mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
fs: Remove "bind" flag check
Felica requires also prevent mount external storage to these paths. The external storage mount is a real block device instead of bind, so remove the "bind" check. The secid of "u:r:su:s0" equals "u:r:init:s0" at init first stage, it will also prevent the init first stage mount, only when current secid is not same as "u:r:init:s0" and same as "u:r:su:s0", we prevents the mount. The below commands should be blocked. adb shell mount -r -w /dev/block/vold/public:179,1 /system adb shell mount -r -w /dev/block/vold/public:179,1 /system_ext adb shell mount -r -w /dev/block/vold/public:179,1 /product adb shell mount -r -w /dev/block/vold/public:179,1 /vendor Change-Id: I0e3ca33b0dd4bd67910a9d2296e297cda542016a Reviewed-on: https://gerrit.mot.com/2177550 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Huosheng Liao <liaohs@motorola.com> Submit-Approved: Jira Key
This commit is contained in:
parent
4c912f3429
commit
e5ab5b3421
1 changed files with 13 additions and 7 deletions
|
|
@ -3106,19 +3106,24 @@ char *copy_mount_string(const void __user *data)
|
|||
* adb shell mount -r -w sdcard /system_ext
|
||||
* adb shell mount -r -w sdcard /product
|
||||
* adb shell mount -r -w sdcard /vendor
|
||||
* adb shell mount -r -w /dev/block/vold/public:179,1 /system
|
||||
* adb shell mount -r -w /dev/block/vold/public:179,1 /system_ext
|
||||
* adb shell mount -r -w /dev/block/vold/public:179,1 /product
|
||||
* adb shell mount -r -w /dev/block/vold/public:179,1 /vendor
|
||||
*/
|
||||
static bool mount_block_check(unsigned long flags, struct path *path)
|
||||
{
|
||||
int i;
|
||||
u32 secid, su_secid;
|
||||
const char *su_secctx = "u:r:su:s0";
|
||||
char *buf, *pathname;
|
||||
u32 secid, su_secid, init_secid;
|
||||
const char *su_secctx = "u:r:su:s0";
|
||||
const char *init_secctx = "u:r:init:s0";
|
||||
const char *blocklist[] = {"/system", "/system_ext", "/product", "/vendor", "/odm", "/oem"};
|
||||
int len = ARRAY_SIZE(blocklist);
|
||||
bool ret = false;
|
||||
|
||||
/* These commands would mount with "bind" flag */
|
||||
if (!(flags & MS_BIND))
|
||||
/* "adb remount" is allowed */
|
||||
if (flags & MS_REMOUNT)
|
||||
return ret;
|
||||
|
||||
buf = (char *)__get_free_page(GFP_KERNEL);
|
||||
|
|
@ -3138,11 +3143,12 @@ static bool mount_block_check(unsigned long flags, struct path *path)
|
|||
goto out_putname;
|
||||
|
||||
security_secctx_to_secid(su_secctx, strlen(su_secctx), &su_secid);
|
||||
security_secctx_to_secid(init_secctx, strlen(init_secctx), &init_secid);
|
||||
security_task_getsecid(current, &secid);
|
||||
|
||||
/* "su" should be blocked */
|
||||
if (secid == su_secid) {
|
||||
pr_warn("Mount on %s is not allowed\n", pathname);
|
||||
/* "su" should be blocked, the secid of su equals init at init first stage*/
|
||||
if ((secid != init_secid) && (secid == su_secid)) {
|
||||
pr_warn("Mount on %s is not allowed with %d\n", pathname, secid);
|
||||
ret = true;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue