2006-03-18 03:35:02 +03:00
|
|
|
/* $NetBSD: policy.c,v 1.21 2006/03/18 00:35:02 peter Exp $ */
|
2002-08-28 07:52:44 +04:00
|
|
|
/* $OpenBSD: policy.c,v 1.15 2002/08/07 00:34:17 vincent Exp $ */
|
2002-06-17 20:29:07 +04:00
|
|
|
/*
|
|
|
|
* Copyright 2002 Niels Provos <provos@citi.umich.edu>
|
|
|
|
* All rights reserved.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
* 3. All advertising materials mentioning features or use of this software
|
|
|
|
* must display the following acknowledgement:
|
|
|
|
* This product includes software developed by Niels Provos.
|
|
|
|
* 4. The name of the author may not be used to endorse or promote products
|
|
|
|
* derived from this software without specific prior written permission.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
|
|
|
|
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
|
|
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
|
|
|
|
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
|
|
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
|
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
|
|
|
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
#include <sys/cdefs.h>
|
2006-03-18 03:35:02 +03:00
|
|
|
__RCSID("$NetBSD: policy.c,v 1.21 2006/03/18 00:35:02 peter Exp $");
|
2002-06-17 20:29:07 +04:00
|
|
|
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/param.h>
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include <sys/tree.h>
|
2002-09-23 08:35:41 +04:00
|
|
|
#include <dirent.h>
|
2002-07-30 20:29:28 +04:00
|
|
|
#include <limits.h>
|
2002-06-17 20:29:07 +04:00
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
|
|
|
#include <unistd.h>
|
|
|
|
#include <grp.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <fcntl.h>
|
|
|
|
#include <ctype.h>
|
|
|
|
#include <err.h>
|
|
|
|
|
|
|
|
#include "intercept.h"
|
|
|
|
#include "systrace.h"
|
|
|
|
|
|
|
|
static int psccompare(struct policy_syscall *, struct policy_syscall *);
|
|
|
|
static int policycompare(struct policy *, struct policy *);
|
|
|
|
static int polnrcompare(struct policy *, struct policy *);
|
2005-06-25 03:21:09 +04:00
|
|
|
static char *systrace_policyfilename(const char *, const char *);
|
2002-09-17 09:07:21 +04:00
|
|
|
static char *systrace_policyline(char *line);
|
2002-10-08 18:49:23 +04:00
|
|
|
static int systrace_policyprocess(struct policy *,
|
|
|
|
char *);
|
2002-06-17 20:29:07 +04:00
|
|
|
static int systrace_writepolicy(struct policy *);
|
|
|
|
|
2002-09-17 09:07:21 +04:00
|
|
|
int systrace_templatedir(void);
|
|
|
|
|
2002-06-17 20:29:07 +04:00
|
|
|
static int
|
|
|
|
psccompare(struct policy_syscall *a, struct policy_syscall *b)
|
|
|
|
{
|
|
|
|
int diff;
|
|
|
|
diff = strcmp(a->emulation, b->emulation);
|
|
|
|
if (diff)
|
|
|
|
return (diff);
|
|
|
|
return (strcmp(a->name, b->name));
|
|
|
|
}
|
|
|
|
|
|
|
|
SPLAY_PROTOTYPE(syscalltree, policy_syscall, node, psccompare);
|
|
|
|
SPLAY_GENERATE(syscalltree, policy_syscall, node, psccompare);
|
|
|
|
|
|
|
|
static SPLAY_HEAD(policytree, policy) policyroot;
|
|
|
|
static SPLAY_HEAD(polnrtree, policy) polnrroot;
|
|
|
|
|
2002-07-30 20:29:28 +04:00
|
|
|
int
|
2002-06-17 20:29:07 +04:00
|
|
|
policycompare(struct policy *a, struct policy *b)
|
|
|
|
{
|
|
|
|
return (strcmp(a->name, b->name));
|
|
|
|
}
|
|
|
|
|
2002-07-30 20:29:28 +04:00
|
|
|
int
|
2002-06-17 20:29:07 +04:00
|
|
|
polnrcompare(struct policy *a, struct policy *b)
|
|
|
|
{
|
|
|
|
int diff = a->policynr - b->policynr;
|
|
|
|
|
|
|
|
if (diff == 0)
|
|
|
|
return (0);
|
|
|
|
if (diff > 0 )
|
|
|
|
return (1);
|
|
|
|
return (-1);
|
|
|
|
}
|
|
|
|
|
|
|
|
SPLAY_PROTOTYPE(policytree, policy, node, policycompare);
|
|
|
|
SPLAY_GENERATE(policytree, policy, node, policycompare);
|
|
|
|
|
|
|
|
SPLAY_PROTOTYPE(polnrtree, policy, nrnode, polnrcompare);
|
|
|
|
SPLAY_GENERATE(polnrtree, policy, nrnode, polnrcompare);
|
|
|
|
|
|
|
|
extern int userpolicy;
|
|
|
|
|
|
|
|
static char policydir[MAXPATHLEN];
|
|
|
|
|
2002-09-23 08:35:41 +04:00
|
|
|
struct tmplqueue templates;
|
|
|
|
|
2002-07-30 20:29:28 +04:00
|
|
|
void
|
2002-08-28 07:52:44 +04:00
|
|
|
systrace_setupdir(char *path)
|
2002-06-17 20:29:07 +04:00
|
|
|
{
|
|
|
|
char *home;
|
|
|
|
struct stat sb;
|
|
|
|
|
2002-08-28 07:52:44 +04:00
|
|
|
if (path == NULL) {
|
|
|
|
home = getenv("HOME");
|
2002-06-17 20:29:07 +04:00
|
|
|
|
2002-08-28 07:52:44 +04:00
|
|
|
if (home == NULL)
|
|
|
|
errx(1, "No HOME environment set");
|
2002-06-17 20:29:07 +04:00
|
|
|
|
2006-03-18 03:35:02 +03:00
|
|
|
if (strlcpy(policydir, home, sizeof(policydir)) >=
|
|
|
|
sizeof(policydir))
|
2002-08-28 07:52:44 +04:00
|
|
|
errx(1, "HOME too long");
|
2002-06-17 20:29:07 +04:00
|
|
|
|
2006-03-18 03:35:02 +03:00
|
|
|
if (strlcat(policydir, "/.systrace", sizeof(policydir)) >=
|
|
|
|
sizeof(policydir))
|
2002-08-28 07:52:44 +04:00
|
|
|
errx(1, "HOME too long");
|
2006-03-18 03:35:02 +03:00
|
|
|
} else if (strlcpy(policydir, path, sizeof(policydir)) >=
|
|
|
|
sizeof(policydir))
|
2002-08-28 07:52:44 +04:00
|
|
|
errx(1, "policy directory too long");
|
|
|
|
|
2002-06-17 20:29:07 +04:00
|
|
|
|
|
|
|
if (stat(policydir, &sb) != -1) {
|
|
|
|
if (!(sb.st_mode & S_IFDIR))
|
|
|
|
errx(1, "Not a directory: \"%s\"", policydir);
|
|
|
|
} else if (mkdir(policydir, 0700) == -1)
|
2003-03-26 20:00:57 +03:00
|
|
|
err(1, "mkdir(%s)", policydir);
|
2002-06-17 20:29:07 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
int
|
2002-08-28 07:52:44 +04:00
|
|
|
systrace_initpolicy(char *file, char *path)
|
2002-06-17 20:29:07 +04:00
|
|
|
{
|
|
|
|
SPLAY_INIT(&policyroot);
|
|
|
|
SPLAY_INIT(&polnrroot);
|
|
|
|
|
2002-09-23 08:35:41 +04:00
|
|
|
if (userpolicy) {
|
2002-08-28 07:52:44 +04:00
|
|
|
systrace_setupdir(path);
|
2002-09-23 08:35:41 +04:00
|
|
|
systrace_templatedir();
|
|
|
|
}
|
2002-06-17 20:29:07 +04:00
|
|
|
|
|
|
|
if (file != NULL)
|
|
|
|
return (systrace_readpolicy(file));
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|
|
|
|
|
|
|
|
struct policy *
|
|
|
|
systrace_findpolicy(const char *name)
|
|
|
|
{
|
|
|
|
struct policy tmp;
|
|
|
|
|
|
|
|
tmp.name = name;
|
|
|
|
|
|
|
|
return (SPLAY_FIND(policytree, &policyroot, &tmp));
|
|
|
|
}
|
|
|
|
|
|
|
|
struct policy *
|
|
|
|
systrace_findpolnr(int nr)
|
|
|
|
{
|
|
|
|
struct policy tmp;
|
|
|
|
|
|
|
|
tmp.policynr = nr;
|
|
|
|
|
|
|
|
return (SPLAY_FIND(polnrtree, &polnrroot, &tmp));
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
systrace_newpolicynr(int fd, struct policy *tmp)
|
|
|
|
{
|
|
|
|
if (tmp->policynr != -1)
|
|
|
|
return (-1);
|
|
|
|
|
|
|
|
if ((tmp->policynr = intercept_newpolicy(fd)) == -1) {
|
2003-06-01 04:12:34 +04:00
|
|
|
/* XXX - maybe free policy structure here */
|
2002-06-17 20:29:07 +04:00
|
|
|
return (-1);
|
|
|
|
}
|
|
|
|
|
|
|
|
SPLAY_INSERT(polnrtree, &polnrroot, tmp);
|
|
|
|
|
|
|
|
return (tmp->policynr);
|
|
|
|
}
|
|
|
|
|
|
|
|
struct policy *
|
|
|
|
systrace_newpolicy(const char *emulation, const char *name)
|
|
|
|
{
|
|
|
|
struct policy *tmp;
|
|
|
|
|
|
|
|
if ((tmp = systrace_findpolicy(name)) != NULL)
|
|
|
|
return (tmp);
|
|
|
|
|
|
|
|
tmp = calloc(1, sizeof(struct policy));
|
|
|
|
if (tmp == NULL)
|
|
|
|
return (NULL);
|
|
|
|
|
|
|
|
tmp->policynr = -1;
|
|
|
|
|
|
|
|
/* New policies requires intialization */
|
|
|
|
if ((tmp->name = strdup(name)) == NULL)
|
|
|
|
err(1, "%s:%d: strdup", __func__, __LINE__);
|
|
|
|
strlcpy(tmp->emulation, emulation, sizeof(tmp->emulation));
|
|
|
|
|
|
|
|
SPLAY_INSERT(policytree, &policyroot, tmp);
|
|
|
|
SPLAY_INIT(&tmp->pflqs);
|
|
|
|
TAILQ_INIT(&tmp->filters);
|
|
|
|
TAILQ_INIT(&tmp->prefilters);
|
|
|
|
|
|
|
|
return (tmp);
|
|
|
|
}
|
|
|
|
|
2003-06-03 08:33:44 +04:00
|
|
|
void
|
|
|
|
systrace_freepolicy(struct policy *policy)
|
|
|
|
{
|
|
|
|
struct filter *filter;
|
|
|
|
struct policy_syscall *pflq;
|
|
|
|
|
|
|
|
if (policy->flags & POLICY_CHANGED) {
|
|
|
|
if (systrace_writepolicy(policy) == -1)
|
|
|
|
fprintf(stderr, "Failed to write policy for %s\n",
|
|
|
|
policy->name);
|
|
|
|
}
|
|
|
|
|
|
|
|
while ((filter = TAILQ_FIRST(&policy->prefilters)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&policy->prefilters, filter, policy_next);
|
|
|
|
filter_free(filter);
|
|
|
|
}
|
|
|
|
|
|
|
|
while ((filter = TAILQ_FIRST(&policy->filters)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&policy->filters, filter, policy_next);
|
|
|
|
filter_free(filter);
|
|
|
|
}
|
|
|
|
|
|
|
|
while ((pflq = SPLAY_ROOT(&policy->pflqs)) != NULL) {
|
|
|
|
SPLAY_REMOVE(syscalltree, &policy->pflqs, pflq);
|
|
|
|
|
|
|
|
while ((filter = TAILQ_FIRST(&pflq->flq)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&pflq->flq, filter, next);
|
|
|
|
filter_free(filter);
|
|
|
|
}
|
|
|
|
|
|
|
|
free(pflq);
|
|
|
|
}
|
|
|
|
|
|
|
|
SPLAY_REMOVE(policytree, &policyroot, policy);
|
|
|
|
if (policy->policynr != -1)
|
|
|
|
SPLAY_REMOVE(polnrtree, &polnrroot, policy);
|
|
|
|
|
2005-06-25 03:21:09 +04:00
|
|
|
/* XXX: */
|
|
|
|
free((char *)__UNCONST(policy->name));
|
2003-06-03 08:33:44 +04:00
|
|
|
free(policy);
|
|
|
|
}
|
|
|
|
|
2002-06-17 20:29:07 +04:00
|
|
|
struct filterq *
|
|
|
|
systrace_policyflq(struct policy *policy, const char *emulation,
|
|
|
|
const char *name)
|
|
|
|
{
|
|
|
|
