blob: 00e211c77f2b69d61bc207a575a27eda634f3e67 [file] [log] [blame]
Mark Salyzyn12717162014-04-29 15:49:14 -07001/*
Ashish Sharma8626cce2011-07-07 18:16:01 -07002** Copyright 2011, The Android Open Source Project
3**
4** Licensed under the Apache License, Version 2.0 (the "License");
5** you may not use this file except in compliance with the License.
6** You may obtain a copy of the License at
7**
8** http://www.apache.org/licenses/LICENSE-2.0
9**
10** Unless required by applicable law or agreed to in writing, software
11** distributed under the License is distributed on an "AS IS" BASIS,
12** WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13** See the License for the specific language governing permissions and
14** limitations under the License.
15*/
16
JP Abgrall29656d32011-09-22 14:25:10 -070017// #define LOG_NDEBUG 0
18
Ashish Sharma8626cce2011-07-07 18:16:01 -070019#define LOG_TAG "qtaguid"
20
Ashish Sharma9b5c7742011-08-03 00:31:19 -070021#include <errno.h>
Ashish Sharma8626cce2011-07-07 18:16:01 -070022#include <fcntl.h>
Mark Salyzyn0425b642014-03-07 15:08:20 -080023#include <inttypes.h>
24#include <pthread.h>
Ashish Sharma8626cce2011-07-07 18:16:01 -070025#include <stdio.h>
26#include <string.h>
27#include <unistd.h>
Mark Salyzyn0425b642014-03-07 15:08:20 -080028
29#include <cutils/qtaguid.h>
30#include <log/log.h>
Ashish Sharma8626cce2011-07-07 18:16:01 -070031
JP Abgrall243123f2011-09-09 15:02:08 -070032static const char* CTRL_PROCPATH = "/proc/net/xt_qtaguid/ctrl";
33static const int CTRL_MAX_INPUT_LEN = 128;
34static const char *GLOBAL_PACIFIER_PARAM = "/sys/module/xt_qtaguid/parameters/passive";
35static const char *TAG_PACIFIER_PARAM = "/sys/module/xt_qtaguid/parameters/tag_tracking_passive";
Ashish Sharma8626cce2011-07-07 18:16:01 -070036
JP Abgrall243123f2011-09-09 15:02:08 -070037/*
38 * One per proccess.
39 * Once the device is open, this process will have its socket tags tracked.
40 * And on exit or untimely death, all socket tags will be removed.
41 * A process can only open /dev/xt_qtaguid once.
42 * It should not close it unless it is really done with all the socket tags.
43 * Failure to open it will be visible when socket tagging will be attempted.
44 */
45static int resTrackFd = -1;
46pthread_once_t resTrackInitDone = PTHREAD_ONCE_INIT;
47
48/* Only call once per process. */
49void qtaguid_resTrack(void) {
50 resTrackFd = TEMP_FAILURE_RETRY(open("/dev/xt_qtaguid", O_RDONLY));
51 if (resTrackFd >=0) {
52 TEMP_FAILURE_RETRY(fcntl(resTrackFd, F_SETFD, FD_CLOEXEC));
53 }
54}
55
56/*
57 * Returns:
58 * 0 on success.
59 * -errno on failure.
60 */
61static int write_ctrl(const char *cmd) {
62 int fd, res, savedErrno;
63
Steve Block69f4cd72011-10-20 11:54:09 +010064 ALOGV("write_ctrl(%s)", cmd);
JP Abgrall243123f2011-09-09 15:02:08 -070065
66 fd = TEMP_FAILURE_RETRY(open(CTRL_PROCPATH, O_WRONLY));
Ashish Sharma9b5c7742011-08-03 00:31:19 -070067 if (fd < 0) {
68 return -errno;
69 }
Ashish Sharma8626cce2011-07-07 18:16:01 -070070
JP Abgrall243123f2011-09-09 15:02:08 -070071 res = TEMP_FAILURE_RETRY(write(fd, cmd, strlen(cmd)));
72 if (res < 0) {
73 savedErrno = errno;
74 } else {
75 savedErrno = 0;
76 }
77 if (res < 0) {
Steve Blockfe71a612012-01-04 19:19:03 +000078 ALOGI("Failed write_ctrl(%s) res=%d errno=%d", cmd, res, savedErrno);
JP Abgrall243123f2011-09-09 15:02:08 -070079 }
80 close(fd);
81 return -savedErrno;
82}
83
84static int write_param(const char *param_path, const char *value) {
85 int param_fd;
86 int res;
87
88 param_fd = TEMP_FAILURE_RETRY(open(param_path, O_WRONLY));
89 if (param_fd < 0) {
90 return -errno;
91 }
92 res = TEMP_FAILURE_RETRY(write(param_fd, value, strlen(value)));
93 if (res < 0) {
94 return -errno;
95 }
96 close(param_fd);
97 return 0;
98}
99
100int qtaguid_tagSocket(int sockfd, int tag, uid_t uid) {
101 char lineBuf[CTRL_MAX_INPUT_LEN];
102 int res;
Jeff Sharkeye34b9172012-05-02 16:01:31 -0700103 uint64_t kTag = ((uint64_t)tag << 32);
JP Abgrall243123f2011-09-09 15:02:08 -0700104
105 pthread_once(&resTrackInitDone, qtaguid_resTrack);
106
Mark Salyzyn0425b642014-03-07 15:08:20 -0800107 snprintf(lineBuf, sizeof(lineBuf), "t %d %" PRIu64 " %d", sockfd, kTag, uid);
JP Abgrall243123f2011-09-09 15:02:08 -0700108
Mark Salyzyn0425b642014-03-07 15:08:20 -0800109 ALOGV("Tagging socket %d with tag %" PRIx64 "{%u,0} for uid %d", sockfd, kTag, tag, uid);
JP Abgrall243123f2011-09-09 15:02:08 -0700110
111 res = write_ctrl(lineBuf);
112 if (res < 0) {
Mark Salyzyn0425b642014-03-07 15:08:20 -0800113 ALOGI("Tagging socket %d with tag %" PRIx64 "(%d) for uid %d failed errno=%d",
JP Abgrall243123f2011-09-09 15:02:08 -0700114 sockfd, kTag, tag, uid, res);
Ashish Sharma9b5c7742011-08-03 00:31:19 -0700115 }
116
Ashish Sharma9b5c7742011-08-03 00:31:19 -0700117 return res;
118}
119
JP Abgrall243123f2011-09-09 15:02:08 -0700120int qtaguid_untagSocket(int sockfd) {
121 char lineBuf[CTRL_MAX_INPUT_LEN];
122 int res;
Ashish Sharma9b5c7742011-08-03 00:31:19 -0700123
Steve Block69f4cd72011-10-20 11:54:09 +0100124 ALOGV("Untagging socket %d", sockfd);
JP Abgrall243123f2011-09-09 15:02:08 -0700125
126 snprintf(lineBuf, sizeof(lineBuf), "u %d", sockfd);
127 res = write_ctrl(lineBuf);
128 if (res < 0) {
Steve Blockfe71a612012-01-04 19:19:03 +0000129 ALOGI("Untagging socket %d failed errno=%d", sockfd, res);
JP Abgrall243123f2011-09-09 15:02:08 -0700130 }
131
132 return res;
133}
134
135int qtaguid_setCounterSet(int counterSetNum, uid_t uid) {
136 char lineBuf[CTRL_MAX_INPUT_LEN];
137 int res;
138
Steve Block69f4cd72011-10-20 11:54:09 +0100139 ALOGV("Setting counters to set %d for uid %d", counterSetNum, uid);
JP Abgrall243123f2011-09-09 15:02:08 -0700140
141 snprintf(lineBuf, sizeof(lineBuf), "s %d %d", counterSetNum, uid);
142 res = write_ctrl(lineBuf);
143 return res;
144}
145
146int qtaguid_deleteTagData(int tag, uid_t uid) {
147 char lineBuf[CTRL_MAX_INPUT_LEN];
Mark Salyzyn12717162014-04-29 15:49:14 -0700148 int cnt = 0, res = 0;
JP Abgrall243123f2011-09-09 15:02:08 -0700149 uint64_t kTag = (uint64_t)tag << 32;
150
Mark Salyzyn0425b642014-03-07 15:08:20 -0800151 ALOGV("Deleting tag data with tag %" PRIx64 "{%d,0} for uid %d", kTag, tag, uid);
JP Abgrall243123f2011-09-09 15:02:08 -0700152
153 pthread_once(&resTrackInitDone, qtaguid_resTrack);
154
Mark Salyzyn0425b642014-03-07 15:08:20 -0800155 snprintf(lineBuf, sizeof(lineBuf), "d %" PRIu64 " %d", kTag, uid);
JP Abgrall243123f2011-09-09 15:02:08 -0700156 res = write_ctrl(lineBuf);
157 if (res < 0) {
Mark Salyzyn0425b642014-03-07 15:08:20 -0800158 ALOGI("Deleting tag data with tag %" PRIx64 "/%d for uid %d failed with cnt=%d errno=%d",
JP Abgrall243123f2011-09-09 15:02:08 -0700159 kTag, tag, uid, cnt, errno);
160 }
161
162 return res;
163}
164
165int qtaguid_setPacifier(int on) {
JP Abgrall243123f2011-09-09 15:02:08 -0700166 const char *value;
167
168 value = on ? "Y" : "N";
169 if (write_param(GLOBAL_PACIFIER_PARAM, value) < 0) {
Ashish Sharma9b5c7742011-08-03 00:31:19 -0700170 return -errno;
171 }
JP Abgrall243123f2011-09-09 15:02:08 -0700172 if (write_param(TAG_PACIFIER_PARAM, value) < 0) {
173 return -errno;
Ashish Sharma9b5c7742011-08-03 00:31:19 -0700174 }
JP Abgrall243123f2011-09-09 15:02:08 -0700175 return 0;
Ashish Sharma8626cce2011-07-07 18:16:01 -0700176}