This source file includes following definitions.
- IsRunningOnValgrind
- sys_open
- GetFileNameInWhitelist
- IsAllowedOpenFlags
- ipc_socketpair_
- Init
- Access
- Open
- PathAndFlagsSyscall
- HandleRequest
- HandleRemoteCommand
- AccessFileForIPC
- OpenFileForIPC
- GetFileNameIfAllowedToAccess
- GetFileNameIfAllowedToOpen
#include "sandbox/linux/services/broker_process.h"
#include <fcntl.h>
#include <signal.h>
#include <sys/socket.h>
#include <sys/stat.h>
#include <sys/syscall.h>
#include <sys/types.h>
#include <sys/wait.h>
#include <unistd.h>
#include <algorithm>
#include <string>
#include <vector>
#include "base/basictypes.h"
#include "base/callback.h"
#include "base/compiler_specific.h"
#include "base/logging.h"
#include "base/pickle.h"
#include "base/posix/eintr_wrapper.h"
#include "base/posix/unix_domain_socket_linux.h"
#include "base/process/process_metrics.h"
#include "base/third_party/valgrind/valgrind.h"
#include "build/build_config.h"
#include "sandbox/linux/services/linux_syscalls.h"
#if defined(OS_ANDROID) && !defined(MSG_CMSG_CLOEXEC)
#define MSG_CMSG_CLOEXEC 0x40000000
#endif
namespace {
bool IsRunningOnValgrind() { return RUNNING_ON_VALGRIND; }
int sys_open(const char* pathname, int flags) {
const int mode = 0;
if (IsRunningOnValgrind()) {
return open(pathname, flags, mode);
} else {
return syscall(__NR_openat, AT_FDCWD, pathname, flags, mode);
}
}
static const size_t kMaxMessageLength = 4096;
static const int kCurrentProcessOpenFlagsMask = O_CLOEXEC;
bool GetFileNameInWhitelist(const std::vector<std::string>& allowed_file_names,
const char* requested_filename,
const char** file_to_open) {
if (file_to_open && *file_to_open) {
RAW_LOG(FATAL, "*file_to_open should be NULL");
return false;
}
std::vector<std::string>::const_iterator it;
for (it = allowed_file_names.begin(); it != allowed_file_names.end(); it++) {
if (strcmp(requested_filename, it->c_str()) == 0) {
if (file_to_open)
*file_to_open = it->c_str();
return true;
}
}
return false;
}
bool IsAllowedOpenFlags(int flags) {
const int access_mode = flags & O_ACCMODE;
if (access_mode != O_RDONLY && access_mode != O_WRONLY &&
access_mode != O_RDWR) {
return false;
}
if (flags & O_CREAT) {
return false;
}
if (flags & kCurrentProcessOpenFlagsMask)
return false;
const int creation_and_status_flags = flags & ~O_ACCMODE;
const int known_flags =
O_APPEND | O_ASYNC | O_CLOEXEC | O_CREAT | O_DIRECT |
O_DIRECTORY | O_EXCL | O_LARGEFILE | O_NOATIME | O_NOCTTY |
O_NOFOLLOW | O_NONBLOCK | O_NDELAY | O_SYNC | O_TRUNC;
const int unknown_flags = ~known_flags;
const bool has_unknown_flags = creation_and_status_flags & unknown_flags;
return !has_unknown_flags;
}
}
namespace sandbox {
BrokerProcess::BrokerProcess(int denied_errno,
const std::vector<std::string>& allowed_r_files,
const std::vector<std::string>& allowed_w_files,
bool fast_check_in_client,
bool quiet_failures_for_tests)
: denied_errno_(denied_errno),
initialized_(false),
is_child_(false),
fast_check_in_client_(fast_check_in_client),
quiet_failures_for_tests_(quiet_failures_for_tests),
broker_pid_(-1),
allowed_r_files_(allowed_r_files),
allowed_w_files_(allowed_w_files),
ipc_socketpair_(-1) {
}
BrokerProcess::~BrokerProcess() {
if (initialized_ && ipc_socketpair_ != -1) {
PCHECK(0 == IGNORE_EINTR(close(ipc_socketpair_)));
PCHECK(0 == kill(broker_pid_, SIGKILL));
siginfo_t process_info;
int ret = HANDLE_EINTR(waitid(P_PID, broker_pid_, &process_info, WEXITED));
PCHECK(0 == ret);
}
}
bool BrokerProcess::Init(
const base::Callback<bool(void)>& broker_process_init_callback) {
CHECK(!initialized_);
int socket_pair[2];
if (socketpair(AF_UNIX, SOCK_SEQPACKET, 0, socket_pair)) {
LOG(ERROR) << "Failed to create socketpair";
return false;
}
