From 090a1da69705ab33ae9a49214636e2176638bf7f Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Tue, 21 Jun 2022 18:24:43 +0200 Subject: [PATCH] Revert "Revert "Revert "ANDROID: GKI: Add module load time protected symbol lookup""" This reverts commit 5ffc4c2275478f8d4c17795dc5f1b552559fff26. It conflicts in bad ways with the module code changes in 5.19-rc1 so revert it for now. If it is still needed, it can be added back later. Bug: 200082547 Bug: 214445388 Cc: Ramji Jiyani Signed-off-by: Greg Kroah-Hartman Change-Id: Ibf0b85c355cfc3e1a45c213a131a12c9e3061349 --- android/abi_gki_modules_exports | 1 - android/abi_gki_modules_protected | 1 - arch/arm64/configs/gki_defconfig | 2 -- arch/x86/configs/gki_defconfig | 2 -- init/Kconfig | 13 -------- kernel/Makefile | 17 ----------- kernel/gki_module.c | 50 ------------------------------- kernel/module-internal.h | 14 --------- kernel/module.c | 19 +----------- 9 files changed, 1 insertion(+), 118 deletions(-) delete mode 100644 android/abi_gki_modules_exports delete mode 100644 android/abi_gki_modules_protected delete mode 100644 kernel/gki_module.c diff --git a/android/abi_gki_modules_exports b/android/abi_gki_modules_exports deleted file mode 100644 index 88b5a4b3adce..000000000000 --- a/android/abi_gki_modules_exports +++ /dev/null @@ -1 +0,0 @@ -[abi_symbol_list] diff --git a/android/abi_gki_modules_protected b/android/abi_gki_modules_protected deleted file mode 100644 index 88b5a4b3adce..000000000000 --- a/android/abi_gki_modules_protected +++ /dev/null @@ -1 +0,0 @@ -[abi_symbol_list] diff --git a/arch/arm64/configs/gki_defconfig b/arch/arm64/configs/gki_defconfig index 8d23da6e3c27..3f6c4bfdc14e 100644 --- a/arch/arm64/configs/gki_defconfig +++ b/arch/arm64/configs/gki_defconfig @@ -85,8 +85,6 @@ CONFIG_SHADOW_CALL_STACK=y CONFIG_MODULES=y CONFIG_MODULE_UNLOAD=y CONFIG_MODVERSIONS=y -CONFIG_MODULE_SIG=y -CONFIG_MODULE_SIG_PROTECT=y CONFIG_BLK_DEV_ZONED=y CONFIG_BLK_INLINE_ENCRYPTION=y CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK=y diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig index 7b79035c7fe2..ff4e9c54c6e0 100644 --- a/arch/x86/configs/gki_defconfig +++ b/arch/x86/configs/gki_defconfig @@ -71,8 +71,6 @@ CONFIG_JUMP_LABEL=y CONFIG_MODULES=y CONFIG_MODULE_UNLOAD=y CONFIG_MODVERSIONS=y -CONFIG_MODULE_SIG=y -CONFIG_MODULE_SIG_PROTECT=y CONFIG_BLK_DEV_ZONED=y CONFIG_BLK_INLINE_ENCRYPTION=y CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK=y diff --git a/init/Kconfig b/init/Kconfig index eb985fb119e1..195ee291ce5c 100644 --- a/init/Kconfig +++ b/init/Kconfig @@ -2041,19 +2041,6 @@ config MODULE_SIG_FORCE Reject unsigned modules or signed modules for which we don't have a key. Without this, such modules will simply taint the kernel. -config MODULE_SIG_PROTECT - bool "Android GKI module protection" - depends on MODULE_SIG && !MODULE_SIG_FORCE - help - Enables Android GKI symbol and export protection support. - - This modifies the behavior of the MODULE_SIG_FORCE as follows: - - Allows Android GKI Modules signed using MODULE_SIG_ALL during build. - - Allows other modules to load if they don't violate the access to - Android GKI protected symbols and do not export the symbols already - exported by the Android GKI modules. Loading will fail and return - -EACCES (Permission denied) if symbol access contidions are not met. - config MODULE_SIG_ALL bool "Automatically sign all modules" default y diff --git a/kernel/Makefile b/kernel/Makefile index 551dde497093..847a82bfe0e3 100644 --- a/kernel/Makefile +++ b/kernel/Makefile @@ -70,7 +70,6 @@ obj-$(CONFIG_MODULES) += module.o obj-$(CONFIG_MODULE_DECOMPRESS) += module_decompress.o obj-$(CONFIG_MODULE_SIG) += module_signing.o obj-$(CONFIG_MODULE_SIG_FORMAT) += module_signature.o -obj-$(CONFIG_MODULE_SIG_PROTECT) += gki_module.o obj-$(CONFIG_KALLSYMS) += kallsyms.o obj-$(CONFIG_BSD_PROCESS_ACCT) += acct.o obj-$(CONFIG_CRASH_CORE) += crash_core.o @@ -162,19 +161,3 @@ $(obj)/kheaders_data.tar.xz: FORCE $(call cmd,genikh) clean-files := kheaders_data.tar.xz kheaders.md5 - -# -# ANDROID: GKI: Generate headerfiles required for gki_module.o -# -# Dependencies on generated files need to be listed explicitly -$(obj)/gki_module.o: $(obj)/gki_module_protected.h $(obj)/gki_module_exported.h - -$(obj)/gki_module_protected.h: $(srctree)/android/abi_gki_modules_protected \ - $(srctree)/scripts/gen_gki_modules_headers.sh - $(Q)$(CONFIG_SHELL) $(srctree)/scripts/gen_gki_modules_headers.sh $@ \ - "$(srctree)" - -$(obj)/gki_module_exported.h: $(srctree)/android/abi_gki_modules_exports \ - $(srctree)/scripts/gen_gki_modules_headers.sh - $(Q)$(CONFIG_SHELL) $(srctree)/scripts/gen_gki_modules_headers.sh $@ \ - "$(srctree)" diff --git a/kernel/gki_module.c b/kernel/gki_module.c deleted file mode 100644 index 24651dfc34f8..000000000000 --- a/kernel/gki_module.c +++ /dev/null @@ -1,50 +0,0 @@ -// SPDX-License-Identifier: GPL-2.0-only -/* - * Copyright 2021 Google LLC - * Author: ramjiyani@google.com (Ramji Jiyani) - */ - -#include -#include -#include -#include -#include - -/* - * Build time generated header files - * - * gki_module_exported.h -- Symbols protected from _export_ by unsigned modules - * gki_module_protected.h -- Symbols protected from _access_ by unsigned modules - */ -#include "gki_module_protected.h" -#include "gki_module_exported.h" - -#define MAX_STRCMP_LEN (max(MAX_PROTECTED_NAME_LEN, MAX_EXPORTED_NAME_LEN)) - -/* bsearch() comparision callback */ -static int cmp_name(const void *sym, const void *protected_sym) -{ - return strncmp(sym, protected_sym, MAX_STRCMP_LEN); -} - -/** - * gki_is_module_protected_symbol - Is a symbol protected from unsigned module? - * - * @name: Symbol being checked against protection from unsigned module - */ -bool gki_is_module_protected_symbol(const char *name) -{ - return bsearch(name, gki_protected_symbols, NO_OF_PROTECTED_SYMBOLS, - MAX_PROTECTED_NAME_LEN, cmp_name) != NULL; -} - -/** - * gki_is_module_exported_symbol - Is a symbol exported from a GKI module? - * - * @name: Symbol being checked against exported symbols from GKI modules - */ -bool gki_is_module_exported_symbol(const char *name) -{ - return bsearch(name, gki_exported_symbols, NO_OF_EXPORTED_SYMBOLS, - MAX_EXPORTED_NAME_LEN, cmp_name) != NULL; -} diff --git a/kernel/module-internal.h b/kernel/module-internal.h index 64d82612f35a..8c381c99062f 100644 --- a/kernel/module-internal.h +++ b/kernel/module-internal.h @@ -48,17 +48,3 @@ static inline void module_decompress_cleanup(struct load_info *info) { } #endif - -#ifdef CONFIG_MODULE_SIG_PROTECT -extern bool gki_is_module_exported_symbol(const char *name); -extern bool gki_is_module_protected_symbol(const char *name); -#else -static inline bool gki_is_module_exported_symbol(const char *name) -{ - return 0; -} -static inline bool gki_is_module_protected_symbol(const char *name) -{ - return 0; -} -#endif /* CONFIG_MODULE_SIG_PROTECT */ diff --git a/kernel/module.c b/kernel/module.c index cc846a80b229..c9e2342da28e 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -267,7 +267,7 @@ static void module_assert_mutex_or_preempt(void) #endif } -#if defined(CONFIG_MODULE_SIG) && !defined(CONFIG_MODULE_SIG_PROTECT) +#ifdef CONFIG_MODULE_SIG static bool sig_enforce = IS_ENABLED(CONFIG_MODULE_SIG_FORCE); module_param(sig_enforce, bool_enable_only, 0644); @@ -2244,14 +2244,6 @@ static int verify_exported_symbols(struct module *mod) .name = kernel_symbol_name(s), .gplok = true, }; - - if (!mod->sig_ok && gki_is_module_exported_symbol( - kernel_symbol_name(s))) { - pr_err("%s: exporting protected symbol(%s)\n", - mod->name, kernel_symbol_name(s)); - return -EACCES; - } - if (find_symbol(&fsa)) { pr_err("%s: exports duplicate symbol %s" " (owned by %s)\n", @@ -2319,13 +2311,6 @@ static int simplify_symbols(struct module *mod, const struct load_info *info) break; case SHN_UNDEF: - if (!mod->sig_ok && - gki_is_module_protected_symbol(name)) { - pr_err("%s: is not an Android GKI signed module. It can not access protected symbol: %s\n", - mod->name, name); - return -EACCES; - } - ksym = resolve_symbol_wait(mod, info, name); /* Ok if resolved. */ if (ksym && !IS_ERR(ksym)) { @@ -4027,8 +4012,6 @@ static int load_module(struct load_info *info, const char __user *uargs, "kernel\n", mod->name); add_taint_module(mod, TAINT_UNSIGNED_MODULE, LOCKDEP_STILL_OK); } -#else - mod->sig_ok = 0; #endif /* To avoid stressing percpu allocator, do this once we're unique. */