Skip to content

Commit

Permalink
ima: Don't modify file descriptor mode on the fly
Browse files Browse the repository at this point in the history
Commit a408e4a ("ima: open a new file instance if no read
permissions") already introduced a second open to measure a file when the
original file descriptor does not allow it. However, it didn't remove the
existing method of changing the mode of the original file descriptor, which
is still necessary if the current process does not have enough privileges
to open a new one.

Changing the mode isn't really an option, as the filesystem might need to
do preliminary steps to make the read possible. Thus, this patch removes
the code and keeps the second open as the only option to measure a file
when it is unreadable with the original file descriptor.

Cc: <[email protected]> # 4.20.x: 0014cc0 ima: Set file->f_mode
Fixes: 2fe5d6d ("ima: integrity appraisal extension")
Signed-off-by: Roberto Sassu <[email protected]>
Reviewed-by: Christoph Hellwig <[email protected]>
Signed-off-by: Mimi Zohar <[email protected]>
  • Loading branch information
robertosassu authored and mimizohar committed Nov 29, 2020
1 parent dea87d0 commit 207cdd5
Showing 1 changed file with 5 additions and 15 deletions.
20 changes: 5 additions & 15 deletions security/integrity/ima/ima_crypto.c
Original file line number Diff line number Diff line change
Expand Up @@ -537,7 +537,7 @@ int ima_calc_file_hash(struct file *file, struct ima_digest_data *hash)
loff_t i_size;
int rc;
struct file *f = file;
bool new_file_instance = false, modified_mode = false;
bool new_file_instance = false;

/*
* For consistency, fail file's opened with the O_DIRECT flag on
Expand All @@ -555,18 +555,10 @@ int ima_calc_file_hash(struct file *file, struct ima_digest_data *hash)
O_TRUNC | O_CREAT | O_NOCTTY | O_EXCL);
flags |= O_RDONLY;
f = dentry_open(&file->f_path, flags, file->f_cred);
if (IS_ERR(f)) {
/*
* Cannot open the file again, lets modify f_mode
* of original and continue
*/
pr_info_ratelimited("Unable to reopen file for reading.\n");
f = file;
f->f_mode |= FMODE_READ;
modified_mode = true;
} else {
new_file_instance = true;
}
if (IS_ERR(f))
return PTR_ERR(f);

new_file_instance = true;
}

i_size = i_size_read(file_inode(f));
Expand All @@ -581,8 +573,6 @@ int ima_calc_file_hash(struct file *file, struct ima_digest_data *hash)
out:
if (new_file_instance)
fput(f);
else if (modified_mode)
f->f_mode &= ~FMODE_READ;
return rc;
}

Expand Down

0 comments on commit 207cdd5

Please sign in to comment.