From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Howells Date: Wed, 29 May 2019 11:00:57 +0000 Subject: Re: [PATCH 3/7] vfs: Add a mount-notification facility Message-Id: <14347.1559127657@warthog.procyon.org.uk> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit List-Id: References: <155905930702.7587.7100265859075976147.stgit@warthog.procyon.org.uk> <155905933492.7587.6968545866041839538.stgit@warthog.procyon.org.uk> In-Reply-To: To: Jann Horn , casey@schaufler-ca.com Cc: dhowells@redhat.com, Al Viro , raven@themaw.net, linux-fsdevel , Linux API , linux-block@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module , kernel list Jann Horn wrote: > > +void post_mount_notification(struct mount *changed, > > + struct mount_notification *notify) > > +{ > > + const struct cred *cred = current_cred(); > > This current_cred() looks bogus to me. Can't mount topology changes > come from all sorts of places? For example, umount_mnt() from > umount_tree() from dissolve_on_fput() from __fput(), which could > happen pretty much anywhere depending on where the last reference gets > dropped? IIRC, that's what Casey argued is the right thing to do from a security PoV. Casey? Maybe I should pass in NULL creds in the case that an event is being generated because an object is being destroyed due to the last usage[*] being removed. [*] Usage, not ref - Superblocks are a bit weird in their accounting. David