.57%
Yongqin Liu118.03%114.29%
J. Bruce Fields64.38%114.29%
Total137100.00%7100.00%


static int sb_finish_set_opts(struct super_block *sb) { struct superblock_security_struct *sbsec = sb->s_security; struct dentry *root = sb->s_root; struct inode *root_inode = d_backing_inode(root); int rc = 0; if (sbsec->behavior == SECURITY_FS_USE_XATTR) { /* Make sure that the xattr handler exists and that no error other than -ENODATA is returned by getxattr on the root directory. -ENODATA is ok, as this may be the first boot of the SELinux kernel before we have assigned xattr values to the filesystem. */ if (!(root_inode->i_opflags & IOP_XATTR)) { printk(KERN_WARNING "SELinux: (dev %s, type %s) has no " "xattr support\n", sb->s_id, sb->s_type->name); rc = -EOPNOTSUPP; goto out; } rc = __vfs_getxattr(root, root_inode, XATTR_NAME_SELINUX, NULL, 0); if (rc < 0 && rc != -ENODATA) { if (rc == -EOPNOTSUPP) printk(KERN_WARNING "SELinux: (dev %s, type " "%s) has no security xattr handler\n", sb->s_id, sb->s_type->name); else printk(KERN_WARNING "SELinux: (dev %s, type " "%s) getxattr errno %d\n", sb->s_id, sb->s_type->name, -rc); goto out; } } sbsec->flags |= SE_SBINITIALIZED; /* * Explicitly set or clear SBLABEL_MNT. It's not sufficient to simply * leave the flag untouched because sb_clone_mnt_opts might be handing * us a superblock that needs the flag to be cleared. */ if (selinux_is_sblabel_mnt(sb)) sbsec->flags |= SBLABEL_MNT; else sbsec->flags &= ~SBLABEL_MNT; /* Initialize the root inode. */ rc = inode_doinit_with_dentry(root_inode, root); /* Initialize any other inodes associated with the superblock, e.g. inodes created prior to initial policy load or inodes created during get_sb by a pseudo filesystem that directly populates itself. */ spin_lock(&sbsec->isec_lock); next_inode: if (!list_empty(&sbsec->isec_head)) { struct inode_security_struct *isec = list_entry(sbsec->isec_head.next, struct inode_security_struct, list); struct inode *inode = isec->inode; list_del_init(&isec->list); spin_unlock(&sbsec->isec_lock); inode = igrab(inode); if (inode) { if (!IS_PRIVATE(inode)) inode_doinit(inode); iput(inode); } spin_lock(&sbsec->isec_lock); goto next_inode; } spin_unlock(&sbsec->isec_lock); out: return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris21866.06%426.67%
Andrew Morton5416.36%320.00%
Linus Torvalds154.55%16.67%
David P. Quigley154.55%213.33%
Scott Mayhew92.73%16.67%
Stephen D. Smalley82.42%16.67%
Andreas Gruenbacher61.82%16.67%
David Howells30.91%16.67%
Al Viro20.61%16.67%
Total330100.00%15100.00%

/* * This function should allow an FS to ask what it's mount security * options were so it can use those later for submounts, displaying * mount options, or whatever. */
static int selinux_get_mnt_opts(const struct super_block *sb, struct security_mnt_opts *opts) { int rc = 0, i; struct superblock_security_struct *sbsec = sb->s_security; char *context = NULL; u32 len; char tmp; security_init_mnt_opts(opts); if (!(sbsec->flags & SE_SBINITIALIZED)) return -EINVAL; if (!selinux_state.initialized) return -EINVAL; /* make sure we always check enough bits to cover the mask */ BUILD_BUG_ON(SE_MNTMASK >= (1 << NUM_SEL_MNT_OPTS)); tmp = sbsec->flags & SE_MNTMASK; /* count the number of mount options for this sb */ for (i = 0; i < NUM_SEL_MNT_OPTS; i++) { if (tmp & 0x01) opts->num_mnt_opts++; tmp >>= 1; } /* Check if the Label support flag is set */ if (sbsec->flags & SBLABEL_MNT) opts->num_mnt_opts++; opts->mnt_opts = kcalloc(opts->num_mnt_opts, sizeof(char *), GFP_ATOMIC); if (!opts->mnt_opts) { rc = -ENOMEM; goto out_free; } opts->mnt_opts_flags = kcalloc(opts->num_mnt_opts, sizeof(int), GFP_ATOMIC); if (!opts->mnt_opts_flags) { rc = -ENOMEM; goto out_free; } i = 0; if (sbsec->flags & FSCONTEXT_MNT) { rc = security_sid_to_context(&selinux_state, sbsec->sid, &context, &len); if (rc) goto out_free; opts->mnt_opts[i] = context; opts->mnt_opts_flags[i++] = FSCONTEXT_MNT; } if (sbsec->flags & CONTEXT_MNT) { rc = security_sid_to_context(&selinux_state, sbsec->mntpoint_sid, &context, &len); if (rc) goto out_free; opts->mnt_opts[i] = context; opts->mnt_opts_flags[i++] = CONTEXT_MNT; } if (sbsec->flags & DEFCONTEXT_MNT) { rc = security_sid_to_context(&selinux_state, sbsec->def_sid, &context, &len); if (rc) goto out_free; opts->mnt_opts[i] = context; opts->mnt_opts_flags[i++] = DEFCONTEXT_MNT; } if (sbsec->flags & ROOTCONTEXT_MNT) { struct dentry *root = sbsec->sb->s_root; struct inode_security_struct *isec = backing_inode_security(root); rc = security_sid_to_context(&selinux_state, isec->sid, &context, &len); if (rc) goto out_free; opts->mnt_opts[i] = context; opts->mnt_opts_flags[i++] = ROOTCONTEXT_MNT; } if (sbsec->flags & SBLABEL_MNT) { opts->mnt_opts[i] = NULL; opts->mnt_opts_flags[i++] = SBLABEL_MNT; } BUG_ON(i != opts->num_mnt_opts); return 0; out_free: security_free_mnt_opts(opts); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris43886.90%555.56%
David P. Quigley479.33%222.22%
Stephen D. Smalley152.98%111.11%
Andreas Gruenbacher40.79%111.11%
Total504100.00%9100.00%


static int bad_option(struct superblock_security_struct *sbsec, char flag, u32 old_sid, u32 new_sid) { char mnt_flags = sbsec->flags & SE_MNTMASK; /* check if the old mount command had the same options */ if (sbsec->flags & SE_SBINITIALIZED) if (!(sbsec->flags & flag) || (old_sid != new_sid)) return 1; /* check if we were passed the same options twice, * aka someone passed context=a,context=b */ if (!(sbsec->flags & SE_SBINITIALIZED)) if (mnt_flags & flag) return 1; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris6478.05%150.00%
David P. Quigley1821.95%150.00%
Total82100.00%2100.00%

/* * Allow filesystems with binary mount data to explicitly set mount point * labeling information. */
static int selinux_set_mnt_opts(struct super_block *sb, struct security_mnt_opts *opts, unsigned long kern_flags, unsigned long *set_kern_flags) { const struct cred *cred = current_cred(); int rc = 0, i; struct superblock_security_struct *sbsec = sb->s_security; const char *name = sb->s_type->name; struct dentry *root = sbsec->sb->s_root; struct inode_security_struct *root_isec; u32 fscontext_sid = 0, context_sid = 0, rootcontext_sid = 0; u32 defcontext_sid = 0; char **mount_options = opts->mnt_opts; int *flags = opts->mnt_opts_flags; int num_opts = opts->num_mnt_opts; mutex_lock(&sbsec->lock); if (!selinux_state.initialized) { if (!num_opts) { /* Defer initialization until selinux_complete_init, after the initial policy is loaded and the security server is ready to handle calls. */ goto out; } rc = -EINVAL; printk(KERN_WARNING "SELinux: Unable to set superblock options " "before the security server is initialized\n"); goto out; } if (kern_flags && !set_kern_flags) { /* Specifying internal flags without providing a place to * place the results is not allowed */ rc = -EINVAL; goto out; } /* * Binary mount data FS will come through this function twice. Once * from an explicit call and once from the generic calls from the vfs. * Since the generic VFS calls will not contain any security mount data * we need to skip the double mount verification. * * This does open a hole in which we will not notice if the first * mount using this sb set explict options and a second mount using * this sb does not set any security options. (The first options * will be used for both mounts) */ if ((sbsec->flags & SE_SBINITIALIZED) && (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA) && (num_opts == 0)) goto out; root_isec = backing_inode_security_novalidate(root); /* * parse the mount options, check if they are valid sids. * also check if someone is trying to mount the same sb more * than once with different security options. */ for (i = 0; i < num_opts; i++) { u32 sid; if (flags[i] == SBLABEL_MNT) continue; rc = security_context_str_to_sid(&selinux_state, mount_options[i], &sid, GFP_KERNEL); if (rc) { printk(KERN_WARNING "SELinux: security_context_str_to_sid" "(%s) failed for (dev %s, type %s) errno=%d\n", mount_options[i], sb->s_id, name, rc); goto out; } switch (flags[i]) { case FSCONTEXT_MNT: fscontext_sid = sid; if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, fscontext_sid)) goto out_double_mount; sbsec->flags |= FSCONTEXT_MNT; break; case CONTEXT_MNT: context_sid = sid; if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, context_sid)) goto out_double_mount; sbsec->flags |= CONTEXT_MNT; break; case ROOTCONTEXT_MNT: rootcontext_sid = sid; if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, rootcontext_sid)) goto out_double_mount; sbsec->flags |= ROOTCONTEXT_MNT; break; case DEFCONTEXT_MNT: defcontext_sid = sid; if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, defcontext_sid)) goto out_double_mount; sbsec->flags |= DEFCONTEXT_MNT; break; default: rc = -EINVAL; goto out; } } if (sbsec->flags & SE_SBINITIALIZED) { /* previously mounted with options, but not on this attempt? */ if ((sbsec->flags & SE_MNTMASK) && !num_opts) goto out_double_mount; rc = 0; goto out; } if (strcmp(sb->s_type->name, "proc") == 0) sbsec->flags |= SE_SBPROC | SE_SBGENFS; if (!strcmp(sb->s_type->name, "debugfs") || !strcmp(sb->s_type->name, "tracefs") || !strcmp(sb->s_type->name, "sysfs") || !strcmp(sb->s_type->name, "pstore") || !strcmp(sb->s_type->name, "cgroup") || !strcmp(sb->s_type->name, "cgroup2")) sbsec->flags |= SE_SBGENFS; if (!sbsec->behavior) { /* * Determine the labeling behavior to use for this * filesystem type. */ rc = security_fs_use(&selinux_state, sb); if (rc) { printk(KERN_WARNING "%s: security_fs_use(%s) returned %d\n", __func__, sb->s_type->name, rc); goto out; } } /* * If this is a user namespace mount and the filesystem type is not * explicitly whitelisted, then no contexts are allowed on the command * line and security labels must be ignored. */ if (sb->s_user_ns != &init_user_ns && strcmp(sb->s_type->name, "tmpfs") && strcmp(sb->s_type->name, "ramfs") && strcmp(sb->s_type->name, "devpts")) { if (context_sid || fscontext_sid || rootcontext_sid || defcontext_sid) { rc = -EACCES; goto out; } if (sbsec->behavior == SECURITY_FS_USE_XATTR) { sbsec->behavior = SECURITY_FS_USE_MNTPOINT; rc = security_transition_sid(&selinux_state, current_sid(), current_sid(), SECCLASS_FILE, NULL, &sbsec->mntpoint_sid); if (rc) goto out; } goto out_set_opts; } /* sets the context of the superblock for the fs being mounted. */ if (fscontext_sid) { rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred); if (rc) goto out; sbsec->sid = fscontext_sid; } /* * Switch to using mount point labeling behavior. * sets the label used on all file below the mountpoint, and will set * the superblock context if not already set. */ if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !context_sid) { sbsec->behavior = SECURITY_FS_USE_NATIVE; *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; } if (context_sid) { if (!fscontext_sid) { rc = may_context_mount_sb_relabel(context_sid, sbsec, cred); if (rc) goto out; sbsec->sid = context_sid; } else { rc = may_context_mount_inode_relabel(context_sid, sbsec, cred); if (rc) goto out; } if (!rootcontext_sid) rootcontext_sid = context_sid; sbsec->mntpoint_sid = context_sid; sbsec->behavior = SECURITY_FS_USE_MNTPOINT; } if (rootcontext_sid) { rc = may_context_mount_inode_relabel(rootcontext_sid, sbsec, cred); if (rc) goto out; root_isec->sid = rootcontext_sid; root_isec->initialized = LABEL_INITIALIZED; } if (defcontext_sid) { if (sbsec->behavior != SECURITY_FS_USE_XATTR && sbsec->behavior != SECURITY_FS_USE_NATIVE) { rc = -EINVAL; printk(KERN_WARNING "SELinux: defcontext option is " "invalid for this filesystem type\n"); goto out; } if (defcontext_sid != sbsec->def_sid) { rc = may_context_mount_inode_relabel(defcontext_sid, sbsec, cred); if (rc) goto out; } sbsec->def_sid = defcontext_sid; } out_set_opts: rc = sb_finish_set_opts(sb); out: mutex_unlock(&sbsec->lock); return rc; out_double_mount: rc = -EINVAL; printk(KERN_WARNING "SELinux: mount invalid. Same superblock, different " "security settings for (dev %s, type %s)\n", sb->s_id, name); goto out; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris55154.02%619.35%
Andrew Morton11711.47%412.90%
Stephen D. Smalley929.02%412.90%
Seth Forshee797.75%13.23%
David Quigley656.37%26.45%
Antonio Murdaca242.35%13.23%
David P. Quigley242.35%26.45%
Linus Torvalds151.47%13.23%
David Howells141.37%13.23%
Jeff Vander Stoep121.18%13.23%
James Morris111.08%13.23%
Paul Moore70.69%13.23%
Andreas Gruenbacher30.29%26.45%
Nikolay Aleksandrov20.20%13.23%
Rasmus Villemoes20.20%13.23%
Harvey Harrison10.10%13.23%
Adrian Bunk10.10%13.23%
Total1020100.00%31100.00%


