mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
fs: Add Felica mount requirement
Mounts on "/system", "/system_ext", "/product", "/vendor" should be blocked in the root environment. e.g. adb root adb shell mount -r -w sdcard /system adb shell mount -r -w sdcard /system_ext adb shell mount -r -w sdcard /product adb shell mount -r -w sdcard /vendor Change-Id: I6637dbd93f43da04ee4d47f167c95d5531d43710 Reviewed-on: https://gerrit.mot.com/2175517 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Binsheng Que <quebs2@motorola.com> Reviewed-by: Huosheng Liao <liaohs@motorola.com> Submit-Approved: Jira Key
This commit is contained in:
parent
f1162ae375
commit
523f17e0ea
2 changed files with 69 additions and 0 deletions
|
|
@ -22,6 +22,13 @@ config FS_EPOLL_WAKEUP_DEBUG
|
|||
This option enables printing thread ID and name of eventpoll wakeup source
|
||||
while waking up system for debug purpose. Keep it off if not sure.
|
||||
|
||||
config FELICA_MOUNT_BLOCK
|
||||
bool "Block mount sdcard to system path"
|
||||
default n
|
||||
help
|
||||
Mounts on "/system", "/system_ext", "/product", "/vendor" should be blocked
|
||||
in the root environment.
|
||||
|
||||
if BLOCK
|
||||
|
||||
config FS_IOMAP
|
||||
|
|
|
|||
|
|
@ -30,6 +30,7 @@
|
|||
#include <uapi/linux/mount.h>
|
||||
#include <linux/fs_context.h>
|
||||
#include <linux/shmem_fs.h>
|
||||
#include <linux/types.h>
|
||||
|
||||
#include "pnode.h"
|
||||
#include "internal.h"
|
||||
|
|
@ -3095,6 +3096,62 @@ char *copy_mount_string(const void __user *data)
|
|||
return data ? strndup_user(data, PATH_MAX) : NULL;
|
||||
}
|
||||
|
||||
#ifdef CONFIG_FELICA_MOUNT_BLOCK
|
||||
/*
|
||||
* Felica requirement:
|
||||
* Mounts on "/system", "/system_ext", "/product", "/vendor" should be blocked
|
||||
* e.g.
|
||||
* adb root
|
||||
* adb shell mount -r -w sdcard /system
|
||||
* adb shell mount -r -w sdcard /system_ext
|
||||
* adb shell mount -r -w sdcard /product
|
||||
* adb shell mount -r -w sdcard /vendor
|
||||
*/
|
||||
static bool mount_block_check(unsigned long flags, const char __user *dir_name)
|
||||
{
|
||||
int i;
|
||||
u32 secid, su_secid;
|
||||
const char *su_secctx = "u:r:su:s0";
|
||||
struct filename *dir_filename = getname(dir_name);
|
||||
const char *blocklist[] = {"/system", "/system_ext", "/product", "/vendor", "/odm", "/oem"};
|
||||
int len = ARRAY_SIZE(blocklist);
|
||||
bool ret = false;
|
||||
|
||||
/* These commands would mount with "bind" flag */
|
||||
if (!(flags & MS_BIND))
|
||||
return ret;
|
||||
|
||||
/* Check mount point */
|
||||
dir_filename = getname(dir_name);
|
||||
if (IS_ERR(dir_filename))
|
||||
return ret;
|
||||
|
||||
if (!dir_filename->name)
|
||||
goto out_putname;
|
||||
|
||||
for (i = 0; i < len; i++) {
|
||||
if (!strncmp(dir_filename->name, blocklist[i], strlen(blocklist[i])) ||
|
||||
!strncmp(dir_filename->name, blocklist[i] + 1, strlen(blocklist[i]) - 1))
|
||||
break;
|
||||
}
|
||||
if (i == len)
|
||||
goto out_putname;
|
||||
|
||||
security_secctx_to_secid(su_secctx, strlen(su_secctx), &su_secid);
|
||||
security_task_getsecid(current, &secid);
|
||||
|
||||
/* "su" should be blocked */
|
||||
if (secid == su_secid) {
|
||||
pr_warn("Mount on %s is not allowed\n", dir_filename->name);
|
||||
ret = true;
|
||||
}
|
||||
|
||||
out_putname:
|
||||
putname(dir_filename);
|
||||
return ret;
|
||||
}
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Flags is a 32-bit value that allows up to 31 non-fs dependent flags to
|
||||
* be given to the mount() call (ie: read-only, no-dev, no-suid etc).
|
||||
|
|
@ -3116,6 +3173,11 @@ long do_mount(const char *dev_name, const char __user *dir_name,
|
|||
unsigned int mnt_flags = 0, sb_flags;
|
||||
int retval = 0;
|
||||
|
||||
#ifdef CONFIG_FELICA_MOUNT_BLOCK
|
||||
if (mount_block_check(flags, dir_name))
|
||||
return -EPERM;
|
||||
#endif
|
||||
|
||||
/* Discard magic */
|
||||
if ((flags & MS_MGC_MSK) == MS_MGC_VAL)
|
||||
flags &= ~MS_MGC_MSK;
|
||||
|
|
|
|||
Loading…
Reference in a new issue