From: "Serge E. Hallyn" <serue@us.ibm.com>
To: linux-kernel@vger.kernel.org
Cc: mm-commits@vger.kernel.org, mschmidt@redhat.com,
dhowells@redhat.com, jmorris@namei.org, sds@tycho.nsa.gov
Subject: Re: + bsdacct-switch-credentials-for-writing-to-the-accounting-file.patch added to -mm tree
Date: Fri, 21 Aug 2009 10:57:42 -0500 [thread overview]
Message-ID: <20090821155742.GA16842@us.ibm.com> (raw)
In-Reply-To: <200908202139.n7KLdq6D006632@imap1.linux-foundation.org>
Quoting akpm@linux-foundation.org (akpm@linux-foundation.org):
>
> The patch titled
> bsdacct: switch credentials for writing to the accounting file
> has been added to the -mm tree. Its filename is
> bsdacct-switch-credentials-for-writing-to-the-accounting-file.patch
>
> Before you just go and hit "reply", please:
> a) Consider who else should be cc'ed
> b) Prefer to cc a suitable mailing list as well
> c) Ideally: find the original patch on the mailing list and do a
> reply-to-all to that, adding suitable additional cc's
>
> *** Remember to use Documentation/SubmitChecklist when testing your code ***
>
> See http://userweb.kernel.org/~akpm/stuff/added-to-mm.txt to find
> out what to do about this
>
> The current -mm tree may be found at http://userweb.kernel.org/~akpm/mmotm/
>
> ------------------------------------------------------
> Subject: bsdacct: switch credentials for writing to the accounting file
> From: Michal Schmidt <mschmidt@redhat.com>
>
> When process accounting is enabled, every exiting process writes a log to
> the account file. In addition, every once in a while one of the exiting
> processes checks whether there's enough free space for the log.
>
> SELinux policy may or may not allow the exiting process to stat the fs.
> So unsuspecting processes start generating AVC denials just because
> someone enabled process accounting.
>
> For these filesystem operations, the exiting process's credentials should
> be temporarily switched to that of the process which enabled accounting,
> because it's really that process which wanted to have the accounting
> information logged.
>
> Signed-off-by: Michal Schmidt <mschmidt@redhat.com>
> Acked-by: David Howells <dhowells@redhat.com>
Acked-by: Serge Hallyn <serue@us.ibm.com>
> Cc: James Morris <jmorris@namei.org>
> Cc: Serge Hallyn <serue@us.ibm.com>
> Cc: Stephen Smalley <sds@tycho.nsa.gov>
> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
> ---
>
> kernel/acct.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff -puN kernel/acct.c~bsdacct-switch-credentials-for-writing-to-the-accounting-file kernel/acct.c
> --- a/kernel/acct.c~bsdacct-switch-credentials-for-writing-to-the-accounting-file
> +++ a/kernel/acct.c
> @@ -491,13 +491,17 @@ static void do_acct_process(struct bsd_a
> u64 run_time;
> struct timespec uptime;
> struct tty_struct *tty;
> + const struct cred *orig_cred;
> +
> + /* Perform file operations on behalf of whoever enabled accounting */
> + orig_cred = override_creds(file->f_cred);
>
> /*
> * First check to see if there is enough free_space to continue
> * the process accounting system.
> */
> if (!check_free_space(acct, file))
> - return;
> + goto out;
>
> /*
> * Fill the accounting struct with the needed info as recorded
> @@ -578,6 +582,8 @@ static void do_acct_process(struct bsd_a
> sizeof(acct_t), &file->f_pos);
> current->signal->rlim[RLIMIT_FSIZE].rlim_cur = flim;
> set_fs(fs);
> +out:
> + revert_creds(orig_cred);
> }
>
> /**
> _
>
> Patches currently in -mm which might be from mschmidt@redhat.com are
>
> bsdacct-switch-credentials-for-writing-to-the-accounting-file.patch
>
> --
> To unsubscribe from this list: send the line "unsubscribe mm-commits" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
next parent reply other threads:[~2009-08-21 15:57 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <200908202139.n7KLdq6D006632@imap1.linux-foundation.org>
2009-08-21 15:57 ` Serge E. Hallyn [this message]
2009-08-24 1:34 ` + bsdacct-switch-credentials-for-writing-to-the-accounting-file.patch added to -mm tree James Morris
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090821155742.GA16842@us.ibm.com \
--to=serue@us.ibm.com \
--cc=dhowells@redhat.com \
--cc=jmorris@namei.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mm-commits@vger.kernel.org \
--cc=mschmidt@redhat.com \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox