Andreas Gruenbacher | 33d3dff | 2009-12-17 21:24:29 -0500 | [diff] [blame] | 1 | #include <linux/fanotify.h> |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 2 | #include <linux/fdtable.h> |
| 3 | #include <linux/fsnotify_backend.h> |
| 4 | #include <linux/init.h> |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 5 | #include <linux/jiffies.h> |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 6 | #include <linux/kernel.h> /* UINT_MAX */ |
Eric Paris | 1c52906 | 2009-12-17 21:24:28 -0500 | [diff] [blame] | 7 | #include <linux/mount.h> |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 8 | #include <linux/sched.h> |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 9 | #include <linux/types.h> |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 10 | #include <linux/wait.h> |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 11 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 12 | #include "fanotify.h" |
Eric Paris | 767cd46 | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 13 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 14 | static bool should_merge(struct fsnotify_event *old_fsn, |
| 15 | struct fsnotify_event *new_fsn) |
| 16 | { |
| 17 | struct fanotify_event_info *old, *new; |
| 18 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 19 | pr_debug("%s: old=%p new=%p\n", __func__, old_fsn, new_fsn); |
| 20 | old = FANOTIFY_E(old_fsn); |
| 21 | new = FANOTIFY_E(new_fsn); |
| 22 | |
| 23 | if (old_fsn->inode == new_fsn->inode && old->tgid == new->tgid && |
| 24 | old->path.mnt == new->path.mnt && |
| 25 | old->path.dentry == new->path.dentry) |
| 26 | return true; |
Eric Paris | 767cd46 | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 27 | return false; |
| 28 | } |
| 29 | |
Eric Paris | f70ab54 | 2010-07-28 10:18:37 -0400 | [diff] [blame] | 30 | /* and the list better be locked by something too! */ |
Jan Kara | 83c0e1b | 2014-01-28 18:53:22 +0100 | [diff] [blame] | 31 | static int fanotify_merge(struct list_head *list, struct fsnotify_event *event) |
Eric Paris | 767cd46 | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 32 | { |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 33 | struct fsnotify_event *test_event; |
| 34 | bool do_merge = false; |
Eric Paris | 767cd46 | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 35 | |
| 36 | pr_debug("%s: list=%p event=%p\n", __func__, list, event); |
| 37 | |
Jan Kara | 13116df | 2014-01-28 18:29:24 +0100 | [diff] [blame] | 38 | #ifdef CONFIG_FANOTIFY_ACCESS_PERMISSIONS |
| 39 | /* |
| 40 | * Don't merge a permission event with any other event so that we know |
| 41 | * the event structure we have created in fanotify_handle_event() is the |
| 42 | * one we should check for permission response. |
| 43 | */ |
| 44 | if (event->mask & FAN_ALL_PERM_EVENTS) |
Jan Kara | 83c0e1b | 2014-01-28 18:53:22 +0100 | [diff] [blame] | 45 | return 0; |
Jan Kara | 13116df | 2014-01-28 18:29:24 +0100 | [diff] [blame] | 46 | #endif |
| 47 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 48 | list_for_each_entry_reverse(test_event, list, list) { |
| 49 | if (should_merge(test_event, event)) { |
| 50 | do_merge = true; |
Eric Paris | a12a7dd | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 51 | break; |
| 52 | } |
| 53 | } |
Eric Paris | f70ab54 | 2010-07-28 10:18:37 -0400 | [diff] [blame] | 54 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 55 | if (!do_merge) |
Jan Kara | 83c0e1b | 2014-01-28 18:53:22 +0100 | [diff] [blame] | 56 | return 0; |
Eric Paris | f70ab54 | 2010-07-28 10:18:37 -0400 | [diff] [blame] | 57 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 58 | test_event->mask |= event->mask; |
Jan Kara | 83c0e1b | 2014-01-28 18:53:22 +0100 | [diff] [blame] | 59 | return 1; |
