Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2008 The Android Open Source Project |
| 3 | * All rights reserved. |
| 4 | * |
| 5 | * Redistribution and use in source and binary forms, with or without |
| 6 | * modification, are permitted provided that the following conditions |
| 7 | * are met: |
| 8 | * * Redistributions of source code must retain the above copyright |
| 9 | * notice, this list of conditions and the following disclaimer. |
| 10 | * * Redistributions in binary form must reproduce the above copyright |
| 11 | * notice, this list of conditions and the following disclaimer in |
| 12 | * the documentation and/or other materials provided with the |
| 13 | * distribution. |
| 14 | * |
| 15 | * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
| 16 | * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
| 17 | * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS |
| 18 | * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE |
| 19 | * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, |
| 20 | * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, |
| 21 | * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS |
| 22 | * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED |
| 23 | * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, |
| 24 | * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT |
| 25 | * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 26 | * SUCH DAMAGE. |
| 27 | */ |
| 28 | |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 29 | #include "system_properties/contexts_split.h" |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 30 | |
| 31 | #include <ctype.h> |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 32 | #include <limits.h> |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 33 | #include <stdlib.h> |
| 34 | #include <string.h> |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 35 | #include <sys/stat.h> |
| 36 | |
| 37 | #include <async_safe/log.h> |
| 38 | |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 39 | #include "system_properties/context_node.h" |
| 40 | #include "system_properties/system_properties.h" |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 41 | |
| 42 | class ContextListNode : public ContextNode { |
| 43 | public: |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 44 | ContextListNode(ContextListNode* next, const char* context, const char* filename) |
| 45 | : ContextNode(strdup(context), filename), next(next) { |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 46 | } |
| 47 | |
| 48 | ~ContextListNode() { |
| 49 | free(const_cast<char*>(context())); |
| 50 | } |
| 51 | |
| 52 | ContextListNode* next; |
| 53 | }; |
| 54 | |
| 55 | struct PrefixNode { |
| 56 | PrefixNode(struct PrefixNode* next, const char* prefix, ContextListNode* context) |
| 57 | : prefix(strdup(prefix)), prefix_len(strlen(prefix)), context(context), next(next) { |
| 58 | } |
| 59 | ~PrefixNode() { |
| 60 | free(prefix); |
| 61 | } |
| 62 | char* prefix; |
| 63 | const size_t prefix_len; |
| 64 | ContextListNode* context; |
| 65 | PrefixNode* next; |
| 66 | }; |
| 67 | |
| 68 | template <typename List, typename... Args> |
| 69 | static inline void ListAdd(List** list, Args... args) { |
| 70 | *list = new List(*list, args...); |
| 71 | } |
| 72 | |
| 73 | static void ListAddAfterLen(PrefixNode** list, const char* prefix, ContextListNode* context) { |
| 74 | size_t prefix_len = strlen(prefix); |
| 75 | |
| 76 | auto next_list = list; |
| 77 | |
| 78 | while (*next_list) { |
| 79 | if ((*next_list)->prefix_len < prefix_len || (*next_list)->prefix[0] == '*') { |
| 80 | ListAdd(next_list, prefix, context); |
| 81 | return; |
| 82 | } |
| 83 | next_list = &(*next_list)->next; |
| 84 | } |
| 85 | ListAdd(next_list, prefix, context); |
| 86 | } |
| 87 | |
| 88 | template <typename List, typename Func> |
