misc: Remove Samsung KNOX VPN sprinkles

* Will make upstream merges easier

Change-Id: Iafad6c78f627fed05e6c97e65106a75a285d87b5
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
Kevin F. Haggerty
2019-08-05 09:12:32 +02:00
committed by Francescodario Cuzzocrea
parent 7fb0e30d17
commit 2c9ddf637d
6 changed files with 0 additions and 254 deletions
-161
View File
@@ -77,17 +77,6 @@
#include <net/netns/generic.h>
#include <net/rtnetlink.h>
#include <net/sock.h>
// ------------- START of KNOX_VPN ------------------//
#include <linux/types.h>
#include <linux/udp.h>
#include <linux/tcp.h>
#include <linux/ip.h>
#include <net/ip.h>
#define META_MARK_BASE_LOWER 100
#define META_MARK_BASE_UPPER 500
// ------------- END of KNOX_VPN -------------------//
#include <asm/uaccess.h>
@@ -120,28 +109,6 @@ do { \
} while (0)
#endif
// ------------- START of KNOX_VPN ------------------//
/* The KNOX framework marks packets intended to a VPN client for special processing differently.
* The marked packets hit special IP table rules and are routed back to user space using the TUN driver
* for policy based treatment by the VPN client.
* Some VPN clients can make more intelligent decisions based on the UID/PID information.
* For such clients, we mark packets to be in the range >= META_MARK_BASE_LOWER and < META_MARK_BASE_UPPER.
* When such packets are seen, we update the IP headers to carry UID/PID information
* in the IP options - all other packets are ignored.
* Also, see the comments above the individual steps taken in the code for details
*/
/* Metadata header structure */
struct knox_meta_param {
uid_t uid;
pid_t pid;
};
#define TUN_META_HDR_SZ sizeof(struct knox_meta_param)
#define TUN_META_MARK_OFFSET offsetof(struct knox_meta_param, uid)
// ------------- END of KNOX_VPN -------------------//
#define FLT_EXACT_COUNT 8
struct tap_filter {
unsigned int count; /* Number of addrs. Zero means disabled */
@@ -793,67 +760,6 @@ static ssize_t tun_chr_aio_write(struct kiocb *iocb, const struct iovec *iv,
return result;
}
// ------------- START of KNOX_VPN ------------------//
/* KNOX VPN packets have extra bytes because they carry meta information by default
* Such packets have sizeof(struct tun_meta_header) extra bytes in the IP options
* This automatically reflects in the IP header length (IHL)
*/
static int knoxvpn_process_uidpid(struct tun_struct *tun, struct sk_buff *skb,
const struct iovec *iv, int *len, ssize_t * total)
{
struct skb_shared_info *knox_shinfo = NULL;
struct knox_meta_param metalocal = { 0, 0 };
if (skb != NULL)
knox_shinfo = skb_shinfo(skb);
else {
#ifdef TUN_DEBUG
pr_err("KNOX: NULL SKB in knoxvpn_process_uidpid");
#endif
return 0;
}
if (knox_shinfo == NULL) {
#ifdef TUN_DEBUG
pr_err("KNOX: knox_shinfo value is null");
#endif
return 0;
}
if (knox_shinfo->knox_mark >= META_MARK_BASE_LOWER && knox_shinfo->knox_mark <= META_MARK_BASE_UPPER) {
metalocal.uid = knox_shinfo->uid;
metalocal.pid = knox_shinfo->pid;
}
if (knox_shinfo != NULL) {
knox_shinfo->uid = knox_shinfo->pid = 0;
knox_shinfo->knox_mark = 0;
}
if (tun->flags & TUN_META_HDR) {
#ifdef TUN_DEBUG
pr_err("KNOX: Appending uid: %d and pid: %d", metalocal.uid,
metalocal.pid);
#endif
if (unlikely
(memcpy_toiovecend
(iv, (void *)&metalocal, (*total),
sizeof(struct knox_meta_param)))) {
#ifdef TUN_DEBUG
pr_err("KNOX: Failed to copy buffer to userspace");
#endif
return -1;
}
(*total) += TUN_META_HDR_SZ;
}
