diff options
author | Amir Goldstein <amir73il@gmail.com> | 2020-05-24 10:24:41 +0300 |
---|---|---|
committer | Jan Kara <jack@suse.cz> | 2020-05-25 11:43:56 +0300 |
commit | 2f02fd3fa13e51713b630164f8a8e5b42de8283b (patch) | |
tree | ec622ee1d08a8ea486de9b8798e238a32ad5fff7 /security | |
parent | 5e23663b49e1e8ee6b805356259e3062edac5e2b (diff) | |
download | linux-2f02fd3fa13e51713b630164f8a8e5b42de8283b.tar.xz |
fanotify: fix ignore mask logic for events on child and on dir
The comments in fanotify_group_event_mask() say:
"If the event is on dir/child and this mark doesn't care about
events on dir/child, don't send it!"
Specifically, mount and filesystem marks do not care about events
on child, but they can still specify an ignore mask for those events.
For example, a group that has:
- A mount mark with mask 0 and ignore_mask FAN_OPEN
- An inode mark on a directory with mask FAN_OPEN | FAN_OPEN_EXEC
with flag FAN_EVENT_ON_CHILD
A child file open for exec would be reported to group with the FAN_OPEN
event despite the fact that FAN_OPEN is in ignore mask of mount mark,
because the mark iteration loop skips over non-inode marks for events
on child when calculating the ignore mask.
Move ignore mask calculation to the top of the iteration loop block
before excluding marks for events on dir/child.
Link: https://lore.kernel.org/r/20200524072441.18258-1-amir73il@gmail.com
Reported-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/linux-fsdevel/20200521162443.GA26052@quack2.suse.cz/
Fixes: 55bf882c7f13 "fanotify: fix merging marks masks with FAN_ONDIR"
Fixes: b469e7e47c8a "fanotify: fix handling of events on child..."
Signed-off-by: Amir Goldstein <amir73il@gmail.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Diffstat (limited to 'security')
0 files changed, 0 insertions, 0 deletions