Re: [PATCH 1/5] fs: Verify access of user towards block device file when mounting
From: Mike Snitzer <hidden>
Date: 2015-09-30 23:42:18
Also in:
dm-devel, linux-bcache, linux-fsdevel, lkml, selinux
On Wed, Sep 30 2015 at 4:15pm -0400, Seth Forshee [off-list ref] wrote:
quoted hunk ↗ jump to hunk
When mounting a filesystem on a block device there is currently no verification that the user has appropriate access to the device file passed to mount. This has not been an issue so far since the user in question has always been root, but this must be changed before allowing unprivileged users to mount in user namespaces. To fix this, add an argument to lookup_bdev() to specify the required permissions. If the mask of permissions is zero, or if the user has CAP_SYS_ADMIN, the permission check is skipped, otherwise the lookup fails if the user does not have the specified access rights for the inode at the supplied path. Callers associated with mounting are updated to pass permission masks to lookup_bdev() so that these mounts will fail for an unprivileged user who lacks permissions for the block device inode. All other callers pass 0 to maintain their current behaviors. Signed-off-by: Seth Forshee <redacted> --- drivers/md/bcache/super.c | 2 +- drivers/md/dm-table.c | 2 +- drivers/mtd/mtdsuper.c | 6 +++++- fs/block_dev.c | 18 +++++++++++++++--- fs/quota/quota.c | 2 +- include/linux/fs.h | 2 +- 6 files changed, 24 insertions(+), 8 deletions(-)diff --git a/drivers/md/dm-table.c b/drivers/md/dm-table.c index e76ed003769e..35bb3ea4cbe2 100644 --- a/drivers/md/dm-table.c +++ b/drivers/md/dm-table.c@@ -380,7 +380,7 @@ int dm_get_device(struct dm_target *ti, const char *path, fmode_t mode, BUG_ON(!t); /* convert the path to a device */ - bdev = lookup_bdev(path); + bdev = lookup_bdev(path, 0); if (IS_ERR(bdev)) { dev = name_to_dev_t(path); if (!dev)
Given dm_get_device() is passed @mode why not have it do something like you did in blkdev_get_by_path()? e.g.:
quoted hunk ↗ jump to hunk
diff --git a/fs/block_dev.c b/fs/block_dev.c index 26cee058dc02..54d94cd64577 100644 --- a/fs/block_dev.c +++ b/fs/block_dev.c@@ -1394,9 +1394,14 @@ struct block_device *blkdev_get_by_path(const char *path, fmode_t mode, void *holder) { struct block_device *bdev; + int perm = 0; int err; - bdev = lookup_bdev(path); + if (mode & FMODE_READ) + perm |= MAY_READ; + if (mode & FMODE_WRITE) + perm |= MAY_WRITE; + bdev = lookup_bdev(path, perm); if (IS_ERR(bdev)) return bdev;