Enable vold to set level from user.

We want various per-user directories to have their SELinux MLS level
set to restrict access from other users, as an improvement to user
isolation.

We extend vold_prepare_subdirs to implement this if a flag is
set. vold itself then sets the flag based on a new property,
ro.vold.level_from_user. This is to allow testing of further
incremental work to ensure system apps correctly handle the new
restriction on different devices rather than causing immediate
breakage. Eventually this will go away and the restriction will apply
everywhere.

Bug: 141677108
Test: Manual, with and without propery set.
Change-Id: I8e2207bd94b487bdcc09fd4d80b031027dfea1e3
This commit is contained in:
Alan Stokes 2020-02-07 09:29:38 +00:00
parent d70e2b4ea9
commit be3db7b7ae
3 changed files with 57 additions and 9 deletions

View file

@ -791,6 +791,11 @@ bool fscrypt_lock_user_key(userid_t user_id) {
static bool prepare_subdirs(const std::string& action, const std::string& volume_uuid, static bool prepare_subdirs(const std::string& action, const std::string& volume_uuid,
userid_t user_id, int flags) { userid_t user_id, int flags) {
// TODO(b/141677108): Remove this & make it the default behavior
if (android::base::GetProperty("ro.vold.level_from_user", "0") == "1") {
flags |= android::os::IVold::STORAGE_FLAG_LEVEL_FROM_USER;
}
if (0 != android::vold::ForkExecvp( if (0 != android::vold::ForkExecvp(
std::vector<std::string>{prepare_subdirs_path, action, volume_uuid, std::vector<std::string>{prepare_subdirs_path, action, volume_uuid,
std::to_string(user_id), std::to_string(flags)})) { std::to_string(user_id), std::to_string(flags)})) {

View file

@ -164,6 +164,7 @@ interface IVold {
const int STORAGE_FLAG_DE = 1; const int STORAGE_FLAG_DE = 1;
const int STORAGE_FLAG_CE = 2; const int STORAGE_FLAG_CE = 2;
const int STORAGE_FLAG_LEVEL_FROM_USER = 4;
const int REMOUNT_MODE_NONE = 0; const int REMOUNT_MODE_NONE = 0;
const int REMOUNT_MODE_DEFAULT = 1; const int REMOUNT_MODE_DEFAULT = 1;

View file

@ -54,20 +54,33 @@ static bool valid_uuid(const std::string& s) {
return s.size() < 40 && s.find_first_not_of("0123456789abcdefABCDEF-_") == std::string::npos; return s.size() < 40 && s.find_first_not_of("0123456789abcdefABCDEF-_") == std::string::npos;
} }
static bool prepare_dir(struct selabel_handle* sehandle, mode_t mode, uid_t uid, gid_t gid, static bool prepare_dir_for_user(struct selabel_handle* sehandle, mode_t mode, uid_t uid, gid_t gid,
const std::string& path) { const std::string& path, uid_t user_id) {
auto clearfscreatecon = android::base::make_scope_guard([] { setfscreatecon(nullptr); }); auto clearfscreatecon = android::base::make_scope_guard([] { setfscreatecon(nullptr); });
auto secontext = std::unique_ptr<char, void (*)(char*)>(nullptr, freecon); auto secontext = std::unique_ptr<char, void (*)(char*)>(nullptr, freecon);
char* tmp_secontext; if (sehandle) {
if (sehandle && selabel_lookup(sehandle, &tmp_secontext, path.c_str(), S_IFDIR) == 0) { char* tmp_secontext;
secontext.reset(tmp_secontext);
if (selabel_lookup(sehandle, &tmp_secontext, path.c_str(), S_IFDIR) == 0) {
secontext.reset(tmp_secontext);
if (user_id != (uid_t)-1) {
if (selinux_android_context_with_level(secontext.get(), &tmp_secontext, user_id,
(uid_t)-1) != 0) {
PLOG(ERROR) << "Unable to create context with level for: " << path;
return false;
}
secontext.reset(tmp_secontext); // Free the context
}
}
} }
LOG(DEBUG) << "Setting up mode " << std::oct << mode << std::dec << " uid " << uid << " gid " LOG(DEBUG) << "Setting up mode " << std::oct << mode << std::dec << " uid " << uid << " gid "
<< gid << " context " << (secontext ? secontext.get() : "null") << gid << " context " << (secontext ? secontext.get() : "null")
<< " on path: " << path; << " on path: " << path;
if (secontext) { if (secontext) {
if (setfscreatecon(secontext.get()) != 0) { if (setfscreatecon(secontext.get()) != 0) {
PLOG(ERROR) << "Unable to read setfscreatecon for: " << path; PLOG(ERROR) << "Unable to setfscreatecon for: " << path;
return false; return false;
} }
} }
@ -93,6 +106,11 @@ static bool prepare_dir(struct selabel_handle* sehandle, mode_t mode, uid_t uid,
return true; return true;
} }
static bool prepare_dir(struct selabel_handle* sehandle, mode_t mode, uid_t uid, gid_t gid,
const std::string& path) {
return prepare_dir_for_user(sehandle, mode, uid, gid, path, (uid_t)-1);
}
static bool rmrf_contents(const std::string& path) { static bool rmrf_contents(const std::string& path) {
auto dirp = std::unique_ptr<DIR, int (*)(DIR*)>(opendir(path.c_str()), closedir); auto dirp = std::unique_ptr<DIR, int (*)(DIR*)>(opendir(path.c_str()), closedir);
if (!dirp) { if (!dirp) {
@ -148,8 +166,17 @@ static bool prepare_apex_subdirs(struct selabel_handle* sehandle, const std::str
static bool prepare_subdirs(const std::string& volume_uuid, int user_id, int flags) { static bool prepare_subdirs(const std::string& volume_uuid, int user_id, int flags) {
struct selabel_handle* sehandle = selinux_android_file_context_handle(); struct selabel_handle* sehandle = selinux_android_file_context_handle();
if (volume_uuid.empty()) { const uid_t user_for_level =
if (flags & android::os::IVold::STORAGE_FLAG_DE) { (flags & android::os::IVold::STORAGE_FLAG_LEVEL_FROM_USER) ? user_id : -1;
if (flags & android::os::IVold::STORAGE_FLAG_DE) {
auto user_de_path = android::vold::BuildDataUserDePath(volume_uuid, user_id);
if (!prepare_dir_for_user(sehandle, 0771, AID_SYSTEM, AID_SYSTEM, user_de_path,
user_for_level)) {
return false;
}
if (volume_uuid.empty()) {
auto misc_de_path = android::vold::BuildDataMiscDePath(user_id); auto misc_de_path = android::vold::BuildDataMiscDePath(user_id);
if (!prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/vold")) return false; if (!prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/vold")) return false;
if (!prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/storaged")) return false; if (!prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/storaged")) return false;
@ -158,6 +185,12 @@ static bool prepare_subdirs(const std::string& volume_uuid, int user_id, int fla
prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/apexrollback"); prepare_dir(sehandle, 0700, 0, 0, misc_de_path + "/apexrollback");
prepare_apex_subdirs(sehandle, misc_de_path); prepare_apex_subdirs(sehandle, misc_de_path);
auto profiles_de_path = android::vold::BuildDataProfilesDePath(user_id);
if (!prepare_dir_for_user(sehandle, 0771, AID_SYSTEM, AID_SYSTEM, profiles_de_path,
user_for_level)) {
return false;
}
auto vendor_de_path = android::vold::BuildDataVendorDePath(user_id); auto vendor_de_path = android::vold::BuildDataVendorDePath(user_id);
if (!prepare_dir(sehandle, 0700, AID_SYSTEM, AID_SYSTEM, vendor_de_path + "/fpdata")) { if (!prepare_dir(sehandle, 0700, AID_SYSTEM, AID_SYSTEM, vendor_de_path + "/fpdata")) {
return false; return false;
@ -167,11 +200,20 @@ static bool prepare_subdirs(const std::string& volume_uuid, int user_id, int fla
return false; return false;
} }
} }
if (flags & android::os::IVold::STORAGE_FLAG_CE) { }
if (flags & android::os::IVold::STORAGE_FLAG_CE) {
auto user_ce_path = android::vold::BuildDataUserCePath(volume_uuid, user_id);
if (!prepare_dir_for_user(sehandle, 0771, AID_SYSTEM, AID_SYSTEM, user_ce_path,
user_for_level)) {
return false;
}
if (volume_uuid.empty()) {
auto misc_ce_path = android::vold::BuildDataMiscCePath(user_id); auto misc_ce_path = android::vold::BuildDataMiscCePath(user_id);
if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/vold")) return false; if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/vold")) return false;
if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/storaged")) return false; if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/storaged")) return false;
if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/rollback")) return false; if (!prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/rollback")) return false;
// TODO: Return false if this returns false once sure this should succeed. // TODO: Return false if this returns false once sure this should succeed.
prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/apexrollback"); prepare_dir(sehandle, 0700, 0, 0, misc_ce_path + "/apexrollback");
prepare_apex_subdirs(sehandle, misc_ce_path); prepare_apex_subdirs(sehandle, misc_ce_path);