4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 1) // SPDX-License-Identifier: GPL-2.0
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 2) /*
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 3) * Ioctl to get a verity file's digest
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 4) *
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 5) * Copyright 2019 Google LLC
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 6) */
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 7)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 8) #include "fsverity_private.h"
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 9)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 10) #include <linux/uaccess.h>
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 11)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 12) /**
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 13) * fsverity_ioctl_measure() - get a verity file's digest
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 14) * @filp: file to get digest of
6377a38bd345b (Eric Biggers 2020-05-11 12:21:17 -0700 15) * @_uarg: user pointer to fsverity_digest
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 16) *
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 17) * Retrieve the file digest that the kernel is enforcing for reads from a verity
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 18) * file. See the "FS_IOC_MEASURE_VERITY" section of
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 19) * Documentation/filesystems/fsverity.rst for the documentation.
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 20) *
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 21) * Return: 0 on success, -errno on failure
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 22) */
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 23) int fsverity_ioctl_measure(struct file *filp, void __user *_uarg)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 24) {
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 25) const struct inode *inode = file_inode(filp);
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 26) struct fsverity_digest __user *uarg = _uarg;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 27) const struct fsverity_info *vi;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 28) const struct fsverity_hash_alg *hash_alg;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 29) struct fsverity_digest arg;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 30)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 31) vi = fsverity_get_info(inode);
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 32) if (!vi)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 33) return -ENODATA; /* not a verity file */
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 34) hash_alg = vi->tree_params.hash_alg;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 35)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 36) /*
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 37) * The user specifies the digest_size their buffer has space for; we can
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 38) * return the digest if it fits in the available space. We write back
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 39) * the actual size, which may be shorter than the user-specified size.
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 40) */
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 41)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 42) if (get_user(arg.digest_size, &uarg->digest_size))
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 43) return -EFAULT;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 44) if (arg.digest_size < hash_alg->digest_size)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 45) return -EOVERFLOW;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 46)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 47) memset(&arg, 0, sizeof(arg));
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 48) arg.digest_algorithm = hash_alg - fsverity_hash_algs;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 49) arg.digest_size = hash_alg->digest_size;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 50)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 51) if (copy_to_user(uarg, &arg, sizeof(arg)))
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 52) return -EFAULT;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 53)
ed45e20164934 (Eric Biggers 2020-11-13 13:19:17 -0800 54) if (copy_to_user(uarg->digest, vi->file_digest, hash_alg->digest_size))
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 55) return -EFAULT;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 56)
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 57) return 0;
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 58) }
4dd893d832cf4 (Eric Biggers 2019-07-22 09:26:23 -0700 59) EXPORT_SYMBOL_GPL(fsverity_ioctl_measure);