Re: [PATCH v3 3/5] quota: Don't issue audit messages on quota enforcing

Jan Kara <[email protected]>
Newsgroups org.kernel.vger.linux-security-module,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-xfs
Message-ID <xommujufw6puvxysjes2nl55uc4ovjachsh4nl54gosyvg4huz@uui7ik3irsnl>
On Thu 02-07-26 11:33:21, [email protected] wrote:
> From: Carlos Maiolino <[email protected]>
> 
> Calling capable() to determine if we can bypass quota enforcement or not
> can trigger spurious audit messages. We don't really require it here so
> just use the capable_noaudit() version.
> 
> Signed-off-by: Carlos Maiolino <[email protected]>
> Cc: Jan Kara <[email protected]>
> Cc: Serge E. Hallyn <[email protected]>
> Cc: Dave Chinner <[email protected]>
> Cc: Eric Sandeen <[email protected]>
> Cc: Dr. Thomas Orgis" <[email protected]>
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
> Reviewed-by: "Darrick J. Wong" <[email protected]>
> Reviewed-by: Christoph Hellwig <[email protected]>

Makes sense. Feel free to add:

Acked-by: Jan Kara <[email protected]>

								Honza
> ---
>  fs/quota/dquot.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/fs/quota/dquot.c b/fs/quota/dquot.c
> index 9850de3955d3..dab93422a57b 100644
> --- a/fs/quota/dquot.c
> +++ b/fs/quota/dquot.c
> @@ -1308,7 +1308,7 @@ static int ignore_hardlimit(struct dquot *dquot)
>  {
>  	struct mem_dqinfo *info = &sb_dqopt(dquot->dq_sb)->info[dquot->dq_id.type];
>  
> -	return capable(CAP_SYS_RESOURCE) &&
> +	return capable_noaudit(CAP_SYS_RESOURCE) &&
>  	       (info->dqi_format->qf_fmt_id != QFMT_VFS_OLD ||
>  		!(info->dqi_flags & DQF_ROOT_SQUASH));
>  }
> -- 
> 2.54.0
> 
-- 
Jan Kara <[email protected]>
SUSE Labs, CR
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.