Re: [PATCH v8 1/6] reiserfs: Switch to security_inode_init_security()
Paul Moore <[email protected]>
| Newsgroups | gmane.comp.file-systems.reiserfs.general,gmane.comp.file-systems.ocfs2.devel,gmane.linux.kernel.lsm,gmane.linux.kernel |
|---|---|
| Message-ID | <CAHC9VhS1htA=cFqbc3KJsrZ3by6_m=f3Bd0sTbztC=qMZEvedA@mail.gmail.com> |
On Tue, Mar 14, 2023 at 4:18 AM Roberto Sassu <[email protected]> wrote: > > From: Roberto Sassu <[email protected]> > > In preparation for removing security_old_inode_init_security(), switch to > security_inode_init_security(). Commit 572302af1258 ("reiserfs: Add missing > calls to reiserfs_security_free()") fixed possible memory leaks and another > issue related to adding an xattr at inode creation time. > > Define the initxattrs callback reiserfs_initxattrs(), to populate the > name/value/len triple in the reiserfs_security_handle() with the first > xattr provided by LSMs. Make a copy of the xattr value, as > security_inode_init_security() frees it. > > After the call to security_inode_init_security(), remove the check for > returning -EOPNOTSUPP, as security_inode_init_security() changes it to > zero. > > Multiple xattrs are currently not supported, as the > reiserfs_security_handle structure is exported to user space. As a > consequence, even if EVM is invoked, it will not provide an xattr (if it > is not the first to set it, its xattr will be discarded; if it is the > first, it does not have xattrs to calculate the HMAC on). > > Signed-off-by: Roberto Sassu <[email protected]> > Reviewed-by: Casey Schaufler <[email protected]> > Reviewed-by: Mimi Zohar <[email protected]> > --- > fs/reiserfs/xattr_security.c | 23 ++++++++++++++++++----- > 1 file changed, 18 insertions(+), 5 deletions(-) Merged into lsm/next, thanks. -- paul-moore.com