diff --git a/fs/Kconfig b/fs/Kconfig index be0622d91cb2..f4638142e51b 100644 --- a/fs/Kconfig +++ b/fs/Kconfig @@ -22,13 +22,6 @@ config FS_EPOLL_WAKEUP_DEBUG This option enables printing thread ID and name of eventpoll wakeup source while waking up system for debug purpose. Keep it off if not sure. -config FELICA_MOUNT_BLOCK - bool "Block mount sdcard to system path" - default n - help - Mounts on "/system", "/system_ext", "/product", "/vendor" should be blocked - in the root environment. - if BLOCK config FS_IOMAP diff --git a/fs/namespace.c b/fs/namespace.c index efabde926a13..7955b65334e8 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -30,7 +30,6 @@ #include #include #include -#include #include "pnode.h" #include "internal.h" @@ -3103,62 +3102,6 @@ char *copy_mount_string(const void __user *data) return data ? strndup_user(data, PATH_MAX) : NULL; } -#ifdef CONFIG_FELICA_MOUNT_BLOCK -/* - * Felica requirement: - * Mounts on "/system", "/system_ext", "/product", "/vendor" should be blocked - * e.g. - * adb root - * adb shell mount -r -w sdcard /system - * adb shell mount -r -w sdcard /system_ext - * adb shell mount -r -w sdcard /product - * adb shell mount -r -w sdcard /vendor -*/ -static bool mount_block_check(unsigned long flags, const char __user *dir_name) -{ - int i; - u32 secid, su_secid; - const char *su_secctx = "u:r:su:s0"; - struct filename *dir_filename = getname(dir_name); - const char *blocklist[] = {"/system", "/system_ext", "/product", "/vendor", "/odm", "/oem"}; - int len = ARRAY_SIZE(blocklist); - bool ret = false; - - /* These commands would mount with "bind" flag */ - if (!(flags & MS_BIND)) - return ret; - - /* Check mount point */ - dir_filename = getname(dir_name); - if (IS_ERR(dir_filename)) - return ret; - - if (!dir_filename->name) - goto out_putname; - - for (i = 0; i < len; i++) { - if (!strncmp(dir_filename->name, blocklist[i], strlen(blocklist[i])) || - !strncmp(dir_filename->name, blocklist[i] + 1, strlen(blocklist[i]) - 1)) - break; - } - if (i == len) - goto out_putname; - - security_secctx_to_secid(su_secctx, strlen(su_secctx), &su_secid); - security_task_getsecid(current, &secid); - - /* "su" should be blocked */ - if (secid == su_secid) { - pr_warn("Mount on %s is not allowed\n", dir_filename->name); - ret = true; - } - -out_putname: - putname(dir_filename); - return ret; -} -#endif - /* * Flags is a 32-bit value that allows up to 31 non-fs dependent flags to * be given to the mount() call (ie: read-only, no-dev, no-suid etc). @@ -3180,11 +3123,6 @@ long do_mount(const char *dev_name, const char __user *dir_name, unsigned int mnt_flags = 0, sb_flags; int retval = 0; -#ifdef CONFIG_FELICA_MOUNT_BLOCK - if (mount_block_check(flags, dir_name)) - return -EPERM; -#endif - /* Discard magic */ if ((flags & MS_MGC_MSK) == MS_MGC_VAL) flags &= ~MS_MGC_MSK;