Home | History | Annotate | Line # | Download | only in sys
verified_exec.h revision 1.7
      1  1.7  blymn /*	$NetBSD: verified_exec.h,v 1.7 2005/04/20 13:44:46 blymn Exp $	*/
      2  1.1  blymn 
      3  1.1  blymn /*-
      4  1.7  blymn  * Copyright 2005 Elad Efrat <elad (at) bsd.org.il>
      5  1.7  blymn  * Copyright 2005 Brett Lymn <blymn (at) netbsd.org>
      6  1.1  blymn  *
      7  1.7  blymn  * This code is derived from software contributed to The NetBSD Foundation
      8  1.7  blymn  * by Brett Lymn and Elad Efrat
      9  1.1  blymn  *
     10  1.1  blymn  * Redistribution and use in source and binary forms, with or without
     11  1.1  blymn  * modification, are permitted provided that the following conditions
     12  1.1  blymn  * are met:
     13  1.1  blymn  * 1. Redistributions of source code must retain the above copyright
     14  1.1  blymn  *    notice, this list of conditions and the following disclaimer.
     15  1.7  blymn  * 2. Neither the name of The NetBSD Foundation nor the names of its
     16  1.7  blymn  *    contributors may be used to endorse or promote products derived
     17  1.7  blymn  *    from this software without specific prior written permission.
     18  1.7  blymn  *
     19  1.7  blymn  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  1.7  blymn  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  1.7  blymn  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  1.7  blymn  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  1.7  blymn  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  1.7  blymn  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  1.7  blymn  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  1.7  blymn  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  1.7  blymn  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  1.7  blymn  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  1.7  blymn  * POSSIBILITY OF SUCH DAMAGE.
     30  1.1  blymn  */
     31  1.1  blymn 
     32  1.7  blymn #include <sys/cdefs.h>
     33  1.7  blymn __KERNEL_RCSID(0, "$NetBSD: verified_exec.h,v 1.7 2005/04/20 13:44:46 blymn Exp $");
     34  1.7  blymn 
     35  1.1  blymn /*
     36  1.1  blymn  *
     37  1.1  blymn  * Definitions for the Verified Executables kernel function.
     38  1.1  blymn  *
     39  1.1  blymn  */
     40  1.1  blymn #include <sys/param.h>
     41  1.7  blymn #include <sys/hash.h>
     42  1.1  blymn 
     43  1.1  blymn #ifndef V_EXEC_H
     44  1.1  blymn #define V_EXEC_H 1
     45  1.1  blymn 
     46  1.7  blymn /* Max length of the fingerprint type string, including terminating \0 char */
     47  1.7  blymn #define VERIEXEC_TYPE_MAXLEN 9
     48  1.1  blymn 
     49  1.7  blymn struct veriexec_params  {
     50  1.1  blymn 	unsigned char type;
     51  1.7  blymn 	unsigned char fp_type[VERIEXEC_TYPE_MAXLEN];  /* type of fingerprint
     52  1.7  blymn 							 this is */
     53  1.1  blymn 	char file[MAXPATHLEN];
     54  1.7  blymn 	unsigned int size;  /* number of bytes in the fingerprint */
     55  1.7  blymn 	unsigned char *fingerprint;
     56  1.7  blymn };
     57  1.7  blymn 
     58  1.7  blymn struct veriexec_sizing_params {
     59  1.7  blymn 	dev_t dev;
     60  1.7  blymn 	size_t hash_size;
     61  1.1  blymn };
     62  1.1  blymn 
     63  1.7  blymn struct veriexec_fp_report {
     64  1.7  blymn 	unsigned size;
     65  1.7  blymn 	unsigned char *fingerprints;
     66  1.7  blymn };
     67  1.7  blymn 
     68  1.7  blymn 
     69  1.1  blymn /*
     70  1.1  blymn  * Types of veriexec inodes we can have
     71  1.1  blymn  */
     72  1.1  blymn #define VERIEXEC_DIRECT   0  /* Allow direct execution */
     73  1.1  blymn #define VERIEXEC_INDIRECT 1  /* Only allow indirect execution */
     74  1.1  blymn #define VERIEXEC_FILE     2  /* Fingerprint of a plain file */
     75  1.1  blymn 
     76  1.7  blymn #define VERIEXEC_LOAD _IOW('S', 0x1, struct veriexec_params)
     77  1.7  blymn #define VERIEXEC_TABLESIZE _IOW('S', 0x2, struct veriexec_sizing_params)
     78  1.7  blymn #define VERIEXEC_FINGERPRINTS _IOWR('S', 0x3, struct veriexec_fp_report)
     79  1.7  blymn 
     80  1.7  blymn #ifdef _KERNEL
     81  1.7  blymn void	veriexecattach(struct device *, struct device *, void *);
     82  1.7  blymn int     veriexecopen(dev_t, int, int, struct proc *);
     83  1.7  blymn int     veriexecclose(dev_t, int, int, struct proc *);
     84  1.7  blymn int     veriexecioctl(dev_t, u_long, caddr_t, int, struct proc *);
     85  1.7  blymn 
     86  1.7  blymn /* defined in kern_verifiedexec.c */
     87  1.7  blymn extern char *veriexec_fp_names;
     88  1.7  blymn 
     89  1.1  blymn /*
     90  1.7  blymn  * Operations vector for verified exec, this defines the characteristics
     91  1.7  blymn  * for the fingerprint type.
