android_kernel_motorola_sm6375/security/tomoyo
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Tetsuo Handa 3ba06256d2 tomoyo: fallback to realpath if symlink's pathname does not exist
commit ada1986d07976d60bed5017aa38b7f7cf27883f7 upstream.

Alfred Agrell found that TOMOYO cannot handle execveat(AT_EMPTY_PATH)
inside chroot environment where /dev and /proc are not mounted, for
commit 51f39a1f0c ("syscalls: implement execveat() system call") missed
that TOMOYO tries to canonicalize argv[0] when the filename fed to the
executed program as argv[0] is supplied using potentially nonexistent
pathname.

Since "/dev/fd/<fd>" already lost symlink information used for obtaining
that <fd>, it is too late to reconstruct symlink's pathname. Although
<filename> part of "/dev/fd/<fd>/<filename>" might not be canonicalized,
TOMOYO cannot use tomoyo_realpath_nofollow() when /dev or /proc is not
mounted. Therefore, fallback to tomoyo_realpath_from_path() when
tomoyo_realpath_nofollow() failed.

Reported-by: Alfred Agrell <blubban@gmail.com>
Closes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1082001
Fixes: 51f39a1f0c ("syscalls: implement execveat() system call")
Cc: stable@vger.kernel.org # v3.19+
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-08 16:20:41 +01:00
..
policy
.gitignore
audit.c
common.c
common.h
condition.c
domain.c tomoyo: fallback to realpath if symlink's pathname does not exist 2024-11-08 16:20:41 +01:00
environ.c
file.c
gc.c
group.c
Kconfig
load_policy.c
Makefile tomoyo: fix broken dependency on *.conf.default 2023-02-06 07:52:35 +01:00
memory.c
mount.c
network.c
realpath.c
securityfs_if.c
tomoyo.c lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
util.c