diff options
| author | Eric Paris <eparis@redhat.com> | 2011-04-25 12:54:27 -0400 |
|---|---|---|
| committer | Eric Paris <eparis@redhat.com> | 2011-04-25 18:13:15 -0400 |
| commit | f48b7399840b453e7282b523f535561fe9638a2d (patch) | |
| tree | 29eed009469d35473367708ea60b9c5b01fc0c5f /security | |
| parent | 0dc1ba24f7fff659725eecbba2c9ad679a0954cd (diff) | |
LSM: split LSM_AUDIT_DATA_FS into _PATH and _INODE
The lsm common audit code has wacky contortions making sure which pieces
of information are set based on if it was given a path, dentry, or
inode. Split this into path and inode to get rid of some of the code
complexity.
Signed-off-by: Eric Paris <eparis@redhat.com>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
Diffstat (limited to 'security')
| -rw-r--r-- | security/lsm_audit.c | 50 | ||||
| -rw-r--r-- | security/selinux/avc.c | 2 | ||||
| -rw-r--r-- | security/selinux/hooks.c | 50 | ||||
| -rw-r--r-- | security/smack/smack.h | 8 | ||||
| -rw-r--r-- | security/smack/smack_lsm.c | 32 |
5 files changed, 74 insertions, 68 deletions
diff --git a/security/lsm_audit.c b/security/lsm_audit.c index 908aa712816a..2e846052cbf4 100644 --- a/security/lsm_audit.c +++ b/security/lsm_audit.c | |||
| @@ -210,7 +210,6 @@ static inline void print_ipv4_addr(struct audit_buffer *ab, __be32 addr, | |||
| 210 | static void dump_common_audit_data(struct audit_buffer *ab, | 210 | static void dump_common_audit_data(struct audit_buffer *ab, |
| 211 | struct common_audit_data *a) | 211 | struct common_audit_data *a) |
| 212 | { | 212 | { |
| 213 | struct inode *inode = NULL; | ||
| 214 | struct task_struct *tsk = current; | 213 | struct task_struct *tsk = current; |
| 215 | 214 | ||
| 216 | if (a->tsk) | 215 | if (a->tsk) |
| @@ -229,33 +228,40 @@ static void dump_common_audit_data(struct audit_buffer *ab, | |||
| 229 | case LSM_AUDIT_DATA_CAP: | 228 | case LSM_AUDIT_DATA_CAP: |
| 230 | audit_log_format(ab, " capability=%d ", a->u.cap); | 229 | audit_log_format(ab, " capability=%d ", a->u.cap); |
| 231 | break; | 230 | break; |
| 232 | case LSM_AUDIT_DATA_FS: | 231 | case LSM_AUDIT_DATA_PATH: { |
| 233 | if (a->u.fs.path.dentry) { | 232 | struct dentry *dentry = a->u.path.dentry; |
| 234 | struct dentry *dentry = a->u.fs.path.dentry; | 233 | struct inode *inode; |
| 235 | if (a->u.fs.path.mnt) { | 234 | |
| 236 | audit_log_d_path(ab, "path=", &a->u.fs.path); | 235 | if (a->u.path.mnt) { |
| 237 | } else { | 236 | audit_log_d_path(ab, "path=", &a->u.path); |
| 238 | audit_log_format(ab, " name="); | 237 | } else { |
| 239 | audit_log_untrustedstring(ab, | 238 | audit_log_format(ab, " name="); |
| 240 | dentry->d_name.name); | 239 | audit_log_untrustedstring(ab, |
| 241 | } | 240 | dentry->d_name.name); |
| 242 | inode = dentry->d_inode; | ||
| 243 | } else if (a->u.fs.inode) { | ||
| 244 | struct dentry *dentry; | ||
| 245 | inode = a->u.fs.inode; | ||
| 246 | dentry = d_find_alias(inode); | ||
| 247 | if (dentry) { | ||
| 248 | audit_log_format(ab, " name="); | ||
| 249 | audit_log_untrustedstring(ab, | ||
| 250 | dentry->d_name.name); | ||
| 251 | dput(dentry); | ||
| 252 | } | ||
| 253 | } | 241 | } |
