From 7b145c3ad44f21d39611e96475ea1e2ef86c0e82 Mon Sep 17 00:00:00 2001 From: Vamsi krishna Gattupalli Date: Tue, 1 Dec 2020 20:11:51 +0530 Subject: [PATCH] msm: ADSPRPC: Handle third party applications Reject the session when third party applications try to spawn signed PD and channel configured as secure. Change-Id: Iab18ad364985372f8007b6dda933ef4e5adf0213 Acked-by: Nishant Chaubey Signed-off-by: Vamsi krishna Gattupalli --- drivers/char/adsprpc.c | 35 +++++++++++++++++++++++++++++++---- 1 file changed, 31 insertions(+), 4 deletions(-) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index f31e1441fd6d..a49bd2be871b 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -195,7 +195,19 @@ /* Fastrpc remote process attributes */ enum fastrpc_proc_attr { - FASTRPC_MODE_UNSIGNED_MODULE = (1 << 3), + /* Macro for Debug attr */ + FASTRPC_MODE_DEBUG = 1 << 0, + /* Macro for Ptrace */ + FASTRPC_MODE_PTRACE = 1 << 1, + /* Macro for CRC Check */ + FASTRPC_MODE_CRC = 1 << 2, + /* Macro for Unsigned PD */ + FASTRPC_MODE_UNSIGNED_MODULE = 1 << 3, + /* Macro for Adaptive QoS */ + FASTRPC_MODE_ADAPTIVE_QOS = 1 << 4, + /* Macro for System Process */ + FASTRPC_MODE_SYSTEM_PROCESS = 1 << 5, + /* Macro for Prvileged Process */ FASTRPC_MODE_PRIVILEGED = (1 << 6), }; @@ -3718,6 +3730,9 @@ static int fastrpc_init_process(struct fastrpc_file *fl, { int err = 0; struct fastrpc_ioctl_init *init = &uproc->init; + int cid = fl->cid; + struct fastrpc_apps *me = &gfa; + struct fastrpc_channel_ctx *chan = &me->channel[cid]; VERIFY(err, init->filelen < INIT_FILELEN_MAX && init->memlen < INIT_MEMLEN_MAX); @@ -3732,6 +3747,16 @@ static int fastrpc_init_process(struct fastrpc_file *fl, goto bail; } + if (chan->unsigned_support && fl->dev_minor == MINOR_NUM_DEV) { + /* Make sure third party applications */ + /* can spawn only unsigned PD when */ + /* channel configured as secure. */ + if (chan->secure && !(uproc->attrs & FASTRPC_MODE_UNSIGNED_MODULE)) { + err = -ECONNREFUSED; + goto bail; + } + } + err = fastrpc_channel_open(fl); if (err) goto bail; @@ -5387,6 +5412,7 @@ static int fastrpc_get_info(struct fastrpc_file *fl, uint32_t *info) { int err = 0; uint32_t cid; + struct fastrpc_apps *me = &gfa; VERIFY(err, fl != NULL); if (err) @@ -5395,8 +5421,9 @@ static int fastrpc_get_info(struct fastrpc_file *fl, uint32_t *info) err = fastrpc_set_process_info(fl); if (err) goto bail; + cid = *info; if (fl->cid == -1) { - cid = *info; + struct fastrpc_channel_ctx *chan = &me->channel[cid]; VERIFY(err, cid < NUM_CHANNELS); if (err) { err = -ECHRNG; @@ -5411,8 +5438,8 @@ static int fastrpc_get_info(struct fastrpc_file *fl, uint32_t *info) * offload. Untrusted apps will be restricted from * offloading to signed PD using DSP HAL. */ - if (fl->apps->channel[cid].secure == SECURE_CHANNEL - && !fl->apps->channel[cid].unsigned_support) { + if (chan->secure == SECURE_CHANNEL + && !chan->unsigned_support) { ADSPRPC_ERR( "cannot use domain %d with non-secure device\n", cid);