struct policy_syscall tmp2, *tmp;
|
|
|
|
|
|
|
|
strlcpy(tmp2.emulation, emulation, sizeof(tmp2.emulation));
|
|
|
|
strlcpy(tmp2.name, name, sizeof(tmp2.name));
|
|
|
|
|
|
|
|
tmp = SPLAY_FIND(syscalltree, &policy->pflqs, &tmp2);
|
|
|
|
if (tmp != NULL)
|
|
|
|
return (&tmp->flq);
|
|
|
|
|
|
|
|
if ((tmp = calloc(1, sizeof(struct policy_syscall))) == NULL)
|
|
|
|
err(1, "%s:%d: out of memory", __func__, __LINE__);
|
|
|
|
|
|
|
|
strlcpy(tmp->emulation, emulation, sizeof(tmp->emulation));
|
|
|
|
strlcpy(tmp->name, name, sizeof(tmp->name));
|
|
|
|
TAILQ_INIT(&tmp->flq);
|
|
|
|
|
|
|
|
SPLAY_INSERT(syscalltree, &policy->pflqs, tmp);
|
|
|
|
|
|
|
|
return (&tmp->flq);
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
systrace_modifypolicy(int fd, int policynr, const char *name, short action)
|
|
|
|
{
|
|
|
|
struct policy *policy;
|
|
|
|
int res;
|
|
|
|
|
|
|
|
if ((policy = systrace_findpolnr(policynr)) == NULL)
|
|
|
|
return (-1);
|
|
|
|
|
|
|
|
res = intercept_modifypolicy(fd, policynr, policy->emulation,
|
2002-07-30 20:29:28 +04:00
|
|
|
name, action);
|
2002-06-17 20:29:07 +04:00
|
|
|
|
|
|
|
return (res);
|
|
|
|
}
|
|
|
|
|
2002-07-30 20:29:28 +04:00
|
|
|
char *
|
2005-06-25 03:21:09 +04:00
|
|
|
systrace_policyfilename(const char *dirname, const char *name)
|
2002-06-17 20:29:07 +04:00
|
|
|
{
|
|
|
|
static char file[2*MAXPATHLEN];
|
|
|
|
const char *p;
|
|
|
|
int i, plen;
|
|
|
|
|
|
|
|
if (strlen(name) + strlen(dirname) + 1 >= sizeof(file))
|
|
|
|
return (NULL);
|
|
|
|
|
|
|
|
strlcpy(file, dirname, sizeof(file));
|
|
|
|
i = strlen(file);
|
|
|
|
file[i++] = '/';
|
|
|
|
plen = i;
|
|
|
|
|
|
|
|
p = name;
|
|
|
|
while (*p) {
|
2004-10-29 23:51:36 +04:00
|
|
|
if (!isalnum((unsigned char)*p)) {
|
2002-06-17 20:29:07 +04:00
|
|
|
if (i != plen)
|
|
|
|
file[i++] = '_';
|
|
|
|
} else
|
|
|
|
file[i++] = *p;
|
|
|
|
p++;
|
|
|
|
}
|
|
|
|
|
|
|
|
file[i] = '\0';
|
|
|
|
|
|
|
|
return (file);
|
|
|
|
}
|
|
|
|
|
2005-08-10 22:19:21 +04:00
|
|
|
char *
|
|
|
|
systrace_getpolicyfilename(const char *name)
|
2002-06-17 20:29:07 +04:00
|
|
|
{
|
|
|
|
char *file = NULL;
|
|
|
|
|
|
|
|
if (userpolicy) {
|
|
|
|
file = systrace_policyfilename(policydir, name);
|
2005-08-11 01:33:36 +04:00
|
|
|
/* Check if the user policy file exists */
|
2002-06-17 20:29:07 +04:00
|
|
|
if (file != NULL && access(file, R_OK) == -1)
|
|
|
|
file = NULL;
|
|
|
|
}
|
|
|
|
|
2005-08-11 01:33:36 +04:00
|
|
|
/* Read global policy */
|
2005-08-10 22:19:21 +04:00
|
|
|
if (file == NULL)
|
2002-06-17 20:29:07 +04:00
|
|
|
file = systrace_policyfilename(POLICY_PATH, name);
|
2005-08-10 22:19:21 +04:00
|
|
|
|
|
|
|
return (file);
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
systrace_addpolicy(const char *name)
|
|
|
|
{
|
|
|
|
char *file = NULL;
|
|
|
|
|
|
|
|
if ((file = systrace_getpolicyfilename(name)) == NULL)
|
|
|
|
return (-1);
|
2002-06-17 20:29:07 +04:00
|
|
|
|
|
|
|
return (systrace_readpolicy(file));
|
|
|
|
}
|
|
|
|
|
2002-09-23 08:35:41 +04:00
|
|
|
/*
|
|
|
|
* Reads policy templates from the template directory.