return 0;
}
// ------------- END of KNOX_VPN ------------------//
/* Put packet to the user space buffer */
static ssize_t tun_put_user(struct tun_struct *tun,
struct sk_buff *skb,
@@ -924,12 +830,6 @@ static ssize_t tun_put_user(struct tun_struct *tun,
total += tun->vnet_hdr_sz;
}
// ------------- START of KNOX_VPN ------------------//
if (knoxvpn_process_uidpid(tun, skb, iv, &len, &total) < 0) {
return -EINVAL;
}
// ------------- END of KNOX_VPN ------------------//
len = min_t(int, skb->len, len);
skb_copy_datagram_const_iovec(skb, 0, iv, total, len);
@@ -1112,15 +1012,6 @@ static int tun_flags(struct tun_struct *tun)
{
int flags = 0;
// ------------- START of KNOX_VPN ------------------//
/* Checks if meta header is enabled so that
* packets will be prepended with meta data(UID/PID)
*/
if (tun->flags & TUN_META_HDR) {
flags |= IFF_META_HDR;
}
// ------------- END of KNOX_VPN -------------------//
if (tun->flags & TUN_TUN_DEV)
flags |= IFF_TUN;
else
@@ -1275,14 +1166,6 @@ static int tun_set_iff(struct net *net, struct file *file, struct ifreq *ifr)
tun_debug(KERN_INFO, tun, "tun_set_iff\n");
// ------------- START of KNOX_VPN ------------------//
if (ifr->ifr_flags & IFF_META_HDR) {
tun->flags |= TUN_META_HDR;
} else {
tun->flags &= ~TUN_META_HDR;
}
// ------------- END of KNOX_VPN -------------------//
if (ifr->ifr_flags & IFF_NO_PI)
tun->flags |= TUN_NO_PI;
else
@@ -1377,11 +1260,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
int sndbuf;
int vnet_hdr_sz;
int ret;
// ------------- START of KNOX_VPN ------------------//
int knox_flag = 0;
int tun_meta_param;
int tun_meta_value;
// ------------- END of KNOX_VPN -------------------//
#ifdef CONFIG_ANDROID_PARANOID_NETWORK
if (cmd != TUNGETIFF && !capable(CAP_NET_ADMIN)) {
@@ -1397,13 +1275,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
/* Currently this just means: "what IFF flags are valid?".
* This is needed because we never checked for invalid flags on
* TUNSETIFF. */
// ------------- START of KNOX_VPN ------------------//
knox_flag |= IFF_META_HDR;
return put_user(IFF_TUN | IFF_TAP | IFF_NO_PI | IFF_ONE_QUEUE |
IFF_VNET_HDR | knox_flag,
(unsigned int __user*)argp);
// ------------- END of KNOX_VPN -------------------//
}
rtnl_lock();
@@ -1553,38 +1424,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
tun->vnet_hdr_sz = vnet_hdr_sz;
break;
// ------------- START of KNOX_VPN ------------------//
case TUNGETMETAPARAM:
if (copy_from_user(&tun_meta_param, argp,
sizeof(tun_meta_param))) {
ret = -EFAULT;
break;
}
ret = 0;
switch (tun_meta_param) {
case TUN_GET_META_HDR_SZ:
tun_meta_value = TUN_META_HDR_SZ;
break;
case TUN_GET_META_MARK_OFFSET:
tun_meta_value = TUN_META_MARK_OFFSET;
break;
default:
ret = -EINVAL;
break;
}
if (!ret) {
if (copy_to_user(argp, &tun_meta_value,
sizeof(tun_meta_value)))
ret = -EFAULT;
}
break;
// ------------- END of KNOX_VPN -------------------//
case TUNATTACHFILTER:
/* Can be set only for TAPs */
ret = -EINVAL;
-9
View File
@@ -78,15 +78,6 @@
#define TUN_F_TSO_ECN 0x08 /* I can handle TSO with ECN bits. */
#define TUN_F_UFO 0x10 /* I can handle UFO packets */
// ------------- START of KNOX_VPN ------------------//
#define TUN_META_HDR 0x0800
#define TUNGETMETAPARAM _IOR('T', 218, int)
#define IFF_META_HDR 0x0004
#define TUN_GET_META_HDR_SZ 0
#define TUN_GET_META_MARK_OFFSET 1
#define DEFAULT_IHL 5
// ------------- END of KNOX_VPN -------------------//
/* Protocol info prepended to the packets (when IFF_NO_PI is not set) */
#define TUN_PKT_STRIP 0x0001
struct tun_pi {
-7
View File
@@ -278,13 +278,6 @@ struct skb_shared_info {
/* Intermediate layers must ensure that destructor_arg
* remains valid until skb destructor */
void * destructor_arg;
// ------------- START of KNOX_VPN ------------------//
uid_t uid;
pid_t pid;
u_int32_t knox_mark;
// ------------- END of KNOX_VPN -------------------//
/* must be last field, see pskb_expand_head() */
skb_frag_t frags[MAX_SKB_FRAGS];
-2
View File
@@ -381,8 +381,6 @@ struct sock {
__u32 sk_mark;
u32 sk_classid;
struct cg_proto *sk_cgrp;
uid_t knox_uid;
pid_t knox_pid;
void (*sk_state_change)(struct sock *sk);
void (*sk_data_ready)(struct sock *sk, int bytes);
void (*sk_write_space)(struct sock *sk);
-5
View File
@@ -1144,11 +1144,6 @@ static struct sock *sk_prot_alloc(struct proto *prot, gfp_t priority,
if (!try_module_get(prot->owner))
goto out_free_sec;
sk_tx_queue_clear(sk);
// ------------- START of KNOX_VPN ------------------//
sk->knox_uid = current->cred->uid;
sk->knox_pid = current->tgid;
// ------------- END of KNOX_VPN -------------------//
}
return sk;
-70
View File
@@ -37,13 +37,6 @@
#include <linux/netfilter/x_tables.h>
#include <linux/netfilter/xt_connmark.h>
// ------------- START of KNOX_VPN ------------------//
#include <linux/types.h>
#include <linux/tcp.h>
#include <linux/ip.h>
#include <net/ip.h>
// ------------- END of KNOX_VPN -------------------//
MODULE_AUTHOR("Henrik Nordstrom <hno@marasystems.com>");
MODULE_DESCRIPTION("Xtables: connection mark operations");
MODULE_LICENSE("GPL");
@@ -52,66 +45,6 @@ MODULE_ALIAS("ip6t_CONNMARK");
MODULE_ALIAS("ipt_connmark");
MODULE_ALIAS("ip6t_connmark");
// ------------- START of KNOX_VPN ------------------//
/* KNOX framework uses mark value 100 to 500
* when the special meta data is added
* This will indicate to the kernel code that
* it needs to append meta data to the packets
*/
#define META_MARK_BASE_LOWER 100
#define META_MARK_BASE_UPPER 500
/* Structure to hold metadata values
* intended for VPN clients to make
* more intelligent decisions
* when the KNOX meta mark
* feature is enabled
*/
struct knox_meta_param {
uid_t uid;
pid_t pid;
};
static unsigned int knoxvpn_uidpid(struct sk_buff *skb, u_int32_t newmark)
{
int szMetaData;
struct skb_shared_info *knox_shinfo = NULL;
szMetaData = sizeof(struct knox_meta_param);
if (skb != NULL) {
knox_shinfo = skb_shinfo(skb);
} else {
pr_err("KNOX: NULL SKB - no KNOX processing");
return -1;
}
if( skb->sk == NULL) {
pr_err("KNOX: skb->sk value is null");
return -1;
}
if( knox_shinfo == NULL) {
pr_err("KNOX: knox_shinfo is null");
return -1;
}
if (newmark < META_MARK_BASE_LOWER || newmark > META_MARK_BASE_UPPER) {
pr_err("KNOX: The mark is out of range");
return -1;
} else {
knox_shinfo->uid = skb->sk->knox_uid;
knox_shinfo->pid = skb->sk->knox_pid;
knox_shinfo->knox_mark = newmark;
}
return 0;
}
// ------------- END of KNOX_VPN -------------------//
static unsigned int
connmark_tg(struct sk_buff *skb, const struct xt_action_param *par)
{
@@ -144,9 +77,6 @@ connmark_tg(struct sk_buff *skb, const struct xt_action_param *par)
newmark = (skb->mark & ~info->nfmask) ^
(ct->mark & info->ctmask);
skb->mark = newmark;
// ------------- START of KNOX_VPN -----------------//
knoxvpn_uidpid(skb, newmark);
// ------------- END of KNOX_VPN -------------------//
break;
}
return XT_CONTINUE;