提交 1fc0f78c 编写于 作者: A Al Viro

->permission() sanitizing: MAY_NOT_BLOCK

Duplicate the flags argument into mask bitmap.
Signed-off-by: NAl Viro <viro@zeniv.linux.org.uk>
上级 178ea735
...@@ -318,13 +318,16 @@ static inline int exec_permission(struct inode *inode, unsigned int flags) ...@@ -318,13 +318,16 @@ static inline int exec_permission(struct inode *inode, unsigned int flags)
{ {
int ret; int ret;
struct user_namespace *ns = inode_userns(inode); struct user_namespace *ns = inode_userns(inode);
int mask = MAY_EXEC;
if (flags & IPERM_FLAG_RCU)
mask |= MAY_NOT_BLOCK;
if (inode->i_op->permission) { if (inode->i_op->permission) {
ret = inode->i_op->permission(inode, MAY_EXEC, flags); ret = inode->i_op->permission(inode, mask, flags);
if (likely(!ret)) if (likely(!ret))
goto ok; goto ok;
} else { } else {
ret = acl_permission_check(inode, MAY_EXEC, flags); ret = acl_permission_check(inode, mask, flags);
if (likely(!ret)) if (likely(!ret))
goto ok; goto ok;
if (ret != -EACCES) if (ret != -EACCES)
......
...@@ -316,7 +316,7 @@ static int proc_sys_permission(struct inode *inode, int mask,unsigned int flags) ...@@ -316,7 +316,7 @@ static int proc_sys_permission(struct inode *inode, int mask,unsigned int flags)
if (!table) /* global root - r-xr-xr-x */ if (!table) /* global root - r-xr-xr-x */
error = mask & MAY_WRITE ? -EACCES : 0; error = mask & MAY_WRITE ? -EACCES : 0;
else /* Use the permissions on the sysctl table entry */ else /* Use the permissions on the sysctl table entry */
error = sysctl_perm(head->root, table, mask); error = sysctl_perm(head->root, table, mask & ~MAY_NOT_BLOCK);
sysctl_head_finish(head); sysctl_head_finish(head);
return error; return error;
......
...@@ -63,6 +63,7 @@ struct inodes_stat_t { ...@@ -63,6 +63,7 @@ struct inodes_stat_t {
#define MAY_ACCESS 16 #define MAY_ACCESS 16
#define MAY_OPEN 32 #define MAY_OPEN 32
#define MAY_CHDIR 64 #define MAY_CHDIR 64
#define MAY_NOT_BLOCK 128 /* called from RCU mode, don't block */
/* /*
* flags in file.f_mode. Note that FMODE_READ and FMODE_WRITE must correspond * flags in file.f_mode. Note that FMODE_READ and FMODE_WRITE must correspond
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册