Commit 4e2f0b48 authored by Kay Sievers's avatar Kay Sievers Committed by Greg Kroah-Hartman

Driver-Core: devtmpfs - reset inode permissions before unlinking

commit 5e31d76f upstream.

Before unlinking the inode, reset the current permissions of possible
references like hardlinks, so granted permissions can not be retained
across the device lifetime by creating hardlinks, in the unusual case
that there is a user-writable directory on the same filesystem.
Signed-off-by: default avatarKay Sievers <kay.sievers@vrfy.org>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@suse.de>
parent 3048a0db
...@@ -295,6 +295,19 @@ int devtmpfs_delete_node(struct device *dev) ...@@ -295,6 +295,19 @@ int devtmpfs_delete_node(struct device *dev)
if (dentry->d_inode) { if (dentry->d_inode) {
err = vfs_getattr(nd.path.mnt, dentry, &stat); err = vfs_getattr(nd.path.mnt, dentry, &stat);
if (!err && dev_mynode(dev, dentry->d_inode, &stat)) { if (!err && dev_mynode(dev, dentry->d_inode, &stat)) {
struct iattr newattrs;
/*
* before unlinking this node, reset permissions
* of possible references like hardlinks
*/
newattrs.ia_uid = 0;
newattrs.ia_gid = 0;
newattrs.ia_mode = stat.mode & ~0777;
newattrs.ia_valid =
ATTR_UID|ATTR_GID|ATTR_MODE;
mutex_lock(&dentry->d_inode->i_mutex);
notify_change(dentry, &newattrs);
mutex_unlock(&dentry->d_inode->i_mutex);
err = vfs_unlink(nd.path.dentry->d_inode, err = vfs_unlink(nd.path.dentry->d_inode,
dentry); dentry);
if (!err || err == -ENOENT) if (!err || err == -ENOENT)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment