From 2c9ddf637dea0cd20d104bcc90abc1d42ffdd73b Mon Sep 17 00:00:00 2001 From: "Kevin F. Haggerty" Date: Wed, 17 May 2017 20:33:20 -0600 Subject: [PATCH] misc: Remove Samsung KNOX VPN sprinkles * Will make upstream merges easier Change-Id: Iafad6c78f627fed05e6c97e65106a75a285d87b5 Signed-off-by: Kevin F. Haggerty --- drivers/net/tun.c | 161 ------------------------------------ include/linux/if_tun.h | 9 -- include/linux/skbuff.h | 7 -- include/net/sock.h | 2 - net/core/sock.c | 5 -- net/netfilter/xt_connmark.c | 70 ---------------- 6 files changed, 254 deletions(-) diff --git a/drivers/net/tun.c b/drivers/net/tun.c index 5b471a2f661..657fcb84b98 100644 --- a/drivers/net/tun.c +++ b/drivers/net/tun.c @@ -77,17 +77,6 @@ #include #include #include -// ------------- START of KNOX_VPN ------------------// -#include -#include -#include -#include -#include - -#define META_MARK_BASE_LOWER 100 -#define META_MARK_BASE_UPPER 500 - -// ------------- END of KNOX_VPN -------------------// #include @@ -120,28 +109,6 @@ do { \ } while (0) #endif -// ------------- START of KNOX_VPN ------------------// -/* The KNOX framework marks packets intended to a VPN client for special processing differently. - * The marked packets hit special IP table rules and are routed back to user space using the TUN driver - * for policy based treatment by the VPN client. - * Some VPN clients can make more intelligent decisions based on the UID/PID information. - * For such clients, we mark packets to be in the range >= META_MARK_BASE_LOWER and < META_MARK_BASE_UPPER. - * When such packets are seen, we update the IP headers to carry UID/PID information - * in the IP options - all other packets are ignored. - * Also, see the comments above the individual steps taken in the code for details - */ - -/* Metadata header structure */ - -struct knox_meta_param { - uid_t uid; - pid_t pid; -}; - -#define TUN_META_HDR_SZ sizeof(struct knox_meta_param) -#define TUN_META_MARK_OFFSET offsetof(struct knox_meta_param, uid) -// ------------- END of KNOX_VPN -------------------// - #define FLT_EXACT_COUNT 8 struct tap_filter { unsigned int count; /* Number of addrs. Zero means disabled */ @@ -793,67 +760,6 @@ static ssize_t tun_chr_aio_write(struct kiocb *iocb, const struct iovec *iv, return result; } -// ------------- START of KNOX_VPN ------------------// - -/* KNOX VPN packets have extra bytes because they carry meta information by default - * Such packets have sizeof(struct tun_meta_header) extra bytes in the IP options - * This automatically reflects in the IP header length (IHL) - */ -static int knoxvpn_process_uidpid(struct tun_struct *tun, struct sk_buff *skb, - const struct iovec *iv, int *len, ssize_t * total) -{ - struct skb_shared_info *knox_shinfo = NULL; - struct knox_meta_param metalocal = { 0, 0 }; - - if (skb != NULL) - knox_shinfo = skb_shinfo(skb); - else { - #ifdef TUN_DEBUG - pr_err("KNOX: NULL SKB in knoxvpn_process_uidpid"); - #endif - return 0; - } - - if (knox_shinfo == NULL) { - #ifdef TUN_DEBUG - pr_err("KNOX: knox_shinfo value is null"); - #endif - return 0; - } - - if (knox_shinfo->knox_mark >= META_MARK_BASE_LOWER && knox_shinfo->knox_mark <= META_MARK_BASE_UPPER) { - metalocal.uid = knox_shinfo->uid; - metalocal.pid = knox_shinfo->pid; - } - - if (knox_shinfo != NULL) { - knox_shinfo->uid = knox_shinfo->pid = 0; - knox_shinfo->knox_mark = 0; - } - - if (tun->flags & TUN_META_HDR) { -#ifdef TUN_DEBUG - pr_err("KNOX: Appending uid: %d and pid: %d", metalocal.uid, - metalocal.pid); -#endif - if (unlikely - (memcpy_toiovecend - (iv, (void *)&metalocal, (*total), - sizeof(struct knox_meta_param)))) { -#ifdef TUN_DEBUG - pr_err("KNOX: Failed to copy buffer to userspace"); -#endif - return -1; - } - (*total) += TUN_META_HDR_SZ; - } - - return 0; - -} - -// ------------- END of KNOX_VPN ------------------// - /* Put packet to the user space buffer */ static ssize_t tun_put_user(struct tun_struct *tun, struct sk_buff *skb, @@ -924,12 +830,6 @@ static ssize_t tun_put_user(struct tun_struct *tun, total += tun->vnet_hdr_sz; } -// ------------- START of KNOX_VPN ------------------// - if (knoxvpn_process_uidpid(tun, skb, iv, &len, &total) < 0) { - return -EINVAL; - } -// ------------- END of KNOX_VPN ------------------// - len = min_t(int, skb->len, len); skb_copy_datagram_const_iovec(skb, 0, iv, total, len); @@ -1112,15 +1012,6 @@ static int tun_flags(struct tun_struct *tun) { int flags = 0; -// ------------- START of KNOX_VPN ------------------// - /* Checks if meta header is enabled so that - * packets will be prepended with meta data(UID/PID) - */ - if (tun->flags & TUN_META_HDR) { - flags |= IFF_META_HDR; - } -// ------------- END of KNOX_VPN -------------------// - if (tun->flags & TUN_TUN_DEV) flags |= IFF_TUN; else @@ -1275,14 +1166,6 @@ static int tun_set_iff(struct net *net, struct file *file, struct ifreq *ifr) tun_debug(KERN_INFO, tun, "tun_set_iff\n"); -// ------------- START of KNOX_VPN ------------------// - if (ifr->ifr_flags & IFF_META_HDR) { - tun->flags |= TUN_META_HDR; - } else { - tun->flags &= ~TUN_META_HDR; - } -// ------------- END of KNOX_VPN -------------------// - if (ifr->ifr_flags & IFF_NO_PI) tun->flags |= TUN_NO_PI; else @@ -1377,11 +1260,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd, int sndbuf; int vnet_hdr_sz; int ret; -// ------------- START of KNOX_VPN ------------------// - int knox_flag = 0; - int tun_meta_param; - int tun_meta_value; -// ------------- END of KNOX_VPN -------------------// #ifdef CONFIG_ANDROID_PARANOID_NETWORK if (cmd != TUNGETIFF && !capable(CAP_NET_ADMIN)) { @@ -1397,13 +1275,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd, /* Currently this just means: "what IFF flags are valid?". * This is needed because we never checked for invalid flags on * TUNSETIFF. */ - -// ------------- START of KNOX_VPN ------------------// - knox_flag |= IFF_META_HDR; - return put_user(IFF_TUN | IFF_TAP | IFF_NO_PI | IFF_ONE_QUEUE | - IFF_VNET_HDR | knox_flag, - (unsigned int __user*)argp); -// ------------- END of KNOX_VPN -------------------// } rtnl_lock(); @@ -1553,38 +1424,6 @@ static long __tun_chr_ioctl(struct file *file, unsigned int cmd, tun->vnet_hdr_sz = vnet_hdr_sz; break; -// ------------- START of KNOX_VPN ------------------// - case TUNGETMETAPARAM: - - if (copy_from_user(&tun_meta_param, argp, - sizeof(tun_meta_param))) { - ret = -EFAULT; - break; - } - - ret = 0; - switch (tun_meta_param) { - case TUN_GET_META_HDR_SZ: - tun_meta_value = TUN_META_HDR_SZ; - break; - - case TUN_GET_META_MARK_OFFSET: - tun_meta_value = TUN_META_MARK_OFFSET; - break; - - default: - ret = -EINVAL; - break; - } - - if (!ret) { - if (copy_to_user(argp, &tun_meta_value, - sizeof(tun_meta_value))) - ret = -EFAULT; - } - break; -// ------------- END of KNOX_VPN -------------------// - case TUNATTACHFILTER: /* Can be set only for TAPs */ ret = -EINVAL; diff --git a/include/linux/if_tun.h b/include/linux/if_tun.h index cfb387275fe..08edf76fe1a 100644 --- a/include/linux/if_tun.h +++ b/include/linux/if_tun.h @@ -78,15 +78,6 @@ #define TUN_F_TSO_ECN 0x08 /* I can handle TSO with ECN bits. */ #define TUN_F_UFO 0x10 /* I can handle UFO packets */ -// ------------- START of KNOX_VPN ------------------// -#define TUN_META_HDR 0x0800 -#define TUNGETMETAPARAM _IOR('T', 218, int) -#define IFF_META_HDR 0x0004 -#define TUN_GET_META_HDR_SZ 0 -#define TUN_GET_META_MARK_OFFSET 1 -#define DEFAULT_IHL 5 -// ------------- END of KNOX_VPN -------------------// - /* Protocol info prepended to the packets (when IFF_NO_PI is not set) */ #define TUN_PKT_STRIP 0x0001 struct tun_pi { diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h