diff options
author | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2016-01-30 22:23:26 -0500 |
---|---|---|
committer | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2016-02-21 09:06:09 -0500 |
commit | 39eeb4fb97f60dbdfc823c1a673a8844b9226b60 (patch) | |
tree | 46e37e2211017237abd363a0dd1b3737da741ed0 /fs/exec.c | |
parent | e40ba6d56b41754b37b995dbc8035b2b3a6afd8a (diff) |
security: define kernel_read_file hook
The kernel_read_file security hook is called prior to reading the file
into memory.
Changelog v4+:
- export security_kernel_read_file()
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Acked-by: Kees Cook <keescook@chromium.org>
Acked-by: Luis R. Rodriguez <mcgrof@kernel.org>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
Diffstat (limited to 'fs/exec.c')
-rw-r--r-- | fs/exec.c | 4 |
1 files changed, 4 insertions, 0 deletions
@@ -842,6 +842,10 @@ int kernel_read_file(struct file *file, void **buf, loff_t *size, | |||
842 | if (!S_ISREG(file_inode(file)->i_mode) || max_size < 0) | 842 | if (!S_ISREG(file_inode(file)->i_mode) || max_size < 0) |
843 | return -EINVAL; | 843 | return -EINVAL; |
844 | 844 | ||
845 | ret = security_kernel_read_file(file, id); | ||
846 | if (ret) | ||
847 | return ret; | ||
848 | |||
845 | i_size = i_size_read(file_inode(file)); | 849 | i_size = i_size_read(file_inode(file)); |
846 | if (max_size > 0 && i_size > max_size) | 850 | if (max_size > 0 && i_size > max_size) |
847 | return -EFBIG; | 851 | return -EFBIG; |