| 242 | inode = dentry->d_inode; | ||
| 254 | if (inode) | 243 | if (inode) |
| 255 | audit_log_format(ab, " dev=%s ino=%lu", | 244 | audit_log_format(ab, " dev=%s ino=%lu", |
| 256 | inode->i_sb->s_id, | 245 | inode->i_sb->s_id, |
| 257 | inode->i_ino); | 246 | inode->i_ino); |
| 258 | break; | 247 | break; |
| 248 | } | ||
| 249 | case LSM_AUDIT_DATA_INODE: { | ||
| 250 | struct dentry *dentry; | ||
| 251 | struct inode *inode; | ||
| 252 | |||
| 253 | inode = a->u.inode; | ||
| 254 | dentry = d_find_alias(inode); | ||
| 255 | if (dentry) { | ||
| 256 | audit_log_format(ab, " name="); | ||
| 257 | audit_log_untrustedstring(ab, | ||
| 258 | dentry->d_name.name); | ||
| 259 | dput(dentry); | ||
| 260 | } | ||
| 261 | audit_log_format(ab, " dev=%s ino=%lu", inode->i_sb->s_id, | ||
| 262 | inode->i_ino); | ||
| 263 | break; | ||
| 264 | } | ||
| 259 | case LSM_AUDIT_DATA_TASK: | 265 | case LSM_AUDIT_DATA_TASK: |
| 260 | tsk = a->u.tsk; | 266 | tsk = a->u.tsk; |
| 261 | if (tsk && tsk->pid) { | 267 | if (tsk && tsk->pid) { |
diff --git a/security/selinux/avc.c b/security/selinux/avc.c index 1d027e29ce8d..ce742f1778e1 100644 --- a/security/selinux/avc.c +++ b/security/selinux/avc.c | |||
| @@ -531,7 +531,7 @@ int avc_audit(u32 ssid, u32 tsid, | |||
| 531 | * during retry. However this is logically just as if the operation | 531 | * during retry. However this is logically just as if the operation |
| 532 | * happened a little later. | 532 | * happened a little later. |
| 533 | */ | 533 | */ |
| 534 | if ((a->type == LSM_AUDIT_DATA_FS) && | 534 | if ((a->type == LSM_AUDIT_DATA_INODE) && |
| 535 | (flags & IPERM_FLAG_RCU)) | 535 | (flags & IPERM_FLAG_RCU)) |
| 536 | return -ECHILD; | 536 | return -ECHILD; |
| 537 | 537 | ||
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index ed5f29aa0a38..ad664d3056eb 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c | |||
| @@ -1488,8 +1488,8 @@ static int inode_has_perm(const struct cred *cred, | |||
| 1488 | 1488 | ||
| 1489 | if (!adp) { | 1489 | if (!adp) { |
| 1490 | adp = &ad; | 1490 | adp = &ad; |
| 1491 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1491 | COMMON_AUDIT_DATA_INIT(&ad, INODE); |
| 1492 | ad.u.fs.inode = inode; | 1492 | ad.u.inode = inode; |
| 1493 | } | 1493 | } |
| 1494 | 1494 | ||
| 1495 | return avc_has_perm_flags(sid, isec->sid, isec->sclass, perms, adp, flags); | 1495 | return avc_has_perm_flags(sid, isec->sid, isec->sclass, perms, adp, flags); |
| @@ -1506,9 +1506,9 @@ static inline int dentry_has_perm(const struct cred *cred, | |||
| 1506 | struct inode *inode = dentry->d_inode; | 1506 | struct inode *inode = dentry->d_inode; |
| 1507 | struct common_audit_data ad; | 1507 | struct common_audit_data ad; |
| 1508 | 1508 | ||
| 1509 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1509 | COMMON_AUDIT_DATA_INIT(&ad, PATH); |
| 1510 | ad.u.fs.path.mnt = mnt; | 1510 | ad.u.path.mnt = mnt; |
| 1511 | ad.u.fs.path.dentry = dentry; | 1511 | ad.u.path.dentry = dentry; |
| 1512 | return inode_has_perm(cred, inode, av, &ad, 0); | 1512 | return inode_has_perm(cred, inode, av, &ad, 0); |
| 1513 | } | 1513 | } |
| 1514 | 1514 | ||
