The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH =-v3 00/21] fanotify: novel file access notification and permission system
@ 2008-11-12 16:10 Eric Paris
  2008-11-12 16:10 ` [PATCH =-v3 01/21] filesystem notification: create fs/notify to contain all fs notification Eric Paris
                   ` (20 more replies)
  0 siblings, 21 replies; 34+ messages in thread
From: Eric Paris @ 2008-11-12 16:10 UTC (permalink / raw)
  To: linux-kernel, malware-list; +Cc: viro, alan, arjan, greg, tytso, akpm

the following is a file notification and access system intended to allow
a variety of userspace programs to get information about filesystem
events no matter where or how they happen on a system and use that in
conjunction with the actual on disk data related to that event to
provide additional services such as file change indexing or content
based antivirus scanning.  Minor changes are almost certainly possible
to make this notification and access interface usable for HSMs.  fscking
all notify is generally refered to as fanotify, or for the weak of heart
you can call it file access notify system.  The ideas behind this
code are based on talpa the GPL antivirus interface originally written
by Sophos and on the feedback from lkml and malware-list.  This is
however a complete rewrite from scratch.

The last patch set addressed every complaint/critisism from lists.  This
set adds a couple new features, some documentation, and a couple fixes to
the networking headers to support bi-arch machines.

**fanotify-executive-summary**

fanotify has a number of event types and only sends events for S_ISREG()
files.  These events incluse open, read, write, and permissions checking
for open and read.  The permissions checking events require that the
listener return some sort of allow/deny/more_time response as the
original process blocks until it gets an event (or times out)
listeners may register a group which will get notifications about
any combination of these events, it will be up to the listener to
determine what events they are interested in hearing or mediating access
decisions for.

groups are a construct in which userspace indicates what priority (only
really used for permission type events) and what type of events its
listeners want to hear.  A single group may have unlimited listeners but
each event will only go to ONE listener.  Two groups may register for
the same type of events and one listener in EACH group will get a copy
of the event.

The user interface for fanotify is all through sockopt calls.  Userspace
pulls events from the kernel using getsockopt and sends responses to the
kernel using setsockopt.  These are the only socket operations defined
for PF_FANOTIFY sockets.

---

Eric Paris (21):
      fanotify: add Documentation
      fanotify: allow fastpath entries to survive inode modification
      fanotify: evict misbehaving clients
      fanotify: all userspace to set timeouts
      fanotify: add option to clear all fastpaths
      fanotify: send file f_flags along with notifications
      fanotify: send tgid with notification messages
      fanotify: send pid with fanotify notification events
      fanotify: ability for userspace to delay responses
      fanotify: user interface for access decisions
      fanotify: give a special access permission check
      fanotify: blocking and access granting
      fanotify: add group priorities
      fanotify: add a userspace interface for fastpaths
      fanotify: fastpath to ignore certain in core inodes
      fanotify: add a userspace interface for fanotify notifications
      fanotify: make use of the new fsnotify_open_exec calls
      fsnotify: sys_execve and sys_uselib do not call into fsnotify
      fanotify: fscking all notify, system wide file access notification
      fsnotify: pass a file instead of an inode to open, read, and write
      filesystem notification: create fs/notify to contain all fs notification


