All of lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Hurley <peter@hurleysoftware.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Jiri Slaby <jslaby@suse.cz>,
	linux-audit@redhat.com, linux-kernel@vger.kernel.org,
	Peter Hurley <peter@hurleysoftware.com>
Subject: [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push
Date: Sat,  9 Jan 2016 20:58:59 -0800	[thread overview]
Message-ID: <1452401948-30790-7-git-send-email-peter@hurleysoftware.com> (raw)
In-Reply-To: <1452401948-30790-1-git-send-email-peter@hurleysoftware.com>

In canonical read mode, each line read and logged is pushed separately
with tty_audit_push(). For all single-threaded processes and multi-threaded
processes reading from only one tty, this patch has no effect; the last line
read will still be the entry pushed to the audit log because the tty
association cannot have changed between tty_audit_add_data() and
tty_audit_push().

For multi-threaded processes reading from different ttys concurrently,
the audit log will have mixed log entries anyway. Consider two ttys
audited concurrently:

CPU0                           CPU1
----------                     ------------
tty_audit_add_data(ttyA)
                               tty_audit_add_data(ttyB)
tty_audit_push()
                               tty_audit_add_data(ttyB)
                               tty_audit_push()

This patch will now cause the ttyB output to be split into separate
audit log entries.

However, this possibility is equally likely without this patch:

CPU0                           CPU1
----------                     ------------
                               tty_audit_add_data(ttyB)
tty_audit_add_data(ttyA)
tty_audit_push()
                               tty_audit_add_data(ttyB)
                               tty_audit_push()

Mixed canonical and non-canonical reads have similar races.

Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
---
 drivers/tty/n_tty.c     |  2 +-
 drivers/tty/tty_audit.c | 11 +++--------
 include/linux/tty.h     |  2 +-
 3 files changed, 5 insertions(+), 10 deletions(-)

diff --git a/drivers/tty/n_tty.c b/drivers/tty/n_tty.c
index 5d060fc..6bab08a 100644
--- a/drivers/tty/n_tty.c
+++ b/drivers/tty/n_tty.c
@@ -2078,7 +2078,7 @@ static int canon_copy_from_read_buf(struct tty_struct *tty,
 			ldata->line_start = ldata->read_tail;
 		else
 			ldata->push = 0;
-		tty_audit_push(tty);
+		tty_audit_push();
 	}
 	return 0;
 }
diff --git a/drivers/tty/tty_audit.c b/drivers/tty/tty_audit.c
index 5f65653..5ae4839 100644
--- a/drivers/tty/tty_audit.c
+++ b/drivers/tty/tty_audit.c
@@ -313,9 +313,9 @@ void tty_audit_add_data(struct tty_struct *tty, const void *data, size_t size)
 /**
  *	tty_audit_push	-	Push buffered data out
  *
- *	Make sure no audit data is pending for @tty on the current process.
+ *	Make sure no audit data is pending on the current process.
  */
-void tty_audit_push(struct tty_struct *tty)
+void tty_audit_push(void)
 {
 	struct tty_audit_buf *buf;
 	unsigned long flags;
@@ -331,13 +331,8 @@ void tty_audit_push(struct tty_struct *tty)
 	spin_unlock_irqrestore(&current->sighand->siglock, flags);
 
 	if (buf) {
-		int major, minor;
-
-		major = tty->driver->major;
-		minor = tty->driver->minor_start + tty->index;
 		mutex_lock(&buf->mutex);
-		if (buf->major == major && buf->minor == minor)
-			tty_audit_buf_push(buf);
+		tty_audit_buf_push(buf);
 		mutex_unlock(&buf->mutex);
 		tty_audit_buf_put(buf);
 	}
diff --git a/include/linux/tty.h b/include/linux/tty.h
index c1d1f08..21e3722 100644
--- a/include/linux/tty.h
+++ b/include/linux/tty.h
@@ -608,7 +608,7 @@ extern void tty_audit_add_data(struct tty_struct *tty, const void *data,
 extern void tty_audit_exit(void);
 extern void tty_audit_fork(struct signal_struct *sig);
 extern void tty_audit_tiocsti(struct tty_struct *tty, char ch);
-extern void tty_audit_push(struct tty_struct *tty);
+extern void tty_audit_push(void);
 extern int tty_audit_push_current(void);
 #else
 static inline void tty_audit_add_data(struct tty_struct *tty, const void *data,
-- 
2.7.0

  parent reply	other threads:[~2016-01-10  4:58 UTC|newest]

Thread overview: 59+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-11-11  2:05 [PATCH 00/15] Rework tty audit Peter Hurley
2015-11-11  2:05 ` [PATCH 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley
2015-11-11  2:05 ` [PATCH 02/15] tty: audit: Never audit packet mode Peter Hurley
2015-11-11  2:05 ` [PATCH 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley
2015-11-12 19:10   ` Richard Guy Briggs
2015-11-12 19:58     ` Peter Hurley
2015-11-13  2:15       ` Richard Guy Briggs
2015-11-13  2:27         ` Peter Hurley
2015-11-13  3:28           ` Richard Guy Briggs
2015-11-16 13:25             ` Peter Hurley
2015-11-11  2:05 ` [PATCH 04/15] tty: audit: Defer audit buffer association Peter Hurley
2015-11-11  2:05 ` [PATCH 05/15] tty: audit: Take siglock directly Peter Hurley
2015-11-11  2:05 ` [PATCH 06/15] tty: audit: Ignore current association for audit push Peter Hurley
2015-11-11  2:05 ` [PATCH 07/15] tty: audit: Combine push functions Peter Hurley
2015-11-11  2:05 ` [PATCH 08/15] tty: audit: Track tty association with dev_t Peter Hurley
2015-11-11  2:05 ` [PATCH 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley
2015-11-11  2:05 ` [PATCH 10/15] tty: audit: Remove false memory optimization Peter Hurley
2015-11-11  2:05 ` [PATCH 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley
2015-11-11  2:05 ` [PATCH 12/15] tty: audit: Simplify first-use allocation Peter Hurley
2015-11-11  2:05 ` [PATCH 13/15] tty: audit: Check audit enable first Peter Hurley
2015-11-11  2:05 ` [PATCH 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley
2015-11-11  2:06 ` [PATCH 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley
2015-11-13  2:31 ` [PATCH 00/15] Rework tty audit Peter Hurley
2015-12-21  0:39 ` Paul Moore
2016-01-10  4:58 ` [RESEND][PATCH " Peter Hurley
2016-01-10  4:58   ` [RESEND][PATCH 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley
2016-01-10  4:58   ` [RESEND][PATCH 02/15] tty: audit: Never audit packet mode Peter Hurley
2016-01-10  4:58   ` [RESEND][PATCH 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley
2016-01-10  4:58   ` [RESEND][PATCH 04/15] tty: audit: Defer audit buffer association Peter Hurley
2016-01-10  4:58   ` [RESEND][PATCH 05/15] tty: audit: Take siglock directly Peter Hurley
2016-01-10  4:58   ` Peter Hurley [this message]
2016-01-10  5:36     ` [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push kbuild test robot
2016-01-10  5:36       ` kbuild test robot
2016-01-10  7:00       ` Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 07/15] tty: audit: Combine push functions Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 08/15] tty: audit: Track tty association with dev_t Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 10/15] tty: audit: Remove false memory optimization Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 12/15] tty: audit: Simplify first-use allocation Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 13/15] tty: audit: Check audit enable first Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley
2016-01-10  4:59   ` [RESEND][PATCH 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley
2016-01-10  6:55   ` [PATCH v2 00/15] Rework tty audit Peter Hurley
2016-01-10  6:55     ` [PATCH v2 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley
2016-01-10  6:55     ` [PATCH v2 02/15] tty: audit: Never audit packet mode Peter Hurley
2016-01-10  6:55     ` [PATCH v2 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley
2016-01-10  6:55     ` [PATCH v2 04/15] tty: audit: Defer audit buffer association Peter Hurley
2016-01-10  6:55     ` [PATCH v2 05/15] tty: audit: Take siglock directly Peter Hurley
2016-01-10  6:55     ` [PATCH v2 06/15] tty: audit: Ignore current association for audit push Peter Hurley
2016-01-10  6:55     ` [PATCH v2 07/15] tty: audit: Combine push functions Peter Hurley
2016-01-10  6:55     ` [PATCH v2 08/15] tty: audit: Track tty association with dev_t Peter Hurley
2016-01-10  6:55     ` [PATCH v2 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley
2016-01-10  6:55     ` [PATCH v2 10/15] tty: audit: Remove false memory optimization Peter Hurley
2016-01-10  6:55     ` [PATCH v2 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley
2016-01-10  6:55     ` [PATCH v2 12/15] tty: audit: Simplify first-use allocation Peter Hurley
2016-01-10  6:55     ` [PATCH v2 13/15] tty: audit: Check audit enable first Peter Hurley
2016-01-10  6:55     ` [PATCH v2 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley
2016-01-10  6:55     ` [PATCH v2 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1452401948-30790-7-git-send-email-peter@hurleysoftware.com \
    --to=peter@hurleysoftware.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=jslaby@suse.cz \
    --cc=linux-audit@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.