Unverified Commit 924f4403 authored by Mickaël Salaün's avatar Mickaël Salaün
Browse files

landlock: Factor out check_access_path()

Merge check_access_path() into current_check_access_path() and make
hook_path_mknod() use it.

Cc: Günther Noack <gnoack@google.com>
Link: https://lore.kernel.org/r/20250108154338.1129069-4-mic@digikod.net


Signed-off-by: default avatarMickaël Salaün <mic@digikod.net>
parent 0e4db4f8
Loading
Loading
Loading
Loading
+11 −21
Original line number Diff line number Diff line
@@ -908,28 +908,22 @@ static bool is_access_to_paths_allowed(
	return allowed_parent1 && allowed_parent2;
}

static int check_access_path(const struct landlock_ruleset *const domain,
			     const struct path *const path,
static int current_check_access_path(const struct path *const path,
				     access_mask_t access_request)
{
	const struct landlock_ruleset *const dom = get_current_fs_domain();
	layer_mask_t layer_masks[LANDLOCK_NUM_ACCESS_FS] = {};

	access_request = landlock_init_layer_masks(
		domain, access_request, &layer_masks, LANDLOCK_KEY_INODE);
	if (is_access_to_paths_allowed(domain, path, access_request,
				       &layer_masks, NULL, 0, NULL, NULL))
	if (!dom)
		return 0;
	return -EACCES;
}

static int current_check_access_path(const struct path *const path,
				     const access_mask_t access_request)
{
	const struct landlock_ruleset *const dom = get_current_fs_domain();

	if (!dom)
	access_request = landlock_init_layer_masks(
		dom, access_request, &layer_masks, LANDLOCK_KEY_INODE);
	if (is_access_to_paths_allowed(dom, path, access_request, &layer_masks,
				       NULL, 0, NULL, NULL))
		return 0;
	return check_access_path(dom, path, access_request);

	return -EACCES;
}

static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
@@ -1413,11 +1407,7 @@ static int hook_path_mknod(const struct path *const dir,
			   struct dentry *const dentry, const umode_t mode,
			   const unsigned int dev)
{
	const struct landlock_ruleset *const dom = get_current_fs_domain();

	if (!dom)
		return 0;
	return check_access_path(dom, dir, get_mode_access(mode));
	return current_check_access_path(dir, get_mode_access(mode));
}

static int hook_path_symlink(const struct path *const dir,