#if !defined(THREAD_SANITIZER)
DCHECK_EQ(1, base::GetNumberOfThreads(base::GetCurrentProcessHandle()));
#endif
int child_pid = fork();
if (child_pid == -1) {
close(socket_pair[0]);
close(socket_pair[1]);
return false;
}
if (child_pid) {
close(socket_pair[0]);
shutdown(socket_pair[1], SHUT_RD);
ipc_socketpair_ = socket_pair[1];
is_child_ = false;
broker_pid_ = child_pid;
initialized_ = true;
return true;
} else {
close(socket_pair[1]);
shutdown(socket_pair[0], SHUT_WR);
ipc_socketpair_ = socket_pair[0];
is_child_ = true;
CHECK(broker_process_init_callback.Run());
initialized_ = true;
for (;;) {
HandleRequest();
}
_exit(1);
}
NOTREACHED();
}
int BrokerProcess::Access(const char* pathname, int mode) const {
return PathAndFlagsSyscall(kCommandAccess, pathname, mode);
}
int BrokerProcess::Open(const char* pathname, int flags) const {
return PathAndFlagsSyscall(kCommandOpen, pathname, flags);
}
int BrokerProcess::PathAndFlagsSyscall(enum IPCCommands syscall_type,
const char* pathname, int flags) const {
int recvmsg_flags = 0;
RAW_CHECK(initialized_);
RAW_CHECK(syscall_type == kCommandOpen || syscall_type == kCommandAccess);
if (!pathname)
return -EFAULT;
if (syscall_type == kCommandOpen && (flags & kCurrentProcessOpenFlagsMask)) {
RAW_CHECK(kCurrentProcessOpenFlagsMask == O_CLOEXEC);
recvmsg_flags |= MSG_CMSG_CLOEXEC;
flags &= ~O_CLOEXEC;
}
if (fast_check_in_client_) {
if (syscall_type == kCommandOpen &&
!GetFileNameIfAllowedToOpen(pathname, flags, NULL)) {
return -denied_errno_;
}
if (syscall_type == kCommandAccess &&
!GetFileNameIfAllowedToAccess(pathname, flags, NULL)) {
return -denied_errno_;
}
}
Pickle write_pickle;
write_pickle.WriteInt(syscall_type);
write_pickle.WriteString(pathname);
write_pickle.WriteInt(flags);
RAW_CHECK(write_pickle.size() <= kMaxMessageLength);
int returned_fd = -1;
uint8_t reply_buf[kMaxMessageLength];
ssize_t msg_len = UnixDomainSocket::SendRecvMsgWithFlags(ipc_socketpair_,
reply_buf,
sizeof(reply_buf),
recvmsg_flags,
&returned_fd,
write_pickle);
if (msg_len <= 0) {
if (!quiet_failures_for_tests_)
RAW_LOG(ERROR, "Could not make request to broker process");
return -ENOMEM;
}
Pickle read_pickle(reinterpret_cast<char*>(reply_buf), msg_len);
PickleIterator iter(read_pickle);
int return_value = -1;
if (read_pickle.ReadInt(&iter, &return_value)) {
switch (syscall_type) {
case kCommandAccess:
RAW_CHECK(returned_fd == -1);
return return_value;
case kCommandOpen:
if (return_value < 0) {
RAW_CHECK(returned_fd == -1);
return return_value;
} else {
RAW_CHECK(returned_fd >= 0);
return returned_fd;
}
default:
RAW_LOG(ERROR, "Unsupported command");
return -ENOSYS;
}
} else {
RAW_LOG(ERROR, "Could not read pickle");
NOTREACHED();
return -ENOMEM;
}
}
bool BrokerProcess::HandleRequest() const {
std::vector<int> fds;
char buf[kMaxMessageLength];
errno = 0;
const ssize_t msg_len = UnixDomainSocket::RecvMsg(ipc_socketpair_, buf,
sizeof(buf), &fds);
if (msg_len == 0 || (msg_len == -1 && errno == ECONNRESET)) {
_exit(0);
}
if (msg_len < 0 || fds.size() != 1 || fds.at(0) < 0) {
PLOG(ERROR) << "Error reading message from the client";
return false;
}
const int temporary_ipc = fds.at(0);
Pickle pickle(buf, msg_len);
PickleIterator iter(pickle);
int command_type;
if (pickle.ReadInt(&iter, &command_type)) {
bool r = false;
switch (command_type) {
case kCommandAccess:
case kCommandOpen:
r = HandleRemoteCommand(static_cast<IPCCommands>(command_type),
temporary_ipc, pickle, iter);
break;
default:
NOTREACHED();
r = false;
break;
}
int ret = IGNORE_EINTR(close(temporary_ipc));
DCHECK(!ret) << "Could not close temporary IPC channel";
return r;
}
LOG(ERROR) << "Error parsing IPC request";
return false;
}
bool BrokerProcess::HandleRemoteCommand(IPCCommands command_type, int reply_ipc,
