login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2010
»
November
»
19
Re: [PATCH] fs: call security_d_instantiate in d_obtain_alias V2
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: J. Bruce Fields
Subject:
Re: [PATCH] fs: call security_d_instantiate in d_obtain_alias V2
Date: Friday, November 19, 2010 - 3:35 pm
On Thu, Nov 18, 2010 at 08:52:55PM -0500, Josef Bacik wrote:
quoted text
> While trying to track down some NFS problems with BTRFS, I kept noticing I was > getting -EACCESS for no apparent reason. Eric Paris and printk() helped me > figure out that it was SELinux that was giving me grief, with the following > denial > > type=AVC msg=audit(1290013638.413:95): avc: denied { 0x800000 } for pid=1772 > comm="nfsd" name="" dev=sda1 ino=256 scontext=system_u:system_r:kernel_t:s0 > tcontext=system_u:object_r:unlabeled_t:s0 tclass=file > > Turns out this is because in d_obtain_alias if we can't find an alias we create > one and do all the normal instantiation stuff, but we don't do the > security_d_instantiate. > > Usually we are protected from getting a hashed dentry that hasn't yet run > security_d_instantiate() by the parent's i_mutex, but obviously this isn't an > option there, so in order to deal with the case that a second thread comes in > and finds our new dentry before we get to run security_d_instantiate(), we go > ahead and call it if we find a dentry already. Eric assures me that this is ok > as the code checks to see if the dentry has been initialized already so calling > security_d_instantiate() against the same dentry multiple times is ok. With > this patch I'm no longer getting errant -EACCESS values.
Thanks, I can't see any reason that wouldn't work. --b.
quoted text
> > Signed-off-by: Josef Bacik <josef@redhat.com> > --- > V1->V2: > -added second security_d_instantiate() call > > fs/dcache.c | 3 +++ > 1 files changed, 3 insertions(+), 0 deletions(-) > > diff --git a/fs/dcache.c b/fs/dcache.c > index 23702a9..119d489 100644 > --- a/fs/dcache.c > +++ b/fs/dcache.c > @@ -1201,9 +1201,12 @@ struct dentry *d_obtain_alias(struct inode *inode) > spin_unlock(&tmp->d_lock); > > spin_unlock(&dcache_lock); > + security_d_instantiate(tmp, inode); > return tmp; > > out_iput: > + if (res && !IS_ERR(res)) > + security_d_instantiate(res, inode); > iput(inode); > return res; > } > -- > 1.6.6.1 >
--
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
[PATCH] fs: call security_d_instantiate in d_obtain_alias V2
, Josef Bacik
, (Thu Nov 18, 6:52 pm)
Re: [PATCH] fs: call security_d_instantiate in d_obtain_al ...
, J. Bruce Fields
, (Fri Nov 19, 3:35 pm)
Re: [PATCH] fs: call security_d_instantiate in d_obtain_al ...
, J. Bruce Fields
, (Sat Nov 20, 7:59 pm)
Re: [PATCH] fs: call security_d_instantiate in d_obtain_al ...
, Josef Bacik
, (Sun Nov 21, 8:44 am)
Re: [PATCH] fs: call security_d_instantiate in d_obtain_al ...
, Josef Bacik
, (Mon Nov 29, 1:41 pm)
Re: [PATCH] fs: call security_d_instantiate in d_obtain_al ...
, Eric Sandeen
, (Fri Dec 17, 1:45 pm)
Navigation
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Ingo Molnar
Re: [PATCH 0/3] v2 Make hierarchical RCU less IPI-happy and add more tracing
Jeremy Fitzhardinge
Re: Linux 2.6.28.10 and Linux 2.6.29.6 XEN Guest Support Broken x86_64 in BUILD
Nick Piggin
Re: [patch] CFS (Completely Fair Scheduler), v2
Gary Hade
Re: [PATCH 0/5][RFC] Physical PCI slot objects
Dave Johnson
Re: expected behavior of PF_PACKET on NETIF_F_HW_VLAN_RX device?
linux-netdev
:
Arnd Bergmann
Re: 64-bit net_device_stats
Stephens, Allan
RE: [PATCH]: tipc: Fix oops on send prior to entering networked mode
frank.blaschka
[patch 3/5] [PATCH] qeth: support z/VM VSWITCH Port Isolation
Wu Fengguang
Re: [PATCH] dm9601: handle corrupt mac address
David Miller
Re: [PATCH net-2.6.24] Fix refcounting problem with netif_rx_reschedule()
git
:
Junio C Hamano
Re: [PATCH] [RFC] add Message-ID field to log on git-am operation
Junio C Hamano
Re: Handling large files with GIT
Karl
Re: [ANNOUNCE] pg - A patch porcelain for GIT
Josh Triplett
Re: [RFC][PATCH 00/10] Sparse: Git's "make check" target
Pierre Habouzit
Re: [PATCH] git-daemon: more powerful base-path/user-path settings, using formats.
git-commits-head
:
Linux Kernel Mailing List
MIPS: RBTX4939: Fix IOC pin-enable register updating
Linux Kernel Mailing List
regulator: update email address for Liam Girdwood
Linux Kernel Mailing List
[SCSI] ipr: add message to error table
Linux Kernel Mailing List
powerpc/32: Wire up the trampoline code for kdump
Linux Kernel Mailing List
USB: omap_udc: sync with OMAP tree
openbsd-misc
:
Josh Grosse
Re: error : pkg add phpMyAdmin
Brian Candler
Re: OBSD's perspective on SELinux
Jacob Meuser
Re: /dev/audio: Device busy
David Vasek
Re: Inexpensive, low power, "wall wart" computer
William Boshuck
Re: Richard Stallman...
Colocation donated by:
Syndicate