All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] fs/timerfd: reject ALARM timerfds without CAP_WAKE_ALARM
@ 2016-06-08 23:08 Eric Caruso
  2016-06-09 21:48 ` [tip:timers/core] timerfd: Reject " tip-bot for Eric Caruso
  0 siblings, 1 reply; 2+ messages in thread
From: Eric Caruso @ 2016-06-08 23:08 UTC (permalink / raw)
  To: Thomas Gleixner; +Cc: Todd Poynor, linux-kernel, Eric Caruso

From: Eric Caruso <ejcaruso@google.com>

timerfd gives processes a way to set wake alarms, but
unlike timers made using timer_create, timerfds don't
check whether the process has CAP_WAKE_ALARM before
setting alarm-time timers. CAP_WAKE_ALARM is supposed to
gate this behavior and so it makes sense that we should
deny permission to create such timerfds if the process
doesn't have this capability.

Signed-off-by: Eric Caruso <ejcaruso@google.com>
---
 fs/timerfd.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/fs/timerfd.c b/fs/timerfd.c
index 053818d..9ae4abb 100644
--- a/fs/timerfd.c
+++ b/fs/timerfd.c
@@ -390,6 +390,11 @@ SYSCALL_DEFINE2(timerfd_create, int, clockid, int, flags)
 	     clockid != CLOCK_BOOTTIME_ALARM))
 		return -EINVAL;
 
+	if (!capable(CAP_WAKE_ALARM) &&
+	    (clockid == CLOCK_REALTIME_ALARM ||
+	     clockid == CLOCK_BOOTTIME_ALARM))
+		return -EPERM;
+
 	ctx = kzalloc(sizeof(*ctx), GFP_KERNEL);
 	if (!ctx)
 		return -ENOMEM;
@@ -433,6 +438,11 @@ static int do_timerfd_settime(int ufd, int flags,
 		return ret;
 	ctx = f.file->private_data;
 
+	if (!capable(CAP_WAKE_ALARM) && isalarm(ctx)) {
+		fdput(f);
+		return -EPERM;
+	}
+
 	timerfd_setup_cancel(ctx, flags);
 
 	/*
-- 
2.8.0.rc3.226.g39d4020

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* [tip:timers/core] timerfd: Reject ALARM timerfds without CAP_WAKE_ALARM
  2016-06-08 23:08 [PATCH] fs/timerfd: reject ALARM timerfds without CAP_WAKE_ALARM Eric Caruso
@ 2016-06-09 21:48 ` tip-bot for Eric Caruso
  0 siblings, 0 replies; 2+ messages in thread
From: tip-bot for Eric Caruso @ 2016-06-09 21:48 UTC (permalink / raw)
  To: linux-tip-commits; +Cc: tglx, toddpoynor, ejcaruso, mingo, hpa, linux-kernel

Commit-ID:  2895a5e5b3ae78d9923a91fce405d4a2f32c4309
Gitweb:     http://git.kernel.org/tip/2895a5e5b3ae78d9923a91fce405d4a2f32c4309
Author:     Eric Caruso <ejcaruso@google.com>
AuthorDate: Wed, 8 Jun 2016 16:08:59 -0700
Committer:  Thomas Gleixner <tglx@linutronix.de>
CommitDate: Thu, 9 Jun 2016 23:42:38 +0200

timerfd: Reject ALARM timerfds without CAP_WAKE_ALARM

timerfd gives processes a way to set wake alarms, but unlike timers made using
timer_create, timerfds don't check whether the process has CAP_WAKE_ALARM
before setting alarm-time timers. CAP_WAKE_ALARM is supposed to gate this
behavior and so it makes sense that we should deny permission to create such
timerfds if the process doesn't have this capability.

Signed-off-by: Eric Caruso <ejcaruso@google.com>
Cc: Todd Poynor <toddpoynor@google.com>
Link: http://lkml.kernel.org/r/1465427339-96209-1-git-send-email-ejcaruso@chromium.org
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>

---
 fs/timerfd.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/fs/timerfd.c b/fs/timerfd.c
index 053818d..9ae4abb 100644
--- a/fs/timerfd.c
+++ b/fs/timerfd.c
@@ -390,6 +390,11 @@ SYSCALL_DEFINE2(timerfd_create, int, clockid, int, flags)
 	     clockid != CLOCK_BOOTTIME_ALARM))
 		return -EINVAL;
 
+	if (!capable(CAP_WAKE_ALARM) &&
+	    (clockid == CLOCK_REALTIME_ALARM ||
+	     clockid == CLOCK_BOOTTIME_ALARM))
+		return -EPERM;
+
 	ctx = kzalloc(sizeof(*ctx), GFP_KERNEL);
 	if (!ctx)
 		return -ENOMEM;
@@ -433,6 +438,11 @@ static int do_timerfd_settime(int ufd, int flags,
 		return ret;
 	ctx = f.file->private_data;
 
+	if (!capable(CAP_WAKE_ALARM) && isalarm(ctx)) {
+		fdput(f);
+		return -EPERM;
+	}
+
 	timerfd_setup_cancel(ctx, flags);
 
 	/*

^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2016-06-09 21:49 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-06-08 23:08 [PATCH] fs/timerfd: reject ALARM timerfds without CAP_WAKE_ALARM Eric Caruso
2016-06-09 21:48 ` [tip:timers/core] timerfd: Reject " tip-bot for Eric Caruso

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.