const Pickle& read_pickle,
PickleIterator iter) const {
std::string requested_filename;
int flags = 0;
if (!read_pickle.ReadString(&iter, &requested_filename) ||
!read_pickle.ReadInt(&iter, &flags)) {
return -1;
}
Pickle write_pickle;
std::vector<int> opened_files;
switch (command_type) {
case kCommandAccess:
AccessFileForIPC(requested_filename, flags, &write_pickle);
break;
case kCommandOpen:
OpenFileForIPC(requested_filename, flags, &write_pickle, &opened_files);
break;
default:
LOG(ERROR) << "Invalid IPC command";
break;
}
CHECK_LE(write_pickle.size(), kMaxMessageLength);
ssize_t sent = UnixDomainSocket::SendMsg(reply_ipc, write_pickle.data(),
write_pickle.size(), opened_files);
for (std::vector<int>::iterator it = opened_files.begin();
it < opened_files.end(); ++it) {
int ret = IGNORE_EINTR(close(*it));
DCHECK(!ret) << "Could not close file descriptor";
}
if (sent <= 0) {
LOG(ERROR) << "Could not send IPC reply";
return false;
}
return true;
}
void BrokerProcess::AccessFileForIPC(const std::string& requested_filename,
int mode, Pickle* write_pickle) const {
DCHECK(write_pickle);
const char* file_to_access = NULL;
const bool safe_to_access_file = GetFileNameIfAllowedToAccess(
requested_filename.c_str(), mode, &file_to_access);
if (safe_to_access_file) {
CHECK(file_to_access);
int access_ret = access(file_to_access, mode);
int access_errno = errno;
if (!access_ret)
write_pickle->WriteInt(0);
else
write_pickle->WriteInt(-access_errno);
} else {
write_pickle->WriteInt(-denied_errno_);
}
}
void BrokerProcess::OpenFileForIPC(const std::string& requested_filename,
int flags, Pickle* write_pickle,
std::vector<int>* opened_files) const {
DCHECK(write_pickle);
DCHECK(opened_files);
const char* file_to_open = NULL;
const bool safe_to_open_file = GetFileNameIfAllowedToOpen(
requested_filename.c_str(), flags, &file_to_open);
if (safe_to_open_file) {
CHECK(file_to_open);
int opened_fd = sys_open(file_to_open, flags);
if (opened_fd < 0) {
write_pickle->WriteInt(-errno);
} else {
opened_files->push_back(opened_fd);
write_pickle->WriteInt(0);
}
} else {
write_pickle->WriteInt(-denied_errno_);
}
}
bool BrokerProcess::GetFileNameIfAllowedToAccess(const char* requested_filename,
int requested_mode, const char** file_to_access) const {
if (requested_mode != F_OK &&
requested_mode & ~(R_OK | W_OK)) {
return false;
}
switch (requested_mode) {
case F_OK:
return GetFileNameInWhitelist(allowed_r_files_, requested_filename,
file_to_access) ||
GetFileNameInWhitelist(allowed_w_files_, requested_filename,
file_to_access);
case R_OK:
return GetFileNameInWhitelist(allowed_r_files_, requested_filename,
file_to_access);
case W_OK:
return GetFileNameInWhitelist(allowed_w_files_, requested_filename,
file_to_access);
case R_OK | W_OK:
{
bool allowed_for_read_and_write =
GetFileNameInWhitelist(allowed_r_files_, requested_filename, NULL) &&
GetFileNameInWhitelist(allowed_w_files_, requested_filename,
file_to_access);
return allowed_for_read_and_write;
}
default:
return false;
}
}
bool BrokerProcess::GetFileNameIfAllowedToOpen(const char* requested_filename,
int requested_flags, const char** file_to_open) const {
if (!IsAllowedOpenFlags(requested_flags)) {
return false;
}
switch (requested_flags & O_ACCMODE) {
case O_RDONLY:
return GetFileNameInWhitelist(allowed_r_files_, requested_filename,
file_to_open);
case O_WRONLY:
return GetFileNameInWhitelist(allowed_w_files_, requested_filename,
file_to_open);
case O_RDWR:
{
bool allowed_for_read_and_write =
GetFileNameInWhitelist(allowed_r_files_, requested_filename, NULL) &&
GetFileNameInWhitelist(allowed_w_files_, requested_filename,
file_to_open);
return allowed_for_read_and_write;
}
default:
return false;
}
}
}