mirror of
https://github.com/LineageOS/android_kernel_samsung_msm8226.git
synced 2026-09-28 00:00:22 +02:00
misc: Remove Samsung KNOX VPN sprinkles
* Will make upstream merges easier Change-Id: Iafad6c78f627fed05e6c97e65106a75a285d87b5 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
7fb0e30d17
commit
2c9ddf637d
@@ -77,17 +77,6 @@
|
||||
#include <net/netns/generic.h>
|
||||
#include <net/rtnetlink.h>
|
||||
#include <net/sock.h>
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
#include <linux/types.h>
|
||||
#include <linux/udp.h>
|
||||
#include <linux/tcp.h>
|
||||
#include <linux/ip.h>
|
||||
#include <net/ip.h>
|
||||
|
||||
#define META_MARK_BASE_LOWER 100
|
||||
#define META_MARK_BASE_UPPER 500
|
||||
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
#include <asm/uaccess.h>
|
||||
|
||||
@@ -120,28 +109,6 @@ do { \
|
||||
} while (0)
|
||||
#endif
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
/* The KNOX framework marks packets intended to a VPN client for special processing differently.
|
||||
* The marked packets hit special IP table rules and are routed back to user space using the TUN driver
|
||||
* for policy based treatment by the VPN client.
|
||||
* Some VPN clients can make more intelligent decisions based on the UID/PID information.
|
||||
* For such clients, we mark packets to be in the range >= META_MARK_BASE_LOWER and < META_MARK_BASE_UPPER.
|
||||
* When such packets are seen, we update the IP headers to carry UID/PID information
|
||||
* in the IP options - all other packets are ignored.
|
||||
* Also, see the comments above the individual steps taken in the code for details
|
||||
*/
|
||||
|
||||
/* Metadata header structure */
|
||||
|
||||
struct knox_meta_param {
|
||||
uid_t uid;
|
||||
pid_t pid;
|
||||
};
|
||||
|
||||
#define TUN_META_HDR_SZ sizeof(struct knox_meta_param)
|
||||
#define TUN_META_MARK_OFFSET offsetof(struct knox_meta_param, uid)
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
#define FLT_EXACT_COUNT 8
|
||||
struct tap_filter {
|
||||
unsigned int count; /* Number of addrs. Zero means disabled */
|
||||
@@ -793,67 +760,6 @@ static ssize_t tun_chr_aio_write(struct kiocb *iocb, const struct iovec *iv,
|
||||
return result;
|
||||
}
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
|
||||
/* KNOX VPN packets have extra bytes because they carry meta information by default
|
||||
* Such packets have sizeof(struct tun_meta_header) extra bytes in the IP options
|
||||
* This automatically reflects in the IP header length (IHL)
|
||||
*/
|
||||
static int knoxvpn_process_uidpid(struct tun_struct *tun, struct sk_buff *skb,
|
||||
const struct iovec *iv, int *len, ssize_t * total)
|
||||
{
|
||||
struct skb_shared_info *knox_shinfo = NULL;
|
||||
struct knox_meta_param metalocal = { 0, 0 };
|
||||
|
||||
if (skb != NULL)
|
||||
knox_shinfo = skb_shinfo(skb);
|
||||
else {
|
||||
#ifdef TUN_DEBUG
|
||||
pr_err("KNOX: NULL SKB in knoxvpn_process_uidpid");
|
||||
#endif
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (knox_shinfo == NULL) {
|
||||
#ifdef TUN_DEBUG
|
||||
pr_err("KNOX: knox_shinfo value is null");
|
||||
#endif
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (knox_shinfo->knox_mark >= META_MARK_BASE_LOWER && knox_shinfo->knox_mark <= META_MARK_BASE_UPPER) {
|
||||
metalocal.uid = knox_shinfo->uid;
|
||||
metalocal.pid = knox_shinfo->pid;
|
||||
}
|
||||
|
||||
if (knox_shinfo != NULL) {
|
||||
knox_shinfo->uid = knox_shinfo->pid = 0;
|
||||
knox_shinfo->knox_mark = 0;
|
||||
}
|
||||
|
||||
if (tun->flags & TUN_META_HDR) {
|
||||
#ifdef TUN_DEBUG
|
||||
pr_err("KNOX: Appending uid: %d and pid: %d", metalocal.uid,
|
||||
metalocal.pid);
|
||||
#endif
|
||||
if (unlikely
|
||||
(memcpy_toiovecend
|
||||
(iv, (void *)&metalocal, (*total),
|
||||
sizeof(struct knox_meta_param)))) {
|
||||
#ifdef TUN_DEBUG
|
||||
pr_err("KNOX: Failed to copy buffer to userspace");
|
||||
#endif
|
||||
return -1;
|
||||
}
|
||||
(*total) += TUN_META_HDR_SZ;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
}
|
||||
|
||||
// ------------- END of KNOX_VPN ------------------//
|
||||
|
||||
/* Put packet to the user space buffer */
|
||||
static ssize_t tun_put_user(struct tun_struct *tun,
|
||||
struct sk_buff *skb,
|
||||
@@ -924,12 +830,6 @@ static ssize_t tun_put_user(struct tun_struct *tun,
|
||||
total += tun->vnet_hdr_sz;
|
||||
}
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
if (knoxvpn_process_uidpid(tun, skb, iv, &len, &total) < 0) {
|
||||
return -EINVAL;
|
||||
}
|
||||
// ------------- END of KNOX_VPN ------------------//
|
||||
|
||||
len = min_t(int, skb->len, len);
|
||||
|
||||
skb_copy_datagram_const_iovec(skb, 0, iv, total, len);
|
||||
@@ -1112,15 +1012,6 @@ static int tun_flags(struct tun_struct *tun)
|
||||
{
|
||||
int flags = 0;
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
/* Checks if meta header is enabled so that
|
||||
* packets will be prepended with meta data(UID/PID)
|
||||
*/
|
||||
if (tun->flags & TUN_META_HDR) {
|
||||
flags |= IFF_META_HDR;
|
||||
}
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
if (tun->flags & TUN_TUN_DEV)
|
||||
flags |= IFF_TUN;
|
||||
else
|
||||
@@ -1275,14 +1166,6 @@ static int tun_set_iff(struct net *net, struct file *file, struct ifreq *ifr)
|
||||
|
||||
tun_debug(KERN_INFO, tun, "tun_set_iff\n");
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
if (ifr->ifr_flags & IFF_META_HDR) {
|
||||
tun->flags |= TUN_META_HDR;
|
||||
} else {
|
||||
tun->flags &= ~TUN_META_HDR;
|
||||
}
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
if (ifr->ifr_flags & IFF_NO_PI)
|
||||
tun->flags |= TUN_NO_PI;
|
||||
else
|
||||
@@ -1377,11 +1260,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
|
||||
int sndbuf;
|
||||
int vnet_hdr_sz;
|
||||
int ret;
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
int knox_flag = 0;
|
||||
int tun_meta_param;
|
||||
int tun_meta_value;
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
#ifdef CONFIG_ANDROID_PARANOID_NETWORK
|
||||
if (cmd != TUNGETIFF && !capable(CAP_NET_ADMIN)) {
|
||||
@@ -1397,13 +1275,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
|
||||
/* Currently this just means: "what IFF flags are valid?".
|
||||
* This is needed because we never checked for invalid flags on
|
||||
* TUNSETIFF. */
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
knox_flag |= IFF_META_HDR;
|
||||
return put_user(IFF_TUN | IFF_TAP | IFF_NO_PI | IFF_ONE_QUEUE |
|
||||
IFF_VNET_HDR | knox_flag,
|
||||
(unsigned int __user*)argp);
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
}
|
||||
|
||||
rtnl_lock();
|
||||
@@ -1553,38 +1424,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
|
||||
tun->vnet_hdr_sz = vnet_hdr_sz;
|
||||
break;
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
case TUNGETMETAPARAM:
|
||||
|
||||
if (copy_from_user(&tun_meta_param, argp,
|
||||
sizeof(tun_meta_param))) {
|
||||
ret = -EFAULT;
|
||||
break;
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
switch (tun_meta_param) {
|
||||
case TUN_GET_META_HDR_SZ:
|
||||
tun_meta_value = TUN_META_HDR_SZ;
|
||||
break;
|
||||
|
||||
case TUN_GET_META_MARK_OFFSET:
|
||||
tun_meta_value = TUN_META_MARK_OFFSET;
|
||||
break;
|
||||
|
||||
default:
|
||||
ret = -EINVAL;
|
||||
break;
|
||||
}
|
||||
|
||||
if (!ret) {
|
||||
if (copy_to_user(argp, &tun_meta_value,
|
||||
sizeof(tun_meta_value)))
|
||||
ret = -EFAULT;
|
||||
}
|
||||
break;
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
case TUNATTACHFILTER:
|
||||
/* Can be set only for TAPs */
|
||||
ret = -EINVAL;
|
||||
|
||||
@@ -78,15 +78,6 @@
|
||||
#define TUN_F_TSO_ECN 0x08 /* I can handle TSO with ECN bits. */
|
||||
#define TUN_F_UFO 0x10 /* I can handle UFO packets */
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
#define TUN_META_HDR 0x0800
|
||||
#define TUNGETMETAPARAM _IOR('T', 218, int)
|
||||
#define IFF_META_HDR 0x0004
|
||||
#define TUN_GET_META_HDR_SZ 0
|
||||
#define TUN_GET_META_MARK_OFFSET 1
|
||||
#define DEFAULT_IHL 5
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
/* Protocol info prepended to the packets (when IFF_NO_PI is not set) */
|
||||
#define TUN_PKT_STRIP 0x0001
|
||||
struct tun_pi {
|
||||
|
||||
@@ -278,13 +278,6 @@ struct skb_shared_info {
|
||||
/* Intermediate layers must ensure that destructor_arg
|
||||
* remains valid until skb destructor */
|
||||
void * destructor_arg;
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
uid_t uid;
|
||||
pid_t pid;
|
||||
u_int32_t knox_mark;
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
|
||||
/* must be last field, see pskb_expand_head() */
|
||||
skb_frag_t frags[MAX_SKB_FRAGS];
|
||||
|
||||
@@ -381,8 +381,6 @@ struct sock {
|
||||
__u32 sk_mark;
|
||||
u32 sk_classid;
|
||||
struct cg_proto *sk_cgrp;
|
||||
uid_t knox_uid;
|
||||
pid_t knox_pid;
|
||||
void (*sk_state_change)(struct sock *sk);
|
||||
void (*sk_data_ready)(struct sock *sk, int bytes);
|
||||
void (*sk_write_space)(struct sock *sk);
|
||||
|
||||
@@ -1144,11 +1144,6 @@ static struct sock *sk_prot_alloc(struct proto *prot, gfp_t priority,
|
||||
if (!try_module_get(prot->owner))
|
||||
goto out_free_sec;
|
||||
sk_tx_queue_clear(sk);
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
sk->knox_uid = current->cred->uid;
|
||||
sk->knox_pid = current->tgid;
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
}
|
||||
|
||||
return sk;
|
||||
|
||||
@@ -37,13 +37,6 @@
|
||||
#include <linux/netfilter/x_tables.h>
|
||||
#include <linux/netfilter/xt_connmark.h>
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
#include <linux/types.h>
|
||||
#include <linux/tcp.h>
|
||||
#include <linux/ip.h>
|
||||
#include <net/ip.h>
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
MODULE_AUTHOR("Henrik Nordstrom <hno@marasystems.com>");
|
||||
MODULE_DESCRIPTION("Xtables: connection mark operations");
|
||||
MODULE_LICENSE("GPL");
|
||||
@@ -52,66 +45,6 @@ MODULE_ALIAS("ip6t_CONNMARK");
|
||||
MODULE_ALIAS("ipt_connmark");
|
||||
MODULE_ALIAS("ip6t_connmark");
|
||||
|
||||
// ------------- START of KNOX_VPN ------------------//
|
||||
|
||||
/* KNOX framework uses mark value 100 to 500
|
||||
* when the special meta data is added
|
||||
* This will indicate to the kernel code that
|
||||
* it needs to append meta data to the packets
|
||||
*/
|
||||
|
||||
#define META_MARK_BASE_LOWER 100
|
||||
#define META_MARK_BASE_UPPER 500
|
||||
|
||||
/* Structure to hold metadata values
|
||||
* intended for VPN clients to make
|
||||
* more intelligent decisions
|
||||
* when the KNOX meta mark
|
||||
* feature is enabled
|
||||
*/
|
||||
|
||||
struct knox_meta_param {
|
||||
uid_t uid;
|
||||
pid_t pid;
|
||||
};
|
||||
|
||||
static unsigned int knoxvpn_uidpid(struct sk_buff *skb, u_int32_t newmark)
|
||||
{
|
||||
int szMetaData;
|
||||
struct skb_shared_info *knox_shinfo = NULL;
|
||||
|
||||
szMetaData = sizeof(struct knox_meta_param);
|
||||
if (skb != NULL) {
|
||||
knox_shinfo = skb_shinfo(skb);
|
||||
} else {
|
||||
pr_err("KNOX: NULL SKB - no KNOX processing");
|
||||
return -1;
|
||||
}
|
||||
|
||||
if( skb->sk == NULL) {
|
||||
pr_err("KNOX: skb->sk value is null");
|
||||
return -1;
|
||||
}
|
||||
|
||||
if( knox_shinfo == NULL) {
|
||||
pr_err("KNOX: knox_shinfo is null");
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (newmark < META_MARK_BASE_LOWER || newmark > META_MARK_BASE_UPPER) {
|
||||
pr_err("KNOX: The mark is out of range");
|
||||
return -1;
|
||||
} else {
|
||||
knox_shinfo->uid = skb->sk->knox_uid;
|
||||
knox_shinfo->pid = skb->sk->knox_pid;
|
||||
knox_shinfo->knox_mark = newmark;
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
|
||||
static unsigned int
|
||||
connmark_tg(struct sk_buff *skb, const struct xt_action_param *par)
|
||||
{
|
||||
@@ -144,9 +77,6 @@ connmark_tg(struct sk_buff *skb, const struct xt_action_param *par)
|
||||
newmark = (skb->mark & ~info->nfmask) ^
|
||||
(ct->mark & info->ctmask);
|
||||
skb->mark = newmark;
|
||||
// ------------- START of KNOX_VPN -----------------//
|
||||
knoxvpn_uidpid(skb, newmark);
|
||||
// ------------- END of KNOX_VPN -------------------//
|
||||
break;
|
||||
}
|
||||
return XT_CONTINUE;
|
||||
|
||||
Reference in New Issue
Block a user