]> git.karo-electronics.de Git - karo-tx-linux.git/commitdiff
mISDN: add support for group membership check
authorJeff Mahoney <jeffm@suse.com>
Wed, 19 Jun 2013 00:05:36 +0000 (10:05 +1000)
committerStephen Rothwell <sfr@canb.auug.org.au>
Wed, 19 Jun 2013 07:12:47 +0000 (17:12 +1000)
This patch adds a module parameter to allow a group access to the mISDN
devices.  Otherwise, unpriviledged users on systems with ISDN hardware
have the ability to dial out, potentially causing expensive bills.

Based on a different implementation by Patrick Koppen.

Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Acked-by: Jeff Mahoney <jeffm@suse.com>
Cc: Patrick Koppen <isdn4linux@koppen.de>
Cc: Karsten Keil <isdn@linux-pingi.de>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
drivers/isdn/mISDN/core.c
drivers/isdn/mISDN/core.h
drivers/isdn/mISDN/socket.c

index da30c5cb96096b6ff366c4473b9199ae20a72919..174aa3f17afb0a6708e9f6a87da6a1b4b6e19ea4 100644 (file)
 #include "core.h"
 
 static u_int debug;
+static u_int gid;
+kgid_t misdn_permitted_gid;
 
 MODULE_AUTHOR("Karsten Keil");
 MODULE_LICENSE("GPL");
 module_param(debug, uint, S_IRUGO | S_IWUSR);
+module_param(gid, uint, 0);
+MODULE_PARM_DESC(gid, "Unix group for accessing misdn socket (default 0)");
 
 static u64             device_ids;
 #define MAX_DEVICE_ID  63
@@ -372,6 +376,8 @@ mISDNInit(void)
 {
        int     err;
 
+       misdn_permitted_gid = make_kgid(current_user_ns(), gid);
+
        printk(KERN_INFO "Modular ISDN core version %d.%d.%d\n",
               MISDN_MAJOR_VERSION, MISDN_MINOR_VERSION, MISDN_RELEASE);
        mISDN_init_clock(&debug);
index 52695bb81ee7a80721fb22d76980d85300096f03..5f509bf93c00558b15e99754ef19837be9148f97 100644 (file)
@@ -17,6 +17,7 @@
 
 extern struct mISDNdevice      *get_mdevice(u_int);
 extern int                     get_mdevice_count(void);
+extern kgid_t misdn_permitted_gid;
 
 /* stack status flag */
 #define mISDN_STACK_ACTION_MASK                0x0000ffff
index e47dcb9d1e91d0ea3e383cdf8b8b09dcde2fce0a..8dcef368e9dacdf5fa90ec8c7996dd871c8ea2e7 100644 (file)
@@ -612,6 +612,11 @@ data_sock_create(struct net *net, struct socket *sock, int protocol)
 {
        struct sock *sk;
 
+       if (!capable(CAP_SYS_ADMIN) &&
+                       !gid_eq(misdn_permitted_gid, current_gid()) &&
+                       !in_group_p(misdn_permitted_gid))
+               return -EPERM;
+
        if (sock->type != SOCK_DGRAM)
                return -ESOCKTNOSUPPORT;
 
@@ -694,6 +699,10 @@ base_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
        case IMSETDEVNAME:
        {
                struct mISDN_devrename dn;
+               if (!capable(CAP_SYS_ADMIN) &&
+                               !gid_eq(misdn_permitted_gid, current_gid()) &&
+                               !in_group_p(misdn_permitted_gid))
+                       return -EPERM;
                if (copy_from_user(&dn, (void __user *)arg,
                                   sizeof(dn))) {
                        err = -EFAULT;