static int selinux_cmp_sb_context(const struct super_block *oldsb, const struct super_block *newsb) { struct superblock_security_struct *old = oldsb->s_security; struct superblock_security_struct *new = newsb->s_security; char oldflags = old->flags & SE_MNTMASK; char newflags = new->flags & SE_MNTMASK; if (oldflags != newflags) goto mismatch; if ((oldflags & FSCONTEXT_MNT) && old->sid != new->sid) goto mismatch; if ((oldflags & CONTEXT_MNT) && old->mntpoint_sid != new->mntpoint_sid) goto mismatch; if ((oldflags & DEFCONTEXT_MNT) && old->def_sid != new->def_sid) goto mismatch; if (oldflags & ROOTCONTEXT_MNT) { struct inode_security_struct *oldroot = backing_inode_security(oldsb->s_root); struct inode_security_struct *newroot = backing_inode_security(newsb->s_root); if (oldroot->sid != newroot->sid) goto mismatch; } return 0; mismatch: printk(KERN_WARNING "SELinux: mount invalid. Same superblock, " "different security settings for (dev %s, " "type %s)\n", newsb->s_id, newsb->s_type->name); return -EBUSY; }

Contributors

PersonTokensPropCommitsCommitProp
Jeff Layton18696.88%133.33%
David Howells42.08%133.33%
Andreas Gruenbacher21.04%133.33%
Total192100.00%3100.00%


static int selinux_sb_clone_mnt_opts(const struct super_block *oldsb, struct super_block *newsb, unsigned long kern_flags, unsigned long *set_kern_flags) { int rc = 0; const struct superblock_security_struct *oldsbsec = oldsb->s_security; struct superblock_security_struct *newsbsec = newsb->s_security; int set_fscontext = (oldsbsec->flags & FSCONTEXT_MNT); int set_context = (oldsbsec->flags & CONTEXT_MNT); int set_rootcontext = (oldsbsec->flags & ROOTCONTEXT_MNT); /* * if the parent was able to be mounted it clearly had no special lsm * mount options. thus we can safely deal with this superblock later */ if (!selinux_state.initialized) return 0; /* * Specifying internal flags without providing a place to * place the results is not allowed. */ if (kern_flags && !set_kern_flags) return -EINVAL; /* how can we clone if the old one wasn't set up?? */ BUG_ON(!(oldsbsec->flags & SE_SBINITIALIZED)); /* if fs is reusing a sb, make sure that the contexts match */ if (newsbsec->flags & SE_SBINITIALIZED) return selinux_cmp_sb_context(oldsb, newsb); mutex_lock(&newsbsec->lock); newsbsec->flags = oldsbsec->flags; newsbsec->sid = oldsbsec->sid; newsbsec->def_sid = oldsbsec->def_sid; newsbsec->behavior = oldsbsec->behavior; if (newsbsec->behavior == SECURITY_FS_USE_NATIVE && !(kern_flags & SECURITY_LSM_NATIVE_LABELS) && !set_context) { rc = security_fs_use(&selinux_state, newsb); if (rc) goto out; } if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !set_context) { newsbsec->behavior = SECURITY_FS_USE_NATIVE; *set_kern_flags |= SECURITY_LSM_NATIVE_LABELS; } if (set_context) { u32 sid = oldsbsec->mntpoint_sid; if (!set_fscontext) newsbsec->sid = sid; if (!set_rootcontext) { struct inode_security_struct *newisec = backing_inode_security(newsb->s_root); newisec->sid = sid; } newsbsec->mntpoint_sid = sid; } if (set_rootcontext) { const struct inode_security_struct *oldisec = backing_inode_security(oldsb->s_root); struct inode_security_struct *newisec = backing_inode_security(newsb->s_root); newisec->sid = oldisec->sid; } sb_finish_set_opts(newsb); out: mutex_unlock(&newsbsec->lock); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris19857.06%640.00%
Scott Mayhew8524.50%16.67%
Andrew Morton205.76%213.33%
Jeff Layton154.32%16.67%
David P. Quigley82.31%16.67%
Andreas Gruenbacher82.31%16.67%
Stephen D. Smalley61.73%16.67%
David Howells61.73%16.67%
Al Viro10.29%16.67%
Total347100.00%15100.00%


static int selinux_parse_opts_str(char *options, struct security_mnt_opts *opts) { char *p; char *context = NULL, *defcontext = NULL; char *fscontext = NULL, *rootcontext = NULL; int rc, num_mnt_opts = 0; opts->num_mnt_opts = 0; /* Standard string-based options. */ while ((p = strsep(&options, "|")) != NULL) { int token; substring_t args[MAX_OPT_ARGS]; if (!*p) continue; token = match_token(p, tokens, args); switch (token) { case Opt_context: if (context || defcontext) { rc = -EINVAL; printk(KERN_WARNING SEL_MOUNT_FAIL_MSG); goto out_err; } context = match_strdup(&args[0]); if (!context) { rc = -ENOMEM; goto out_err; } break; case Opt_fscontext: if (fscontext) { rc = -EINVAL; printk(KERN_WARNING SEL_MOUNT_FAIL_MSG); goto out_err; } fscontext = match_strdup(&args[0]); if (!fscontext) { rc = -ENOMEM; goto out_err; } break; case Opt_rootcontext: if (rootcontext) { rc = -EINVAL; printk(KERN_WARNING SEL_MOUNT_FAIL_MSG); goto out_err; } rootcontext = match_strdup(&args[0]); if (!rootcontext) { rc = -ENOMEM; goto out_err; } break; case Opt_defcontext: if (context || defcontext) { rc = -EINVAL; printk(KERN_WARNING SEL_MOUNT_FAIL_MSG); goto out_err; } defcontext = match_strdup(&args[0]); if (!defcontext) { rc = -ENOMEM; goto out_err; } break; case Opt_labelsupport: break; default: rc = -EINVAL; printk(KERN_WARNING "SELinux: unknown mount option\n"); goto out_err; } } rc = -ENOMEM; opts->mnt_opts = kcalloc(NUM_SEL_MNT_OPTS, sizeof(char *), GFP_KERNEL); if (!opts->mnt_opts) goto out_err; opts->mnt_opts_flags = kcalloc(NUM_SEL_MNT_OPTS, sizeof(int), GFP_KERNEL); if (!opts->mnt_opts_flags) goto out_err; if (fscontext) { opts->mnt_opts[num_mnt_opts] = fscontext; opts->mnt_opts_flags[num_mnt_opts++] = FSCONTEXT_MNT; } if (context) { opts->mnt_opts[num_mnt_opts] = context; opts->mnt_opts_flags[num_mnt_opts++] = CONTEXT_MNT; } if (rootcontext) { opts->mnt_opts[num_mnt_opts] = rootcontext; opts->mnt_opts_flags[num_mnt_opts++] = ROOTCONTEXT_MNT; } if (defcontext) { opts->mnt_opts[num_mnt_opts] = defcontext; opts->mnt_opts_flags[num_mnt_opts++] = DEFCONTEXT_MNT; } opts->num_mnt_opts = num_mnt_opts; return 0; out_err: security_free_mnt_opts(opts); kfree(context); kfree(defcontext); kfree(fscontext); kfree(rootcontext); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris38573.75%228.57%
Andrew Morton12523.95%114.29%
Paul Moore50.96%114.29%
David P. Quigley40.77%114.29%
Tetsuo Handa20.38%114.29%
Adrian Bunk10.19%114.29%
Total522100.00%7100.00%

