aboutsummaryrefslogtreecommitdiffstats
path: root/libsysutils
diff options
context:
space:
mode:
authorNick Kralevich <nnk@google.com>2011-04-18 16:29:45 -0700
committerAndroid Git Automerger <android-git-automerger@android.com>2011-04-18 16:29:45 -0700
commit4aadb7f6df4fd21f66c37b8ac0ea8ebf939b41bf (patch)
tree211f6b4dc1b14c9db51eb8cb6690fafb4d629b56 /libsysutils
parente4bcf8305748e8799df9047fb0f6881553dd43b5 (diff)
parentb620a0b1c7ae486e979826200e8e441605b0a5d6 (diff)
downloadsystem_core-4aadb7f6df4fd21f66c37b8ac0ea8ebf939b41bf.zip
system_core-4aadb7f6df4fd21f66c37b8ac0ea8ebf939b41bf.tar.gz
system_core-4aadb7f6df4fd21f66c37b8ac0ea8ebf939b41bf.tar.bz2
am b620a0b1: Validate sender credentials on netlink msg receive
* commit 'b620a0b1c7ae486e979826200e8e441605b0a5d6': Validate sender credentials on netlink msg receive
Diffstat (limited to 'libsysutils')
-rw-r--r--libsysutils/src/NetlinkListener.cpp29
1 files changed, 26 insertions, 3 deletions
diff --git a/libsysutils/src/NetlinkListener.cpp b/libsysutils/src/NetlinkListener.cpp
index e2a354e..fb088e1 100644
--- a/libsysutils/src/NetlinkListener.cpp
+++ b/libsysutils/src/NetlinkListener.cpp
@@ -17,6 +17,7 @@
#include <sys/types.h>
#include <sys/socket.h>
+#include <linux/netlink.h>
#include <string.h>
#define LOG_TAG "NetlinkListener"
@@ -32,10 +33,32 @@ NetlinkListener::NetlinkListener(int socket) :
bool NetlinkListener::onDataAvailable(SocketClient *cli)
{
int socket = cli->getSocket();
- int count;
+ ssize_t count;
+ char cred_msg[CMSG_SPACE(sizeof(struct ucred))];
+ struct sockaddr_nl snl;
+ struct iovec iov = {mBuffer, sizeof(mBuffer)};
+ struct msghdr hdr = {&snl, sizeof(snl), &iov, 1, cred_msg, sizeof(cred_msg), 0};
- if ((count = recv(socket, mBuffer, sizeof(mBuffer), 0)) < 0) {
- SLOGE("recv failed (%s)", strerror(errno));
+ if ((count = recvmsg(socket, &hdr, 0)) < 0) {
+ SLOGE("recvmsg failed (%s)", strerror(errno));
+ return false;
+ }
+
+ if ((snl.nl_groups != 1) || (snl.nl_pid != 0)) {
+ SLOGE("ignoring non-kernel netlink multicast message");
+ return false;
+ }
+
+ struct cmsghdr * cmsg = CMSG_FIRSTHDR(&hdr);
+
+ if (cmsg == NULL || cmsg->cmsg_type != SCM_CREDENTIALS) {
+ SLOGE("ignoring message with no sender credentials");
+ return false;
+ }
+
+ struct ucred * cred = (struct ucred *)CMSG_DATA(cmsg);
+ if (cred->uid != 0) {
+ SLOGE("ignoring message from non-root UID %d", cred->uid);
return false;
}