From: Amir Goldstein <amir73il@gmail.com>
To: Jan Kara <jack@suse.cz>
Cc: linux-fsdevel@vger.kernel.org
Subject: [PATCH v2 15/16] fanotify: refine rules for when name is reported
Date: Mon, 17 Feb 2020 15:14:54 +0200 [thread overview]
Message-ID: <20200217131455.31107-16-amir73il@gmail.com> (raw)
In-Reply-To: <20200217131455.31107-1-amir73il@gmail.com>
With FAN_REPORT_NAME, name will be reported if event is in the mask of a
watching parent or filesystem mark.
Name will not be reported if event is only in the mask of a mark on the
victim inode itself.
If event is only in the mask of a marked mount, name will be reported if
the victim inode is not the mount's root. Note that the mount's root
could be a non-directory in case of bind mount.
Signed-off-by: Amir Goldstein <amir73il@gmail.com>
---
fs/notify/fanotify/fanotify.c | 37 +++++++++++++++++++++++++++++------
1 file changed, 31 insertions(+), 6 deletions(-)
diff --git a/fs/notify/fanotify/fanotify.c b/fs/notify/fanotify/fanotify.c
index 43c338a8a2f1..45203c1484b9 100644
--- a/fs/notify/fanotify/fanotify.c
+++ b/fs/notify/fanotify/fanotify.c
@@ -202,6 +202,32 @@ static u32 fanotify_group_event_mask(struct fsnotify_group *group,
!(mark->mask & FS_EVENT_ON_CHILD)))
continue;
+ /*
+ * fanotify_alloc_event() uses the "on child" flag as indication
+ * for reporting name, but the flag will be masked out before
+ * reporting to user.
+ *
+ * With FAN_REPORT_NAME, name will be reported if event is in
+ * the mask of a watching parent or filesystem mark.
+ * name will not be reported if event is only in the mask of a
+ * mark on the victim inode itself.
+ * If event is only in the mask of a marked mount, name will be
+ * reported if the victim inode is not the mount's root. Note
+ * that the mount's root could be a non-directory in case of
+ * bind mount.
+ */
+ if (FAN_GROUP_FLAG(group, FAN_REPORT_NAME) &&
+ event_mask & mark->mask & FS_EVENTS_POSS_ON_CHILD) {
+ user_mask |= FS_EVENT_ON_CHILD;
+ if (type == FSNOTIFY_OBJ_TYPE_SB ||
+ (type == FSNOTIFY_OBJ_TYPE_VFSMOUNT &&
+ !WARN_ON_ONCE(data_type != FSNOTIFY_EVENT_PATH) &&
+ path->dentry != path->mnt->mnt_root)) {
+ event_mask |= FS_EVENT_ON_CHILD;
+ marks_mask |= FS_EVENT_ON_CHILD;
+ }
+ }
+
marks_mask |= mark->mask;
marks_ignored_mask |= mark->ignored_mask;
}
@@ -344,9 +370,8 @@ struct fanotify_event *fanotify_alloc_event(struct fsnotify_group *group,
* With flag FAN_REPORT_NAME, we report the parent fid and name for
* events possible "on child" in addition to reporting the child fid.
* If parent is unknown (dentry is disconnected) or parent is not on the
- * same filesystem as child (dentry is sb root), only "child" fid is
- * reported. Events are reported the same way when reported to sb, mount
- * or inode marks and when reported to a directory watching children.
+ * same filesystem/mount as child (dentry is sb/mount root), only the
+ * "child" fid is reported.
* Allocate an fanotify_name_event struct and copy the name.
*/
if (mask & FAN_DIR_MODIFY && !(WARN_ON_ONCE(!file_name))) {
@@ -357,7 +382,7 @@ struct fanotify_event *fanotify_alloc_event(struct fsnotify_group *group,
id = NULL;
dir = inode;
} else if (FAN_GROUP_FLAG(group, FAN_REPORT_NAME) &&
- mask & FS_EVENTS_POSS_ON_CHILD &&
+ mask & FS_EVENT_ON_CHILD &&
likely(dentry && !IS_ROOT(dentry))) {
parent = dget_parent(dentry);
dir = d_inode(parent);
@@ -400,7 +425,7 @@ struct fanotify_event *fanotify_alloc_event(struct fsnotify_group *group,
* directory and child watches exist.