|
|
|
|
* These policies can be inserted during interactive policy
|
|
|
|
* generation.
|
|
|
|
*/
|
|
|
|
|
|
|
|
int
|
|
|
|
systrace_templatedir(void)
|
|
|
|
{
|
|
|
|
char filename[MAXPATHLEN];
|
|
|
|
DIR *dir = NULL;
|
|
|
|
struct stat sb;
|
|
|
|
struct dirent *dp;
|
|
|
|
struct template *template;
|
|
|
|
int off;
|
|
|
|
|
|
|
|
TAILQ_INIT(&templates);
|
|
|
|
|
|
|
|
if (userpolicy) {
|
|
|
|
if (strlcpy(filename, policydir, sizeof(filename)) >=
|
|
|
|
sizeof(filename))
|
|
|
|
goto error;
|
|
|
|
if (strlcat(filename, "/templates", sizeof(filename)) >=
|
|
|
|
sizeof(filename))
|
|
|
|
goto error;
|
|
|
|
|
|
|
|
/* Check if template directory exists */
|
|
|
|
if (stat(filename, &sb) != -1 && (sb.st_mode & S_IFDIR))
|
|
|
|
dir = opendir(filename);
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Read global policy */
|
|
|
|
if (dir == NULL) {
|
|
|
|
strlcpy(filename, POLICY_PATH, sizeof(filename));
|
|
|
|
strlcat(filename, "/templates", sizeof(filename));
|
|
|
|
if (stat(filename, &sb) != -1 && (sb.st_mode & S_IFDIR))
|
|
|
|
dir = opendir(filename);
|
|
|
|
if (dir == NULL)
|
|
|
|
return (-1);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (strlcat(filename, "/", sizeof(filename)) >= sizeof(filename))
|
|
|
|
goto error;
|
|
|
|
off = strlen(filename);
|
|
|
|
|
|
|
|
while ((dp = readdir(dir)) != NULL) {
|
|
|
|
filename[off] = '\0';
|
|
|
|
if (strlcat(filename, dp->d_name, sizeof(filename)) >=
|
|
|
|
sizeof(filename))
|
|
|
|
goto error;
|
|
|
|
|
|
|
|
if (stat(filename, &sb) == -1 || !(sb.st_mode & S_IFREG))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
template = systrace_readtemplate(filename, NULL, NULL);
|
|
|
|
if (template == NULL)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
TAILQ_INSERT_TAIL(&templates, template, next);
|
|
|
|
}
|
|
|
|
closedir(dir);
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
|
|
|
|
error:
|
|
|
|
errx(1, "%s: template name too long", __func__);
|
|
|
|
}
|
|
|
|
|
|
|
|
struct template *
|
|
|
|
systrace_readtemplate(char *filename, struct policy *policy,
|
|
|
|
struct template *template)
|
|
|
|
{
|
|
|
|
FILE *fp;
|
|
|
|
char line[_POSIX2_LINE_MAX], *p;
|
|
|
|
char *emulation, *name, *description;
|
|
|
|
int linenumber = 0;
|
|
|
|
|
|
|
|
if ((fp = fopen(filename, "r")) == NULL)
|
|
|
|
return (NULL);
|
|
|
|
|
2002-10-08 18:49:23 +04:00
|
|
|
/* Set up pid with current information */
|
2002-09-23 08:35:41 +04:00
|
|
|
while (fgets(line, sizeof(line), fp)) {
|
|
|
|
linenumber++;
|
|
|
|
|
|
|
|
if ((p = systrace_policyline(line)) == NULL) {
|
|
|
|
fprintf(stderr, "%s:%d: input line too long.\n",
|
|
|
|
filename, linenumber);
|
|
|
|
template = NULL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (strlen(p) == 0)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (!strncasecmp(p, "Template: ", 10)) {
|
|
|
|
p += 10;
|
|
|
|
name = strsep(&p, ",");
|
|
|
|
if (p == NULL)
|
|
|
|
goto error;
|
|
|
|
if (strncasecmp(p, " Emulation: ", 12))
|
|
|
|
goto error;
|
|
|
|
p += 12;
|
|
|
|
emulation = strsep(&p, ", ");
|
|
|
|
if (p == NULL)
|
|
|
|
goto error;
|
|
|
|
if (strncasecmp(p, " Description: ", 14))
|
|
|
|
goto error;
|
|
|
|
p += 14;
|
|
|
|
description = p;
|
|
|
|
|
|
|
|
if (template != NULL)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
template = calloc(1, sizeof(struct template));
|
|
|
|
if (template == NULL)
|
|
|
|
err(1, "calloc");
|
|
|
|
|
|
|
|
template->filename = strdup(filename);
|
|
|
|
template->name = strdup(name);
|
|
|
|
template->emulation = strdup(emulation);
|
|
|
|
template->description = strdup(description);
|
|
|
|
|
|
|
|
if (template->filename == NULL ||
|
|
|
|
template->name == NULL ||
|
|
|
|
template->emulation == NULL ||
|
|
|
|
template->description == NULL)
|
|
|
|
err(1, "strdup");
|
|
|
|
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (policy == NULL)
|
2006-03-18 03:12:02 +03:00
|
|
|
goto out;
|
2002-09-23 08:35:41 +04:00
|
|
|
|
|
|
|
if (systrace_policyprocess(policy, p) == -1)
|
|
|
|
goto error;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
|
|
|
fclose(fp);
|
|
|
|
return (template);
|
|
|
|
|
|
|
|
error:
|
|
|
|
fprintf(stderr, "%s:%d: syntax error.\n", filename, linenumber);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2002-09-17 09:07:21 +04:00
|
|
|
/* Removes trailing whitespace and comments from the input line */
|
|
|
|
|
|
|
|
static char *
|
|
|
|
systrace_policyline(char *line)
|
|
|
|
{
|
|
|
|
char *p;
|
2002-12-04 06:19:05 +03:00
|
|
|
int quoted = 0;
|
2002-09-17 09:07:21 +04:00
|
|
|
|
|
|
|
if ((p = strchr(line, '\n')) == NULL)
|
|
|
|
return (NULL);
|
|
|
|
*p = '\0';
|
|
|
|
|
2002-12-04 06:19:05 +03:00
|
|
|
/* Remove comments from the input line but ignore # that are part
|
|
|
|
* of the system call name or within quotes.
|
|
|
|
*/
|
|
|
|
for (p = line; *p; p++) {
|
|
|
|
if (*p == '"')
|
|
|
|
quoted = quoted ? 0 : 1;
|
|
|
|
if (*p == '#') {
|
|
|
|
if (quoted)
|
|
|
|
continue;
|
|
|
|
if (p != line && *(p-1) == '-')
|
|
|
|
continue;
|
2002-09-17 09:07:21 +04:00
|
|
|
*p = '\0';
|
2002-12-04 06:19:05 +03:00
|
|
|
break;
|
|
|
|
}
|
2002-09-17 09:07:21 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Remove trailing white space */
|
|
|
|
p = line + strlen(line) - 1;
|
|
|
|
while (p > line) {
|
2004-10-29 23:51:36 +04:00
|
|
|
if (!isspace((unsigned char)*p))
|
2002-09-17 09:07:21 +04:00
|
|
|
break;
|
|
|
|
*p-- = '\0';
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Ignore white space at start of line */
|
|
|
|
p = line;
|
|
|
|
p += strspn(p, " \t");
|
|
|
|
|
|
|
|
return (p);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Parse a single line from a policy and convert it into a policy filter.
|
|
|
|
* Predicates are matched.
|
|
|
|
*/
|
|
|
|
|
|
|
|
static int
|
|
|
|
systrace_policyprocess(struct policy *policy, char *p)
|
|
|
|
{
|
2002-10-08 18:49:23 +04:00
|
|
|
char line[_POSIX2_LINE_MAX];
|
2002-09-17 09:07:21 +04:00
|
|
|
char *name, *emulation, *rule;
|
|
|
|
struct filter *filter, *parsed;
|
|
|
|
short action, future;
|
2002-11-25 09:25:09 +03:00
|
|
|
int resolved = 0, res, isvalid;
|
2002-10-08 18:49:23 +04:00
|
|
|
|
|
|
|
/* Delay predicate evaluation if we are root */
|
2002-09-17 09:07:21 +04:00
|
|
|
|
|
|
|
emulation = strsep(&p, "-");
|
|
|
|
if (p == NULL || *p == '\0')
|
|
|
|
return (-1);
|
|
|
|
|
|
|
|
if (strcmp(emulation, policy->emulation))
|
|
|
|
return (-1);
|
|
|
|
|
|
|
|
name = strsep(&p, ":");
|
|
|
|
if (p == NULL || *p != ' ')
|
|
|
|
return (-1);
|
2002-11-25 09:25:09 +03:00
|
|
|
|
|
|
|
isvalid = intercept_isvalidsystemcall(emulation, name);
|
|
|
|
|
2002-09-17 09:07:21 +04:00
|
|
|
p++;
|
|
|
|
rule = p;
|
|
|
|
|
|
|
|
if ((p = strrchr(p, ',')) != NULL && !strncasecmp(p, ", if", 4)) {
|
|
|
|
*p = '\0';
|
2002-10-08 18:49:23 +04:00
|
|
|
res = filter_parse_simple(rule, &action, &future);
|
|
|
|
*p = ',';
|
|
|
|
if (res == 0) {
|
|
|
|
/* Need to make a real policy out of it */
|
|
|
|
snprintf(line, sizeof(line), "true then %s", rule);
|
|
|
|
rule = line;
|
|
|
|
}
|
|
|
|
} else if (filter_parse_simple(rule, &action, &future) == 0)
|
|
|
|
resolved = 1;
|
2002-09-17 09:07:21 +04:00
|
|
|
|
2002-11-25 09:25:09 +03:00
|
|
|
/* For now, everything that does not seem to be a valid syscall
|
|
|
|
* does not get fast kernel policies even though the aliasing
|
|
|
|
* system supports it.
|
|
|
|
*/
|
|
|
|
if (resolved && !isvalid) {
|
|
|
|
resolved = 0;
|
|
|
|
snprintf(line, sizeof(line), "true then %s", rule);
|
|
|
|
rule = line;
|
|
|
|
}
|
|
|
|
|
2002-10-08 18:49:23 +04:00
|
|
|
/* If the simple parser did not match, try real parser */
|
|
|
|
if (!resolved) {
|
2002-09-17 09:07:21 +04:00
|
|
|
if (parse_filter(rule, &parsed) == -1)
|
|
|
|
return (-1);
|
2002-10-08 18:49:23 +04:00
|
|
|
|
2002-09-17 09:07:21 +04:00
|
|
|
filter_free(parsed);
|
|
|
|
}
|
|
|
|
|
|
|
|
filter = calloc(1, sizeof(struct filter));
|
|
|
|
if (filter == NULL)
|
|
|
|
err(1, "%s:%d: calloc", __func__, __LINE__);
|
|
|
|
|
|
|
|
filter->rule = strdup(rule);
|
|
|
|
if (filter->rule == NULL)
|
|
|
|
err(1, "%s:%d: strdup", __func__, __LINE__);
|
|
|
|
|
|
|
|
strlcpy(filter->name, name, sizeof(filter->name));
|
|
|
|
strlcpy(filter->emulation, emulation, sizeof(filter->emulation));
|
|
|
|
|
|
|
|
TAILQ_INSERT_TAIL(&policy->prefilters, filter, policy_next);
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|
|
|
|
|
2002-06-17 20:29:07 +04:00
|
|
|
int
|
|
|
|
systrace_readpolicy(char *filename)
|
|
|
|
{
|
|
|
|
FILE *fp;
|
|
|
|
struct policy *policy;
|
2002-07-30 20:29:28 +04:00
|
|
|
char line[_POSIX2_LINE_MAX], *p;
|
2002-09-17 09:07:21 +04:00
|
|
|
char *emulation, *name;
|
2002-06-17 20:29:07 +04:00
|
|
|
int linenumber = 0;
|
|
|
|
int res = -1;
|
|
|
|
|
|
|
|
if ((fp = fopen(filename, "r")) == NULL)
|
|
|
|
return (-1);
|
|
|
|
|
|
|
|
policy = NULL;
|
|
|
|
while (fgets(line, sizeof(line), fp)) {
|
|
|
|
linenumber++;
|
2002-09-17 09:07:21 +04:00
|
|
|
|
|
|
|
if ((p = systrace_policyline(line)) == NULL) {
|
2002-06-17 20:29:07 +04:00
|
|
|
fprintf(stderr, "%s:%d: input line too long.\n",
|
|
|
|
filename, linenumber);
|
|
|
|
goto out;
|
|
|
|
}
|
2002-08-30 21:09:31 +04:00
|
|
|
|
2002-06-17 20:29:07 +04:00
|
|
|
if (strlen(p) == 0)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (!strncasecmp(p, "Policy: ", 8)) {
|
|
|
|
p += 8;
|
|
|
|
name = strsep(&p, ",");
|
|
|
|
if (p == NULL)
|
|
|
|
goto error;
|
|
|
|
if (strncasecmp(p, " Emulation: ", 12))
|
|
|
|
goto error;
|
|
|
|
p += 12;
|
|
|
|
emulation = p;
|
|
|
|
|
|
|
|
policy = systrace_newpolicy(emulation, name);
|
|
|
|
if (policy == NULL)
|
|
|
|
goto error;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (policy == NULL)
|
|
|
|
goto error;
|
|
|
|
|
|
|
|
if (!strncasecmp(p, "detached", 8)) {
|
|
|
|
policy->flags |= POLICY_DETACHED;
|
|
|
|
policy = NULL;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
2002-09-17 09:07:21 +04:00
|
|
|
if (systrace_policyprocess(policy, p) == -1)
|
2002-06-17 20:29:07 +04:00
|
|
|
goto error;
|
|
|
|
}
|
|
|
|
res = 0;
|
|
|
|
|
|
|
|
out:
|
|
|
|
fclose(fp);
|
|
|
|
return (res);
|
|
|
|
|
|
|
|
error:
|
2002-09-17 09:07:21 +04:00
|
|
|
fprintf(stderr, "%s:%d: syntax error.\n", filename, linenumber);
|
2002-06-17 20:29:07 +04:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2002-07-30 20:29:28 +04:00
|
|
|
int
|
2002-06-17 20:29:07 +04:00
|
|
|
systrace_writepolicy(struct policy *policy)
|
|
|
|
{
|
|
|
|
FILE *fp;
|
|
|
|
int fd;
|
|
|
|
char *p;
|
|
|
|
char tmpname[2*MAXPATHLEN];
|
|
|
|
char finalname[2*MAXPATHLEN];
|
|
|
|
struct filter *filter;
|
|
|
|
|
|
|
|
if ((p = systrace_policyfilename(policydir, policy->name)) == NULL)
|
|
|
|
return (-1);
|
|
|
|
strlcpy(finalname, p, sizeof(finalname));
|
|
|
|
if ((p = systrace_policyfilename(policydir, "tmpXXXXXXXX")) == NULL)
|
|
|
|
return (-1);
|
|
|
|
strlcpy(tmpname, p, sizeof(tmpname));
|
|
|
|
if ((fd = mkstemp(tmpname)) == -1 ||
|
|
|
|
(fp = fdopen(fd, "w+")) == NULL) {
|
|
|
|
if (fd != -1) {
|
|
|
|
unlink(tmpname);
|
|
|
|
close(fd);
|
|
|
|
}
|
|
|
|
return (-1);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
fprintf(fp, "Policy: %s, Emulation: %s\n",
|
|
|
|
policy->name, policy->emulation);
|
|
|
|
if (policy->flags & POLICY_DETACHED) {
|
|
|
|
fprintf(fp, "detached\n");
|
|
|
|
} else {
|
|
|
|
TAILQ_FOREACH(filter, &policy->prefilters, policy_next) {
|
|
|
|
fprintf(fp, "\t%s-%s: %s\n",
|
|
|
|
filter->emulation, filter->name, filter->rule);
|
|
|
|
}
|
|
|
|
TAILQ_FOREACH(filter, &policy->filters, policy_next) {
|
|
|
|
fprintf(fp, "\t%s-%s: %s\n",
|
|
|
|
filter->emulation, filter->name, filter->rule);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
fprintf(fp, "\n");
|
|
|
|
fclose(fp);
|
|
|
|
|
|
|
|
if (rename(tmpname, finalname) == -1) {
|
|
|
|
warn("rename(%s, %s)", tmpname, finalname);
|
|
|
|
return (-1);
|
|
|
|
}
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
systrace_dumppolicy(void)
|
|
|
|
{
|
|
|
|
struct policy *policy;
|
|
|
|
|
|
|
|
SPLAY_FOREACH(policy, policytree, &policyroot) {
|
|
|
|
if (!(policy->flags & POLICY_CHANGED))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (systrace_writepolicy(policy) == -1)
|
|
|
|
fprintf(stderr, "Failed to write policy for %s\n",
|
|
|
|
policy->name);
|
2002-09-16 08:31:46 +04:00
|
|
|
else
|
|
|
|
policy->flags &= ~POLICY_CHANGED;
|
2002-06-17 20:29:07 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|