 Documentation/filesystems/fanotify/fanotify.txt    |  214 ++++++
 .../filesystems/fanotify/fanotify_tester.c         |  255 +++++++
 fs/Kconfig                                         |   39 -
 fs/Makefile                                        |    5 
 fs/aio.c                                           |    7 
 fs/compat.c                                        |    5 
 fs/dnotify.c                                       |  194 -----
 fs/exec.c                                          |   15 
 fs/inode.c                                         |    6 
 fs/inotify.c                                       |  773 --------------------
 fs/inotify_user.c                                  |  778 --------------------
 fs/nfsd/vfs.c                                      |    4 
 fs/notify/Kconfig                                  |   52 +
 fs/notify/Makefile                                 |    6 
 fs/notify/access.c                                 |  222 ++++++
 fs/notify/dnotify.c                                |  194 +++++
 fs/notify/fanotify.c                               |  152 ++++
 fs/notify/fanotify.h                               |  112 +++
 fs/notify/fastpath.c                               |  264 +++++++
 fs/notify/group.c                                  |  163 ++++
 fs/notify/inotify.c                                |  773 ++++++++++++++++++++
 fs/notify/inotify_user.c                           |  778 ++++++++++++++++++++
 fs/notify/notification.c                           |  277 +++++++
 fs/open.c                                          |    7 
 fs/read_write.c                                    |   14 
 include/linux/Kbuild                               |    1 
 include/linux/fanotify.h                           |  197 +++++
 include/linux/fs.h                                 |    5 
 include/linux/fsnotify.h                           |   39 +
 include/linux/sched.h                              |    1 
 include/linux/socket.h                             |    5 
 mm/mmap.c                                          |    7 
 mm/mprotect.c                                      |    6 
 mm/nommu.c                                         |    7 
 net/Makefile                                       |    1 
 net/core/sock.c                                    |    6 
 net/fanotify/Makefile                              |    5 
 net/fanotify/af_fanotify.c                         |  295 ++++++++
 net/fanotify/af_fanotify.h                         |   20 +
 39 files changed, 4096 insertions(+), 1808 deletions(-)
 create mode 100644 Documentation/filesystems/fanotify/fanotify.txt
 create mode 100644 Documentation/filesystems/fanotify/fanotify_tester.c
 delete mode 100644 fs/dnotify.c
 delete mode 100644 fs/inotify.c
 delete mode 100644 fs/inotify_user.c
 create mode 100644 fs/notify/Kconfig
 create mode 100644 fs/notify/Makefile
 create mode 100644 fs/notify/access.c
 create mode 100644 fs/notify/dnotify.c
 create mode 100644 fs/notify/fanotify.c
 create mode 100644 fs/notify/fanotify.h
 create mode 100644 fs/notify/fastpath.c
 create mode 100644 fs/notify/group.c
 create mode 100644 fs/notify/inotify.c
 create mode 100644 fs/notify/inotify_user.c
 create mode 100644 fs/notify/notification.c
 create mode 100644 include/linux/fanotify.h
 create mode 100644 net/fanotify/Makefile
 create mode 100644 net/fanotify/af_fanotify.c
 create mode 100644 net/fanotify/af_fanotify.h

-- 
Signature

^ permalink raw reply	[flat|nested] 34+ messages in thread

end of thread, other threads:[~2009-12-08 15:25 UTC | newest]

Thread overview: 34+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-11-12 16:10 [PATCH =-v3 00/21] fanotify: novel file access notification and permission system Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 01/21] filesystem notification: create fs/notify to contain all fs notification Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 02/21] fsnotify: pass a file instead of an inode to open, read, and write Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 03/21] fanotify: fscking all notify, system wide file access notification Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 04/21] fsnotify: sys_execve and sys_uselib do not call into fsnotify Eric Paris
2008-11-12 16:49   ` Christoph Hellwig
2008-11-12 21:15     ` Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 05/21] fanotify: make use of the new fsnotify_open_exec calls Eric Paris
2008-11-12 16:10 ` [PATCH =-v3 06/21] fanotify: add a userspace interface for fanotify notifications Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 07/21] fanotify: fastpath to ignore certain in core inodes Eric Paris
2008-11-12 16:50   ` Christoph Hellwig
2008-11-12 16:56     ` Alan Cox
2008-11-12 16:58       ` Christoph Hellwig
2008-11-12 20:52         ` Eric Paris
2009-12-08 15:22           ` John Ogness
2008-11-12 22:38   ` Peter Zijlstra
2008-11-12 16:11 ` [PATCH =-v3 08/21] fanotify: add a userspace interface for fastpaths Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 09/21] fanotify: add group priorities Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 10/21] fanotify: blocking and access granting Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 11/21] fanotify: give a special access permission check Eric Paris
2008-11-12 16:53   ` Christoph Hellwig
2008-11-12 21:23     ` Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 12/21] fanotify: user interface for access decisions Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 13/21] fanotify: ability for userspace to delay responses Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 14/21] fanotify: send pid with fanotify notification events Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 15/21] fanotify: send tgid with notification messages Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 16/21] fanotify: send file f_flags along with notifications Eric Paris
2008-11-12 16:11 ` [PATCH =-v3 17/21] fanotify: add option to clear all fastpaths Eric Paris
2008-11-12 16:12 ` [PATCH =-v3 18/21] fanotify: all userspace to set timeouts Eric Paris
2008-11-12 16:56   ` Christoph Hellwig
2008-11-12 21:14     ` Eric Paris
2008-11-12 16:12 ` [PATCH =-v3 19/21] fanotify: evict misbehaving clients Eric Paris
2008-11-12 16:12 ` [PATCH =-v3 20/21] fanotify: allow fastpath entries to survive inode modification Eric Paris
2008-11-12 16:12 ` [PATCH =-v3 21/21] fanotify: add Documentation Eric Paris

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox