1 | | - | use std::path::Path; |
| 1 | + | use std::{fmt::Debug, marker::PhantomData, path::Path}; |
2 | 2 | | |
3 | 3 | | use aya::{ |
4 | 4 | | include_bytes_aligned, |
| 5 | + | maps::{AsyncPerfEventArray, MapData}, |
5 | 6 | | programs::{lsm::LsmLink, Lsm}, |
| 7 | + | util::online_cpus, |
6 | 8 | | Bpf, BpfLoader, Btf, |
7 | 9 | | }; |
| 10 | + | use bytes::BytesMut; |
| 11 | + | use guardity_common::{ |
| 12 | + | Alert, AlertBprmCheckSecurity, AlertFileOpen, AlertSetuid, AlertSocketBind, AlertSocketConnect, |
| 13 | + | }; |
| 14 | + | use tokio::{ |
| 15 | + | sync::mpsc::{self, Receiver}, |
| 16 | + | task, |
| 17 | + | }; |
8 | 18 | | |
9 | 19 | | pub mod fs; |
10 | 20 | | pub mod policy; |
11 | 21 | | |
12 | 22 | | pub struct PolicyManager { |
13 | | - | pub bpf: Bpf, |
14 | | - | pub bprm_check_security: Option<Hook>, |
15 | | - | pub file_open: Option<Hook>, |
16 | | - | pub setuid: Option<Hook>, |
17 | | - | pub socket_bind: Option<Hook>, |
18 | | - | pub socket_connect: Option<Hook>, |
| 23 | + | bpf: Bpf, |
| 24 | + | bprm_check_security: Option<BprmCheckSecurityHook>, |
| 25 | + | file_open: Option<FileOpenHook>, |
| 26 | + | task_fix_setuid: Option<TaskFixSetuidHook>, |
| 27 | + | socket_bind: Option<SocketBindHook>, |
| 28 | + | socket_connect: Option<SocketConnectHook>, |
19 | 29 | | } |
20 | | - | |
21 | | - | pub type Foo = Option<u32>; |
22 | 30 | | |
23 | 31 | | impl PolicyManager { |
24 | 32 | | pub fn new<P: AsRef<Path>>(bpf_path: P) -> anyhow::Result<Self> { |
| skipped 14 lines |
39 | 47 | | bpf, |
40 | 48 | | bprm_check_security: None, |
41 | 49 | | file_open: None, |
42 | | - | setuid: None, |
| 50 | + | task_fix_setuid: None, |
43 | 51 | | socket_bind: None, |
44 | 52 | | socket_connect: None, |
45 | 53 | | }) |
| skipped 1 lines |
47 | 55 | | |
48 | 56 | | pub fn attach_bprm_check_security(&mut self) -> anyhow::Result<()> { |
49 | 57 | | let link = attach_program(&mut self.bpf, "bprm_check_security")?; |
50 | | - | let bprm_check_security = Hook::new(link)?; |
| 58 | + | let perf_array = perf_array(&mut self.bpf, "ALERT_BPRM_CHECK_SECURITY")?; |
| 59 | + | let bprm_check_security = Hook::new(link, perf_array)?; |
51 | 60 | | self.bprm_check_security = Some(bprm_check_security); |
52 | 61 | | |
53 | 62 | | Ok(()) |
54 | 63 | | } |
55 | 64 | | |
| 65 | + | pub fn bprm_check_security(&mut self) -> anyhow::Result<&mut BprmCheckSecurityHook> { |
| 66 | + | match self.bprm_check_security { |
| 67 | + | Some(ref mut bprm_check_security) => Ok(bprm_check_security), |
| 68 | + | None => Err(anyhow::anyhow!("bprm_check_security is not attached")), |
| 69 | + | } |
| 70 | + | } |
| 71 | + | |
56 | 72 | | pub fn attach_file_open(&mut self) -> anyhow::Result<()> { |
57 | 73 | | let link = attach_program(&mut self.bpf, "file_open")?; |
58 | | - | let file_open = Hook::new(link)?; |