/* * string mount options parsing and call set the sbsec */
static int superblock_doinit(struct super_block *sb, void *data) { int rc = 0; char *options = data; struct security_mnt_opts opts; security_init_mnt_opts(&opts); if (!data) goto out; BUG_ON(sb->s_type->fs_flags & FS_BINARY_MOUNTDATA); rc = selinux_parse_opts_str(options, &opts); if (rc) goto out_err; out: rc = selinux_set_mnt_opts(sb, &opts, 0, NULL); out_err: security_free_mnt_opts(&opts); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris9595.96%150.00%
David Quigley44.04%150.00%
Total99100.00%2100.00%


static void selinux_write_opts(struct seq_file *m, struct security_mnt_opts *opts) { int i; char *prefix; for (i = 0; i < opts->num_mnt_opts; i++) { char *has_comma; if (opts->mnt_opts[i]) has_comma = strchr(opts->mnt_opts[i], ','); else has_comma = NULL; switch (opts->mnt_opts_flags[i]) { case CONTEXT_MNT: prefix = CONTEXT_STR; break; case FSCONTEXT_MNT: prefix = FSCONTEXT_STR; break; case ROOTCONTEXT_MNT: prefix = ROOTCONTEXT_STR; break; case DEFCONTEXT_MNT: prefix = DEFCONTEXT_STR; break; case SBLABEL_MNT: seq_putc(m, ','); seq_puts(m, LABELSUPP_STR); continue; default: BUG(); return; }; /* we need a comma before each option */ seq_putc(m, ','); seq_puts(m, prefix); if (has_comma) seq_putc(m, '\"'); seq_escape(m, opts->mnt_opts[i], "\"\n\\"); if (has_comma) seq_putc(m, '\"'); } }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris15179.47%350.00%
David P. Quigley3518.42%116.67%
Kees Cook31.58%116.67%
Adrian Bunk10.53%116.67%
Total190100.00%6100.00%


static int selinux_sb_show_options(struct seq_file *m, struct super_block *sb) { struct security_mnt_opts opts; int rc; rc = selinux_get_mnt_opts(sb, &opts); if (rc) { /* before policy load we may get EINVAL, don't show anything */ if (rc == -EINVAL) rc = 0; return rc; } selinux_write_opts(m, &opts); security_free_mnt_opts(&opts); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris71100.00%2100.00%
Total71100.00%2100.00%


static inline u16 inode_mode_to_security_class(umode_t mode) { switch (mode & S_IFMT) { case S_IFSOCK: return SECCLASS_SOCK_FILE; case S_IFLNK: return SECCLASS_LNK_FILE; case S_IFREG: return SECCLASS_FILE; case S_IFBLK: return SECCLASS_BLK_FILE; case S_IFDIR: return SECCLASS_DIR; case S_IFCHR: return SECCLASS_CHR_FILE; case S_IFIFO: return SECCLASS_FIFO_FILE; } return SECCLASS_FILE; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton63100.00%2100.00%
Total63100.00%2100.00%


static inline int default_protocol_stream(int protocol) { return (protocol == IPPROTO_IP || protocol == IPPROTO_TCP); }

Contributors

PersonTokensPropCommitsCommitProp
James Morris21100.00%1100.00%
Total21100.00%1100.00%


static inline int default_protocol_dgram(int protocol) { return (protocol == IPPROTO_IP || protocol == IPPROTO_UDP); }

Contributors

PersonTokensPropCommitsCommitProp
James Morris21100.00%1100.00%
Total21100.00%1100.00%


static inline u16 socket_type_to_security_class(int family, int type, int protocol) { int extsockclass = selinux_policycap_extsockclass(); switch (family) { case PF_UNIX: switch (type) { case SOCK_STREAM: case SOCK_SEQPACKET: return SECCLASS_UNIX_STREAM_SOCKET; case SOCK_DGRAM: case SOCK_RAW: return SECCLASS_UNIX_DGRAM_SOCKET; } break; case PF_INET: case PF_INET6: switch (type) { case SOCK_STREAM: case SOCK_SEQPACKET: if (default_protocol_stream(protocol)) return SECCLASS_TCP_SOCKET; else if (extsockclass && protocol == IPPROTO_SCTP) return SECCLASS_SCTP_SOCKET; else return SECCLASS_RAWIP_SOCKET; case SOCK_DGRAM: if (default_protocol_dgram(protocol)) return SECCLASS_UDP_SOCKET; else if (extsockclass && (protocol == IPPROTO_ICMP || protocol == IPPROTO_ICMPV6)) return SECCLASS_ICMP_SOCKET; else return SECCLASS_RAWIP_SOCKET; case SOCK_DCCP: return SECCLASS_DCCP_SOCKET; default: return SECCLASS_RAWIP_SOCKET; } break; case PF_NETLINK: switch (protocol) { case NETLINK_ROUTE: return SECCLASS_NETLINK_ROUTE_SOCKET; case NETLINK_SOCK_DIAG: return SECCLASS_NETLINK_TCPDIAG_SOCKET; case NETLINK_NFLOG: return SECCLASS_NETLINK_NFLOG_SOCKET; case NETLINK_XFRM: return SECCLASS_NETLINK_XFRM_SOCKET; case NETLINK_SELINUX: return SECCLASS_NETLINK_SELINUX_SOCKET; case NETLINK_ISCSI: return SECCLASS_NETLINK_ISCSI_SOCKET; case NETLINK_AUDIT: return SECCLASS_NETLINK_AUDIT_SOCKET; case NETLINK_FIB_LOOKUP: return SECCLASS_NETLINK_FIB_LOOKUP_SOCKET; case NETLINK_CONNECTOR: return SECCLASS_NETLINK_CONNECTOR_SOCKET; case NETLINK_NETFILTER: return SECCLASS_NETLINK_NETFILTER_SOCKET; case NETLINK_DNRTMSG: return SECCLASS_NETLINK_DNRT_SOCKET; case NETLINK_KOBJECT_UEVENT: return SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET; case NETLINK_GENERIC: return SECCLASS_NETLINK_GENERIC_SOCKET; case NETLINK_SCSITRANSPORT: return SECCLASS_NETLINK_SCSITRANSPORT_SOCKET; case NETLINK_RDMA: return SECCLASS_NETLINK_RDMA_SOCKET; case NETLINK_CRYPTO: return SECCLASS_NETLINK_CRYPTO_SOCKET; default: return SECCLASS_NETLINK_SOCKET; } case PF_PACKET: return SECCLASS_PACKET_SOCKET; case PF_KEY: return SECCLASS_KEY_SOCKET; case PF_APPLETALK: return SECCLASS_APPLETALK_SOCKET; } if (extsockclass) { switch (family) { case PF_AX25: return SECCLASS_AX25_SOCKET; case PF_IPX: return SECCLASS_IPX_SOCKET; case PF_NETROM: return SECCLASS_NETROM_SOCKET; case PF_ATMPVC: return SECCLASS_ATMPVC_SOCKET; case PF_X25: return SECCLASS_X25_SOCKET; case PF_ROSE: return SECCLASS_ROSE_SOCKET; case PF_DECnet: return SECCLASS_DECNET_SOCKET; case PF_ATMSVC: return SECCLASS_ATMSVC_SOCKET; case PF_RDS: return SECCLASS_RDS_SOCKET; case PF_IRDA: return SECCLASS_IRDA_SOCKET; case PF_PPPOX: return SECCLASS_PPPOX_SOCKET; case PF_LLC: return SECCLASS_LLC_SOCKET; case PF_CAN: return SECCLASS_CAN_SOCKET; case PF_TIPC: return SECCLASS_TIPC_SOCKET; case PF_BLUETOOTH: return SECCLASS_BLUETOOTH_SOCKET; case PF_IUCV: return SECCLASS_IUCV_SOCKET; case PF_RXRPC: return SECCLASS_RXRPC_SOCKET; case PF_ISDN: return SECCLASS_ISDN_SOCKET; case PF_PHONET: return SECCLASS_PHONET_SOCKET; case PF_IEEE802154: return SECCLASS_IEEE802154_SOCKET; case PF_CAIF: return SECCLASS_CAIF_SOCKET; case PF_ALG: return SECCLASS_ALG_SOCKET; case PF_NFC: return SECCLASS_NFC_SOCKET; case PF_VSOCK: return SECCLASS_VSOCK_SOCKET; case PF_KCM: return SECCLASS_KCM_SOCKET; case PF_QIPCRTR: return SECCLASS_QIPCRTR_SOCKET; case PF_SMC: return SECCLASS_SMC_SOCKET; #if PF_MAX > 44 #error New address family defined, please update this function. #endif } } return SECCLASS_SOCKET; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley26557.61%535.71%
James Morris9019.57%428.57%
Andrew Morton8819.13%17.14%
Linus Torvalds71.52%17.14%
Christopher J. PeBenito61.30%17.14%
Luis Ressel30.65%17.14%
Pavel Emelyanov10.22%17.14%
Total460100.00%14100.00%


static int selinux_genfs_get_sid(struct dentry *dentry, u16 tclass, u16 flags, u32 *sid) { int rc; struct super_block *sb = dentry->d_sb; char *buffer, *path; buffer = (char *)__get_free_page(GFP_KERNEL); if (!buffer) return -ENOMEM; path = dentry_path_raw(dentry, buffer, PAGE_SIZE); if (IS_ERR(path)) rc = PTR_ERR(path); else { if (flags & SE_SBPROC) { /* each process gets a /proc/PID/ entry. Strip off the * PID part to get a valid selinux labeling. * e.g. /proc/1/net/rpc/nfs -> /net/rpc/nfs */ while (path[1] >= '0' && path[1] <= '9') { path[1] = '/'; path++; } } rc = security_genfs_sid(&selinux_state, sb->s_type->name, path, tclass, sid); } free_page((unsigned long)buffer); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton8856.05%120.00%
Lucian Adrian Grijincu3924.84%120.00%
Stephen D. Smalley2918.47%240.00%
Al Viro10.64%120.00%
Total157100.00%5100.00%

/* The inode's security attributes must be initialized before first use. */
static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry) { struct superblock_security_struct *sbsec = NULL; struct inode_security_struct *isec = inode->i_security; u32 task_sid, sid = 0; u16 sclass; struct dentry *dentry; #define INITCONTEXTLEN 255 char *context = NULL; unsigned len = 0; int rc = 0; if (isec->initialized == LABEL_INITIALIZED) return 0; spin_lock(&isec->lock); if (isec->initialized == LABEL_INITIALIZED) goto out_unlock; if (isec->sclass == SECCLASS_FILE) isec->sclass = inode_mode_to_security_class(inode->i_mode); sbsec = inode->i_sb->s_security; if (!(sbsec->flags & SE_SBINITIALIZED)) { /* Defer initialization until selinux_complete_init, after the initial policy is loaded and the security server is ready to handle calls. */ spin_lock(&sbsec->isec_lock); if (list_empty(&isec->list)) list_add(&isec->list, &sbsec->isec_head); spin_unlock(&sbsec->isec_lock); goto out_unlock; } sclass = isec->sclass; task_sid = isec->task_sid; sid = isec->sid; isec->initialized = LABEL_PENDING; spin_unlock(&isec->lock); switch (sbsec->behavior) { case SECURITY_FS_USE_NATIVE: break; case SECURITY_FS_USE_XATTR: if (!(inode->i_opflags & IOP_XATTR)) { sid = sbsec->def_sid; break; } /* Need a dentry, since the xattr API requires one. Life would be simpler if we could just pass the inode. */ if (opt_dentry) { /* Called from d_instantiate or d_splice_alias. */ dentry = dget(opt_dentry); } else { /* * Called from selinux_complete_init, try to find a dentry. * Some filesystems really want a connected one, so try * that first. We could split SECURITY_FS_USE_XATTR in * two, depending upon that... */ dentry = d_find_alias(inode); if (!dentry) dentry = d_find_any_alias(inode); } if (!dentry) { /* * this is can be hit on boot when a file is accessed * before the policy is loaded. When we load policy we * may find inodes that have no dentry on the * sbsec->isec_head list. No reason to complain as these * will get fixed up the next time we go through * inode_doinit with a dentry, before these inodes could * be used again by userspace. */ goto out; } len = INITCONTEXTLEN; context = kmalloc(len+1, GFP_NOFS); if (!context) { rc = -ENOMEM; dput(dentry); goto out; } context[len] = '\0'; rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, context, len); if (rc == -ERANGE) { kfree(context); /* Need a larger buffer. Query for the right size. */ rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, NULL, 0); if (rc < 0) { dput(dentry); goto out; } len = rc; context = kmalloc(len+1, GFP_NOFS); if (!context) { rc = -ENOMEM; dput(dentry); goto out; } context[len] = '\0'; rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, context, len); } dput(dentry); if (rc < 0) { if (rc != -ENODATA) { printk(KERN_WARNING "SELinux: %s: getxattr returned " "%d for dev=%s ino=%ld\n", __func__, -rc, inode->i_sb->s_id, inode->i_ino); kfree(context); goto out; } /* Map ENODATA to the default file SID */ sid = sbsec->def_sid; rc = 0; } else { rc = security_context_to_sid_default(&selinux_state, context, rc, &sid, sbsec->def_sid, GFP_NOFS); if (rc) { char *dev = inode->i_sb->s_id; unsigned long ino = inode->i_ino; if (rc == -EINVAL) { if (printk_ratelimit()) printk(KERN_NOTICE "SELinux: inode=%lu on dev=%s was found to have an invalid " "context=%s. This indicates you may need to relabel the inode or the " "filesystem in question.\n", ino, dev, context); } else { printk(KERN_WARNING "SELinux: %s: context_to_sid(%s) " "returned %d for dev=%s ino=%ld\n", __func__, context, -rc, dev, ino); } kfree(context); /* Leave with the unlabeled SID */ rc = 0; break; } } kfree(context); break; case SECURITY_FS_USE_TASK: sid = task_sid; break; case SECURITY_FS_USE_TRANS: /* Default to the fs SID. */ sid = sbsec->sid; /* Try to obtain a transition SID. */ rc = security_transition_sid(&selinux_state, task_sid, sid, sclass, NULL, &sid); if (rc) goto out; break; case SECURITY_FS_USE_MNTPOINT: sid = sbsec->mntpoint_sid; break; default: /* Default to the fs superblock SID. */ sid = sbsec->sid; if ((sbsec->flags & SE_SBGENFS) && !S_ISLNK(inode->i_mode)) { /* We must have a dentry to determine the label on * procfs inodes */ if (opt_dentry) { /* Called from d_instantiate or * d_splice_alias. */ dentry = dget(opt_dentry); } else { /* Called from selinux_complete_init, try to * find a dentry. Some filesystems really want * a connected one, so try that first. */ dentry = d_find_alias(inode); if (!dentry) dentry = d_find_any_alias(inode); } /* * This can be hit on boot when a file is accessed * before the policy is loaded. When we load policy we * may find inodes that have no dentry on the * sbsec->isec_head list. No reason to complain as * these will get fixed up the next time we go through * inode_doinit() with a dentry, before these inodes * could be used again by userspace. */ if (!dentry) goto out; rc = selinux_genfs_get_sid(dentry, sclass, sbsec->flags, &sid); dput(dentry); if (rc) goto out; } break; } out: spin_lock(&isec->lock); if (isec->initialized == LABEL_PENDING) { if (!sid || rc) { isec->initialized = LABEL_INVALID; goto out_unlock; } isec->initialized = LABEL_INITIALIZED; isec->sid = sid; } out_unlock: spin_unlock(&isec->lock); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton52260.98%310.34%
Andreas Gruenbacher10812.62%413.79%
Eric Paris10111.80%724.14%
Al Viro364.21%26.90%
Stephen D. Smalley323.74%620.69%
Paul Moore313.62%13.45%
James Morris101.17%26.90%
David P. Quigley91.05%13.45%
David Quigley40.47%13.45%
Harvey Harrison20.23%13.45%
Lucian Adrian Grijincu10.12%13.45%
Total856100.00%29100.00%

/* Convert a Linux signal to an access vector. */
static inline u32 signal_to_av(int sig) { u32 perm = 0; switch (sig) { case SIGCHLD: /* Commonly granted from child to parent. */ perm = PROCESS__SIGCHLD; break; case SIGKILL: /* Cannot be caught or ignored */ perm = PROCESS__SIGKILL; break; case SIGSTOP: /* Cannot be caught or ignored */ perm = PROCESS__SIGSTOP; break; default: /* All other signals. */ perm = PROCESS__SIGNAL; break; } return perm; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton58100.00%1100.00%
Total58100.00%1100.00%

#if CAP_LAST_CAP > 63 #error Fix SELinux to handle capabilities > 63. #endif /* Check whether a task is allowed to use a capability. */
static int cred_has_capability(const struct cred *cred, int cap, int audit, bool initns) { struct common_audit_data ad; struct av_decision avd; u16 sclass; u32 sid = cred_sid(cred); u32 av = CAP_TO_MASK(cap); int rc; ad.type = LSM_AUDIT_DATA_CAP; ad.u.cap = cap; switch (CAP_TO_INDEX(cap)) { case 0: sclass = initns ? SECCLASS_CAPABILITY : SECCLASS_CAP_USERNS; break; case 1: sclass = initns ? SECCLASS_CAPABILITY2 : SECCLASS_CAP2_USERNS; break; default: printk(KERN_ERR "SELinux: out of range capability %d\n", cap); BUG(); return -EINVAL; } rc = avc_has_perm_noaudit(&selinux_state, sid, sid, sclass, av, 0, &avd); if (audit == SECURITY_CAP_AUDIT) { int rc2 = avc_audit(&selinux_state, sid, sid, sclass, av, &avd, rc, &ad, 0); if (rc2) return rc2; } return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley6837.78%426.67%
Eric Paris6234.44%640.00%
Andrew Morton3318.33%16.67%
David Howells147.78%213.33%
Neil Brown21.11%16.67%
Thomas Liu10.56%16.67%
Total180100.00%15100.00%

/* Check whether a task has a particular permission to an inode. The 'adp' parameter is optional and allows other audit data to be passed (e.g. the dentry). */
static int inode_has_perm(const struct cred *cred, struct inode *inode, u32 perms, struct common_audit_data *adp) { struct inode_security_struct *isec; u32 sid; validate_creds(cred); if (unlikely(IS_PRIVATE(inode))) return 0; sid = cred_sid(cred); isec = inode->i_security; return avc_has_perm(&selinux_state, sid, isec->sid, isec->sclass, perms, adp); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3338.82%110.00%
Linus Torvalds1821.18%220.00%
Stephen D. Smalley1720.00%330.00%
David Howells1618.82%330.00%
Thomas Liu11.18%110.00%
Total85100.00%10100.00%

/* Same as inode_has_perm, but pass explicit audit data containing the dentry to help the auditing code to more easily generate the pathname if needed. */
static inline int dentry_has_perm(const struct cred *cred, struct dentry *dentry, u32 av) { struct inode *inode = d_backing_inode(dentry); struct common_audit_data ad; ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry; __inode_security_revalidate(inode, dentry, true); return inode_has_perm(cred, inode, av, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3447.89%112.50%
Eric Paris2129.58%337.50%
Andreas Gruenbacher912.68%112.50%
David Howells68.45%225.00%
Thomas Liu11.41%112.50%
Total71100.00%8100.00%

/* Same as inode_has_perm, but pass explicit audit data containing the path to help the auditing code to more easily generate the pathname if needed. */
static inline int path_has_perm(const struct cred *cred, const struct path *path, u32 av) { struct inode *inode = d_backing_inode(path->dentry); struct common_audit_data ad; ad.type = LSM_AUDIT_DATA_PATH; ad.u.path = *path; __inode_security_revalidate(inode, path->dentry, true); return inode_has_perm(cred, inode, av, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris4051.95%333.33%
Andrew Morton2025.97%111.11%
Andreas Gruenbacher1114.29%111.11%
David Howells45.19%222.22%
Jan Blunck11.30%111.11%
Al Viro11.30%111.11%
Total77100.00%9100.00%

/* Same as path_has_perm, but uses the inode from the file struct. */
static inline int file_path_has_perm(const struct cred *cred, struct file *file, u32 av) { struct common_audit_data ad; ad.type = LSM_AUDIT_DATA_FILE; ad.u.file = file; return inode_has_perm(cred, file_inode(file), av, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
David Howells5396.36%150.00%
Vivek Goyal23.64%150.00%
Total55100.00%2100.00%

#ifdef CONFIG_BPF_SYSCALL static int bpf_fd_pass(struct file *file, u32 sid); #endif /* Check whether a task can use an open file descriptor to access an inode in a given way. Check access to the descriptor itself, and then use dentry_has_perm to check a particular permission to the file. Access to the descriptor is implicitly granted if it has the same SID as the process. If av is zero, then access to the file is not checked, e.g. for cases where only the descriptor is affected like seek. */
static int file_has_perm(const struct cred *cred, struct file *file, u32 av) { struct file_security_struct *fsec = file->f_security; struct inode *inode = file_inode(file); struct common_audit_data ad; u32 sid = cred_sid(cred); int rc; ad.type = LSM_AUDIT_DATA_FILE; ad.u.file = file; if (sid != fsec->sid) { rc = avc_has_perm(&selinux_state, sid, fsec->sid, SECCLASS_FD, FD__USE, &ad); if (rc) goto out; } #ifdef CONFIG_BPF_SYSCALL rc = bpf_fd_pass(file, cred_sid(cred)); if (rc) return rc; #endif /* av is zero if only checking access to the descriptor. */ rc = 0; if (av) rc = inode_has_perm(cred, inode, av, &ad); out: return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton9459.49%110.00%
David Howells2515.82%220.00%
Chenbo Feng2415.19%110.00%
Jan Blunck31.90%110.00%
Eric Paris31.90%110.00%
Stephen D. Smalley31.90%110.00%
Al Viro31.90%110.00%
Vivek Goyal21.27%110.00%
Thomas Liu10.63%110.00%
Total158100.00%10100.00%

/* * Determine the label for an inode that might be unioned. */
static int selinux_determine_inode_label(const struct task_security_struct *tsec, struct inode *dir, const struct qstr *name, u16 tclass, u32 *_new_isid) { const struct superblock_security_struct *sbsec = dir->i_sb->s_security; if ((sbsec->flags & SE_SBINITIALIZED) && (sbsec->behavior == SECURITY_FS_USE_MNTPOINT)) { *_new_isid = sbsec->mntpoint_sid; } else if ((sbsec->flags & SBLABEL_MNT) && tsec->create_sid) { *_new_isid = tsec->create_sid; } else { const struct inode_security_struct *dsec = inode_security(dir); return security_transition_sid(&selinux_state, tsec->sid, dsec->sid, tclass, name, _new_isid); } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
David Howells11184.73%125.00%
Paul Moore118.40%125.00%
Vivek Goyal64.58%125.00%
Stephen D. Smalley32.29%125.00%
Total131100.00%4100.00%

/* Check whether a task can create a file. */
static int may_create(struct inode *dir, struct dentry *dentry, u16 tclass) { const struct task_security_struct *tsec = current_security(); struct inode_security_struct *dsec; struct superblock_security_struct *sbsec; u32 sid, newsid; struct common_audit_data ad; int rc; dsec = inode_security(dir); sbsec = dir->i_sb->s_security; sid = tsec->sid; ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry; rc = avc_has_perm(&selinux_state, sid, dsec->sid, SECCLASS_DIR, DIR__ADD_NAME | DIR__SEARCH, &ad); if (rc) return rc; rc = selinux_determine_inode_label(current_security(), dir, &dentry->d_name, tclass, &newsid); if (rc) return rc; rc = avc_has_perm(&selinux_state, sid, newsid, tclass, FILE__CREATE, &ad); if (rc) return rc; return avc_has_perm(&selinux_state, newsid, sbsec->sid, SECCLASS_FILESYSTEM, FILESYSTEM__ASSOCIATE, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton14677.66%215.38%
David Howells157.98%215.38%
Eric Paris94.79%430.77%
Stephen D. Smalley94.79%17.69%
Andreas Gruenbacher31.60%17.69%
Vivek Goyal31.60%17.69%
Paul Moore21.06%17.69%
Thomas Liu10.53%17.69%
Total188100.00%13100.00%

#define MAY_LINK 0 #define MAY_UNLINK 1 #define MAY_RMDIR 2 /* Check whether a task can link, unlink, or rmdir a file/directory. */
static int may_link(struct inode *dir, struct dentry *dentry, int kind) { struct inode_security_struct *dsec, *isec; struct common_audit_data ad; u32 sid = current_sid(); u32 av; int rc; dsec = inode_security(dir); isec = backing_inode_security(dentry); ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry; av = DIR__SEARCH; av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME); rc = avc_has_perm(&selinux_state, sid, dsec->sid, SECCLASS_DIR, av, &ad); if (rc) return rc; switch (kind) { case MAY_LINK: av = FILE__LINK; break; case MAY_UNLINK: av = FILE__UNLINK; break; case MAY_RMDIR: av = DIR__RMDIR; break; default: printk(KERN_WARNING "SELinux: %s: unrecognized kind %d\n", __func__, kind); return 0; } rc = avc_has_perm(&selinux_state, sid, isec->sid, isec->sclass, av, &ad); return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton15785.79%111.11%
David Howells84.37%222.22%
Eric Paris73.83%333.33%
Stephen D. Smalley63.28%111.11%
Andreas Gruenbacher42.19%111.11%
Thomas Liu10.55%111.11%
Total183100.00%9100.00%


static inline int may_rename(struct inode *old_dir, struct dentry *old_dentry, struct inode *new_dir, struct dentry *new_dentry) { struct inode_security_struct *old_dsec, *new_dsec, *old_isec, *new_isec; struct common_audit_data ad; u32 sid = current_sid(); u32 av; int old_is_dir, new_is_dir; int rc; old_dsec = inode_security(old_dir); old_isec = backing_inode_security(old_dentry); old_is_dir = d_is_dir(old_dentry); new_dsec = inode_security(new_dir); ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = old_dentry; rc = avc_has_perm(&selinux_state, sid, old_dsec->sid, SECCLASS_DIR, DIR__REMOVE_NAME | DIR__SEARCH, &ad); if (rc) return rc; rc = avc_has_perm(&selinux_state, sid, old_isec->sid, old_isec->sclass, FILE__RENAME, &ad); if (rc) return rc; if (old_is_dir && new_dir != old_dir) { rc = avc_has_perm(&selinux_state, sid, old_isec->sid, old_isec->sclass, DIR__REPARENT, &ad); if (rc) return rc; } ad.u.dentry = new_dentry; av = DIR__ADD_NAME | DIR__SEARCH; if (d_is_positive(new_dentry)) av |= DIR__REMOVE_NAME; rc = avc_has_perm(&selinux_state, sid, new_dsec->sid, SECCLASS_DIR, av, &ad); if (rc) return rc; if (d_is_positive(new_dentry)) { new_isec = backing_inode_security(new_dentry); new_is_dir = d_is_dir(new_dentry); rc = avc_has_perm(&selinux_state, sid, new_isec->sid, new_isec->sclass, (new_is_dir ? DIR__RMDIR : FILE__UNLINK), &ad); if (rc) return rc; } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton27184.95%19.09%
David Howells185.64%436.36%
Stephen D. Smalley154.70%19.09%
Andreas Gruenbacher82.51%19.09%
Eric Paris61.88%327.27%
Thomas Liu10.31%19.09%
Total319100.00%11100.00%

/* Check whether a task can perform a filesystem operation. */
static int superblock_has_perm(const struct cred *cred, struct super_block *sb, u32 perms, struct common_audit_data *ad) { struct superblock_security_struct *sbsec; u32 sid = cred_sid(cred); sbsec = sb->s_security; return avc_has_perm(&selinux_state, sid, sbsec->sid, SECCLASS_FILESYSTEM, perms, ad); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton4774.60%116.67%
David Howells1117.46%233.33%
Stephen D. Smalley46.35%233.33%
Thomas Liu11.59%116.67%
Total63100.00%6100.00%

/* Convert a Linux mode and permission mask to an access vector. */
static inline u32 file_mask_to_av(int mode, int mask) { u32 av = 0; if (!S_ISDIR(mode)) { if (mask & MAY_EXEC) av |= FILE__EXECUTE; if (mask & MAY_READ) av |= FILE__READ; if (mask & MAY_APPEND) av |= FILE__APPEND; else if (mask & MAY_WRITE) av |= FILE__WRITE; } else { if (mask & MAY_EXEC) av |= DIR__SEARCH; if (mask & MAY_WRITE) av |= DIR__WRITE; if (mask & MAY_READ) av |= DIR__READ; } return av; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton10196.19%150.00%
Al Viro43.81%150.00%
Total105100.00%2100.00%

/* Convert a Linux file to an access vector. */
static inline u32 file_to_av(struct file *file) { u32 av = 0; if (file->f_mode & FMODE_READ) av |= FILE__READ; if (file->f_mode & FMODE_WRITE) { if (file->f_flags & O_APPEND) av |= FILE__APPEND; else av |= FILE__WRITE; } if (!av) { /* * Special file opened with flags 3 for ioctl-only use. */ av = FILE__IOCTL; } return av; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris71100.00%2100.00%
Total71100.00%2100.00%

/* * Convert a file to an access vector and include the correct open * open permission. */
static inline u32 open_file_to_av(struct file *file) { u32 av = file_to_av(file); struct inode *inode = file_inode(file); if (selinux_policycap_openperm() && inode->i_sb->s_magic != SOCKFS_MAGIC) av |= FILE__OPEN; return av; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris3162.00%250.00%
Stephen D. Smalley1938.00%250.00%
Total50100.00%4100.00%

/* Hook functions begin here. */
static int selinux_binder_set_context_mgr(struct task_struct *mgr) { u32 mysid = current_sid(); u32 mgrsid = task_sid(mgr); return avc_has_perm(&selinux_state, mysid, mgrsid, SECCLASS_BINDER, BINDER__SET_CONTEXT_MGR, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley42100.00%2100.00%
Total42100.00%2100.00%


static int selinux_binder_transaction(struct task_struct *from, struct task_struct *to) { u32 mysid = current_sid(); u32 fromsid = task_sid(from); u32 tosid = task_sid(to); int rc; if (mysid != fromsid) { rc = avc_has_perm(&selinux_state, mysid, fromsid, SECCLASS_BINDER, BINDER__IMPERSONATE, NULL); if (rc) return rc; } return avc_has_perm(&selinux_state, fromsid, tosid, SECCLASS_BINDER, BINDER__CALL, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley91100.00%2100.00%
Total91100.00%2100.00%


static int selinux_binder_transfer_binder(struct task_struct *from, struct task_struct *to) { u32 fromsid = task_sid(from); u32 tosid = task_sid(to); return avc_has_perm(&selinux_state, fromsid, tosid, SECCLASS_BINDER, BINDER__TRANSFER, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley49100.00%2100.00%
Total49100.00%2100.00%


static int selinux_binder_transfer_file(struct task_struct *from, struct task_struct *to, struct file *file) { u32 sid = task_sid(to); struct file_security_struct *fsec = file->f_security; struct dentry *dentry = file->f_path.dentry; struct inode_security_struct *isec; struct common_audit_data ad; int rc; ad.type = LSM_AUDIT_DATA_PATH; ad.u.path = file->f_path; if (sid != fsec->sid) { rc = avc_has_perm(&selinux_state, sid, fsec->sid, SECCLASS_FD, FD__USE, &ad); if (rc) return rc; } #ifdef CONFIG_BPF_SYSCALL rc = bpf_fd_pass(file, sid); if (rc) return rc; #endif if (unlikely(IS_PRIVATE(d_backing_inode(dentry)))) return 0; isec = backing_inode_security(dentry); return avc_has_perm(&selinux_state, sid, isec->sid, isec->sclass, file_to_av(file), &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley15081.52%240.00%
Chenbo Feng2111.41%120.00%
Paul Moore73.80%120.00%
Andreas Gruenbacher63.26%120.00%
Total184100.00%5100.00%


static int selinux_ptrace_access_check(struct task_struct *child, unsigned int mode) { u32 sid = current_sid(); u32 csid = task_sid(child); if (mode & PTRACE_MODE_READ) return avc_has_perm(&selinux_state, sid, csid, SECCLASS_FILE, FILE__READ, NULL); return avc_has_perm(&selinux_state, sid, csid, SECCLASS_PROCESS, PROCESS__PTRACE, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley4260.87%342.86%
Andrew Morton1521.74%114.29%
David Howells1014.49%114.29%
Ingo Molnar11.45%114.29%
Roland McGrath11.45%114.29%
Total69100.00%7100.00%


static int selinux_ptrace_traceme(struct task_struct *parent) { return avc_has_perm(&selinux_state, task_sid(parent), current_sid(), SECCLASS_PROCESS, PROCESS__PTRACE, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
David Howells1959.38%133.33%
Stephen D. Smalley1340.62%266.67%
Total32100.00%3100.00%


static int selinux_capget(struct task_struct *target, kernel_cap_t *effective, kernel_cap_t *inheritable, kernel_cap_t *permitted) { return avc_has_perm(&selinux_state, current_sid(), task_sid(target), SECCLASS_PROCESS, PROCESS__GETCAP, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2965.91%125.00%
Stephen D. Smalley1431.82%250.00%
Casey Schaufler12.27%125.00%
Total44100.00%4100.00%


static int selinux_capset(struct cred *new, const struct cred *old, const kernel_cap_t *effective, const kernel_cap_t *inheritable, const kernel_cap_t *permitted) { return avc_has_perm(&selinux_state, cred_sid(old), cred_sid(new), SECCLASS_PROCESS, PROCESS__SETCAP, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2443.64%233.33%
David Howells1730.91%233.33%
Stephen D. Smalley1425.45%233.33%
Total55100.00%6100.00%