| 89 | static void ListForEach(List* list, Func func) { |
| 90 | while (list) { |
| 91 | func(list); |
| 92 | list = list->next; |
| 93 | } |
| 94 | } |
| 95 | |
| 96 | template <typename List, typename Func> |
| 97 | static List* ListFind(List* list, Func func) { |
| 98 | while (list) { |
| 99 | if (func(list)) { |
| 100 | return list; |
| 101 | } |
| 102 | list = list->next; |
| 103 | } |
| 104 | return nullptr; |
| 105 | } |
| 106 | |
| 107 | template <typename List> |
| 108 | static void ListFree(List** list) { |
| 109 | while (*list) { |
| 110 | auto old_list = *list; |
| 111 | *list = old_list->next; |
| 112 | delete old_list; |
| 113 | } |
| 114 | } |
| 115 | |
| 116 | // The below two functions are duplicated from label_support.c in libselinux. |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 117 | |
| 118 | // The read_spec_entries and read_spec_entry functions may be used to |
| 119 | // replace sscanf to read entries from spec files. The file and |
| 120 | // property services now use these. |
| 121 | |
| 122 | // Read an entry from a spec file (e.g. file_contexts) |
| 123 | static inline int read_spec_entry(char** entry, char** ptr, int* len) { |
| 124 | *entry = nullptr; |
| 125 | char* tmp_buf = nullptr; |
| 126 | |
| 127 | while (isspace(**ptr) && **ptr != '\0') (*ptr)++; |
| 128 | |
| 129 | tmp_buf = *ptr; |
| 130 | *len = 0; |
| 131 | |
| 132 | while (!isspace(**ptr) && **ptr != '\0') { |
| 133 | (*ptr)++; |
| 134 | (*len)++; |
| 135 | } |
| 136 | |
| 137 | if (*len) { |
| 138 | *entry = strndup(tmp_buf, *len); |
| 139 | if (!*entry) return -1; |
| 140 | } |
| 141 | |
| 142 | return 0; |
| 143 | } |
| 144 | |
| 145 | // line_buf - Buffer containing the spec entries . |
| 146 | // num_args - The number of spec parameter entries to process. |
| 147 | // ... - A 'char **spec_entry' for each parameter. |
| 148 | // returns - The number of items processed. |
| 149 | // |
| 150 | // This function calls read_spec_entry() to do the actual string processing. |
| 151 | static int read_spec_entries(char* line_buf, int num_args, ...) { |
| 152 | char **spec_entry, *buf_p; |
| 153 | int len, rc, items, entry_len = 0; |
| 154 | va_list ap; |
| 155 | |
| 156 | len = strlen(line_buf); |
| 157 | if (line_buf[len - 1] == '\n') |
| 158 | line_buf[len - 1] = '\0'; |
| 159 | else |
| 160 | // Handle case if line not \n terminated by bumping |
| 161 | // the len for the check below (as the line is NUL |
| 162 | // terminated by getline(3)) |
| 163 | len++; |
| 164 | |
| 165 | buf_p = line_buf; |
| 166 | while (isspace(*buf_p)) buf_p++; |
| 167 | |
| 168 | // Skip comment lines and empty lines. |
| 169 | if (*buf_p == '#' || *buf_p == '\0') return 0; |
| 170 | |
| 171 | // Process the spec file entries |
| 172 | va_start(ap, num_args); |
| 173 | |
| 174 | items = 0; |
| 175 | while (items < num_args) { |
| 176 | spec_entry = va_arg(ap, char**); |
| 177 | |
| 178 | if (len - 1 == buf_p - line_buf) { |
| 179 | va_end(ap); |
| 180 | return items; |
| 181 | } |
| 182 | |
| 183 | rc = read_spec_entry(spec_entry, &buf_p, &entry_len); |
| 184 | if (rc < 0) { |
| 185 | va_end(ap); |
| 186 | return rc; |
| 187 | } |
| 188 | if (entry_len) items++; |
| 189 | } |
| 190 | va_end(ap); |
| 191 | return items; |
| 192 | } |
| 193 | |
Tom Cherry | f76bbf5 | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 194 | bool ContextsSplit::MapSerialPropertyArea(bool access_rw, bool* fsetxattr_failed) { |
Elliott Hughes | d19f7b1 | 2023-08-30 21:19:55 +0000 | [diff] [blame] | 195 | PropertiesFilename filename(filename_, "properties_serial"); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 196 | if (access_rw) { |
Elliott Hughes | d19f7b1 | 2023-08-30 21:19:55 +0000 | [diff] [blame] | 197 | serial_prop_area_ = prop_area::map_prop_area_rw( |