index f1166355f9d..0810c1d00c7 100644 --- a/include/linux/skbuff.h +++ b/include/linux/skbuff.h @@ -278,13 +278,6 @@ struct skb_shared_info { /* Intermediate layers must ensure that destructor_arg * remains valid until skb destructor */ void * destructor_arg; - - // ------------- START of KNOX_VPN ------------------// - uid_t uid; - pid_t pid; - u_int32_t knox_mark; - // ------------- END of KNOX_VPN -------------------// - /* must be last field, see pskb_expand_head() */ skb_frag_t frags[MAX_SKB_FRAGS]; diff --git a/include/net/sock.h b/include/net/sock.h index aab1be34826..9603b916303 100644 --- a/include/net/sock.h +++ b/include/net/sock.h @@ -381,8 +381,6 @@ struct sock { __u32 sk_mark; u32 sk_classid; struct cg_proto *sk_cgrp; - uid_t knox_uid; - pid_t knox_pid; void (*sk_state_change)(struct sock *sk); void (*sk_data_ready)(struct sock *sk, int bytes); void (*sk_write_space)(struct sock *sk); diff --git a/net/core/sock.c b/net/core/sock.c index bd4025d3e97..9576a6e6695 100644 --- a/net/core/sock.c +++ b/net/core/sock.c @@ -1144,11 +1144,6 @@ static struct sock *sk_prot_alloc(struct proto *prot, gfp_t priority, if (!try_module_get(prot->owner)) goto out_free_sec; sk_tx_queue_clear(sk); - -// ------------- START of KNOX_VPN ------------------// - sk->knox_uid = current->cred->uid; - sk->knox_pid = current->tgid; -// ------------- END of KNOX_VPN -------------------// } return sk; diff --git a/net/netfilter/xt_connmark.c b/net/netfilter/xt_connmark.c index 67fe6a38f52..b4da25975af 100644 --- a/net/netfilter/xt_connmark.c +++ b/net/netfilter/xt_connmark.c @@ -37,13 +37,6 @@ #include #include -// ------------- START of KNOX_VPN ------------------// -#include -#include -#include -#include -// ------------- END of KNOX_VPN -------------------// - MODULE_AUTHOR("Henrik Nordstrom "); MODULE_DESCRIPTION("Xtables: connection mark operations"); MODULE_LICENSE("GPL"); @@ -52,66 +45,6 @@ MODULE_ALIAS("ip6t_CONNMARK"); MODULE_ALIAS("ipt_connmark"); MODULE_ALIAS("ip6t_connmark"); -// ------------- START of KNOX_VPN ------------------// - -/* KNOX framework uses mark value 100 to 500 - * when the special meta data is added - * This will indicate to the kernel code that - * it needs to append meta data to the packets - */ - -#define META_MARK_BASE_LOWER 100 -#define META_MARK_BASE_UPPER 500 - -/* Structure to hold metadata values - * intended for VPN clients to make - * more intelligent decisions - * when the KNOX meta mark - * feature is enabled - */ - -struct knox_meta_param { - uid_t uid; - pid_t pid; -}; - -static unsigned int knoxvpn_uidpid(struct sk_buff *skb, u_int32_t newmark) -{ - int szMetaData; - struct skb_shared_info *knox_shinfo = NULL; - - szMetaData = sizeof(struct knox_meta_param); - if (skb != NULL) { - knox_shinfo = skb_shinfo(skb); - } else { - pr_err("KNOX: NULL SKB - no KNOX processing"); - return -1; - } - - if( skb->sk == NULL) { - pr_err("KNOX: skb->sk value is null"); - return -1; - } - - if( knox_shinfo == NULL) { - pr_err("KNOX: knox_shinfo is null"); - return -1; - } - - if (newmark < META_MARK_BASE_LOWER || newmark > META_MARK_BASE_UPPER) { - pr_err("KNOX: The mark is out of range"); - return -1; - } else { - knox_shinfo->uid = skb->sk->knox_uid; - knox_shinfo->pid = skb->sk->knox_pid; - knox_shinfo->knox_mark = newmark; - } - - return 0; -} - -// ------------- END of KNOX_VPN -------------------// - static unsigned int connmark_tg(struct sk_buff *skb, const struct xt_action_param *par) { @@ -144,9 +77,6 @@ connmark_tg(struct sk_buff *skb, const struct xt_action_param *par) newmark = (skb->mark & ~info->nfmask) ^ (ct->mark & info->ctmask); skb->mark = newmark; -// ------------- START of KNOX_VPN -----------------// - knoxvpn_uidpid(skb, newmark); -// ------------- END of KNOX_VPN -------------------// break; } return XT_CONTINUE;