From e5ab5b34211ec85002294ea6768d107ffb0eeed3 Mon Sep 17 00:00:00 2001 From: jixj Date: Mon, 24 Jan 2022 17:06:53 +0800 Subject: [PATCH] fs: Remove "bind" flag check Felica requires also prevent mount external storage to these paths. The external storage mount is a real block device instead of bind, so remove the "bind" check. The secid of "u:r:su:s0" equals "u:r:init:s0" at init first stage, it will also prevent the init first stage mount, only when current secid is not same as "u:r:init:s0" and same as "u:r:su:s0", we prevents the mount. The below commands should be blocked. adb shell mount -r -w /dev/block/vold/public:179,1 /system adb shell mount -r -w /dev/block/vold/public:179,1 /system_ext adb shell mount -r -w /dev/block/vold/public:179,1 /product adb shell mount -r -w /dev/block/vold/public:179,1 /vendor Change-Id: I0e3ca33b0dd4bd67910a9d2296e297cda542016a Reviewed-on: https://gerrit.mot.com/2177550 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Huosheng Liao Submit-Approved: Jira Key --- fs/namespace.c | 20 +++++++++++++------- 1 file changed, 13 insertions(+), 7 deletions(-) diff --git a/fs/namespace.c b/fs/namespace.c index 8c1b585a3065..fa63b49e993b 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -3106,19 +3106,24 @@ char *copy_mount_string(const void __user *data) * adb shell mount -r -w sdcard /system_ext * adb shell mount -r -w sdcard /product * adb shell mount -r -w sdcard /vendor + * adb shell mount -r -w /dev/block/vold/public:179,1 /system + * adb shell mount -r -w /dev/block/vold/public:179,1 /system_ext + * adb shell mount -r -w /dev/block/vold/public:179,1 /product + * adb shell mount -r -w /dev/block/vold/public:179,1 /vendor */ static bool mount_block_check(unsigned long flags, struct path *path) { int i; - u32 secid, su_secid; - const char *su_secctx = "u:r:su:s0"; char *buf, *pathname; + u32 secid, su_secid, init_secid; + const char *su_secctx = "u:r:su:s0"; + const char *init_secctx = "u:r:init:s0"; const char *blocklist[] = {"/system", "/system_ext", "/product", "/vendor", "/odm", "/oem"}; int len = ARRAY_SIZE(blocklist); bool ret = false; - /* These commands would mount with "bind" flag */ - if (!(flags & MS_BIND)) + /* "adb remount" is allowed */ + if (flags & MS_REMOUNT) return ret; buf = (char *)__get_free_page(GFP_KERNEL); @@ -3138,11 +3143,12 @@ static bool mount_block_check(unsigned long flags, struct path *path) goto out_putname; security_secctx_to_secid(su_secctx, strlen(su_secctx), &su_secid); + security_secctx_to_secid(init_secctx, strlen(init_secctx), &init_secid); security_task_getsecid(current, &secid); - /* "su" should be blocked */ - if (secid == su_secid) { - pr_warn("Mount on %s is not allowed\n", pathname); + /* "su" should be blocked, the secid of su equals init at init first stage*/ + if ((secid != init_secid) && (secid == su_secid)) { + pr_warn("Mount on %s is not allowed with %d\n", pathname, secid); ret = true; }