diff options
| author | Emīls <emils@mullvad.net> | 2021-12-09 16:29:23 +0000 |
|---|---|---|
| committer | Emīls Piņķis <emils@mullvad.net> | 2021-12-13 15:42:55 +0000 |
| commit | 2729ca03f9192a6ab60dd6ba041ff2d7ab3209f3 (patch) | |
| tree | a7f219bd02feb6464226771f5ad1e0a94e67e013 /talpid-core/src | |
| parent | 785254150f39e42256cf36fbf2d2901694dc6e7c (diff) | |
| download | mullvadvpn-2729ca03f9192a6ab60dd6ba041ff2d7ab3209f3.tar.xz mullvadvpn-2729ca03f9192a6ab60dd6ba041ff2d7ab3209f3.zip | |
Allow only root to reach the API in blocked state
Diffstat (limited to 'talpid-core/src')
| -rw-r--r-- | talpid-core/src/firewall/linux.rs | 11 | ||||
| -rw-r--r-- | talpid-core/src/firewall/macos.rs | 10 | ||||
| -rw-r--r-- | talpid-core/src/firewall/mod.rs | 2 |
3 files changed, 18 insertions, 5 deletions
diff --git a/talpid-core/src/firewall/linux.rs b/talpid-core/src/firewall/linux.rs index c10aba6ba8..480bc3c674 100644 --- a/talpid-core/src/firewall/linux.rs +++ b/talpid-core/src/firewall/linux.rs @@ -653,15 +653,26 @@ impl<'a> PolicyBatch<'a> { self.batch.add(&out_rule, nftnl::MsgType::Add); } + /// Adds firewall rules allow traffic to flow to the API. Allows the app to reach the API in + /// blocked states. fn add_allow_endpoint_rules(&mut self, endpoint: &Endpoint) { let mut in_rule = Rule::new(&self.in_chain); check_endpoint(&mut in_rule, End::Src, endpoint); + let allowed_states = nftnl::expr::ct::States::ESTABLISHED.bits(); + in_rule.add_expr(&nft_expr!(ct state)); + in_rule.add_expr(&nft_expr!(bitwise mask allowed_states, xor 0u32)); + in_rule.add_expr(&nft_expr!(cmp != 0u32)); + in_rule.add_expr(&nft_expr!(meta skuid)); + in_rule.add_expr(&nft_expr!(cmp == super::ROOT_UID)); + add_verdict(&mut in_rule, &Verdict::Accept); self.batch.add(&in_rule, nftnl::MsgType::Add); let mut out_rule = Rule::new(&self.out_chain); check_endpoint(&mut out_rule, End::Dst, endpoint); + out_rule.add_expr(&nft_expr!(meta skuid)); + out_rule.add_expr(&nft_expr!(cmp == super::ROOT_UID)); add_verdict(&mut out_rule, &Verdict::Accept); self.batch.add(&out_rule, nftnl::MsgType::Add); diff --git a/talpid-core/src/firewall/macos.rs b/talpid-core/src/firewall/macos.rs index a10f82bc69..de78524249 100644 --- a/talpid-core/src/firewall/macos.rs +++ b/talpid-core/src/firewall/macos.rs @@ -17,9 +17,6 @@ type Result<T> = std::result::Result<T, Error>; /// replaced by allowing the anchor name to be configured from the public API of this crate. const ANCHOR_NAME: &'static str = "mullvad"; -const ROOT_UID: u32 = 0; - -/// The macOS firewall and DNS implementation. pub struct Firewall { pf: pfctl::PfCtl, pf_was_enabled: Option<bool>, @@ -286,11 +283,13 @@ impl Firewall { .proto(pfctl_proto) .keep_state(pfctl::StatePolicy::Keep) .tcp_flags(Self::get_tcp_flags()) - .user(Uid::from(ROOT_UID)) + .user(Uid::from(super::ROOT_UID)) .quick(true) .build()?) } + /// Produces a rule that allows traffic to flow to the API. Allows the app to reach the API in + /// blocked states. fn get_allowed_endpoint_rule( &self, allowed_endpoint: net::Endpoint, @@ -303,6 +302,7 @@ impl Firewall { .to(allowed_endpoint.address) .proto(pfctl_proto) .keep_state(pfctl::StatePolicy::Keep) + .user(Uid::from(super::ROOT_UID)) .quick(true) .build()?) } @@ -359,7 +359,7 @@ impl Firewall { .direction(pfctl::Direction::Out) .to(*ip) .quick(true) - .user(Uid::from(ROOT_UID)) + .user(Uid::from(super::ROOT_UID)) .keep_state(pfctl::StatePolicy::Keep) .build()?, ); diff --git a/talpid-core/src/firewall/mod.rs b/talpid-core/src/firewall/mod.rs index 80714d8338..761691e216 100644 --- a/talpid-core/src/firewall/mod.rs +++ b/talpid-core/src/firewall/mod.rs @@ -82,6 +82,8 @@ const DHCPV4_CLIENT_PORT: u16 = 68; const DHCPV6_SERVER_PORT: u16 = 547; #[cfg(all(unix, not(target_os = "android")))] const DHCPV6_CLIENT_PORT: u16 = 546; +#[cfg(all(unix, not(target_os = "android")))] +const ROOT_UID: u32 = 0; #[cfg(all(unix, not(target_os = "android")))] /// Returns whether an address belongs to a private subnet. |
