Received: by 2002:a05:6a10:1287:0:0:0:0 with SMTP id d7csp6055665pxv; Thu, 29 Jul 2021 05:30:01 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxIIb1BqfexPYNulOgRWom4bFOBqAvWnyT27VILwv3Z4F6mMDy0cAh8WupTInjBosFctwc6 X-Received: by 2002:aa7:cf8b:: with SMTP id z11mr6083672edx.54.1627561801243; Thu, 29 Jul 2021 05:30:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1627561801; cv=none; d=google.com; s=arc-20160816; b=KJdlU8QYs+68XE1i3A47MVrDTpx97rioWm4MUeUTx8rstP1HZDnUKaKRwT3TE+tPI0 pBDmoYYkvHYorPB3tvlzxFYkerGePB48ACfkZ/vHDYwe3HUW7PX49J35NqxCXuwTfpbQ q9nk18pVfwC/uUlKnDvNaGK++cPxSVakiRMJLXumjLvDfTgcFh9s8r1MLHUwfU1KffjY uMRg9HCQYI7IldHt999el26ev+lxVDfNcIPzD71bxdyW4cPgKOWinC8lU9Epdojgc7sZ 4Sr3p/ry77CZREtbVFpzJVuaEeFaDbc5VkosulSCCEs2YHP0G9KSDvOtCJ+q6UQiBnhI NIOA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:from:subject:references:mime-version :message-id:in-reply-to:date:dkim-signature; bh=+YRk0e87Fy4+hULeH4RsY+6kkkKU8k2ny1F7i1QOpA0=; b=SAxST0U8/NJTM35O1qYkMSk+oQnc5tggnyykdS9KSsHvWbBfj1o4vKDWhhRzP/DeaY +5ZX2+oKg/rRNoRd0EFKsqLJNqc4oXRWMTlNhALNPP73Zxup2ybukYquOXeBar4g1Bw+ YmMqRg7NlytGlMXfgZfgD5Wnc2pDMHTRyQfjWRQzrxPv7d+lLkYUuFR7v3MkTb0tjcu7 NhcPMZ7N7v1CR8n9R61COQJQE6aKQUeSoyg6Xnok5R3T1STiwZiXhfNbaoUGfk/aSA54 g/PvvpEA/nw75GOKVIeoum+d6r06pxP6qgS5qBKv6vAGRHMvDnO9lQGNgL37XpxpL58W 6wNw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tSFxuGQd; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id r16si2540512edd.40.2021.07.29.05.29.37; Thu, 29 Jul 2021 05:30:01 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tSFxuGQd; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S236976AbhG2M2p (ORCPT + 99 others); Thu, 29 Jul 2021 08:28:45 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:59946 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S236942AbhG2M2p (ORCPT ); Thu, 29 Jul 2021 08:28:45 -0400 Received: from mail-pj1-x104a.google.com (mail-pj1-x104a.google.com [IPv6:2607:f8b0:4864:20::104a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 26AFAC061765 for ; Thu, 29 Jul 2021 05:28:41 -0700 (PDT) Received: by mail-pj1-x104a.google.com with SMTP id f1-20020a17090a8e81b029017720af1cf6so6290601pjo.9 for ; Thu, 29 Jul 2021 05:28:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:in-reply-to:message-id:mime-version:references:subject:from:to :cc; bh=+YRk0e87Fy4+hULeH4RsY+6kkkKU8k2ny1F7i1QOpA0=; b=tSFxuGQdNoVdUcVNpvyUYv5LfRYz5tAALEw+bB5cWqRIKO9UfX1MkkPxWCjJgBI5Gg b+OCAsyYpCqDs0HpNOYllPUYkC5eXlOC+m7UwDL2lhWfH8gY3DFcldhkiJ12xe74SbfN kFuNtzJAaTGkw8mI3//ipjZx5e7r3MGa9n1c/7KkvClLP2KYO3/IFFJRzFlT8gBN5bSo quVnzSHOpQ7LzyjOrwdJQZJofgjsexqqXxPvRNOYWgsOkBFcW6FjI9e0OQ3UmwpBD+JA kV8otrVsJ6BylChp12z2NT643TNxwnzlNkab3LGpgKF/7mESPR2i4PRVZE/Il2zDH3GM vT5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:in-reply-to:message-id:mime-version :references:subject:from:to:cc; bh=+YRk0e87Fy4+hULeH4RsY+6kkkKU8k2ny1F7i1QOpA0=; b=S+1ei4AHrqZZ5CcV3xubF+RA9cTmgguVdMnt76Vd0mZZh5Kx+uRLz07p6QrRnrhSRV gjbZhJ1ohjHNsFnEPXifq4eFhh4HcYBCXYIDSyWe21YTCBfWOnRo7bU8KgozkLNIxz4s ZwKuwWjJtgn3fPO2LgujfmMVckuYcJFbLk/PicX67vt8i+UuTsgpsReu+8Wvz3VeFDJh fLZMhYakADO/SZJVeeG/GEWGEXIW3H8JKbHpOMjL1LBbdVPeFYGzFfNq7rWKNsbmjO0r 3LoDyaBRJqB7DFDvqC9neJGOsIycN2jbHZOFNopzUxvGldB3XMbpme4LBh/gcp1SeFLH MQuQ== X-Gm-Message-State: AOAM531wblcjFsB0vlZEPNOuAEiOhMzH7AZqwyZKWzvTwY/BGtyOl5Vw 9MYUWmkRSEOK2ekoSgVB6kqyOk7mMhhbod49TW8lZ+3dcueBjbzpRGMlFqCtz/jXcJUSKQQiNcQ iTPpI3lLsdCAfsNjFw6pktXxgjiZi9bj2ZeP8dK328k3T0y7Jpm5EQ/nx0GmF1DQCOPNw5J1Kan tVQol7YYzRLjo= X-Received: from howardchung-p920.tpe.corp.google.com ([2401:fa00:1:10:ff72:1420:4502:fdaf]) (user=howardchung job=sendgmr) by 2002:a17:90a:d3ca:: with SMTP id d10mr14866927pjw.35.1627561720493; Thu, 29 Jul 2021 05:28:40 -0700 (PDT) Date: Thu, 29 Jul 2021 20:27:46 +0800 In-Reply-To: <20210729122751.3728885-1-howardchung@google.com> Message-Id: <20210729202648.Bluez.v6.8.Ifbb69dd6e371da3a914049a94615064479b9024b@changeid> Mime-Version: 1.0 References: <20210729122751.3728885-1-howardchung@google.com> X-Mailer: git-send-email 2.32.0.554.ge1b32706d8-goog Subject: [Bluez PATCH v6 08/13] plugins/admin: add ServiceAllowList method From: Howard Chung To: linux-bluetooth@vger.kernel.org, luiz.dentz@gmail.com Cc: Yun-Hao Chung , Miao-chen Chou Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org From: Yun-Hao Chung This adds code to register interface org.bluez.AdminPolicySet1. The interface will provide methods to limit users to operate certain functions of bluez, such as allow/disallow user to taggle adapter power, or only allow users to connect services in the specified list, etc. This patch also implements ServiceAllowlist in org.bluez.AdminPolicySet1. Reviewed-by: Miao-chen Chou --- The following test steps were performed: 1. Set ServiceAllowList to ["1108","110A","110B","110C","110D","110E", "110F","1112","111E","111F","1203"] ( users are only allowed to connect headset ) 2. Turn on paired WF1000XM3, and listen music on Youtube. 3. Turn on paired K830 (LE device), press any key on keyboard. 4. Turn on paired Samsung Bluetooth Keyboard EE-BT550 (BREDR device), press any key on keyboard. 5. Set ServiceAllowList to ["1124","180A","180F","1812"] ( users are only allowed to connect HID devices ) 6. Turn on paired WF1000XM3, and listen music on Youtube. 7. Turn on paired K830 (LE device), press any key on keyboard. 8. Turn on paired Samsung Bluetooth Keyboard EE-BT550 (BREDR device), press any key on keyboard. 9. Set ServiceAllowList to [] ( users are only allowed to connect any device. ) 10. Turn on paired WF1000XM3, and listen music on Youtube. 11. Turn on paired K830 (LE device), press any key on keyboard. 12. Turn on paired Samsung Bluetooth Keyboard EE-BT550 (BREDR device), press any key on keyboard. Expected results: Step 2,7,8,9,10,11 should success, and step 3,4,6 should fail. (no changes since v1) plugins/admin.c | 127 +++++++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 126 insertions(+), 1 deletion(-) diff --git a/plugins/admin.c b/plugins/admin.c index 923e08cb836b..1fe2904d93d9 100644 --- a/plugins/admin.c +++ b/plugins/admin.c @@ -12,19 +12,29 @@ #include #endif +#include +#include + #include "lib/bluetooth.h" +#include "lib/uuid.h" #include "src/adapter.h" +#include "src/dbus-common.h" #include "src/error.h" #include "src/log.h" #include "src/plugin.h" #include "src/shared/queue.h" +#define ADMIN_POLICY_SET_INTERFACE "org.bluez.AdminPolicySet1" + +static DBusConnection *dbus_conn; + /* |policy_data| has the same life cycle as btd_adapter */ static struct btd_admin_policy { struct btd_adapter *adapter; uint16_t adapter_id; + struct queue *service_allowlist; } *policy_data = NULL; static struct btd_admin_policy *admin_policy_new(struct btd_adapter *adapter) @@ -40,19 +50,120 @@ static struct btd_admin_policy *admin_policy_new(struct btd_adapter *adapter) admin_policy->adapter = adapter; admin_policy->adapter_id = btd_adapter_get_index(adapter); + admin_policy->service_allowlist = NULL; return admin_policy; } +static void free_service_allowlist(struct