Eric Paris | 767cd46 | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 60 | } |
| 61 | |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 62 | #ifdef CONFIG_FANOTIFY_ACCESS_PERMISSIONS |
Jan Kara | f083441 | 2014-04-03 14:46:33 -0700 | [diff] [blame] | 63 | static int fanotify_get_response(struct fsnotify_group *group, |
| 64 | struct fanotify_perm_event_info *event) |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 65 | { |
| 66 | int ret; |
| 67 | |
| 68 | pr_debug("%s: group=%p event=%p\n", __func__, group, event); |
| 69 | |
Lino Sanfilippo | 09e5f14 | 2010-11-19 10:58:07 +0100 | [diff] [blame] | 70 | wait_event(group->fanotify_data.access_waitq, event->response || |
| 71 | atomic_read(&group->fanotify_data.bypass_perm)); |
| 72 | |
Jan Kara | 5838d44 | 2014-08-06 16:03:28 -0700 | [diff] [blame] | 73 | if (!event->response) { /* bypass_perm set */ |
| 74 | /* |
| 75 | * Event was canceled because group is being destroyed. Remove |
| 76 | * it from group's event list because we are responsible for |
| 77 | * freeing the permission event. |
| 78 | */ |
| 79 | fsnotify_remove_event(group, &event->fae.fse); |
Lino Sanfilippo | 09e5f14 | 2010-11-19 10:58:07 +0100 | [diff] [blame] | 80 | return 0; |
Jan Kara | 5838d44 | 2014-08-06 16:03:28 -0700 | [diff] [blame] | 81 | } |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 82 | |
| 83 | /* userspace responded, convert to something usable */ |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 84 | switch (event->response) { |
| 85 | case FAN_ALLOW: |
| 86 | ret = 0; |
| 87 | break; |
| 88 | case FAN_DENY: |
| 89 | default: |
| 90 | ret = -EPERM; |
| 91 | } |
| 92 | event->response = 0; |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 93 | |
Eric Paris | b2d8790 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 94 | pr_debug("%s: group=%p event=%p about to return ret=%d\n", __func__, |
| 95 | group, event, ret); |
| 96 | |
Eric Paris | 9e66e42 | 2009-12-17 21:24:34 -0500 | [diff] [blame] | 97 | return ret; |
| 98 | } |
| 99 | #endif |
| 100 | |
Jan Kara | 83c4c4b | 2014-01-21 15:48:15 -0800 | [diff] [blame] | 101 | static bool fanotify_should_send_event(struct fsnotify_mark *inode_mark, |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 102 | struct fsnotify_mark *vfsmnt_mark, |
Jan Kara | 83c4c4b | 2014-01-21 15:48:15 -0800 | [diff] [blame] | 103 | u32 event_mask, |
| 104 | void *data, int data_type) |
Eric Paris | 1c52906 | 2009-12-17 21:24:28 -0500 | [diff] [blame] | 105 | { |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 106 | __u32 marks_mask, marks_ignored_mask; |
Eric Paris | e1c048b | 2010-10-28 17:21:58 -0400 | [diff] [blame] | 107 | struct path *path = data; |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 108 | |
Jan Kara | 83c4c4b | 2014-01-21 15:48:15 -0800 | [diff] [blame] | 109 | pr_debug("%s: inode_mark=%p vfsmnt_mark=%p mask=%x data=%p" |
| 110 | " data_type=%d\n", __func__, inode_mark, vfsmnt_mark, |
| 111 | event_mask, data, data_type); |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 112 | |
Eric Paris | 1c52906 | 2009-12-17 21:24:28 -0500 | [diff] [blame] | 113 | /* if we don't have enough info to send an event to userspace say no */ |
Linus Torvalds | 2069601 | 2010-08-12 14:23:04 -0700 | [diff] [blame] | 114 | if (data_type != FSNOTIFY_EVENT_PATH) |
Eric Paris | 1c52906 | 2009-12-17 21:24:28 -0500 | [diff] [blame] | 115 | return false; |
| 116 | |
Eric Paris | e1c048b | 2010-10-28 17:21:58 -0400 | [diff] [blame] | 117 | /* sorry, fanotify only gives a damn about files and dirs */ |
David Howells | e36cb0b | 2015-01-29 12:02:35 +0000 | [diff] [blame] | 118 | if (!d_is_reg(path->dentry) && |
David Howells | 54f2a2f | 2015-01-29 12:02:36 +0000 | [diff] [blame] | 119 | !d_can_lookup(path->dentry)) |
