+14
−0
Loading
For file-backed mounts, metadata is fetched via the page cache of backing inodes to avoid double caching and redundant copy ops out of RO uptodate folios, which is used by Android APEXes, ComposeFS, containerd. However, rw_verify_area() was missing prior to metadata accesses. Similar to vfs_iocb_iter_read(), fix this by: - Enabling fanotify pre-content hooks on metadata accesses; - security_file_permission() for security modules. Verified that fanotify pre-content hooks now works correctly. Fixes: fb176750 ("erofs: add file-backed mount support") Acked-by:Amir Goldstein <amir73il@gmail.com> Reviewed-by:
Chunhai Guo <guochunhai@vivo.com> Signed-off-by:
Gao Xiang <hsiangkao@linux.alibaba.com>