| 74 | + | let perf_array = perf_array(&mut self.bpf, "ALERT_FILE_OPEN")?; |
| 75 | + | let file_open = Hook::new(link, perf_array)?; |
59 | 76 | | self.file_open = Some(file_open); |
60 | 77 | | |
61 | 78 | | Ok(()) |
62 | 79 | | } |
63 | 80 | | |
64 | | - | pub fn file_open(&mut self) -> anyhow::Result<&mut Hook> { |
| 81 | + | pub fn file_open(&mut self) -> anyhow::Result<&mut FileOpenHook> { |
65 | 82 | | match self.file_open { |
66 | 83 | | Some(ref mut file_open) => Ok(file_open), |
67 | 84 | | None => Err(anyhow::anyhow!("file_open is not attached")), |
| skipped 2 lines |
70 | 87 | | |
71 | 88 | | pub fn attach_task_fix_setuid(&mut self) -> anyhow::Result<()> { |
72 | 89 | | let link = attach_program(&mut self.bpf, "task_fix_setuid")?; |
73 | | - | let setuid = Hook::new(link)?; |
74 | | - | self.setuid = Some(setuid); |
| 90 | + | let perf_array = perf_array(&mut self.bpf, "ALERT_SETUID")?; |
| 91 | + | let setuid = Hook::new(link, perf_array)?; |
| 92 | + | self.task_fix_setuid = Some(setuid); |
75 | 93 | | |
76 | 94 | | Ok(()) |
77 | 95 | | } |
78 | 96 | | |
79 | | - | pub fn setuid(&mut self) -> anyhow::Result<&mut Hook> { |
80 | | - | match self.setuid { |
| 97 | + | pub fn task_fix_setuid(&mut self) -> anyhow::Result<&mut TaskFixSetuidHook> { |
| 98 | + | match self.task_fix_setuid { |
81 | 99 | | Some(ref mut setuid) => Ok(setuid), |
82 | 100 | | None => Err(anyhow::anyhow!("setuid is not attached")), |
83 | 101 | | } |
| skipped 1 lines |
85 | 103 | | |
86 | 104 | | pub fn attach_socket_bind(&mut self) -> anyhow::Result<()> { |
87 | 105 | | let link = attach_program(&mut self.bpf, "socket_bind")?; |
88 | | - | let socket_bind = Hook::new(link)?; |
| 106 | + | let perf_array = perf_array(&mut self.bpf, "ALERT_SOCKET_BIND")?; |
| 107 | + | let socket_bind = Hook::new(link, perf_array)?; |
89 | 108 | | self.socket_bind = Some(socket_bind); |
90 | 109 | | |
91 | 110 | | Ok(()) |
92 | 111 | | } |
93 | 112 | | |
94 | | - | pub fn socket_bind(&mut self) -> anyhow::Result<&mut Hook> { |
| 113 | + | pub fn socket_bind(&mut self) -> anyhow::Result<&mut SocketBindHook> { |
95 | 114 | | match self.socket_bind { |
96 | 115 | | Some(ref mut socket_bind) => Ok(socket_bind), |
97 | 116 | | None => Err(anyhow::anyhow!("socket_bind is not attached")), |
| skipped 2 lines |
100 | 119 | | |
101 | 120 | | pub fn attach_socket_connect(&mut self) -> anyhow::Result<()> { |
102 | 121 | | let link = attach_program(&mut self.bpf, "socket_connect")?; |
103 | | - | let socket_connect = Hook::new(link)?; |
| 122 | + | let perf_array = perf_array(&mut self.bpf, "ALERT_SOCKET_CONNECT")?; |
| 123 | + | let socket_connect = Hook::new(link, perf_array)?; |
104 | 124 | | self.socket_connect = Some(socket_connect); |
105 | 125 | | |
106 | 126 | | Ok(()) |
107 | 127 | | } |
108 | 128 | | |
109 | | - | pub fn socket_connect(&mut self) -> anyhow::Result<&mut Hook> { |
| 129 | + | pub fn socket_connect(&mut self) -> anyhow::Result<&mut SocketConnectHook> { |
110 | 130 | | match self.socket_connect { |
111 | 131 | | Some(ref mut socket_connect) => Ok(socket_connect), |
112 | 132 | | None => Err(anyhow::anyhow!("socket_connect is not attached")), |
| skipped 11 lines |
124 | 144 | | Ok(link) |
125 | 145 | | } |
126 | 146 | | |
127 | | - | pub struct Hook { |
| 147 | + | fn perf_array(bpf: &mut Bpf, name: &str) -> anyhow::Result<AsyncPerfEventArray<MapData>> { |
| 148 | + | let perf_array = bpf.take_map(name).unwrap().try_into()?; |
| 149 | + | Ok(perf_array) |
| 150 | + | } |
| 151 | + | |
| 152 | + | pub struct Hook<T> |
| 153 | + | where |
| 154 | + | T: Alert, |
| 155 | + | { |
128 | 156 | | #[allow(dead_code)] |
129 | 157 | | program_link: LsmLink, |
| 158 | + | perf_array: AsyncPerfEventArray<MapData>, |
| 159 | + | phantom: PhantomData<T>, |
130 | 160 | | } |
131 | 161 | | |
132 | | - | impl Hook { |
133 | | - | pub fn new(program_link: LsmLink) -> anyhow::Result<Self> { |
134 | | - | Ok(Self { program_link }) |
| 162 | + | impl<T> Hook<T> |
| 163 | + | where |
| 164 | + | T: Alert + Debug + Send + 'static, |
| 165 | + | { |
| 166 | + | fn new( |
| 167 | + | program_link: LsmLink, |
| 168 | + | perf_array: AsyncPerfEventArray<MapData>, |
| 169 | + | ) -> anyhow::Result<Self> { |
| 170 | + | Ok(Self { |
| 171 | + | program_link, |
| 172 | + | perf_array, |
| 173 | + | phantom: PhantomData, |
| 174 | + | }) |
| 175 | + | } |
| 176 | + | |
| 177 | + | pub async fn alerts(&mut self) -> anyhow::Result<Receiver<T>> { |
| 178 | + | let (tx, rx) = mpsc::channel(32); |
| 179 | + | |
| 180 | + | let cpus = online_cpus()?; |
| 181 | + | for cpu_id in cpus { |
| 182 | + | let tx = tx.clone(); |
| 183 | + | let mut buf = self.perf_array.open(cpu_id, None)?; |
| 184 | + | |
| 185 | + | task::spawn(async move { |
| 186 | + | let mut buffers = (0..10) |
| 187 | + | .map(|_| BytesMut::with_capacity(1024)) |
| 188 | + | .collect::<Vec<_>>(); |
| 189 | + | loop { |
| 190 | + | let events = buf.read_events(&mut buffers).await.unwrap(); |
| 191 | + | for buf in buffers.iter_mut().take(events.read) { |
| 192 | + | let alert = { |
| 193 | + | let ptr = buf.as_ptr() as *const T; |
| 194 | + | unsafe { ptr.read_unaligned() } |
| 195 | + | }; |
| 196 | + | tx.send(alert).await.unwrap(); |
| 197 | + | } |
| 198 | + | } |
| 199 | + | }); |
| 200 | + | } |
| 201 | + | |
| 202 | + | Ok(rx) |
135 | 203 | | } |
136 | 204 | | } |
137 | 205 | | |
| 206 | + | pub type BprmCheckSecurityHook = Hook<AlertBprmCheckSecurity>; |
| 207 | + | pub type FileOpenHook = Hook<AlertFileOpen>; |
| 208 | + | pub type TaskFixSetuidHook = Hook<AlertSetuid>; |
| 209 | + | pub type SocketBindHook = Hook<AlertSocketBind>; |
| 210 | + | pub type SocketConnectHook = Hook<AlertSocketConnect>; |
| 211 | + | |