Eric Paris | e1c048b | 2010-10-28 17:21:58 -0400 | [diff] [blame] | 120 | return false; |
| 121 | |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 122 | if (inode_mark && vfsmnt_mark) { |
| 123 | marks_mask = (vfsmnt_mark->mask | inode_mark->mask); |
| 124 | marks_ignored_mask = (vfsmnt_mark->ignored_mask | inode_mark->ignored_mask); |
| 125 | } else if (inode_mark) { |
| 126 | /* |
| 127 | * if the event is for a child and this inode doesn't care about |
| 128 | * events on the child, don't send it! |
| 129 | */ |
| 130 | if ((event_mask & FS_EVENT_ON_CHILD) && |
| 131 | !(inode_mark->mask & FS_EVENT_ON_CHILD)) |
| 132 | return false; |
| 133 | marks_mask = inode_mark->mask; |
| 134 | marks_ignored_mask = inode_mark->ignored_mask; |
| 135 | } else if (vfsmnt_mark) { |
| 136 | marks_mask = vfsmnt_mark->mask; |
| 137 | marks_ignored_mask = vfsmnt_mark->ignored_mask; |
| 138 | } else { |
| 139 | BUG(); |
| 140 | } |
| 141 | |
David Howells | e36cb0b | 2015-01-29 12:02:35 +0000 | [diff] [blame] | 142 | if (d_is_dir(path->dentry) && |
Lino Sanfilippo | 66ba93c | 2015-02-10 14:08:27 -0800 | [diff] [blame] | 143 | !(marks_mask & FS_ISDIR & ~marks_ignored_mask)) |
Eric Paris | 8fcd652 | 2010-10-28 17:21:59 -0400 | [diff] [blame] | 144 | return false; |
| 145 | |
Suzuki K. Poulose | b3c1030 | 2015-03-12 16:26:08 -0700 | [diff] [blame] | 146 | if (event_mask & FAN_ALL_OUTGOING_EVENTS & marks_mask & |
| 147 | ~marks_ignored_mask) |
Eric Paris | 1968f5e | 2010-07-28 10:18:39 -0400 | [diff] [blame] | 148 | return true; |
| 149 | |
| 150 | return false; |
Eric Paris | 1c52906 | 2009-12-17 21:24:28 -0500 | [diff] [blame] | 151 | } |
| 152 | |
Jan Kara | f083441 | 2014-04-03 14:46:33 -0700 | [diff] [blame] | 153 | struct fanotify_event_info *fanotify_alloc_event(struct inode *inode, u32 mask, |
| 154 | struct path *path) |
| 155 | { |
| 156 | struct fanotify_event_info *event; |
| 157 | |
| 158 | #ifdef CONFIG_FANOTIFY_ACCESS_PERMISSIONS |
| 159 | if (mask & FAN_ALL_PERM_EVENTS) { |
| 160 | struct fanotify_perm_event_info *pevent; |
| 161 | |
| 162 | pevent = kmem_cache_alloc(fanotify_perm_event_cachep, |
| 163 | GFP_KERNEL); |
| 164 | if (!pevent) |
| 165 | return NULL; |
| 166 | event = &pevent->fae; |
| 167 | pevent->response = 0; |
| 168 | goto init; |
| 169 | } |
| 170 | #endif |
| 171 | event = kmem_cache_alloc(fanotify_event_cachep, GFP_KERNEL); |
| 172 | if (!event) |
| 173 | return NULL; |
| 174 | init: __maybe_unused |
| 175 | fsnotify_init_event(&event->fse, inode, mask); |
| 176 | event->tgid = get_pid(task_tgid(current)); |
| 177 | if (path) { |
| 178 | event->path = *path; |
| 179 | path_get(&event->path); |
| 180 | } else { |
| 181 | event->path.mnt = NULL; |
| 182 | event->path.dentry = NULL; |
| 183 | } |
| 184 | return event; |
| 185 | } |
| 186 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 187 | static int fanotify_handle_event(struct fsnotify_group *group, |
| 188 | struct inode *inode, |
| 189 | struct fsnotify_mark *inode_mark, |
| 190 | struct fsnotify_mark *fanotify_mark, |
| 191 | u32 mask, void *data, int data_type, |
Jan Kara | 45a22f4 | 2014-02-17 13:09:50 +0100 | [diff] [blame] | 192 | const unsigned char *file_name, u32 cookie) |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 193 | { |
| 194 | int ret = 0; |
| 195 | struct fanotify_event_info *event; |
| 196 | struct fsnotify_event *fsn_event; |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 197 | |
| 198 | BUILD_BUG_ON(FAN_ACCESS != FS_ACCESS); |
| 199 | BUILD_BUG_ON(FAN_MODIFY != FS_MODIFY); |
| 200 | BUILD_BUG_ON(FAN_CLOSE_NOWRITE != FS_CLOSE_NOWRITE); |
| 201 | BUILD_BUG_ON(FAN_CLOSE_WRITE != FS_CLOSE_WRITE); |
| 202 | BUILD_BUG_ON(FAN_OPEN != FS_OPEN); |