     92  1.1  blymn  */
     93  1.1  blymn 
     94  1.7  blymn /* Function types: init, update, final. */
     95  1.7  blymn typedef void (*VERIEXEC_INIT_FN)(void *);
     96  1.7  blymn typedef void (*VERIEXEC_UPDATE_FN)(void *, u_char *, u_int);
     97  1.7  blymn typedef void (*VERIEXEC_FINAL_FN)(u_char *, void *);
     98  1.7  blymn 
     99  1.7  blymn struct veriexec_fp_ops {
    100  1.7  blymn 	char type[VERIEXEC_TYPE_MAXLEN];
    101  1.7  blymn 	size_t hash_len;
    102  1.7  blymn 	size_t context_size;
    103  1.7  blymn 	VERIEXEC_INIT_FN init;
    104  1.7  blymn 	VERIEXEC_UPDATE_FN update;
    105  1.7  blymn 	VERIEXEC_FINAL_FN final;
    106  1.7  blymn 	LIST_ENTRY(veriexec_fp_ops) entries;
    107  1.7  blymn };
    108  1.1  blymn 
    109  1.1  blymn /*
    110  1.1  blymn  * list structure definitions - needed in kern_exec.c
    111  1.1  blymn  */
    112  1.1  blymn 
    113  1.7  blymn /* An entry in the per-device hash table. */
    114  1.7  blymn struct veriexec_hash_entry {
    115  1.7  blymn         ino_t         inode;                        /* Inode number. */
    116  1.7  blymn         unsigned char type;                         /* Entry type. */
    117  1.7  blymn         unsigned char *fp;                          /* Fingerprint. */
    118  1.7  blymn 	struct veriexec_fp_ops *ops;                /* Fingerprint ops vector*/
    119  1.7  blymn         LIST_ENTRY(veriexec_hash_entry) entries;    /* List pointer. */
    120  1.7  blymn };
    121  1.7  blymn 
    122  1.7  blymn LIST_HEAD(veriexec_hashhead, veriexec_hash_entry) *hash_tbl;
    123  1.1  blymn 
    124  1.7  blymn /* Veriexec hash table information. */
    125  1.7  blymn struct veriexec_hashtbl {
    126  1.7  blymn         struct veriexec_hashhead *hash_tbl;
    127  1.7  blymn         size_t hash_size;       /* Number of slots in the table. */
    128  1.7  blymn         dev_t hash_dev;         /* Device ID the hash table refers to. */
    129  1.7  blymn         LIST_ENTRY(veriexec_hashtbl) hash_list;
    130  1.1  blymn };
    131  1.1  blymn 
    132  1.7  blymn /* Global list of hash tables. */
    133  1.7  blymn LIST_HEAD(, veriexec_hashtbl) veriexec_tables;
    134  1.7  blymn 
    135  1.7  blymn /* Mask to ensure bounded access to elements in the hash table. */
    136  1.7  blymn #define VERIEXEC_HASH_MASK(tbl)    ((tbl)->hash_size - 1)
    137  1.1  blymn 
    138  1.7  blymn /*
    139  1.7  blymn  * Hashing function: Takes an inode number modulus the mask to give back
    140  1.7  blymn  * an index into the hash table.
    141  1.7  blymn  */
    142  1.7  blymn #define VERIEXEC_HASH(tbl, inode)  \
    143  1.7  blymn         (hash32_buf(&(inode), sizeof((inode)), HASH32_BUF_INIT) \
    144  1.7  blymn 	 & VERIEXEC_HASH_MASK(tbl))
    145  1.7  blymn 
    146  1.7  blymn /* Callback for hash traversal. */
    147  1.7  blymn typedef void (*VERIEXEC_CALLBACK)(struct veriexec_hash_entry *, dev_t);
    148  1.7  blymn 
    149  1.7  blymn void veriexec_init_fp_ops(void);
    150  1.7  blymn struct veriexec_fp_ops *veriexec_find_ops(u_char *name);
    151  1.7  blymn int veriexec_fp_calc(struct proc *, struct vnode *,
    152  1.7  blymn 		     struct veriexec_hash_entry *, uint64_t, u_char *);
    153  1.7  blymn int veriexec_fp_cmp(struct veriexec_hash_entry *, u_char *);
    154  1.7  blymn 
    155  1.7  blymn struct veriexec_hashtbl *veriexec_tblfind(dev_t);
    156  1.7  blymn struct veriexec_hash_entry *veriexec_lookup(dev_t, ino_t);
    157  1.7  blymn int veriexec_hashadd(struct veriexec_hashtbl *, struct veriexec_hash_entry *);
    158  1.7  blymn void veriexec_hashprint(struct veriexec_hash_entry *, dev_t);
    159  1.7  blymn int veriexec_tblwalk(VERIEXEC_CALLBACK *);
    160  1.7  blymn 
    161  1.7  blymn int veriexec_verify(struct proc *, struct vnode *, struct vattr *,
    162  1.7  blymn 		    const u_char *, int);
    163  1.7  blymn int veriexec_removechk(struct proc *, struct vnode *, const char *);
    164  1.7  blymn void veriexec_init_fp_ops(void);
    165  1.1  blymn 
    166  1.1  blymn #endif
    167  1.7  blymn 
    168  1.7  blymn #ifdef VERIFIED_EXEC_DEBUG
    169  1.7  blymn #define veriexec_dprintf(x) printf x
    170  1.7  blymn #else
    171  1.7  blymn #define veriexec_dprintf(x)
    172  1.7  blymn #endif /* VERIFIED_EXEC_DEBUG */
    173  1.7  blymn 
    174  1.1  blymn #endif
    175