Preload hostuuid for early-boot use

prison0's hostuuid will get set by the hostid rc script, either after
generating it and saving it to /etc/hostid or by simply reading /etc/hostid.

Some things (e.g. arbitrary MAC address generation) may use the hostuuid as
a factor in early boot, so providing a way to read /etc/hostid (if it's
available) and using it before userland starts up is desirable. The code is
written such that the preload doesn't *have* to be /etc/hostid, thus not
assuming that there will be newline at the end of the buffer or even the
exact shape of the newline. White trailing whitespace/non-printables
trimmed, the result will be validated as a valid uuid before it's used for
early boot purposes.

The preload can be turned off with hostuuid_load="NO" in /boot/loader.conf,
just as other preloads; it's worth noting that this is a 37-byte file, the
overhead is believed to be generally minimal.

It doesn't seem necessary at this time to be concerned with kern.hostid.

One does wonder if we should consider validating hostuuids coming in
via jail_set(2); some bits seem to care about uuid form and we bother
validating format of smbios-provided uuid and in-fact whatever uuid comes
from /etc/hostid.

Reviewed by:	karels, delphij, jamie
MFC after:	1 week (don't preload by default, probably)
Differential Revision:	https://reviews.freebsd.org/D24288
This commit is contained in:
Kyle Evans 2020-04-16 00:54:06 +00:00
parent ab23c2784b
commit c318828929
2 changed files with 36 additions and 0 deletions

View File

@ -33,6 +33,11 @@ bitmap_type="splash_image_data" # and place it on the module_path
screensave_load="NO" # Set to YES to load a screensaver module screensave_load="NO" # Set to YES to load a screensaver module
screensave_name="green_saver" # Set to the name of the screensaver module screensave_name="green_saver" # Set to the name of the screensaver module
### Early hostid configuration ############################
hostuuid_load="YES"
hostuuid_name="/etc/hostid"
hostuuid_type="hostuuid"
### Random number generator configuration ################## ### Random number generator configuration ##################
# See rc.conf(5). The entropy_boot_file config variable must agree with the # See rc.conf(5). The entropy_boot_file config variable must agree with the
# settings below. # settings below.

View File

@ -48,6 +48,7 @@ __FBSDID("$FreeBSD$");
#include <sys/taskqueue.h> #include <sys/taskqueue.h>
#include <sys/fcntl.h> #include <sys/fcntl.h>
#include <sys/jail.h> #include <sys/jail.h>
#include <sys/linker.h>
#include <sys/lock.h> #include <sys/lock.h>
#include <sys/mutex.h> #include <sys/mutex.h>
#include <sys/racct.h> #include <sys/racct.h>
@ -61,6 +62,7 @@ __FBSDID("$FreeBSD$");
#include <sys/socket.h> #include <sys/socket.h>
#include <sys/syscallsubr.h> #include <sys/syscallsubr.h>
#include <sys/sysctl.h> #include <sys/sysctl.h>
#include <sys/uuid.h>
#include <sys/vnode.h> #include <sys/vnode.h>
#include <net/if.h> #include <net/if.h>
@ -75,6 +77,7 @@ __FBSDID("$FreeBSD$");
#include <security/mac/mac_framework.h> #include <security/mac/mac_framework.h>
#define DEFAULT_HOSTUUID "00000000-0000-0000-0000-000000000000" #define DEFAULT_HOSTUUID "00000000-0000-0000-0000-000000000000"
#define PRISON0_HOSTUUID_MODULE "hostuuid"
MALLOC_DEFINE(M_PRISON, "prison", "Prison structures"); MALLOC_DEFINE(M_PRISON, "prison", "Prison structures");
static MALLOC_DEFINE(M_PRISON_RACCT, "prison_racct", "Prison racct structures"); static MALLOC_DEFINE(M_PRISON_RACCT, "prison_racct", "Prison racct structures");
@ -218,10 +221,38 @@ static unsigned jail_max_af_ips = 255;
void void
prison0_init(void) prison0_init(void)
{ {
uint8_t *file, *data;
size_t size;
prison0.pr_cpuset = cpuset_ref(thread0.td_cpuset); prison0.pr_cpuset = cpuset_ref(thread0.td_cpuset);
prison0.pr_osreldate = osreldate; prison0.pr_osreldate = osreldate;
strlcpy(prison0.pr_osrelease, osrelease, sizeof(prison0.pr_osrelease)); strlcpy(prison0.pr_osrelease, osrelease, sizeof(prison0.pr_osrelease));
/* If we have a preloaded hostuuid, use it. */
file = preload_search_by_type(PRISON0_HOSTUUID_MODULE);
if (file != NULL) {
data = preload_fetch_addr(file);
size = preload_fetch_size(file);
if (data != NULL) {
/*
* The preloaded data may include trailing whitespace, almost
* certainly a newline; skip over any whitespace or
* non-printable characters to be safe.
*/
while (size > 0 && data[size - 1] <= 0x20) {
data[size--] = '\0';
}
if (validate_uuid(data, size, NULL, 0) == 0) {
(void)strlcpy(prison0.pr_hostuuid, data,
size + 1);
} else if (bootverbose) {
printf("hostuuid: preload data malformed: '%s'",
data);
}
}
}
if (bootverbose)
printf("hostuuid: using %s\n", prison0.pr_hostuuid);
} }
/* /*