| 198 | filename.c_str(), "u:object_r:properties_serial:s0", fsetxattr_failed); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 199 | } else { |
Elliott Hughes | d19f7b1 | 2023-08-30 21:19:55 +0000 | [diff] [blame] | 200 | serial_prop_area_ = prop_area::map_prop_area(filename.c_str()); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 201 | } |
Tom Cherry | f76bbf5 | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 202 | return serial_prop_area_; |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 203 | } |
| 204 | |
| 205 | bool ContextsSplit::InitializePropertiesFromFile(const char* filename) { |
| 206 | FILE* file = fopen(filename, "re"); |
| 207 | if (!file) { |
| 208 | return false; |
| 209 | } |
| 210 | |
| 211 | char* buffer = nullptr; |
| 212 | size_t line_len; |
| 213 | char* prop_prefix = nullptr; |
| 214 | char* context = nullptr; |
| 215 | |
| 216 | while (getline(&buffer, &line_len, file) > 0) { |
| 217 | int items = read_spec_entries(buffer, 2, &prop_prefix, &context); |
| 218 | if (items <= 0) { |
| 219 | continue; |
| 220 | } |
| 221 | if (items == 1) { |
| 222 | free(prop_prefix); |
| 223 | continue; |
| 224 | } |
| 225 | |
| 226 | // init uses ctl.* properties as an IPC mechanism and does not write them |
| 227 | // to a property file, therefore we do not need to create property files |
| 228 | // to store them. |
| 229 | if (!strncmp(prop_prefix, "ctl.", 4)) { |
| 230 | free(prop_prefix); |
| 231 | free(context); |
| 232 | continue; |
| 233 | } |
| 234 | |
| 235 | auto old_context = ListFind( |
| 236 | contexts_, [context](ContextListNode* l) { return !strcmp(l->context(), context); }); |
| 237 | if (old_context) { |
| 238 | ListAddAfterLen(&prefixes_, prop_prefix, old_context); |
| 239 | } else { |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 240 | ListAdd(&contexts_, context, filename_); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 241 | ListAddAfterLen(&prefixes_, prop_prefix, contexts_); |
| 242 | } |
| 243 | free(prop_prefix); |
| 244 | free(context); |
| 245 | } |
| 246 | |
| 247 | free(buffer); |
| 248 | fclose(file); |
| 249 | |
| 250 | return true; |
| 251 | } |
| 252 | |
| 253 | bool ContextsSplit::InitializeProperties() { |
| 254 | // If we do find /property_contexts, then this is being |
| 255 | // run as part of the OTA updater on older release that had |
| 256 | // /property_contexts - b/34370523 |
| 257 | if (InitializePropertiesFromFile("/property_contexts")) { |
| 258 | return true; |
| 259 | } |
| 260 | |
| 261 | // Use property_contexts from /system & /vendor, fall back to those from / |
| 262 | if (access("/system/etc/selinux/plat_property_contexts", R_OK) != -1) { |
| 263 | if (!InitializePropertiesFromFile("/system/etc/selinux/plat_property_contexts")) { |
| 264 | return false; |
| 265 | } |
Tom Cherry | 15786e4 | 2020-07-28 10:56:12 -0700 | [diff] [blame] | 266 | // Don't check for failure here, since we don't always have all of these partitions. |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 267 | // E.g. In case of recovery, the vendor partition will not have mounted and we |
| 268 | // still need the system / platform properties to function. |
Bowgo Tsai | a9fc82f | 2018-02-01 23:03:49 +0800 | [diff] [blame] | 269 | if (access("/vendor/etc/selinux/vendor_property_contexts", R_OK) != -1) { |
| 270 | InitializePropertiesFromFile("/vendor/etc/selinux/vendor_property_contexts"); |
Bowgo Tsai | a9fc82f | 2018-02-01 23:03:49 +0800 | [diff] [blame] | 271 | } |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 272 | } else { |
| 273 | if (!InitializePropertiesFromFile("/plat_property_contexts")) { |
| 274 | return false; |
| 275 | } |
Bowgo Tsai | a9fc82f | 2018-02-01 23:03:49 +0800 | [diff] [blame] | 276 | if (access("/vendor_property_contexts", R_OK) != -1) { |
| 277 | InitializePropertiesFromFile("/vendor_property_contexts"); |
