Commit 2f02fd3f authored by Amir Goldstein's avatar Amir Goldstein Committed by Jan Kara

fanotify: fix ignore mask logic for events on child and on dir

The comments in fanotify_group_event_mask() say:

  "If the event is on dir/child and this mark doesn't care about
   events on dir/child, don't send it!"

Specifically, mount and filesystem marks do not care about events
on child, but they can still specify an ignore mask for those events.
For example, a group that has:
- A mount mark with mask 0 and ignore_mask FAN_OPEN
- An inode mark on a directory with mask FAN_OPEN | FAN_OPEN_EXEC
  with flag FAN_EVENT_ON_CHILD

A child file open for exec would be reported to group with the FAN_OPEN
event despite the fact that FAN_OPEN is in ignore mask of mount mark,
because the mark iteration loop skips over non-inode marks for events
on child when calculating the ignore mask.

Move ignore mask calculation to the top of the iteration loop block
before excluding marks for events on dir/child.

Link: https://lore.kernel.org/r/20200524072441.18258-1-amir73il@gmail.comReported-by: default avatarJan Kara <jack@suse.cz>
Link: https://lore.kernel.org/linux-fsdevel/20200521162443.GA26052@quack2.suse.cz/
Fixes: 55bf882c "fanotify: fix merging marks masks with FAN_ONDIR"
Fixes: b469e7e4 "fanotify: fix handling of events on child..."
Signed-off-by: default avatarAmir Goldstein <amir73il@gmail.com>
Signed-off-by: default avatarJan Kara <jack@suse.cz>
parent 5e23663b
...@@ -232,6 +232,10 @@ static u32 fanotify_group_event_mask(struct fsnotify_group *group, ...@@ -232,6 +232,10 @@ static u32 fanotify_group_event_mask(struct fsnotify_group *group,
if (!fsnotify_iter_should_report_type(iter_info, type)) if (!fsnotify_iter_should_report_type(iter_info, type))
continue; continue;
mark = iter_info->marks[type]; mark = iter_info->marks[type];
/* Apply ignore mask regardless of ISDIR and ON_CHILD flags */
marks_ignored_mask |= mark->ignored_mask;
/* /*
* If the event is on dir and this mark doesn't care about * If the event is on dir and this mark doesn't care about
* events on dir, don't send it! * events on dir, don't send it!
...@@ -249,7 +253,6 @@ static u32 fanotify_group_event_mask(struct fsnotify_group *group, ...@@ -249,7 +253,6 @@ static u32 fanotify_group_event_mask(struct fsnotify_group *group,
continue; continue;
marks_mask |= mark->mask; marks_mask |= mark->mask;
marks_ignored_mask |= mark->ignored_mask;
} }
test_mask = event_mask & marks_mask & ~marks_ignored_mask; test_mask = event_mask & marks_mask & ~marks_ignored_mask;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment