From 444aefd5d5909fd002aa5a27c366673104b099b1 Mon Sep 17 00:00:00 2001 From: ShirkNeko <109797057+ShirkNeko@users.noreply.github.com> Date: Sun, 24 Aug 2025 11:00:17 +0800 Subject: [PATCH] kernel: Modified dynamic signature All files have been renamed to the correct names: Dynamic Manager --- kernel/Makefile | 2 +- kernel/apk_sign.c | 12 +- kernel/core_hook.c | 19 +- kernel/{dynamic_sign.c => dynamic_manager.c} | 180 +++++++++---------- kernel/dynamic_manager.h | 43 +++++ kernel/dynamic_sign.h | 43 ----- kernel/ksu.h | 10 +- kernel/throne_tracker.c | 10 +- 8 files changed, 160 insertions(+), 159 deletions(-) rename kernel/{dynamic_sign.c => dynamic_manager.c} (65%) create mode 100644 kernel/dynamic_manager.h delete mode 100644 kernel/dynamic_sign.h diff --git a/kernel/Makefile b/kernel/Makefile index 5da92fe9..be2f5a5a 100644 --- a/kernel/Makefile +++ b/kernel/Makefile @@ -1,6 +1,6 @@ kernelsu-objs := ksu.o kernelsu-objs += allowlist.o -kernelsu-objs += dynamic_sign.o +kernelsu-objs += dynamic_manager.o kernelsu-objs += apk_sign.o kernelsu-objs += sucompat.o kernelsu-objs += throne_tracker.o diff --git a/kernel/apk_sign.c b/kernel/apk_sign.c index a3589dcd..0da6cfc8 100644 --- a/kernel/apk_sign.c +++ b/kernel/apk_sign.c @@ -15,7 +15,7 @@ #endif #include "apk_sign.h" -#include "dynamic_sign.h" +#include "dynamic_manager.h" #include "klog.h" // IWYU pragma: keep #include "kernel_compat.h" #include "manager_sign.h" @@ -115,7 +115,7 @@ static bool check_block(struct file *fp, u32 *size4, loff_t *pos, u32 *offset, i if (i == 1) { // Dynamic Sign indexing unsigned int size; const char *hash; - if (ksu_get_dynamic_sign_config(&size, &hash)) { + if (ksu_get_dynamic_manager_config(&size, &hash)) { sign_key.size = size; sign_key.sha256 = hash; } @@ -228,8 +228,8 @@ static __always_inline bool check_v2_signature(char *path, bool check_multi_mana return false; } - // If you want to check for multi-manager APK signing, but dynamic signing is not enabled, skip - if (check_multi_manager && !ksu_is_dynamic_sign_enabled()) { + // If you want to check for multi-manager APK signing, but dynamic managering is not enabled, skip + if (check_multi_manager && !ksu_is_dynamic_manager_enabled()) { filp_close(fp, 0); return 0; } @@ -337,7 +337,7 @@ clean: if (check_multi_manager) { // 0: ShirkNeko/SukiSU, 1: Dynamic Sign if (matched_index == 0 || matched_index == 1) { - pr_info("Multi-manager APK detected (dynamic_sign enabled): signature_index=%d\n", matched_index); + pr_info("Multi-manager APK detected (dynamic_manager enabled): signature_index=%d\n", matched_index); return true; } return false; @@ -378,7 +378,7 @@ bool ksu_is_manager_apk(char *path) return check_v2_signature(path, false, NULL); } -bool ksu_is_multi_manager_apk(char *path, int *signature_index) +bool ksu_is_dynamic_manager_apk(char *path, int *signature_index) { return check_v2_signature(path, true, signature_index); } diff --git a/kernel/core_hook.c b/kernel/core_hook.c index bbda97fb..abfebd42 100644 --- a/kernel/core_hook.c +++ b/kernel/core_hook.c @@ -50,6 +50,7 @@ #include "throne_tracker.h" #include "kernel_compat.h" #include "include/ksu_creds.h" +#include "dynamic_manager.h" #ifdef CONFIG_KPM #include "kpm/kpm.h" @@ -429,31 +430,31 @@ int ksu_handle_prctl(int option, unsigned long arg2, unsigned long arg3, return 0; } - // Allow the root manager to configure dynamic signatures - if (arg2 == CMD_DYNAMIC_SIGN) { + // Allow the root manager to configure dynamic manageratures + if (arg2 == CMD_DYNAMIC_MANAGER) { if (!from_root && !from_manager) { return 0; } - struct dynamic_sign_user_config config; + struct dynamic_manager_user_config config; if (copy_from_user(&config, (void __user *)arg3, sizeof(config))) { - pr_err("copy dynamic sign config failed\n"); + pr_err("copy dynamic manager config failed\n"); return 0; } - int ret = ksu_handle_dynamic_sign(&config); + int ret = ksu_handle_dynamic_manager(&config); - if (ret == 0 && config.operation == DYNAMIC_SIGN_OP_GET) { + if (ret == 0 && config.operation == DYNAMIC_MANAGER_OP_GET) { if (copy_to_user((void __user *)arg3, &config, sizeof(config))) { - pr_err("copy dynamic sign config back failed\n"); + pr_err("copy dynamic manager config back failed\n"); return 0; } } if (ret == 0) { if (copy_to_user(result, &reply_ok, sizeof(reply_ok))) { - pr_err("dynamic_sign: prctl reply error\n"); + pr_err("dynamic_manager: prctl reply error\n"); } } return 0; @@ -495,7 +496,7 @@ int ksu_handle_prctl(int option, unsigned long arg2, unsigned long arg3, pr_info("post-fs-data triggered\n"); ksu_on_post_fs_data(); // Initializing Dynamic Signatures - ksu_dynamic_sign_init(); + ksu_dynamic_manager_init(); pr_info("Dynamic sign config loaded during post-fs-data\n"); } break; diff --git a/kernel/dynamic_sign.c b/kernel/dynamic_manager.c similarity index 65% rename from kernel/dynamic_sign.c rename to kernel/dynamic_manager.c index 56c9b9e1..02d38133 100644 --- a/kernel/dynamic_sign.c +++ b/kernel/dynamic_manager.c @@ -15,7 +15,7 @@ #include #endif -#include "dynamic_sign.h" +#include "dynamic_manager.h" #include "klog.h" // IWYU pragma: keep #include "kernel_compat.h" #include "manager.h" @@ -23,7 +23,7 @@ #define MAX_MANAGERS 2 // Dynamic sign configuration -static struct dynamic_sign_config dynamic_sign = { +static struct dynamic_manager_config dynamic_manager = { .size = 0x300, .hash = "0000000000000000000000000000000000000000000000000000000000000000", .is_set = 0 @@ -32,21 +32,21 @@ static struct dynamic_sign_config dynamic_sign = { // Multi-manager state static struct manager_info active_managers[MAX_MANAGERS]; static DEFINE_SPINLOCK(managers_lock); -static DEFINE_SPINLOCK(dynamic_sign_lock); +static DEFINE_SPINLOCK(dynamic_manager_lock); // Work queues for persistent storage -static struct work_struct ksu_save_dynamic_sign_work; -static struct work_struct ksu_load_dynamic_sign_work; -static struct work_struct ksu_clear_dynamic_sign_work; +static struct work_struct ksu_save_dynamic_manager_work; +static struct work_struct ksu_load_dynamic_manager_work; +static struct work_struct ksu_clear_dynamic_manager_work; -bool ksu_is_dynamic_sign_enabled(void) +bool ksu_is_dynamic_manager_enabled(void) { unsigned long flags; bool enabled; - spin_lock_irqsave(&dynamic_sign_lock, flags); - enabled = dynamic_sign.is_set; - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + spin_lock_irqsave(&dynamic_manager_lock, flags); + enabled = dynamic_manager.is_set; + spin_unlock_irqrestore(&dynamic_manager_lock, flags); return enabled; } @@ -56,7 +56,7 @@ void ksu_add_manager(uid_t uid, int signature_index) unsigned long flags; int i; - if (!ksu_is_dynamic_sign_enabled()) { + if (!ksu_is_dynamic_manager_enabled()) { pr_info("Dynamic sign not enabled, skipping multi-manager add\n"); return; } @@ -94,7 +94,7 @@ void ksu_remove_manager(uid_t uid) unsigned long flags; int i; - if (!ksu_is_dynamic_sign_enabled()) { + if (!ksu_is_dynamic_manager_enabled()) { return; } @@ -117,7 +117,7 @@ bool ksu_is_any_manager(uid_t uid) bool is_manager = false; int i; - if (!ksu_is_dynamic_sign_enabled()) { + if (!ksu_is_dynamic_manager_enabled()) { return false; } @@ -145,7 +145,7 @@ int ksu_get_manager_signature_index(uid_t uid) return 1; } - if (!ksu_is_dynamic_sign_enabled()) { + if (!ksu_is_dynamic_manager_enabled()) { return -1; } @@ -197,7 +197,7 @@ int ksu_get_active_managers(struct manager_list_info *info) } // Add dynamic managers - if (ksu_is_dynamic_sign_enabled()) { + if (ksu_is_dynamic_manager_enabled()) { spin_lock_irqsave(&managers_lock, flags); for (i = 0; i < MAX_MANAGERS && count < 2; i++) { @@ -215,42 +215,42 @@ int ksu_get_active_managers(struct manager_list_info *info) return 0; } -static void do_save_dynamic_sign(struct work_struct *work) +static void do_save_dynamic_manager(struct work_struct *work) { - u32 magic = DYNAMIC_SIGN_FILE_MAGIC; - u32 version = DYNAMIC_SIGN_FILE_VERSION; - struct dynamic_sign_config config_to_save; + u32 magic = DYNAMIC_MANAGER_FILE_MAGIC; + u32 version = DYNAMIC_MANAGER_FILE_VERSION; + struct dynamic_manager_config config_to_save; loff_t off = 0; unsigned long flags; struct file *fp; - spin_lock_irqsave(&dynamic_sign_lock, flags); - config_to_save = dynamic_sign; - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + spin_lock_irqsave(&dynamic_manager_lock, flags); + config_to_save = dynamic_manager; + spin_unlock_irqrestore(&dynamic_manager_lock, flags); if (!config_to_save.is_set) { pr_info("Dynamic sign config not set, skipping save\n"); return; } - fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_SIGN, O_WRONLY | O_CREAT | O_TRUNC, 0644); + fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_MANAGER, O_WRONLY | O_CREAT | O_TRUNC, 0644); if (IS_ERR(fp)) { - pr_err("save_dynamic_sign create file failed: %ld\n", PTR_ERR(fp)); + pr_err("save_dynamic_manager create file failed: %ld\n", PTR_ERR(fp)); return; } if (ksu_kernel_write_compat(fp, &magic, sizeof(magic), &off) != sizeof(magic)) { - pr_err("save_dynamic_sign write magic failed.\n"); + pr_err("save_dynamic_manager write magic failed.\n"); goto exit; } if (ksu_kernel_write_compat(fp, &version, sizeof(version), &off) != sizeof(version)) { - pr_err("save_dynamic_sign write version failed.\n"); + pr_err("save_dynamic_manager write version failed.\n"); goto exit; } if (ksu_kernel_write_compat(fp, &config_to_save, sizeof(config_to_save), &off) != sizeof(config_to_save)) { - pr_err("save_dynamic_sign write config failed.\n"); + pr_err("save_dynamic_manager write config failed.\n"); goto exit; } @@ -260,48 +260,48 @@ exit: filp_close(fp, 0); } -static void do_load_dynamic_sign(struct work_struct *work) +static void do_load_dynamic_manager(struct work_struct *work) { loff_t off = 0; ssize_t ret = 0; struct file *fp = NULL; u32 magic; u32 version; - struct dynamic_sign_config loaded_config; + struct dynamic_manager_config loaded_config; unsigned long flags; int i; - fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_SIGN, O_RDONLY, 0); + fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_MANAGER, O_RDONLY, 0); if (IS_ERR(fp)) { if (PTR_ERR(fp) == -ENOENT) { - pr_info("No saved dynamic sign config found\n"); + pr_info("No saved dynamic manager config found\n"); } else { - pr_err("load_dynamic_sign open file failed: %ld\n", PTR_ERR(fp)); + pr_err("load_dynamic_manager open file failed: %ld\n", PTR_ERR(fp)); } return; } if (ksu_kernel_read_compat(fp, &magic, sizeof(magic), &off) != sizeof(magic) || - magic != DYNAMIC_SIGN_FILE_MAGIC) { - pr_err("dynamic sign file invalid magic: %x!\n", magic); + magic != DYNAMIC_MANAGER_FILE_MAGIC) { + pr_err("dynamic manager file invalid magic: %x!\n", magic); goto exit; } if (ksu_kernel_read_compat(fp, &version, sizeof(version), &off) != sizeof(version)) { - pr_err("dynamic sign read version failed\n"); + pr_err("dynamic manager read version failed\n"); goto exit; } - pr_info("dynamic sign file version: %d\n", version); + pr_info("dynamic manager file version: %d\n", version); ret = ksu_kernel_read_compat(fp, &loaded_config, sizeof(loaded_config), &off); if (ret <= 0) { - pr_info("load_dynamic_sign read err: %zd\n", ret); + pr_info("load_dynamic_manager read err: %zd\n", ret); goto exit; } if (ret != sizeof(loaded_config)) { - pr_err("load_dynamic_sign read incomplete config: %zd/%zu\n", ret, sizeof(loaded_config)); + pr_err("load_dynamic_manager read incomplete config: %zd/%zu\n", ret, sizeof(loaded_config)); goto exit; } @@ -324,9 +324,9 @@ static void do_load_dynamic_sign(struct work_struct *work) } } - spin_lock_irqsave(&dynamic_sign_lock, flags); - dynamic_sign = loaded_config; - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + spin_lock_irqsave(&dynamic_manager_lock, flags); + dynamic_manager = loaded_config; + spin_unlock_irqrestore(&dynamic_manager_lock, flags); pr_info("Dynamic sign config loaded: size=0x%x, hash=%.16s...\n", loaded_config.size, loaded_config.hash); @@ -335,12 +335,12 @@ exit: filp_close(fp, 0); } -static bool persistent_dynamic_sign(void) +static bool persistent_dynamic_manager(void) { - return ksu_queue_work(&ksu_save_dynamic_sign_work); + return ksu_queue_work(&ksu_save_dynamic_manager_work); } -static void do_clear_dynamic_sign(struct work_struct *work) +static void do_clear_dynamic_manager(struct work_struct *work) { loff_t off = 0; struct file *fp; @@ -348,15 +348,15 @@ static void do_clear_dynamic_sign(struct work_struct *work) memset(zero_buffer, 0, sizeof(zero_buffer)); - fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_SIGN, O_WRONLY | O_CREAT | O_TRUNC, 0644); + fp = ksu_filp_open_compat(KERNEL_SU_DYNAMIC_MANAGER, O_WRONLY | O_CREAT | O_TRUNC, 0644); if (IS_ERR(fp)) { - pr_err("clear_dynamic_sign create file failed: %ld\n", PTR_ERR(fp)); + pr_err("clear_dynamic_manager create file failed: %ld\n", PTR_ERR(fp)); return; } // Write null bytes to overwrite the file content if (ksu_kernel_write_compat(fp, zero_buffer, sizeof(zero_buffer), &off) != sizeof(zero_buffer)) { - pr_err("clear_dynamic_sign write null bytes failed.\n"); + pr_err("clear_dynamic_manager write null bytes failed.\n"); } else { pr_info("Dynamic sign config file cleared successfully\n"); } @@ -364,12 +364,12 @@ static void do_clear_dynamic_sign(struct work_struct *work) filp_close(fp, 0); } -static bool clear_dynamic_sign_file(void) +static bool clear_dynamic_manager_file(void) { - return ksu_queue_work(&ksu_clear_dynamic_sign_work); + return ksu_queue_work(&ksu_clear_dynamic_manager_work); } -int ksu_handle_dynamic_sign(struct dynamic_sign_user_config *config) +int ksu_handle_dynamic_manager(struct dynamic_manager_user_config *config) { unsigned long flags; int ret = 0; @@ -380,7 +380,7 @@ int ksu_handle_dynamic_sign(struct dynamic_sign_user_config *config) } switch (config->operation) { - case DYNAMIC_SIGN_OP_SET: + case DYNAMIC_MANAGER_OP_SET: if (config->size < 0x100 || config->size > 0x1000) { pr_err("invalid size: 0x%x\n", config->size); return -EINVAL; @@ -400,106 +400,106 @@ int ksu_handle_dynamic_sign(struct dynamic_sign_user_config *config) } } - spin_lock_irqsave(&dynamic_sign_lock, flags); - dynamic_sign.size = config->size; + spin_lock_irqsave(&dynamic_manager_lock, flags); + dynamic_manager.size = config->size; #if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 13, 0) - strscpy(dynamic_sign.hash, config->hash, sizeof(dynamic_sign.hash)); + strscpy(dynamic_manager.hash, config->hash, sizeof(dynamic_manager.hash)); #else - strlcpy(dynamic_sign.hash, config->hash, sizeof(dynamic_sign.hash)); + strlcpy(dynamic_manager.hash, config->hash, sizeof(dynamic_manager.hash)); #endif - dynamic_sign.is_set = 1; - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + dynamic_manager.is_set = 1; + spin_unlock_irqrestore(&dynamic_manager_lock, flags); - persistent_dynamic_sign(); - pr_info("dynamic sign updated: size=0x%x, hash=%.16s... (multi-manager enabled)\n", + persistent_dynamic_manager(); + pr_info("dynamic manager updated: size=0x%x, hash=%.16s... (multi-manager enabled)\n", config->size, config->hash); break; - case DYNAMIC_SIGN_OP_GET: - spin_lock_irqsave(&dynamic_sign_lock, flags); - if (dynamic_sign.is_set) { - config->size = dynamic_sign.size; + case DYNAMIC_MANAGER_OP_GET: + spin_lock_irqsave(&dynamic_manager_lock, flags); + if (dynamic_manager.is_set) { + config->size = dynamic_manager.size; #if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 13, 0) - strscpy(config->hash, dynamic_sign.hash, sizeof(config->hash)); + strscpy(config->hash, dynamic_manager.hash, sizeof(config->hash)); #else - strlcpy(config->hash, dynamic_sign.hash, sizeof(config->hash)); + strlcpy(config->hash, dynamic_manager.hash, sizeof(config->hash)); #endif ret = 0; } else { ret = -ENODATA; } - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + spin_unlock_irqrestore(&dynamic_manager_lock, flags); break; - case DYNAMIC_SIGN_OP_CLEAR: - spin_lock_irqsave(&dynamic_sign_lock, flags); - dynamic_sign.size = 0x300; - strcpy(dynamic_sign.hash, "0000000000000000000000000000000000000000000000000000000000000000"); - dynamic_sign.is_set = 0; - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + case DYNAMIC_MANAGER_OP_CLEAR: + spin_lock_irqsave(&dynamic_manager_lock, flags); + dynamic_manager.size = 0x300; + strcpy(dynamic_manager.hash, "0000000000000000000000000000000000000000000000000000000000000000"); + dynamic_manager.is_set = 0; + spin_unlock_irqrestore(&dynamic_manager_lock, flags); // Clear only dynamic managers, preserve default manager clear_dynamic_manager(); // Clear file using the same method as save - clear_dynamic_sign_file(); + clear_dynamic_manager_file(); pr_info("Dynamic sign config cleared (multi-manager disabled)\n"); break; default: - pr_err("Invalid dynamic sign operation: %d\n", config->operation); + pr_err("Invalid dynamic manager operation: %d\n", config->operation); return -EINVAL; } return ret; } -bool ksu_load_dynamic_sign(void) +bool ksu_load_dynamic_manager(void) { - return ksu_queue_work(&ksu_load_dynamic_sign_work); + return ksu_queue_work(&ksu_load_dynamic_manager_work); } -void ksu_dynamic_sign_init(void) +void ksu_dynamic_manager_init(void) { int i; - INIT_WORK(&ksu_save_dynamic_sign_work, do_save_dynamic_sign); - INIT_WORK(&ksu_load_dynamic_sign_work, do_load_dynamic_sign); - INIT_WORK(&ksu_clear_dynamic_sign_work, do_clear_dynamic_sign); + INIT_WORK(&ksu_save_dynamic_manager_work, do_save_dynamic_manager); + INIT_WORK(&ksu_load_dynamic_manager_work, do_load_dynamic_manager); + INIT_WORK(&ksu_clear_dynamic_manager_work, do_clear_dynamic_manager); // Initialize manager slots for (i = 0; i < MAX_MANAGERS; i++) { active_managers[i].is_active = false; } - ksu_load_dynamic_sign(); + ksu_load_dynamic_manager(); pr_info("Dynamic sign initialized with conditional multi-manager support\n"); } -void ksu_dynamic_sign_exit(void) +void ksu_dynamic_manager_exit(void) { clear_dynamic_manager(); // Save current config before exit - do_save_dynamic_sign(NULL); + do_save_dynamic_manager(NULL); pr_info("Dynamic sign exited with persistent storage\n"); } -// Get dynamic sign configuration for signature verification -bool ksu_get_dynamic_sign_config(unsigned int *size, const char **hash) +// Get dynamic manager configuration for signature verification +bool ksu_get_dynamic_manager_config(unsigned int *size, const char **hash) { unsigned long flags; bool valid = false; - spin_lock_irqsave(&dynamic_sign_lock, flags); - if (dynamic_sign.is_set) { - if (size) *size = dynamic_sign.size; - if (hash) *hash = dynamic_sign.hash; + spin_lock_irqsave(&dynamic_manager_lock, flags); + if (dynamic_manager.is_set) { + if (size) *size = dynamic_manager.size; + if (hash) *hash = dynamic_manager.hash; valid = true; } - spin_unlock_irqrestore(&dynamic_sign_lock, flags); + spin_unlock_irqrestore(&dynamic_manager_lock, flags); return valid; } \ No newline at end of file diff --git a/kernel/dynamic_manager.h b/kernel/dynamic_manager.h new file mode 100644 index 00000000..1c82b692 --- /dev/null +++ b/kernel/dynamic_manager.h @@ -0,0 +1,43 @@ +#ifndef __KSU_H_DYNAMIC_MANAGER +#define __KSU_H_DYNAMIC_MANAGER + +#include +#include "ksu.h" + +#define DYNAMIC_MANAGER_FILE_MAGIC 0x7f445347 // 'DSG', u32 +#define DYNAMIC_MANAGER_FILE_VERSION 1 // u32 +#define KERNEL_SU_DYNAMIC_MANAGER "/data/adb/ksu/.dynamic_manager" + +struct dynamic_manager_config { + unsigned int size; + char hash[65]; + int is_set; +}; + +struct manager_info { + uid_t uid; + int signature_index; + bool is_active; +}; + +// Dynamic sign operations +void ksu_dynamic_manager_init(void); +void ksu_dynamic_manager_exit(void); +int ksu_handle_dynamic_manager(struct dynamic_manager_user_config *config); +bool ksu_load_dynamic_manager(void); +bool ksu_is_dynamic_manager_enabled(void); + +// Multi-manager operations +void ksu_add_manager(uid_t uid, int signature_index); +void ksu_remove_manager(uid_t uid); +bool ksu_is_any_manager(uid_t uid); +int ksu_get_manager_signature_index(uid_t uid); +int ksu_get_active_managers(struct manager_list_info *info); + +// Multi-manager APK verification +bool ksu_is_dynamic_manager_apk(char *path, int *signature_index); + +// Configuration access for signature verification +bool ksu_get_dynamic_manager_config(unsigned int *size, const char **hash); + +#endif \ No newline at end of file diff --git a/kernel/dynamic_sign.h b/kernel/dynamic_sign.h deleted file mode 100644 index e0f93272..00000000 --- a/kernel/dynamic_sign.h +++ /dev/null @@ -1,43 +0,0 @@ -#ifndef __KSU_H_DYNAMIC_SIGN -#define __KSU_H_DYNAMIC_SIGN - -#include -#include "ksu.h" - -#define DYNAMIC_SIGN_FILE_MAGIC 0x7f445347 // 'DSG', u32 -#define DYNAMIC_SIGN_FILE_VERSION 1 // u32 -#define KERNEL_SU_DYNAMIC_SIGN "/data/adb/ksu/.dynamic_sign" - -struct dynamic_sign_config { - unsigned int size; - char hash[65]; - int is_set; -}; - -struct manager_info { - uid_t uid; - int signature_index; - bool is_active; -}; - -// Dynamic sign operations -int ksu_handle_dynamic_sign(struct dynamic_sign_user_config *config); -void ksu_dynamic_sign_init(void); -void ksu_dynamic_sign_exit(void); -bool ksu_load_dynamic_sign(void); -bool ksu_is_dynamic_sign_enabled(void); - -// Multi-manager operations -void ksu_add_manager(uid_t uid, int signature_index); -void ksu_remove_manager(uid_t uid); -bool ksu_is_any_manager(uid_t uid); -int ksu_get_manager_signature_index(uid_t uid); -int ksu_get_active_managers(struct manager_list_info *info); - -// Multi-manager APK verification -bool ksu_is_multi_manager_apk(char *path, int *signature_index); - -// Get dynamic sign configuration for signature verification -bool ksu_get_dynamic_sign_config(unsigned int *size, const char **hash); - -#endif \ No newline at end of file diff --git a/kernel/ksu.h b/kernel/ksu.h index 05e4b5a9..c7c6de97 100644 --- a/kernel/ksu.h +++ b/kernel/ksu.h @@ -29,7 +29,7 @@ #define CMD_ENABLE_KPM 100 #define CMD_HOOK_TYPE 101 #define CMD_GET_SUSFS_FEATURE_STATUS 102 -#define CMD_DYNAMIC_SIGN 103 +#define CMD_DYNAMIC_MANAGER 103 #define CMD_GET_MANAGERS 104 #define EVENT_POST_FS_DATA 1 @@ -48,11 +48,11 @@ #endif #define KSU_FULL_VERSION_STRING 255 -#define DYNAMIC_SIGN_OP_SET 0 -#define DYNAMIC_SIGN_OP_GET 1 -#define DYNAMIC_SIGN_OP_CLEAR 2 +#define DYNAMIC_MANAGER_OP_SET 0 +#define DYNAMIC_MANAGER_OP_GET 1 +#define DYNAMIC_MANAGER_OP_CLEAR 2 -struct dynamic_sign_user_config { +struct dynamic_manager_user_config { unsigned int operation; unsigned int size; char hash[65]; diff --git a/kernel/throne_tracker.c b/kernel/throne_tracker.c index 096ad878..cb7d1d77 100644 --- a/kernel/throne_tracker.c +++ b/kernel/throne_tracker.c @@ -12,7 +12,7 @@ #include "manager.h" #include "throne_tracker.h" #include "kernel_compat.h" -#include "dynamic_sign.h" +#include "dynamic_manager.h" uid_t ksu_manager_uid = KSU_INVALID_UID; @@ -199,7 +199,7 @@ FILLDIR_RETURN_TYPE my_actor(struct dir_context *ctx, const char *name, } int signature_index = -1; - bool is_multi_manager = ksu_is_multi_manager_apk(dirpath, &signature_index); + bool is_multi_manager = ksu_is_dynamic_manager_apk(dirpath, &signature_index); pr_info("Found new base.apk at path: %s, is_multi_manager: %d, signature_index: %d\n", dirpath, is_multi_manager, signature_index); @@ -403,7 +403,7 @@ void ksu_track_throne() } // Check for dynamic managers - if (!dynamic_manager_exist && ksu_is_dynamic_sign_enabled()) { + if (!dynamic_manager_exist && ksu_is_dynamic_manager_enabled()) { list_for_each_entry (np, &uid_list, list) { if (ksu_is_any_manager(np->uid)) { dynamic_manager_exist = true; @@ -421,8 +421,8 @@ void ksu_track_throne() pr_info("Searching manager...\n"); search_manager("/data/app", 2, &uid_list); pr_info("Search manager finished\n"); - } else if (!dynamic_manager_exist && ksu_is_dynamic_sign_enabled()) { - // Always perform search when called from dynamic sign rescan + } else if (!dynamic_manager_exist && ksu_is_dynamic_manager_enabled()) { + // Always perform search when called from dynamic manager rescan pr_info("Dynamic sign enabled, Searching manager...\n"); search_manager("/data/app", 2, &uid_list); pr_info("Search Dynamic sign manager finished\n");