| @@ -1530,8 +1530,8 @@ static int file_has_perm(const struct cred *cred, | |||
| 1530 | u32 sid = cred_sid(cred); | 1530 | u32 sid = cred_sid(cred); |
| 1531 | int rc; | 1531 | int rc; |
| 1532 | 1532 | ||
| 1533 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1533 | COMMON_AUDIT_DATA_INIT(&ad, PATH); |
| 1534 | ad.u.fs.path = file->f_path; | 1534 | ad.u.path = file->f_path; |
| 1535 | 1535 | ||
| 1536 | if (sid != fsec->sid) { | 1536 | if (sid != fsec->sid) { |
| 1537 | rc = avc_has_perm(sid, fsec->sid, | 1537 | rc = avc_has_perm(sid, fsec->sid, |
| @@ -1569,8 +1569,8 @@ static int may_create(struct inode *dir, | |||
| 1569 | sid = tsec->sid; | 1569 | sid = tsec->sid; |
| 1570 | newsid = tsec->create_sid; | 1570 | newsid = tsec->create_sid; |
| 1571 | 1571 | ||
| 1572 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1572 | COMMON_AUDIT_DATA_INIT(&ad, PATH); |
| 1573 | ad.u.fs.path.dentry = dentry; | 1573 | ad.u.path.dentry = dentry; |
| 1574 | 1574 | ||
| 1575 | rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, | 1575 | rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, |
| 1576 | DIR__ADD_NAME | DIR__SEARCH, | 1576 | DIR__ADD_NAME | DIR__SEARCH, |
| @@ -1621,8 +1621,8 @@ static int may_link(struct inode *dir, | |||
| 1621 | dsec = dir->i_security; | 1621 | dsec = dir->i_security; |
| 1622 | isec = dentry->d_inode->i_security; | 1622 | isec = dentry->d_inode->i_security; |
| 1623 | 1623 | ||
| 1624 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1624 | COMMON_AUDIT_DATA_INIT(&ad, PATH); |
| 1625 | ad.u.fs.path.dentry = dentry; | 1625 | ad.u.path.dentry = dentry; |
| 1626 | 1626 | ||
| 1627 | av = DIR__SEARCH; | 1627 | av = DIR__SEARCH; |
| 1628 | av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME); | 1628 | av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME); |
| @@ -1667,9 +1667,9 @@ static inline int may_rename(struct inode *old_dir, | |||
| 1667 | old_is_dir = S_ISDIR(old_dentry->d_inode->i_mode); | 1667 | old_is_dir = S_ISDIR(old_dentry->d_inode->i_mode); |
| 1668 | new_dsec = new_dir->i_security; | 1668 | new_dsec = new_dir->i_security; |
| 1669 | 1669 | ||
| 1670 | COMMON_AUDIT_DATA_INIT(&ad, FS); | 1670 | COMMON_AUDIT_DATA_INIT(&ad, PATH); |
| 1671 | 1671 | ||
| 1672 | ad.u.fs.path.dentry = old_dentry; | 1672 | ad.u.path.dentry = old_dentry; |
| 1673 | rc = avc_has_perm(sid, old_dsec->sid, SECCLASS_DIR, | 1673 | rc = avc_has_perm(sid, old_dsec->sid, SECCLASS_DIR, |
| 1674 | DIR__REMOVE_NAME | DIR__SEARCH, &ad); | 1674 | DIR__REMOVE_NAME | DIR__SEARCH, &ad); |
| 1675 | if (rc) | 1675 | if (rc) |
| @@ -1685,7 +1685,7 @@ static inline int may_rename(struct inode *old_dir, | |||
| 1685 | return rc; | 1685 | return rc; |
| 1686 | } | 1686 | } |
| 1687 | 1687 | ||
| 1688 | ad.u.fs.path.dentry = new_dentry; | 1688 | ad.u.path.dentry = new_dentry; |
| 1689 | av = DIR__ADD_NAME | DIR__SEARCH; | 1689 | av = DIR__ADD_NAME | DIR__SEARCH; |
| 1690 | if (new_dentry->d_inode) | 1690 | if (new_dentry->d_inode) |
| 1691 | av |= DIR__REMOVE_NAME; | 1691 | av |= DIR__REMOVE_NAME; |
| @@ -1991,8 +1991,8 @@ static int selinux_bprm_set_creds(struct linux_binprm *bprm) | |||
| 1991 | return rc; | 1991 | return rc; |