queue *q) +{ + queue_destroy(q, g_free); +} + static void admin_policy_free(void *data) { struct btd_admin_policy *admin_policy = data; + free_service_allowlist(admin_policy->service_allowlist); g_free(admin_policy); } +static struct queue *parse_allow_service_list(struct btd_adapter *adapter, + DBusMessage *msg) +{ + DBusMessageIter iter, arr_iter; + struct queue *uuid_list = NULL; + + dbus_message_iter_init(msg, &iter); + if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_ARRAY) + return NULL; + + uuid_list = queue_new(); + dbus_message_iter_recurse(&iter, &arr_iter); + do { + const int type = dbus_message_iter_get_arg_type(&arr_iter); + char *uuid_param; + bt_uuid_t *uuid; + + if (type == DBUS_TYPE_INVALID) + break; + + if (type != DBUS_TYPE_STRING) + goto failed; + + dbus_message_iter_get_basic(&arr_iter, &uuid_param); + + uuid = g_try_malloc(sizeof(*uuid)); + if (!uuid) + goto failed; + + if (bt_string_to_uuid(uuid, uuid_param)) { + g_free(uuid); + goto failed; + } + + queue_push_head(uuid_list, uuid); + + dbus_message_iter_next(&arr_iter); + } while (true); + + return uuid_list; + +failed: + queue_destroy(uuid_list, g_free); + return NULL; +} + +static bool service_allowlist_set(struct btd_admin_policy *admin_policy, + struct queue *uuid_list) +{ + struct btd_adapter *adapter = admin_policy->adapter; + + if (!btd_adapter_set_allowed_uuids(adapter, uuid_list)) + return false; + + free_service_allowlist(admin_policy->service_allowlist); + admin_policy->service_allowlist = uuid_list; + + return true; +} + +static DBusMessage *set_service_allowlist(DBusConnection *conn, + DBusMessage *msg, void *user_data) +{ + struct btd_admin_policy *admin_policy = user_data; + struct btd_adapter *adapter = admin_policy->adapter; + struct queue *uuid_list = NULL; + const char *sender = dbus_message_get_sender(msg); + + DBG("sender %s", sender); + + /* Parse parameters */ + uuid_list = parse_allow_service_list(adapter, msg); + if (!uuid_list) { + btd_error(admin_policy->adapter_id, + "Failed on parsing allowed service list"); + return btd_error_invalid_args(msg); + } + + if (!service_allowlist_set(admin_policy, uuid_list)) { + free_service_allowlist(uuid_list); + return btd_error_failed(msg, "service_allowlist_set failed"); + } + + return dbus_message_new_method_return(msg); +} + +static const GDBusMethodTable admin_policy_adapter_methods[] = { + { GDBUS_METHOD("SetServiceAllowList", GDBUS_ARGS({ "UUIDs", "as" }), + NULL, set_service_allowlist) }, + { } +}; + static int admin_policy_adapter_probe(struct btd_adapter *adapter) { + const char *adapter_path; + if (policy_data) { btd_warn(policy_data->adapter_id, "Policy data already exists"); @@ -64,8 +175,20 @@ static int admin_policy_adapter_probe(struct btd_adapter *adapter) if (!policy_data) return -ENOMEM; - btd_info(policy_data->adapter_id, "Admin Policy has been enabled"); + adapter_path = adapter_get_path(adapter); + if (!g_dbus_register_interface(dbus_conn, adapter_path, + ADMIN_POLICY_SET_INTERFACE, + admin_policy_adapter_methods, NULL, + NULL, policy_data, admin_policy_free)) { + btd_error(policy_data->adapter_id, + "Admin Policy Set interface init failed on path %s", + adapter_path); + return -EINVAL; + } + + btd_info(policy_data->adapter_id, + "Admin Policy Set interface registered"); return 0; } @@ -79,6 +202,8 @@ static int admin_init(void) { DBG(""); + dbus_conn = btd_get_dbus_connection(); + return btd_register_adapter_driver(&admin_policy_driver); } -- 2.32.0.554.ge1b32706d8-goog