| 203 | BUILD_BUG_ON(FAN_EVENT_ON_CHILD != FS_EVENT_ON_CHILD); |
| 204 | BUILD_BUG_ON(FAN_Q_OVERFLOW != FS_Q_OVERFLOW); |
| 205 | BUILD_BUG_ON(FAN_OPEN_PERM != FS_OPEN_PERM); |
| 206 | BUILD_BUG_ON(FAN_ACCESS_PERM != FS_ACCESS_PERM); |
| 207 | BUILD_BUG_ON(FAN_ONDIR != FS_ISDIR); |
| 208 | |
Jan Kara | 83c4c4b | 2014-01-21 15:48:15 -0800 | [diff] [blame] | 209 | if (!fanotify_should_send_event(inode_mark, fanotify_mark, mask, data, |
| 210 | data_type)) |
| 211 | return 0; |
| 212 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 213 | pr_debug("%s: group=%p inode=%p mask=%x\n", __func__, group, inode, |
| 214 | mask); |
| 215 | |
Jan Kara | f083441 | 2014-04-03 14:46:33 -0700 | [diff] [blame] | 216 | event = fanotify_alloc_event(inode, mask, data); |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 217 | if (unlikely(!event)) |
| 218 | return -ENOMEM; |
| 219 | |
| 220 | fsn_event = &event->fse; |
Jan Kara | 8ba8fa91 | 2014-08-06 16:03:26 -0700 | [diff] [blame] | 221 | ret = fsnotify_add_event(group, fsn_event, fanotify_merge); |
Jan Kara | 83c0e1b | 2014-01-28 18:53:22 +0100 | [diff] [blame] | 222 | if (ret) { |
Jan Kara | 482ef06 | 2014-02-21 19:07:54 +0100 | [diff] [blame] | 223 | /* Permission events shouldn't be merged */ |
| 224 | BUG_ON(ret == 1 && mask & FAN_ALL_PERM_EVENTS); |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 225 | /* Our event wasn't used in the end. Free it. */ |
| 226 | fsnotify_destroy_event(group, fsn_event); |
Jan Kara | 482ef06 | 2014-02-21 19:07:54 +0100 | [diff] [blame] | 227 | |
| 228 | return 0; |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 229 | } |
| 230 | |
| 231 | #ifdef CONFIG_FANOTIFY_ACCESS_PERMISSIONS |
Jan Kara | 8581679 | 2014-01-28 21:38:06 +0100 | [diff] [blame] | 232 | if (mask & FAN_ALL_PERM_EVENTS) { |
Jan Kara | f083441 | 2014-04-03 14:46:33 -0700 | [diff] [blame] | 233 | ret = fanotify_get_response(group, FANOTIFY_PE(fsn_event)); |
Jan Kara | 8581679 | 2014-01-28 21:38:06 +0100 | [diff] [blame] | 234 | fsnotify_destroy_event(group, fsn_event); |
| 235 | } |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 236 | #endif |
| 237 | return ret; |
| 238 | } |
| 239 | |
Eric Paris | 4afeff8 | 2010-10-28 17:21:58 -0400 | [diff] [blame] | 240 | static void fanotify_free_group_priv(struct fsnotify_group *group) |
| 241 | { |
| 242 | struct user_struct *user; |
| 243 | |
| 244 | user = group->fanotify_data.user; |
| 245 | atomic_dec(&user->fanotify_listeners); |
| 246 | free_uid(user); |
| 247 | } |
| 248 | |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 249 | static void fanotify_free_event(struct fsnotify_event *fsn_event) |
| 250 | { |
| 251 | struct fanotify_event_info *event; |
| 252 | |
| 253 | event = FANOTIFY_E(fsn_event); |
| 254 | path_put(&event->path); |
| 255 | put_pid(event->tgid); |
Jan Kara | f083441 | 2014-04-03 14:46:33 -0700 | [diff] [blame] | 256 | #ifdef CONFIG_FANOTIFY_ACCESS_PERMISSIONS |
| 257 | if (fsn_event->mask & FAN_ALL_PERM_EVENTS) { |
| 258 | kmem_cache_free(fanotify_perm_event_cachep, |
| 259 | FANOTIFY_PE(fsn_event)); |
| 260 | return; |
| 261 | } |
| 262 | #endif |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 263 | kmem_cache_free(fanotify_event_cachep, event); |
| 264 | } |
| 265 | |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 266 | const struct fsnotify_ops fanotify_fsnotify_ops = { |
| 267 | .handle_event = fanotify_handle_event, |
Eric Paris | 4afeff8 | 2010-10-28 17:21:58 -0400 | [diff] [blame] | 268 | .free_group_priv = fanotify_free_group_priv, |
Jan Kara | 7053aee | 2014-01-21 15:48:14 -0800 | [diff] [blame] | 269 | .free_event = fanotify_free_event, |
Eric Paris | ff0b16a | 2009-12-17 21:24:25 -0500 | [diff] [blame] | 270 | }; |