mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-09 06:14:34 +02:00
ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE has
no privilege check at all.
The fd-lookup in handshake_nl_done_doit() only confirms that
some pending handshake request exists for the supplied sockfd;
it does not authenticate the sender. An unprivileged process
that guesses or observes a valid sockfd can therefore submit
a DONE with HANDSHAKE_A_DONE_STATUS == 0, leaving the kernel
consumer to proceed as if the handshake succeeded. A non-zero
status on a forged DONE tears down a legitimate in-flight
handshake before tlshd can report its real result.
Fixes: 3b3009ea8a ("net/handshake: Create a NETLINK service for handling handshake requests")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Link: https://patch.msgid.link/20260609141831.90694-1-cel@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
61 lines
1.9 KiB
C
61 lines
1.9 KiB
C
// SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
|
|
/* Do not edit directly, auto-generated from: */
|
|
/* Documentation/netlink/specs/handshake.yaml */
|
|
/* YNL-GEN kernel source */
|
|
/* To regenerate run: tools/net/ynl/ynl-regen.sh */
|
|
|
|
#include <net/netlink.h>
|
|
#include <net/genetlink.h>
|
|
|
|
#include "genl.h"
|
|
|
|
#include <uapi/linux/handshake.h>
|
|
#include <linux/err.h>
|
|
|
|
/* HANDSHAKE_CMD_ACCEPT - do */
|
|
static const struct nla_policy handshake_accept_nl_policy[HANDSHAKE_A_ACCEPT_HANDLER_CLASS + 1] = {
|
|
[HANDSHAKE_A_ACCEPT_HANDLER_CLASS] = NLA_POLICY_MAX(NLA_U32, 2),
|
|
};
|
|
|
|
/* HANDSHAKE_CMD_DONE - do */
|
|
static const struct nla_policy handshake_done_nl_policy[HANDSHAKE_A_DONE_REMOTE_AUTH + 1] = {
|
|
[HANDSHAKE_A_DONE_STATUS] = NLA_POLICY_MAX(NLA_U32, MAX_ERRNO),
|
|
[HANDSHAKE_A_DONE_SOCKFD] = { .type = NLA_S32, },
|
|
[HANDSHAKE_A_DONE_REMOTE_AUTH] = { .type = NLA_U32, },
|
|
};
|
|
|
|
/* Ops table for handshake */
|
|
static const struct genl_split_ops handshake_nl_ops[] = {
|
|
{
|
|
.cmd = HANDSHAKE_CMD_ACCEPT,
|
|
.doit = handshake_nl_accept_doit,
|
|
.policy = handshake_accept_nl_policy,
|
|
.maxattr = HANDSHAKE_A_ACCEPT_HANDLER_CLASS,
|
|
.flags = GENL_ADMIN_PERM | GENL_CMD_CAP_DO,
|
|
},
|
|
{
|
|
.cmd = HANDSHAKE_CMD_DONE,
|
|
.doit = handshake_nl_done_doit,
|
|
.policy = handshake_done_nl_policy,
|
|
.maxattr = HANDSHAKE_A_DONE_REMOTE_AUTH,
|
|
.flags = GENL_ADMIN_PERM | GENL_CMD_CAP_DO,
|
|
},
|
|
};
|
|
|
|
static const struct genl_multicast_group handshake_nl_mcgrps[] = {
|
|
[HANDSHAKE_NLGRP_NONE] = { "none", },
|
|
[HANDSHAKE_NLGRP_TLSHD] = { "tlshd", },
|
|
};
|
|
|
|
struct genl_family handshake_nl_family __ro_after_init = {
|
|
.name = HANDSHAKE_FAMILY_NAME,
|
|
.version = HANDSHAKE_FAMILY_VERSION,
|
|
.netnsok = true,
|
|
.parallel_ops = true,
|
|
.module = THIS_MODULE,
|
|
.split_ops = handshake_nl_ops,
|
|
.n_split_ops = ARRAY_SIZE(handshake_nl_ops),
|
|
.mcgrps = handshake_nl_mcgrps,
|
|
.n_mcgrps = ARRAY_SIZE(handshake_nl_mcgrps),
|
|
};
|