/* * (This comment used to live with the selinux_task_setuid hook, * which was removed). * * Since setuid only affects the current process, and since the SELinux * controls are not based on the Linux identity attributes, SELinux does not * need to control this operation. However, SELinux does control the use of * the CAP_SETUID and CAP_SETGID capabilities using the capable hook. */
static int selinux_capable(const struct cred *cred, struct user_namespace *ns, int cap, int audit) { return cred_has_capability(cred, cap, audit, ns == &init_user_ns); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton1436.84%116.67%
David Howells821.05%116.67%
Eric Paris615.79%233.33%
Serge E. Hallyn513.16%116.67%
Stephen D. Smalley513.16%116.67%
Total38100.00%6100.00%


static int selinux_quotactl(int cmds, int type, int id, struct super_block *sb) { const struct cred *cred = current_cred(); int rc = 0; if (!sb) return 0; switch (cmds) { case Q_SYNC: case Q_QUOTAON: case Q_QUOTAOFF: case Q_SETINFO: case Q_SETQUOTA: rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAMOD, NULL); break; case Q_GETFMT: case Q_GETINFO: case Q_GETQUOTA: rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAGET, NULL); break; default: rc = 0; /* let the kernel handle invalid cmds */ break; } return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton8072.73%133.33%
Eric W. Biedermann2119.09%133.33%
David Howells98.18%133.33%
Total110100.00%3100.00%


static int selinux_quota_on(struct dentry *dentry) { const struct cred *cred = current_cred(); return dentry_has_perm(cred, dentry, FILE__QUOTAON); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton1136.67%125.00%
Eric W. Biedermann930.00%125.00%
David Howells620.00%125.00%
Jan Kara413.33%125.00%
Total30100.00%4100.00%


static int selinux_syslog(int type) { switch (type) { case SYSLOG_ACTION_READ_ALL: /* Read last kernel messages */ case SYSLOG_ACTION_SIZE_BUFFER: /* Return size of the log buffer */ return avc_has_perm(&selinux_state, current_sid(), SECINITSID_KERNEL, SECCLASS_SYSTEM, SYSTEM__SYSLOG_READ, NULL); case SYSLOG_ACTION_CONSOLE_OFF: /* Disable logging to console */ case SYSLOG_ACTION_CONSOLE_ON: /* Enable logging to console */ /* Set level of messages printed to console */ case SYSLOG_ACTION_CONSOLE_LEVEL: return avc_has_perm(&selinux_state, current_sid(), SECINITSID_KERNEL, SECCLASS_SYSTEM, SYSTEM__SYSLOG_CONSOLE, NULL); } /* All other syslog types */ return avc_has_perm(&selinux_state, current_sid(), SECINITSID_KERNEL, SECCLASS_SYSTEM, SYSTEM__SYSLOG_MOD, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley4347.78%228.57%
Andrew Morton2932.22%228.57%
Eric W. Biedermann1213.33%228.57%
Kees Cook66.67%114.29%
Total90100.00%7100.00%

/* * Check that a process has enough memory to allocate a new virtual * mapping. 0 means there is enough memory for the allocation to * succeed and -ENOMEM implies there is not. * * Do not audit the selinux permission check, as this is applied to all * processes that allocate mappings. */
static int selinux_vm_enough_memory(struct mm_struct *mm, long pages) { int rc, cap_sys_admin = 0; rc = cred_has_capability(current_cred(), CAP_SYS_ADMIN, SECURITY_CAP_NOAUDIT, true); if (rc == 0) cap_sys_admin = 1; return cap_sys_admin; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3266.67%114.29%
Serge E. Hallyn612.50%114.29%
Alan Cox36.25%114.29%
Eric Paris24.17%114.29%
David Howells24.17%114.29%
Stephen D. Smalley24.17%114.29%
Casey Schaufler12.08%114.29%
Total48100.00%7100.00%

/* binprm security operations */
static u32 ptrace_parent_sid(void) { u32 sid = 0; struct task_struct *tracer; rcu_read_lock(); tracer = ptrace_parent(current); if (tracer) sid = task_sid(tracer); rcu_read_unlock(); return sid; }

Contributors

PersonTokensPropCommitsCommitProp
Paul Moore4395.56%150.00%
Stephen D. Smalley24.44%150.00%
Total45100.00%2100.00%


static int check_nnp_nosuid(const struct linux_binprm *bprm, const struct task_security_struct *old_tsec, const struct task_security_struct *new_tsec) { int nnp = (bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS); int nosuid = !mnt_may_suid(bprm->file->f_path.mnt); int rc; u32 av; if (!nnp && !nosuid) return 0; /* neither NNP nor nosuid */ if (new_tsec->sid == old_tsec->sid) return 0; /* No change in credentials */ /* * If the policy enables the nnp_nosuid_transition policy capability, * then we permit transitions under NNP or nosuid if the * policy allows the corresponding permission between * the old and new contexts. */ if (selinux_policycap_nnp_nosuid_transition()) { av = 0; if (nnp) av |= PROCESS2__NNP_TRANSITION; if (nosuid) av |= PROCESS2__NOSUID_TRANSITION; rc = avc_has_perm(&selinux_state, old_tsec->sid, new_tsec->sid, SECCLASS_PROCESS2, av, NULL); if (!rc) return 0; } /* * We also permit NNP or nosuid transitions to bounded SIDs, * i.e. SIDs that are guaranteed to only be allowed a subset * of the permissions of the current SID. */ rc = security_bounded_transition(&selinux_state, old_tsec->sid, new_tsec->sid); if (!rc) return 0; /* * On failure, preserve the errno values for NNP vs nosuid. * NNP: Operation not permitted for caller. * nosuid: Permission denied to file. */ if (nnp) return -EPERM; return -EACCES; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley17497.75%480.00%
Andrew Lutomirski42.25%120.00%
Total178100.00%5100.00%


static int selinux_bprm_set_creds(struct linux_binprm *bprm) { const struct task_security_struct *old_tsec; struct task_security_struct *new_tsec; struct inode_security_struct *isec; struct common_audit_data ad; struct inode *inode = file_inode(bprm->file); int rc; /* SELinux context only depends on initial program or script and not * the script interpreter */ if (bprm->called_set_creds) return 0; old_tsec = current_security(); new_tsec = bprm->cred->security; isec = inode_security(inode); /* Default to the current task SID. */ new_tsec->sid = old_tsec->sid; new_tsec->osid = old_tsec->sid; /* Reset fs, key, and sock SIDs on execve. */ new_tsec->create_sid = 0; new_tsec->keycreate_sid = 0; new_tsec->sockcreate_sid = 0; if (old_tsec->exec_sid) { new_tsec->sid = old_tsec->exec_sid; /* Reset exec SID on execve. */ new_tsec->exec_sid = 0; /* Fail on NNP or nosuid if not an allowed transition. */ rc = check_nnp_nosuid(bprm, old_tsec, new_tsec); if (rc) return rc; } else { /* Check for a default transition on this program. */ rc = security_transition_sid(&selinux_state, old_tsec->sid, isec->sid, SECCLASS_PROCESS, NULL, &new_tsec->sid); if (rc) return rc; /* * Fallback to old SID on NNP or nosuid if not an allowed * transition. */ rc = check_nnp_nosuid(bprm, old_tsec, new_tsec); if (rc) new_tsec->sid = old_tsec->sid; } ad.type = LSM_AUDIT_DATA_FILE; ad.u.file = bprm->file; if (new_tsec->sid == old_tsec->sid) { rc = avc_has_perm(&selinux_state, old_tsec->sid, isec->sid, SECCLASS_FILE, FILE__EXECUTE_NO_TRANS, &ad); if (rc) return rc; } else { /* Check permissions for the transition. */ rc = avc_has_perm(&selinux_state, old_tsec->sid, new_tsec->sid, SECCLASS_PROCESS, PROCESS__TRANSITION, &ad); if (rc) return rc; rc = avc_has_perm(&selinux_state, new_tsec->sid, isec->sid, SECCLASS_FILE, FILE__ENTRYPOINT, &ad); if (rc) return rc; /* Check for shared state */ if (bprm->unsafe & LSM_UNSAFE_SHARE) { rc = avc_has_perm(&selinux_state, old_tsec->sid, new_tsec->sid, SECCLASS_PROCESS, PROCESS__SHARE, NULL); if (rc) return -EPERM; } /* Make sure that anyone attempting to ptrace over a task that * changes its SID has the appropriate permit */ if (bprm->unsafe & LSM_UNSAFE_PTRACE) { u32 ptsid = ptrace_parent_sid(); if (ptsid != 0) { rc = avc_has_perm(&selinux_state, ptsid, new_tsec->sid, SECCLASS_PROCESS, PROCESS__PTRACE, NULL); if (rc) return -EPERM; } } /* Clear any possibly unsafe personality bits on exec: */ bprm->per_clear |= PER_CLEAR_ON_SETID; /* Enable secure mode for SIDs transitions unless the noatsecure permission is granted between the two SIDs, i.e. ahp returns 0. */ rc = avc_has_perm(&selinux_state, old_tsec->sid, new_tsec->sid, SECCLASS_PROCESS, PROCESS__NOATSECURE, NULL); bprm->secureexec |= !!rc; } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton21245.01%28.70%
David Howells14731.21%28.70%
Stephen D. Smalley5912.53%417.39%
Kees Cook163.40%28.70%
Eric Paris122.55%417.39%
Paul Moore71.49%28.70%
Michael LeMay61.27%14.35%
Al Viro30.64%14.35%
Andreas Gruenbacher30.64%14.35%
Casey Schaufler20.42%14.35%
Vivek Goyal20.42%14.35%
Thomas Liu10.21%14.35%
Andrew Lutomirski10.21%14.35%
Total471100.00%23100.00%


static int match_file(const void *p, struct file *file, unsigned fd) { return file_has_perm(p, file, file_to_av(file)) ? fd + 1 : 0; }

Contributors

PersonTokensPropCommitsCommitProp
Al Viro38100.00%1100.00%
Total38100.00%1100.00%

/* Derived from fs/exec.c:flush_old_files. */
static inline void flush_unauthorized_files(const struct cred *cred, struct files_struct *files) { struct file *file, *devnull = NULL; struct tty_struct *tty; int drop_tty = 0; unsigned n; tty = get_current_tty(); if (tty) { spin_lock(&tty->files_lock); if (!list_empty(&tty->tty_files)) { struct tty_file_private *file_priv; /* Revalidate access to controlling tty. Use file_path_has_perm on the tty path directly rather than using file_has_perm, as this particular open file may belong to another process and we are only interested in the inode-based check here. */ file_priv = list_first_entry(&tty->tty_files, struct tty_file_private, list); file = file_priv->file; if (file_path_has_perm(cred, file, FILE__READ | FILE__WRITE)) drop_tty = 1; } spin_unlock(&tty->files_lock); tty_kref_put(tty); } /* Reset controlling tty. */ if (drop_tty) no_tty(); /* Revalidate access to inherited open files. */ n = iterate_fd(files, 0, match_file, cred); if (!n) /* none found? */ return; devnull = dentry_open(&selinux_null, O_RDWR, cred); if (IS_ERR(devnull)) devnull = NULL; /* replace all the matching ones with this */ do { replace_fd(n - 1, devnull, 0); } while ((n = iterate_fd(files, n, match_file, cred)) != 0); if (devnull) fput(devnull); }

Contributors

PersonTokensPropCommitsCommitProp
Al Viro5323.45%419.05%
Andrew Morton4821.24%29.52%
Stephen D. Smalley4720.80%314.29%
Nicholas Piggin219.29%29.52%
Eric Paris177.52%29.52%
David Howells114.87%314.29%
Peter Zijlstra93.98%14.76%
Eric W. Biedermann83.54%14.76%
Peter Hurley62.65%14.76%
Alan Cox31.33%14.76%
Akinobu Mita31.33%14.76%
Total226100.00%21100.00%

