diff options
author | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2015-12-28 16:02:29 -0500 |
---|---|---|
committer | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2016-02-18 17:14:03 -0500 |
commit | b44a7dfc6fa16e01f2497c9fa62c3926f94be174 (patch) | |
tree | b48ced5b7c84986778ca4ac3b6bf3f13c74f2ef2 /include/linux/lsm_hooks.h | |
parent | 4b2530d819e179ae3352c38a1ceff929a922d070 (diff) |
vfs: define a generic function to read a file from the kernel
For a while it was looked down upon to directly read files from Linux.
These days there exists a few mechanisms in the kernel that do just
this though to load a file into a local buffer. There are minor but
important checks differences on each. This patch set is the first
attempt at resolving some of these differences.
This patch introduces a common function for reading files from the kernel
with the corresponding security post-read hook and function.
Changelog v4+:
- export security_kernel_post_read_file() - Fengguang Wu
v3:
- additional bounds checking - Luis
v2:
- To simplify patch review, re-ordered patches
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Reviewed-by: Luis R. Rodriguez <mcgrof@suse.com>
Acked-by: Kees Cook <keescook@chromium.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Diffstat (limited to 'include/linux/lsm_hooks.h')
-rw-r--r-- | include/linux/lsm_hooks.h | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/include/linux/lsm_hooks.h b/include/linux/lsm_hooks.h index 71969de4058c..f82631cc7248 100644 --- a/include/linux/lsm_hooks.h +++ b/include/linux/lsm_hooks.h | |||
@@ -561,6 +561,13 @@ | |||
561 | * the kernel module to load. If the module is being loaded from a blob, | 561 | * the kernel module to load. If the module is being loaded from a blob, |
562 | * this argument will be NULL. | 562 | * this argument will be NULL. |
563 | * Return 0 if permission is granted. | 563 | * Return 0 if permission is granted. |
564 | * @kernel_post_read_file: | ||
565 | * Read a file specified by userspace. | ||
566 | * @file contains the file structure pointing to the file being read | ||
567 | * by the kernel. | ||
568 | * @buf pointer to buffer containing the file contents. | ||
569 | * @size length of the file contents. | ||
570 | * Return 0 if permission is granted. | ||
564 | * @task_fix_setuid: | 571 | * @task_fix_setuid: |
565 | * Update the module's state after setting one or more of the user | 572 | * Update the module's state after setting one or more of the user |
566 | * identity attributes of the current process. The @flags parameter | 573 | * identity attributes of the current process. The @flags parameter |
@@ -1457,6 +1464,7 @@ union security_list_options { | |||
1457 | int (*kernel_fw_from_file)(struct file *file, char *buf, size_t size); | 1464 | int (*kernel_fw_from_file)(struct file *file, char *buf, size_t size); |
1458 | int (*kernel_module_request)(char *kmod_name); | 1465 | int (*kernel_module_request)(char *kmod_name); |
1459 | int (*kernel_module_from_file)(struct file *file); | 1466 | int (*kernel_module_from_file)(struct file *file); |
1467 | int (*kernel_post_read_file)(struct file *file, char *buf, loff_t size); | ||
1460 | int (*task_fix_setuid)(struct cred *new, const struct cred *old, | 1468 | int (*task_fix_setuid)(struct cred *new, const struct cred *old, |
1461 | int flags); | 1469 | int flags); |
1462 | int (*task_setpgid)(struct task_struct *p, pid_t pgid); | 1470 | int (*task_setpgid)(struct task_struct *p, pid_t pgid); |
@@ -1716,6 +1724,7 @@ struct security_hook_heads { | |||
1716 | struct list_head kernel_act_as; | 1724 | struct list_head kernel_act_as; |
1717 | struct list_head kernel_create_files_as; | 1725 | struct list_head kernel_create_files_as; |
1718 | struct list_head kernel_fw_from_file; | 1726 | struct list_head kernel_fw_from_file; |
1727 | struct list_head kernel_post_read_file; | ||
1719 | struct list_head kernel_module_request; | 1728 | struct list_head kernel_module_request; |
1720 | struct list_head kernel_module_from_file; | 1729 | struct list_head kernel_module_from_file; |
1721 | struct list_head task_fix_setuid; | 1730 | struct list_head task_fix_setuid; |