Bowgo Tsai | a9fc82f | 2018-02-01 23:03:49 +0800 | [diff] [blame] | 278 | } |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 279 | } |
| 280 | |
| 281 | return true; |
| 282 | } |
| 283 | |
Nate Myren | ae7f33d | 2023-08-28 16:46:39 -0700 | [diff] [blame^] | 284 | bool ContextsSplit::Initialize(bool writable, const char* filename, bool* fsetxattr_failed, bool) { |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 285 | filename_ = filename; |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 286 | if (!InitializeProperties()) { |
| 287 | return false; |
| 288 | } |
| 289 | |
| 290 | if (writable) { |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 291 | mkdir(filename_, S_IRWXU | S_IXGRP | S_IXOTH); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 292 | bool open_failed = false; |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 293 | if (fsetxattr_failed) { |
| 294 | *fsetxattr_failed = false; |
| 295 | } |
| 296 | |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 297 | ListForEach(contexts_, [&fsetxattr_failed, &open_failed](ContextListNode* l) { |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 298 | if (!l->Open(true, fsetxattr_failed)) { |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 299 | open_failed = true; |
| 300 | } |
| 301 | }); |
Tom Cherry | e275d6d | 2017-12-11 23:31:33 -0800 | [diff] [blame] | 302 | if (open_failed || !MapSerialPropertyArea(true, fsetxattr_failed)) { |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 303 | FreeAndUnmap(); |
| 304 | return false; |
| 305 | } |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 306 | } else { |
Tom Cherry | f76bbf5 | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 307 | if (!MapSerialPropertyArea(false, nullptr)) { |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 308 | FreeAndUnmap(); |
| 309 | return false; |
| 310 | } |
| 311 | } |
| 312 | return true; |
| 313 | } |
| 314 | |
Tom Cherry | a5744e2 | 2020-09-01 22:35:56 +0000 | [diff] [blame] | 315 | PrefixNode* ContextsSplit::GetPrefixNodeForName(const char* name) { |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 316 | auto entry = ListFind(prefixes_, [name](PrefixNode* l) { |
| 317 | return l->prefix[0] == '*' || !strncmp(l->prefix, name, l->prefix_len); |
| 318 | }); |
Tom Cherry | a5744e2 | 2020-09-01 22:35:56 +0000 | [diff] [blame] | 319 | |
| 320 | return entry; |
| 321 | } |
| 322 | |
| 323 | prop_area* ContextsSplit::GetPropAreaForName(const char* name) { |
| 324 | auto entry = GetPrefixNodeForName(name); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 325 | if (!entry) { |
| 326 | return nullptr; |
| 327 | } |
| 328 | |
| 329 | auto cnode = entry->context; |
| 330 | if (!cnode->pa()) { |
| 331 | // We explicitly do not check no_access_ in this case because unlike the |
| 332 | // case of foreach(), we want to generate an selinux audit for each |
| 333 | // non-permitted property access in this function. |
| 334 | cnode->Open(false, nullptr); |
| 335 | } |
| 336 | return cnode->pa(); |
| 337 | } |
| 338 | |
| 339 | void ContextsSplit::ForEach(void (*propfn)(const prop_info* pi, void* cookie), void* cookie) { |
| 340 | ListForEach(contexts_, [propfn, cookie](ContextListNode* l) { |
| 341 | if (l->CheckAccessAndOpen()) { |
| 342 | l->pa()->foreach (propfn, cookie); |
| 343 | } |
| 344 | }); |
| 345 | } |
| 346 | |
| 347 | void ContextsSplit::ResetAccess() { |
| 348 | ListForEach(contexts_, [](ContextListNode* l) { l->ResetAccess(); }); |
| 349 | } |
| 350 | |
| 351 | void ContextsSplit::FreeAndUnmap() { |
| 352 | ListFree(&prefixes_); |
| 353 | ListFree(&contexts_); |
Tom Cherry | f76bbf5 | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 354 | prop_area::unmap_prop_area(&serial_prop_area_); |
Tom Cherry | fd44b9f | 2017-11-08 14:01:00 -0800 | [diff] [blame] | 355 | } |