From: Casey Schaufler <casey@schaufler-ca.com>
To: "Ahmed S. Darwish" <darwish.07@gmail.com>,
Jonathan Corbet <corbet@lwn.net>,
Casey Schaufler <casey@schaufler-ca.com>,
Andrew Morton <akpm@linux-foundation.org>
Cc: LKML <linux-kernel@vger.kernel.org>,
Christoph Hellwig <hch@infradead.org>,
Daniel Walker <dwalker@mvista.com>
Subject: Re: [PATCH BUGFIX -rc6] Smackfs: remove redundant lock, fix open(,O_RDWR)
Date: Fri, 21 Mar 2008 11:17:51 -0700 (PDT) [thread overview]
Message-ID: <229474.71421.qm@web36611.mail.mud.yahoo.com> (raw)
In-Reply-To: <20080321150541.GA19083@ubuntu>
--- "Ahmed S. Darwish" <darwish.07@gmail.com> wrote:
> Hi all,
>
> Older smackfs was parsing MAC rules by characters, thus a need of
> locking write sessions on open() was needed. This lock is no longer
> useful now since each rule is handled by a single write() call.
>
> This is also a bugfix since seq_open() was not called if an open()
> O_RDWR flag was given, leading to a seq_read() without an initialized
> seq_file, thus an Oops.
>
> Signed-off-by: Ahmed S. Darwish <darwish.07@gmail.com>
> Reported-by: Jonathan Corbet <corbet@lwn.net>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
> --
>
> security/smack/smackfs.c | 35 ++---------------------------------
> 1 file changed, 2 insertions(+), 33 deletions(-)
>
> diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
> index afe7c9b..cfae8af 100644
> --- a/security/smack/smackfs.c
> +++ b/security/smack/smackfs.c
> @@ -74,11 +74,6 @@ struct smk_list_entry *smack_list;
> #define SEQ_READ_FINISHED 1
>
> /*
> - * Disable concurrent writing open() operations
> - */
> -static struct semaphore smack_write_sem;
> -
> -/*
> * Values for parsing cipso rules
> * SMK_DIGITLEN: Length of a digit field in a rule.
> * SMK_CIPSOMIN: Minimum possible cipso rule length.
> @@ -168,32 +163,7 @@ static struct seq_operations load_seq_ops = {
> */
> static int smk_open_load(struct inode *inode, struct file *file)
> {
> - if ((file->f_flags & O_ACCMODE) == O_RDONLY)
> - return seq_open(file, &load_seq_ops);
> -
> - if (down_interruptible(&smack_write_sem))
> - return -ERESTARTSYS;
> -
> - return 0;
> -}
> -
> -/**
> - * smk_release_load - release() for /smack/load
> - * @inode: inode structure representing file
> - * @file: "load" file pointer
> - *
> - * For a reading session, use the seq_file release
> - * implementation.
> - * Otherwise, we are at the end of a writing session so
> - * clean everything up.
> - */
> -static int smk_release_load(struct inode *inode, struct file *file)
> -{
> - if ((file->f_flags & O_ACCMODE) == O_RDONLY)
> - return seq_release(inode, file);
> -
> - up(&smack_write_sem);
> - return 0;
> + return seq_open(file, &load_seq_ops);
> }
>
> /**
> @@ -341,7 +311,7 @@ static const struct file_operations smk_load_ops = {
> .read = seq_read,
> .llseek = seq_lseek,
> .write = smk_write_load,
> - .release = smk_release_load,
> + .release = seq_release,
> };
>
> /**
> @@ -1011,7 +981,6 @@ static int __init init_smk_fs(void)
> }
> }
>
> - sema_init(&smack_write_sem, 1);
> smk_cipso_doi();
> smk_unlbl_ambient(NULL);
>
> Regards,
>
> --
>
> "Better to light a candle, than curse the darkness"
>
> Ahmed S. Darwish
> Homepage: http://darwish.07.googlepages.com
> Blog: http://darwish-07.blogspot.com
>
>
>
Casey Schaufler
casey@schaufler-ca.com
prev parent reply other threads:[~2008-03-21 18:18 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-21 15:05 [PATCH BUGFIX -rc6] Smackfs: remove redundant lock, fix open(,O_RDWR) Ahmed S. Darwish
2008-03-21 18:17 ` Casey Schaufler [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=229474.71421.qm@web36611.mail.mud.yahoo.com \
--to=casey@schaufler-ca.com \
--cc=akpm@linux-foundation.org \
--cc=corbet@lwn.net \
--cc=darwish.07@gmail.com \
--cc=dwalker@mvista.com \
--cc=hch@infradead.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.