/* * Prepare a process for imminent new credential changes due to exec */
static void selinux_bprm_committing_creds(struct linux_binprm *bprm) { struct task_security_struct *new_tsec; struct rlimit *rlim, *initrlim; int rc, i; new_tsec = bprm->cred->security; if (new_tsec->sid == new_tsec->osid) return; /* Close files for which the new task SID is not authorized. */ flush_unauthorized_files(bprm->cred, current->files); /* Always clear parent death signal on SID transitions. */ current->pdeath_signal = 0; /* Check whether the new SID can inherit resource limits from the old * SID. If not, reset all soft limits to the lower of the current * task's hard limit and the init task's soft limit. * * Note that the setting of hard limits (even to lower them) can be * controlled by the setrlimit check. The inclusion of the init task's * soft limit into the computation is to avoid resetting soft limits * higher than the default soft limit for cases where the default is * lower than the hard limit, e.g. RLIMIT_CORE or RLIMIT_STACK. */ rc = avc_has_perm(&selinux_state, new_tsec->osid, new_tsec->sid, SECCLASS_PROCESS, PROCESS__RLIMITINH, NULL); if (rc) { /* protect against do_prlimit() */ task_lock(current); for (i = 0; i < RLIM_NLIMITS; i++) { rlim = current->signal->rlim + i; initrlim = init_task.signal->rlim + i; rlim->rlim_cur = min(rlim->rlim_max, initrlim->rlim_cur); } task_unlock(current); if (IS_ENABLED(CONFIG_POSIX_TIMERS)) update_rlimit_cpu(current, rlimit(RLIMIT_CPU)); } }

Contributors

PersonTokensPropCommitsCommitProp
David Howells8649.43%216.67%
Andrew Morton4727.01%325.00%
Oleg Nesterov148.05%18.33%
Serge E. Hallyn105.75%18.33%
Nico Pitre74.02%18.33%
Roland McGrath42.30%18.33%
Jiri Slaby31.72%216.67%
Stephen D. Smalley31.72%18.33%
Total174100.00%12100.00%

/* * Clean up the process immediately after the installation of new credentials * due to exec */
static void selinux_bprm_committed_creds(struct linux_binprm *bprm) { const struct task_security_struct *tsec = current_security(); struct itimerval itimer; u32 osid, sid; int rc, i; osid = tsec->osid; sid = tsec->sid; if (sid == osid) return; /* Check whether the new SID can inherit signal state from the old SID. * If not, clear itimers to avoid subsequent signal generation and * flush and unblock signals. * * This must occur _after_ the task SID has been updated so that any * kill done after the flush will be checked against the new SID. */ rc = avc_has_perm(&selinux_state, osid, sid, SECCLASS_PROCESS, PROCESS__SIGINH, NULL); if (rc) { if (IS_ENABLED(CONFIG_POSIX_TIMERS)) { memset(&itimer, 0, sizeof itimer); for (i = 0; i < 3; i++) do_setitimer(i, &itimer, NULL); } spin_lock_irq(&current->sighand->siglock); if (!fatal_signal_pending(current)) { flush_sigqueue(&current->pending); flush_sigqueue(&current->signal->shared_pending); flush_signal_handlers(current, 1); sigemptyset(&current->blocked); recalc_sigpending(); } spin_unlock_irq(&current->sighand->siglock); } /* Wake up the parent if it is waiting so that it can recheck * wait permission to the new task SID. */ read_lock(&tasklist_lock); __wake_up_parent(current, current->real_parent); read_unlock(&tasklist_lock); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton9947.37%216.67%
David Howells3717.70%325.00%
Serge E. Hallyn2712.92%18.33%
Oleg Nesterov2411.48%325.00%
Eric Paris104.78%18.33%
Nico Pitre94.31%18.33%
Stephen D. Smalley31.44%18.33%
Total209100.00%12100.00%

/* superblock security operations */
static int selinux_sb_alloc_security(struct super_block *sb) { return superblock_alloc_security(sb); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton17100.00%1100.00%
Total17100.00%1100.00%


static void selinux_sb_free_security(struct super_block *sb) { superblock_free_security(sb); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton16100.00%2100.00%
Total16100.00%2100.00%


static inline int match_prefix(char *prefix, int plen, char *option, int olen) { if (plen > olen) return 0; return !memcmp(prefix, option, plen); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton41100.00%2100.00%
Total41100.00%2100.00%


static inline int selinux_option(char *option, int len) { return (match_prefix(CONTEXT_STR, sizeof(CONTEXT_STR)-1, option, len) || match_prefix(FSCONTEXT_STR, sizeof(FSCONTEXT_STR)-1, option, len) || match_prefix(DEFCONTEXT_STR, sizeof(DEFCONTEXT_STR)-1, option, len) || match_prefix(ROOTCONTEXT_STR, sizeof(ROOTCONTEXT_STR)-1, option, len) || match_prefix(LABELSUPP_STR, sizeof(LABELSUPP_STR)-1, option, len)); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton5960.82%350.00%
Eric Paris2222.68%233.33%
David P. Quigley1616.49%116.67%
Total97100.00%6100.00%


static inline void take_option(char **to, char *from, int *first, int len) { if (!*first) { **to = ','; *to += 1; } else *first = 0; memcpy(*to, from, len); *to += len; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton63100.00%2100.00%
Total63100.00%2100.00%


static inline void take_selinux_option(char **to, char *from, int *first, int len) { int current_size = 0; if (!*first) { **to = '|'; *to += 1; } else *first = 0; while (current_size < len) { if (*from != '"') { **to = *from; *to += 1; } from += 1; current_size += 1; } }

Contributors

PersonTokensPropCommitsCommitProp
Cory Olmo90100.00%1100.00%
Total90100.00%1100.00%


static int selinux_sb_copy_data(char *orig, char *copy) { int fnosec, fsec, rc = 0; char *in_save, *in_curr, *in_end; char *sec_curr, *nosec_save, *nosec; int open_quote = 0; in_curr = orig; sec_curr = copy; nosec = (char *)get_zeroed_page(GFP_KERNEL); if (!nosec) { rc = -ENOMEM; goto out; } nosec_save = nosec; fnosec = fsec = 1; in_save = in_end = orig; do { if (*in_end == '"') open_quote = !open_quote; if ((*in_end == ',' && open_quote == 0) || *in_end == '\0') { int len = in_end - in_curr; if (selinux_option(in_curr, len)) take_selinux_option(&sec_curr, in_curr, &fsec, len); else take_option(&nosec, in_curr, &fnosec, len); in_curr = in_end + 1; } } while (*in_end++); strcpy(in_save, nosec_save); free_page((unsigned long)nosec_save); out: return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton17482.86%342.86%
Cory Olmo2411.43%114.29%
Gerald Schaefer94.29%114.29%
Eric Paris31.43%228.57%
Total210100.00%7100.00%


static int selinux_sb_remount(struct super_block *sb, void *data) { int rc, i, *flags; struct security_mnt_opts opts; char *secdata, **mount_options; struct superblock_security_struct *sbsec = sb->s_security; if (!(sbsec->flags & SE_SBINITIALIZED)) return 0; if (!data) return 0; if (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA) return 0; security_init_mnt_opts(&opts); secdata = alloc_secdata(); if (!secdata) return -ENOMEM; rc = selinux_sb_copy_data(data, secdata); if (rc) goto out_free_secdata; rc = selinux_parse_opts_str(secdata, &opts); if (rc) goto out_free_secdata; mount_options = opts.mnt_opts; flags = opts.mnt_opts_flags; for (i = 0; i < opts.num_mnt_opts; i++) { u32 sid; if (flags[i] == SBLABEL_MNT) continue; rc = security_context_str_to_sid(&selinux_state, mount_options[i], &sid, GFP_KERNEL); if (rc) { printk(KERN_WARNING "SELinux: security_context_str_to_sid" "(%s) failed for (dev %s, type %s) errno=%d\n", mount_options[i], sb->s_id, sb->s_type->name, rc); goto out_free_opts; } rc = -EINVAL; switch (flags[i]) { case FSCONTEXT_MNT: if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid, sid)) goto out_bad_option; break; case CONTEXT_MNT: if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid, sid)) goto out_bad_option; break; case ROOTCONTEXT_MNT: { struct inode_security_struct *root_isec; root_isec = backing_inode_security(sb->s_root); if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid, sid)) goto out_bad_option; break; } case DEFCONTEXT_MNT: if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid, sid)) goto out_bad_option; break; default: goto out_free_opts; } } rc = 0; out_free_opts: security_free_mnt_opts(&opts); out_free_secdata: free_secdata(secdata); return rc; out_bad_option: printk(KERN_WARNING "SELinux: unable to change security options " "during remount (dev %s, type=%s)\n", sb->s_id, sb->s_type->name); goto out_free_opts; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris29876.21%215.38%
Andrew Morton6416.37%323.08%
Linus Torvalds102.56%17.69%
Cory Olmo61.53%17.69%
Gerald Schaefer30.77%17.69%
Stephen D. Smalley30.77%17.69%
Rasmus Villemoes20.51%17.69%
Nikolay Aleksandrov20.51%17.69%
David Howells20.51%17.69%
Andreas Gruenbacher10.26%17.69%
Total391100.00%13100.00%


static int selinux_sb_kern_mount(struct super_block *sb, int flags, void *data) { const struct cred *cred = current_cred(); struct common_audit_data ad; int rc; rc = superblock_doinit(sb, data); if (rc) return rc; /* Allow all mounts performed by the kernel */ if (flags & MS_KERNMOUNT) return 0; ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = sb->s_root; return superblock_has_perm(cred, sb, FILESYSTEM__MOUNT, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton5966.29%222.22%
James Morris1314.61%222.22%
David Howells1011.24%111.11%
Eric Paris66.74%333.33%
Thomas Liu11.12%111.11%
Total89100.00%9100.00%


static int selinux_sb_statfs(struct dentry *dentry) { const struct cred *cred = current_cred(); struct common_audit_data ad; ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry->d_sb->s_root; return superblock_has_perm(cred, dentry->d_sb, FILESYSTEM__GETATTR, &ad); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3256.14%114.29%
David Howells1831.58%228.57%
Eric Paris610.53%342.86%
Thomas Liu11.75%114.29%
Total57100.00%7100.00%


static int selinux_mount(const char *dev_name, const struct path *path, const char *type, unsigned long flags, void *data) { const struct cred *cred = current_cred(); if (flags & MS_REMOUNT) return superblock_has_perm(cred, path->dentry->d_sb, FILESYSTEM__REMOUNT, NULL); else return path_has_perm(cred, path, FILE__MOUNTON); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton5069.44%112.50%
David Howells1115.28%112.50%
Al Viro811.11%450.00%
Jan Blunck22.78%112.50%
Eric Paris11.39%112.50%
Total72100.00%8100.00%


static int selinux_umount(struct vfsmount *mnt, int flags) { const struct cred *cred = current_cred(); return superblock_has_perm(cred, mnt->mnt_sb, FILESYSTEM__UNMOUNT, NULL); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2772.97%150.00%
David Howells1027.03%150.00%
Total37100.00%2100.00%

/* inode security operations */
static int selinux_inode_alloc_security(struct inode *inode) { return inode_alloc_security(inode); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton17100.00%1100.00%
Total17100.00%1100.00%


static void selinux_inode_free_security(struct inode *inode) { inode_free_security(inode); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton16100.00%1100.00%
Total16100.00%1100.00%


static int selinux_dentry_init_security(struct dentry *dentry, int mode, const struct qstr *name, void **ctx, u32 *ctxlen) { u32 newsid; int rc; rc = selinux_determine_inode_label(current_security(), d_inode(dentry->d_parent), name, inode_mode_to_security_class(mode), &newsid); if (rc) return rc; return security_sid_to_context(&selinux_state, newsid, (char **)ctx, ctxlen); }

