Received: by 2002:a05:6a10:9e8c:0:0:0:0 with SMTP id y12csp482295pxx; Wed, 28 Oct 2020 09:19:14 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxOYGYfnzXY1CMMI0a0eq3Rg9+Lrfo5V/5DEA/wQnK1u7K/yRE8IGAD923Ia8wdgkM4Dljs X-Received: by 2002:aa7:c7d9:: with SMTP id o25mr8911591eds.318.1603901953858; Wed, 28 Oct 2020 09:19:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1603901953; cv=none; d=google.com; s=arc-20160816; b=Etj3L3junv1N+S+m86yoPRRF5wR8+gUSpR9aRWOY5zoje0mw7o+4yhpQvNOOHh/O4I QNZSsMWVg4tRorjPXWzk/D8D3EkccHzieXk8CaULVg6fxxM20LLJdAh3B+aKB3+N16sP gp/F3VkXptvptXZXDDvx40rT5H9sE9g3wVqkCM9LagzWFR/lufxzAKZFKIRxuNwC1UTT ncmWUORVDbIGVYa2H/klzrOVoCVWBdpXDajTGqDwoi/7oHqUB8JvDkcHyQe4GHVnhD7c sIhNtQ5+gQ39HVL3GpKss+1YWgb8jerQQN+1odZXfrdb/y+OUkxrFCNPuM5h8KJjAQDl 2sVw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=zqoXqcvWMBPlSXei6ErKneHNqWSBzP4hmrekRQ6svS4=; b=fjXZ0f5t4/1J4UWkrFCIH/J6Z7fvbii3S1W4RY1Q4fZjjzbXci0vkqmztSL8R2xuMK ZQS0U5Fzy/L8tldhIeGx6WCGdIKCriRD9nr3Wj94uMSIWAYzuAta1xUxc1I0OGRq5Ith Q8wixcFc/xHaD24I0IpDexmCT4V9IMtZ4ExGJJOtvMiirMh5mJDn7RTclb3taBX+o8jV GEhj2cj9hW+5u8c1zR1vns9SXR7Sj0XPtsoGArqIadGREekpzFgE+D5WBBUDyITNw3bw 0cbinwHB21bKWlnOLASRMTVOSt4iTMsIhZgLia2xq4K5pe2W/Sbe1MQDBaCFAjx/43S5 70KA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=fNC63Afm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id w18si3712082eds.554.2020.10.28.09.18.50; Wed, 28 Oct 2020 09:19:13 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=fNC63Afm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1815638AbgJ0RDi (ORCPT + 99 others); Tue, 27 Oct 2020 13:03:38 -0400 Received: from mail-ej1-f68.google.com ([209.85.218.68]:37290 "EHLO mail-ej1-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1815584AbgJ0RD3 (ORCPT ); Tue, 27 Oct 2020 13:03:29 -0400 Received: by mail-ej1-f68.google.com with SMTP id p9so3291518eji.4 for ; Tue, 27 Oct 2020 10:03:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=zqoXqcvWMBPlSXei6ErKneHNqWSBzP4hmrekRQ6svS4=; b=fNC63AfmPG0NHSC10dqVBDM3uNBAK7TLW/sS92s88m9ODkLb7LoaR1nMCuOxljKY7X Y8HE/wk09eqFUi0pA3cKfLDBR/VnyBJTrsaXsjz/qXnNf4QYxpME3VOj/V9xgDJs1T5c IKfIe/4YDTENuVSvUp382qThDt8UYKSivd5c0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=zqoXqcvWMBPlSXei6ErKneHNqWSBzP4hmrekRQ6svS4=; b=HE5J8EOKCCe/kugkyidGjEN4g0uyTl1uzkW9gOHLricBMNl4ksJSxINGwW5o6H+ubM hbpKnQfbTbLfMqkU62rjJhrhIVokRnx2gligoCsZHDXdmsZ84Ax+hBrcZGR7fCbyrWnn 3MvyGg00yAKz/eJmHmEgBW2tk5Gkwm6EdZdUSKXdjxrHcVaBNHnG8aSf8+i7OFVL0RbX ABKRV2ShsjwesckCagi1eyUNjgY8lyhZZkvAcDFHxL5hK7TThZJvnxZxqdYymdHy5MGq UtEEgp6DW9TZcBCOrMy+wE3o2gQFLT/i1dMdN4H1topF5xLyEjkK5GeHkagPm9hkhnaZ IpNg== X-Gm-Message-State: AOAM531Zo89N7wmCEZtorQhs4kluH2BMVICIQXEw8/594JgrKCVrXwJ1 SMdGKFk9apinL01tQ+KlUROshksiMhCq2M6u X-Received: by 2002:a17:906:23f2:: with SMTP id j18mr3290276ejg.526.1603818206443; Tue, 27 Oct 2020 10:03:26 -0700 (PDT) Received: from kpsingh.zrh.corp.google.com ([81.6.44.51]) by smtp.gmail.com with ESMTPSA id ba6sm1315006edb.61.2020.10.27.10.03.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 27 Oct 2020 10:03:25 -0700 (PDT) From: KP Singh To: linux-kernel@vger.kernel.org, bpf@vger.kernel.org Cc: Alexei Starovoitov , Daniel Borkmann , Martin KaFai Lau , Paul Turner , Jann Horn , Hao Luo Subject: [PATCH bpf-next 5/5] bpf: Add tests for task_local_storage Date: Tue, 27 Oct 2020 18:03:17 +0100 Message-Id: <20201027170317.2011119-6-kpsingh@chromium.org> X-Mailer: git-send-email 2.29.0.rc2.309.g374f81d7ae-goog In-Reply-To: <20201027170317.2011119-1-kpsingh@chromium.org> References: <20201027170317.2011119-1-kpsingh@chromium.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: KP Singh The test implements a simple MAC policy which denies an executable from unlinking itself. The LSM program bprm_committed_creds sets a task_local_storage with a pointer to the inode. This is then used to detect if the task is trying to unlink itself in the inode_unlink LSM hook. The test copies /bin/rm to /tmp and executes it in a child thread with the intention of deleting itself. A successful test should prevent the the running executable from deleting itself. The temporary file is cleaned up later in the test. Signed-off-by: KP Singh --- .../bpf/prog_tests/test_local_storage.c | 89 ++++++++++++++++--- .../selftests/bpf/progs/local_storage.c | 44 +++++++-- 2 files changed, 116 insertions(+), 17 deletions(-) diff --git a/tools/testing/selftests/bpf/prog_tests/test_local_storage.c b/tools/testing/selftests/bpf/prog_tests/test_local_storage.c index 91cd6f357246..0e41b27f3471 100644 --- a/tools/testing/selftests/bpf/prog_tests/test_local_storage.c +++ b/tools/testing/selftests/bpf/prog_tests/test_local_storage.c @@ -4,30 +4,83 @@ * Copyright (C) 2020 Google LLC. */ +#define _GNU_SOURCE + +#include +#include +#include #include #include #include "local_storage.skel.h" #include "network_helpers.h" -int create_and_unlink_file(void) +/* Copies an rm binary to a temp file. dest is a mkstemp template */ +int copy_rm(char *dest) { - char fname[PATH_MAX] = "/tmp/fileXXXXXX"; - int fd; + int ret, fd_in, fd_out; + struct stat stat; + + fd_in = open("/bin/rm", O_RDONLY); + if (fd_in < 0) + return fd_in; + + fd_out = mkstemp(dest); + if (fd_out < 0) + return fd_out; - fd = mkstemp(fname); - if (fd < 0) - return fd; + ret = fstat(fd_in, &stat); + if (ret == -1) + return errno; - close(fd); - unlink(fname); + ret = copy_file_range(fd_in, NULL, fd_out, NULL, stat.st_size, 0); + if (ret == -1) + return errno; + + /* Set executable permission on the copied file */ + ret = chmod(dest, 0100); + if (ret == -1) + return errno; + + close(fd_in); + close(fd_out); return 0; } +/* Fork and exec the provided rm binary and return the exit code of the + * forked process and its pid. + */ +int run_self_unlink(int *monitored_pid, const char *rm_path) +{ + int child_pid, child_status, ret; + int null_fd; + + child_pid = fork(); + if (child_pid == 0) { + null_fd = open("/dev/null", O_WRONLY); + dup2(null_fd, STDOUT_FILENO); + dup2(null_fd, STDERR_FILENO); + close(null_fd); + + *monitored_pid = getpid(); + /* Use the copied /usr/bin/rm to delete itself + * /tmp/copy_of_rm /tmp/copy_of_rm. + */ + ret = execlp(rm_path, rm_path, rm_path, NULL); + if (ret) + exit(errno); + } else if (child_pid > 0) { + waitpid(child_pid, &child_status, 0); + return WEXITSTATUS(child_status); + } + + return -EINVAL; +} void test_test_local_storage(void) { struct local_storage *skel = NULL; int err, duration = 0, serv_sk = -1; + char tmp_exec_path[PATH_MAX] = "/tmp/copy_of_rmXXXXXX"; skel = local_storage__open_and_load(); if (CHECK(!skel, "skel_load", "lsm skeleton failed\n")) @@ -37,10 +90,26 @@ void test_test_local_storage(void) if (CHECK(err, "attach", "lsm attach failed: %d\n", err)) goto close_prog; + err = copy_rm(tmp_exec_path); + if (CHECK(err < 0, "copy_executable", "err %d errno %d\n", err, errno)) + goto close_prog; + + /* Sets skel->bss->monitored_pid to the pid of the forked child + * forks a child process that executes tmp_exec_path and tries to + * unlink its executable. This operation should be denied by the loaded + * LSM program. + */ + err = run_self_unlink(&skel->bss->monitored_pid, tmp_exec_path); + if (CHECK(err != EPERM, "run_self_unlink", "err %d want EPERM\n", err)) + goto close_prog; + + /* Set the process being monitored to be the current process */ skel->bss->monitored_pid = getpid(); - err = create_and_unlink_file(); - if (CHECK(err < 0, "exec_cmd", "err %d errno %d\n", err, errno)) + /* Remove the temporary created executable */ + err = unlink(tmp_exec_path); + if (CHECK(err != 0, "unlink", "unable to unlink %s: %d", tmp_exec_path, + errno)) goto close_prog; CHECK(skel->data->inode_storage_result != 0, "inode_storage_result", diff --git a/tools/testing/selftests/bpf/progs/local_storage.c b/tools/testing/selftests/bpf/progs/local_storage.c index 5acf9203a69a..eb280cd0c416 100644 --- a/tools/testing/selftests/bpf/progs/local_storage.c +++ b/tools/testing/selftests/bpf/progs/local_storage.c @@ -17,7 +17,8 @@ int monitored_pid = 0; int inode_storage_result = -1; int sk_storage_result = -1; -struct dummy_storage { +struct local_storage { + struct inode *exec_inode; __u32 value; }; @@ -25,26 +26,40 @@ struct { __uint(type, BPF_MAP_TYPE_INODE_STORAGE); __uint(map_flags, BPF_F_NO_PREALLOC); __type(key, int); - __type(value, struct dummy_storage); + __type(value, struct local_storage); } inode_storage_map SEC(".maps"); struct { __uint(type, BPF_MAP_TYPE_SK_STORAGE); __uint(map_flags, BPF_F_NO_PREALLOC | BPF_F_CLONE); __type(key, int); - __type(value, struct dummy_storage); + __type(value, struct local_storage); } sk_storage_map SEC(".maps"); +struct { + __uint(type, BPF_MAP_TYPE_TASK_STORAGE); + __uint(map_flags, BPF_F_NO_PREALLOC | BPF_F_CLONE); + __type(key, int); + __type(value, struct local_storage); +} task_storage_map SEC(".maps"); + SEC("lsm/inode_unlink") int BPF_PROG(unlink_hook, struct inode *dir, struct dentry *victim) { __u32 pid = bpf_get_current_pid_tgid() >> 32; - struct dummy_storage *storage; + struct local_storage *storage; int err; if (pid != monitored_pid) return 0; + storage = bpf_task_storage_get(&task_storage_map, + bpf_get_current_task_btf(), 0, 0); + + /* Don't let an executable delete itself */ + if (storage && storage->exec_inode == victim->d_inode) + return -EPERM; + storage = bpf_inode_storage_get(&inode_storage_map, victim->d_inode, 0, BPF_SK_STORAGE_GET_F_CREATE); if (!storage) @@ -65,7 +80,7 @@ int BPF_PROG(socket_bind, struct socket *sock, struct sockaddr *address, int addrlen) { __u32 pid = bpf_get_current_pid_tgid() >> 32; - struct dummy_storage *storage; + struct local_storage *storage; int err; if (pid != monitored_pid) @@ -91,7 +106,7 @@ int BPF_PROG(socket_post_create, struct socket *sock, int family, int type, int protocol, int kern) { __u32 pid = bpf_get_current_pid_tgid() >> 32; - struct dummy_storage *storage; + struct local_storage *storage; if (pid != monitored_pid) return 0; @@ -110,7 +125,7 @@ SEC("lsm/file_open") int BPF_PROG(file_open, struct file *file) { __u32 pid = bpf_get_current_pid_tgid() >> 32; - struct dummy_storage *storage; + struct local_storage *storage; if (pid != monitored_pid) return 0; @@ -126,3 +141,18 @@ int BPF_PROG(file_open, struct file *file) storage->value = DUMMY_STORAGE_VALUE; return 0; } + +/* This uses the local storage to remember the inode of the binary that a + * process was originally executing. + */ +SEC("lsm/bprm_committed_creds") +void BPF_PROG(exec, struct linux_binprm *bprm) +{ + struct local_storage *storage; + + storage = bpf_task_storage_get(&task_storage_map, + bpf_get_current_task_btf(), 0, + BPF_LOCAL_STORAGE_GET_F_CREATE); + if (storage) + storage->exec_inode = bprm->file->f_inode; +} -- 2.29.0.rc2.309.g374f81d7ae-goog