*/
fsnotify_init_event(&event->fse, (void *)dentry ?: inode);
- event->mask = mask;
+ event->mask = mask & FANOTIFY_OUTGOING_EVENTS;
if (FAN_GROUP_FLAG(group, FAN_REPORT_TID))
event->pid = get_pid(task_pid(current));
else
@@ -503,7 +528,7 @@ static int fanotify_handle_event(struct fsnotify_group *group,
mask = fanotify_group_event_mask(group, iter_info, mask, data,
data_type);
- if (!mask)
+ if (!(mask & FANOTIFY_OUTGOING_EVENTS))
return 0;
pr_debug("%s: group=%p inode=%p mask=%x\n", __func__, group, inode,
--
2.17.1
next prev parent reply other threads:[~2020-02-17 13:15 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-02-17 13:14 [PATCH v2 00/16] Fanotify event with name info Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 01/16] fsnotify: tidy up FS_ and FAN_ constants Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 02/16] fsnotify: factor helpers fsnotify_dentry() and fsnotify_file() Amir Goldstein
2020-02-25 13:46 ` Jan Kara
2020-02-25 14:27 ` Amir Goldstein
2020-02-26 13:59 ` Jan Kara
2020-02-17 13:14 ` [PATCH v2 03/16] fsnotify: funnel all dirent events through fsnotify_name() Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 04/16] fsnotify: use helpers to access data by data_type Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 05/16] fsnotify: simplify arguments passing to fsnotify_parent() Amir Goldstein
2020-02-19 10:50 ` kbuild test robot
2020-02-19 11:11 ` Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 06/16] fsnotify: pass dentry instead of inode for events possible on child Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 07/16] fsnotify: replace inode pointer with tag Amir Goldstein
2020-02-26 8:20 ` Jan Kara
2020-02-26 9:34 ` Amir Goldstein
2020-02-26 8:52 ` Jan Kara
2020-02-17 13:14 ` [PATCH v2 08/16] fanotify: merge duplicate events on parent and child Amir Goldstein
2020-02-26 9:18 ` Jan Kara
2020-02-26 12:14 ` Amir Goldstein
2020-02-26 14:38 ` Jan Kara
2021-01-22 13:59 ` fanotify_merge improvements Amir Goldstein
2021-01-23 13:30 ` Amir Goldstein
2021-01-25 13:01 ` Jan Kara
2021-01-26 16:21 ` Amir Goldstein
2021-01-27 11:24 ` Jan Kara
2021-01-27 12:57 ` Amir Goldstein
2021-01-27 15:15 ` Jan Kara
2021-01-27 18:03 ` Amir Goldstein
2021-01-28 10:27 ` Jan Kara
2021-01-28 18:50 ` Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 09/16] fanotify: fix merging marks masks with FAN_ONDIR Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 10/16] fanotify: send FAN_DIR_MODIFY event flavor with dir inode and name Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 11/16] fanotify: prepare to encode both parent and child fid's Amir Goldstein
2020-02-26 10:23 ` Jan Kara
2020-02-26 11:53 ` Amir Goldstein
2020-02-26 17:07 ` Jan Kara
2020-02-26 17:50 ` Amir Goldstein
2020-02-27 9:06 ` Amir Goldstein
2020-02-27 11:27 ` Jan Kara
2020-02-27 12:12 ` Amir Goldstein
2020-02-27 13:30 ` Jan Kara
2020-02-27 14:06 ` Amir Goldstein
2020-03-01 16:26 ` Amir Goldstein
2020-03-05 15:49 ` Jan Kara
2020-03-06 11:19 ` Amir Goldstein
2020-03-08 7:29 ` Amir Goldstein
2020-03-18 17:51 ` Jan Kara
2020-03-18 18:50 ` Amir Goldstein
2020-03-19 9:30 ` Jan Kara
2020-03-19 10:07 ` Amir Goldstein
2020-03-30 19:29 ` Amir Goldstein
2020-02-27 11:01 ` Jan Kara
2020-02-17 13:14 ` [PATCH v2 12/16] fanotify: record name info for FAN_DIR_MODIFY event Amir Goldstein
2020-02-17 13:14 ` [PATCH v2 13/16] fanotify: report " Amir Goldstein
2020-02-19 9:43 ` kbuild test robot
2020-02-19 10:17 ` kbuild test robot
2020-02-19 11:22 ` Amir Goldstein
2020-04-16 12:16 ` Michael Kerrisk (man-pages)
2020-04-20 15:53 ` Jan Kara
2020-04-20 18:45 ` Amir Goldstein
2020-04-20 18:47 ` Michael Kerrisk (man-pages)
2020-02-17 13:14 ` [PATCH v2 14/16] fanotify: report parent fid + name with FAN_REPORT_NAME Amir Goldstein
2020-02-17 13:14 ` Amir Goldstein [this message]
2020-02-17 13:14 ` [BONUS][PATCH v2 16/16] fanotify: support limited functionality for unprivileged users Amir Goldstein
2020-02-20 22:10 ` [PATCH v2 00/16] Fanotify event with name info Matthew Bobrowski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200217131455.31107-16-amir73il@gmail.com \
--to=amir73il@gmail.com \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).