Contributors

PersonTokensPropCommitsCommitProp
David Quigley7183.53%120.00%
David Howells78.24%120.00%
Vivek Goyal33.53%120.00%
Stephen D. Smalley33.53%120.00%
Al Viro11.18%120.00%
Total85100.00%5100.00%


static int selinux_dentry_create_files_as(struct dentry *dentry, int mode, struct qstr *name, const struct cred *old, struct cred *new) { u32 newsid; int rc; struct task_security_struct *tsec; rc = selinux_determine_inode_label(old->security, d_inode(dentry->d_parent), name, inode_mode_to_security_class(mode), &newsid); if (rc) return rc; tsec = new->security; tsec->create_sid = newsid; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Vivek Goyal89100.00%1100.00%
Total89100.00%1100.00%


static int selinux_inode_init_security(struct inode *inode, struct inode *dir, const struct qstr *qstr, const char **name, void **value, size_t *len) { const struct task_security_struct *tsec = current_security(); struct superblock_security_struct *sbsec; u32 newsid, clen; int rc; char *context; sbsec = dir->i_sb->s_security; newsid = tsec->create_sid; rc = selinux_determine_inode_label(current_security(), dir, qstr, inode_mode_to_security_class(inode->i_mode), &newsid); if (rc) return rc; /* Possibly defer initialization to selinux_complete_init. */ if (sbsec->flags & SE_SBINITIALIZED) { struct inode_security_struct *isec = inode->i_security; isec->sclass = inode_mode_to_security_class(inode->i_mode); isec->sid = newsid; isec->initialized = LABEL_INITIALIZED; } if (!selinux_state.initialized || !(sbsec->flags & SBLABEL_MNT)) return -EOPNOTSUPP; if (name) *name = XATTR_SELINUX_SUFFIX; if (value && len) { rc = security_sid_to_context_force(&selinux_state, newsid, &context, &clen); if (rc) return rc; *value = context; *len = clen; } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley15871.17%635.29%
Eric Paris4218.92%317.65%
David P. Quigley83.60%211.76%
David Howells62.70%211.76%
Vivek Goyal31.35%15.88%
Tetsuo Handa20.90%15.88%
Paul Moore20.90%15.88%
Andreas Gruenbacher10.45%15.88%
Total222100.00%17100.00%


static int selinux_inode_create(struct inode *dir, struct dentry *dentry, umode_t mode) { return may_create(dir, dentry, SECCLASS_FILE); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2793.10%150.00%
Al Viro26.90%150.00%
Total29100.00%2100.00%


static int selinux_inode_link(struct dentry *old_dentry, struct inode *dir, struct dentry *new_dentry) { return may_link(dir, old_dentry, MAY_LINK); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton31100.00%1100.00%
Total31100.00%1100.00%


static int selinux_inode_unlink(struct inode *dir, struct dentry *dentry) { return may_link(dir, dentry, MAY_UNLINK); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton26100.00%1100.00%
Total26100.00%1100.00%


static int selinux_inode_symlink(struct inode *dir, struct dentry *dentry, const char *name) { return may_create(dir, dentry, SECCLASS_LNK_FILE); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton31100.00%1100.00%
Total31100.00%1100.00%


static int selinux_inode_mkdir(struct inode *dir, struct dentry *dentry, umode_t mask) { return may_create(dir, dentry, SECCLASS_DIR); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2896.55%150.00%
Al Viro13.45%150.00%
Total29100.00%2100.00%


static int selinux_inode_rmdir(struct inode *dir, struct dentry *dentry) { return may_link(dir, dentry, MAY_RMDIR); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton26100.00%1100.00%
Total26100.00%1100.00%


static int selinux_inode_mknod(struct inode *dir, struct dentry *dentry, umode_t mode, dev_t dev) { return may_create(dir, dentry, inode_mode_to_security_class(mode)); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton3497.14%150.00%
Al Viro12.86%150.00%
Total35100.00%2100.00%


static int selinux_inode_rename(struct inode *old_inode, struct dentry *old_dentry, struct inode *new_inode, struct dentry *new_dentry) { return may_rename(old_inode, old_dentry, new_inode, new_dentry); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton38100.00%1100.00%
Total38100.00%1100.00%


static int selinux_inode_readlink(struct dentry *dentry) { const struct cred *cred = current_cred(); return dentry_has_perm(cred, dentry, FILE__READ); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton2066.67%150.00%
David Howells1033.33%150.00%
Total30100.00%2100.00%


static int selinux_inode_follow_link(struct dentry *dentry, struct inode *inode, bool rcu) { const struct cred *cred = current_cred(); struct common_audit_data ad; struct inode_security_struct *isec; u32 sid; validate_creds(cred); ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry; sid = cred_sid(cred); isec = inode_security_rcu(inode, rcu); if (IS_ERR(isec)) return PTR_ERR(isec); return avc_has_perm_flags(&selinux_state, sid, isec->sid, isec->sclass, FILE__READ, &ad, rcu ? MAY_NOT_BLOCK : 0); }

Contributors

PersonTokensPropCommitsCommitProp
Neil Brown6858.62%116.67%
Andreas Gruenbacher1815.52%233.33%
Andrew Morton1714.66%116.67%
David Howells108.62%116.67%
Stephen D. Smalley32.59%116.67%
Total116100.00%6100.00%


static noinline int audit_inode_permission(struct inode *inode, u32 perms, u32 audited, u32 denied, int result, unsigned flags) { struct common_audit_data ad; struct inode_security_struct *isec = inode->i_security; int rc; ad.type = LSM_AUDIT_DATA_INODE; ad.u.inode = inode; rc = slow_avc_audit(&selinux_state, current_sid(), isec->sid, isec->sclass, perms, audited, denied, result, &ad, flags); if (rc) return rc; return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris9191.92%360.00%
Stephen D. Smalley88.08%240.00%
Total99100.00%5100.00%


static int selinux_inode_permission(struct inode *inode, int mask) { const struct cred *cred = current_cred(); u32 perms; bool from_access; unsigned flags = mask & MAY_NOT_BLOCK; struct inode_security_struct *isec; u32 sid; struct av_decision avd; int rc, rc2; u32 audited, denied; from_access = mask & MAY_ACCESS; mask &= (MAY_READ|MAY_WRITE|MAY_EXEC|MAY_APPEND); /* No permission to check. Existence test. */ if (!mask) return 0; validate_creds(cred); if (unlikely(IS_PRIVATE(inode))) return 0; perms = file_mask_to_av(inode->i_mode, mask); sid = cred_sid(cred); isec = inode_security_rcu(inode, flags & MAY_NOT_BLOCK); if (IS_ERR(isec)) return PTR_ERR(isec); rc = avc_has_perm_noaudit(&selinux_state, sid, isec->sid, isec->sclass, perms, 0, &avd); audited = avc_audit_required(perms, &avd, rc, from_access ? FILE__AUDIT_ACCESS : 0, &denied); if (likely(!audited)) return rc; rc2 = audit_inode_permission(inode, perms, audited, denied, rc, flags); if (rc2) return rc2; return rc; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris15969.43%642.86%
Andrew Morton2912.66%17.14%
Andreas Gruenbacher208.73%214.29%
David Howells93.93%17.14%
Al Viro73.06%214.29%
Stephen D. Smalley52.18%214.29%
Total229100.00%14100.00%


static int selinux_inode_setattr(struct dentry *dentry, struct iattr *iattr) { const struct cred *cred = current_cred(); struct inode *inode = d_backing_inode(dentry); unsigned int ia_valid = iattr->ia_valid; __u32 av = FILE__WRITE; /* ATTR_FORCE is just used for ATTR_KILL_S[UG]ID. */ if (ia_valid & ATTR_FORCE) { ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID | ATTR_MODE | ATTR_FORCE); if (!ia_valid) return 0; } if (ia_valid & (ATTR_MODE | ATTR_UID | ATTR_GID | ATTR_ATIME_SET | ATTR_MTIME_SET | ATTR_TIMES_SET)) return dentry_has_perm(cred, dentry, FILE__SETATTR); if (selinux_policycap_openperm() && inode->i_sb->s_magic != SOCKFS_MAGIC && (ia_valid & ATTR_SIZE) && !(ia_valid & ATTR_FILE)) av |= FILE__OPEN; return dentry_has_perm(cred, dentry, av); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton4933.56%111.11%
Américo Wang3121.23%111.11%
Stephen D. Smalley2819.18%333.33%
Eric Paris2013.70%222.22%
David Howells117.53%111.11%
Jeff Vander Stoep74.79%111.11%
Total146100.00%9100.00%


static int selinux_inode_getattr(const struct path *path) { return path_has_perm(current_cred(), path, FILE__GETATTR); }

Contributors

PersonTokensPropCommitsCommitProp
Andrew Morton1252.17%125.00%
Al Viro521.74%125.00%
Eric Paris417.39%125.00%
David Howells28.70%125.00%
Total23100.00%4100.00%


static bool has_cap_mac_admin(bool audit) { const struct cred *cred = current_cred(); int cap_audit = audit ? SECURITY_CAP_AUDIT : SECURITY_CAP_NOAUDIT; if (cap_capable(cred, &init_user_ns, CAP_MAC_ADMIN, cap_audit)) return false; if (cred_has_capability(cred, CAP_MAC_ADMIN, cap_audit, true)) return false; return true; }

Contributors

PersonTokensPropCommitsCommitProp
Stephen D. Smalley5587.30%150.00%
Andrew Morton812.70%150.00%
Total63100.00%2100.00%


static int selinux_inode_setxattr(struct dentry *dentry, const char *name, const void *value, size_t size, int flags) { struct inode *inode = d_backing_inode(dentry); struct inode_security_struct *isec; struct superblock_security_struct *sbsec; struct common_audit_data ad; u32 newsid, sid = current_sid(); int rc = 0; if (strcmp(name, XATTR_NAME_SELINUX)) { rc = cap_inode_setxattr(dentry, name, value, size, flags); if (rc) return rc; /* Not an attribute we recognize, so just check the ordinary setattr permission. */ return dentry_has_perm(current_cred(), dentry, FILE__SETATTR); } sbsec = inode->i_sb->s_security; if (!(sbsec->flags & SBLABEL_MNT)) return -EOPNOTSUPP; if (!inode_owner_or_capable(inode)) return -EPERM; ad.type = LSM_AUDIT_DATA_DENTRY; ad.u.dentry = dentry; isec = backing_inode_security(dentry); rc = avc_has_perm(&selinux_state, sid, isec->sid, isec->sclass, FILE__RELABELFROM, &ad); if (rc) return rc; rc = security_context_to_sid(&selinux_state, value, size, &newsid, GFP_KERNEL); if (rc == -EINVAL) { if (!has_cap_mac_admin(true)) { struct audit_buffer *ab; size_t audit_size; /* We strip a nul only if it is at the end, otherwise the * context contains a nul and we should audit that */ if (value) { const char *str = value; if (str[size - 1] == '\0') audit_size = size - 1; else audit_size = size; } else { audit_size = 0; } ab = audit_log_start(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR); audit_log_format(ab, "op=setxattr invalid_context="); audit_log_n_untrustedstring(ab, value, audit_size); audit_log_end(ab); return rc; } rc = security_context_to_sid_force(&selinux_state, value, size, &newsid); } if (rc) return rc; rc = avc_has_perm(&selinux_state, sid, newsid, isec->sclass, FILE__RELABELTO, &ad); if (rc) return rc; rc = security_validate_transition(&