Files
linux/Documentation
Mimi Zohar 47873220e7 ima: audit log files opened with O_DIRECT flag
commit f9b2a735bd upstream.

Files are measured or appraised based on the IMA policy.  When a
file, in policy, is opened with the O_DIRECT flag, a deadlock
occurs.

The first attempt at resolving this lockdep temporarily removed the
O_DIRECT flag and restored it, after calculating the hash.  The
second attempt introduced the O_DIRECT_HAVELOCK flag. Based on this
flag, do_blockdev_direct_IO() would skip taking the i_mutex a second
time.  The third attempt, by Dmitry Kasatkin, resolves the i_mutex
locking issue, by re-introducing the IMA mutex, but uncovered
another problem.  Reading a file with O_DIRECT flag set, writes
directly to userspace pages.  A second patch allocates a user-space
like memory.  This works for all IMA hooks, except ima_file_free(),
which is called on __fput() to recalculate the file hash.

Until this last issue is addressed, do not 'collect' the
measurement for measuring, appraising, or auditing files opened
with the O_DIRECT flag set.  Based on policy, permit or deny file
access.  This patch defines a new IMA policy rule option named
'permit_directio'.  Policy rules could be defined, based on LSM
or other criteria, to permit specific applications to open files
with the O_DIRECT flag set.

Changelog v1:
- permit or deny file access based IMA policy rules

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Acked-by: Dmitry Kasatkin <d.kasatkin@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2014-06-26 15:17:33 -04:00
..
2014-04-07 16:36:02 -07:00
2011-09-27 18:08:04 +02:00
2012-04-03 13:09:18 +02:00
2014-03-11 06:55:49 -03:00
2014-02-10 16:01:40 -08:00
2014-02-28 15:12:08 -08:00
2011-09-27 18:08:04 +02:00
2013-04-02 09:39:55 -07:00
2014-02-10 16:01:40 -08:00
2013-11-27 11:03:38 -08:00
2011-03-31 11:26:23 -03:00
2013-01-10 01:27:46 +01:00
2014-03-21 13:16:58 +01:00
2013-10-16 13:35:02 -07:00
2014-03-21 13:16:58 +01:00
2014-02-18 08:09:40 -08:00
2010-04-08 11:34:34 +02:00
2011-03-31 11:26:23 -03:00
2013-11-14 11:04:40 -08:00
2014-02-07 08:03:07 -02:00
2014-03-21 13:16:58 +01:00
2013-12-02 14:48:28 +01:00
2013-12-02 14:48:28 +01:00
2011-09-27 18:08:04 +02:00
2014-03-21 13:16:58 +01:00
2013-12-02 14:45:19 +01:00
2012-02-28 16:05:06 +01:00
2013-10-24 10:51:33 +02:00
2011-03-31 11:26:23 -03:00
2013-09-05 16:36:21 -06:00
2012-01-02 13:04:55 +01:00