Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1305440

[RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push

From Peter Hurley <peter@hurleysoftware.com>
Newsgroups linux.kernel
Subject [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push
Date 2016-01-10 06:10 +0100
Message-ID <qPgqm-84a-17@gated-at.bofh.it> (permalink)
References <qPgql-84a-3@gated-at.bofh.it> <qPgql-84a-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


In canonical read mode, each line read and logged is pushed separately
with tty_audit_push(). For all single-threaded processes and multi-threaded
processes reading from only one tty, this patch has no effect; the last line
read will still be the entry pushed to the audit log because the tty
association cannot have changed between tty_audit_add_data() and
tty_audit_push().

For multi-threaded processes reading from different ttys concurrently,
the audit log will have mixed log entries anyway. Consider two ttys
audited concurrently:

CPU0                           CPU1
----------                     ------------
tty_audit_add_data(ttyA)
                               tty_audit_add_data(ttyB)
tty_audit_push()
                               tty_audit_add_data(ttyB)
                               tty_audit_push()

This patch will now cause the ttyB output to be split into separate
audit log entries.

However, this possibility is equally likely without this patch:

CPU0                           CPU1
----------                     ------------
                               tty_audit_add_data(ttyB)
tty_audit_add_data(ttyA)
tty_audit_push()
                               tty_audit_add_data(ttyB)
                               tty_audit_push()

Mixed canonical and non-canonical reads have similar races.

Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
---
 drivers/tty/n_tty.c     |  2 +-
 drivers/tty/tty_audit.c | 11 +++--------
 include/linux/tty.h     |  2 +-
 3 files changed, 5 insertions(+), 10 deletions(-)

diff --git a/drivers/tty/n_tty.c b/drivers/tty/n_tty.c
index 5d060fc..6bab08a 100644
--- a/drivers/tty/n_tty.c
+++ b/drivers/tty/n_tty.c
@@ -2078,7 +2078,7 @@ static int canon_copy_from_read_buf(struct tty_struct *tty,
 			ldata->line_start = ldata->read_tail;
 		else
 			ldata->push = 0;
-		tty_audit_push(tty);
+		tty_audit_push();
 	}
 	return 0;
 }
diff --git a/drivers/tty/tty_audit.c b/drivers/tty/tty_audit.c
index 5f65653..5ae4839 100644
--- a/drivers/tty/tty_audit.c
+++ b/drivers/tty/tty_audit.c
@@ -313,9 +313,9 @@ void tty_audit_add_data(struct tty_struct *tty, const void *data, size_t size)
 /**
  *	tty_audit_push	-	Push buffered data out
  *
- *	Make sure no audit data is pending for @tty on the current process.
+ *	Make sure no audit data is pending on the current process.
  */
-void tty_audit_push(struct tty_struct *tty)
+void tty_audit_push(void)
 {
 	struct tty_audit_buf *buf;
 	unsigned long flags;
@@ -331,13 +331,8 @@ void tty_audit_push(struct tty_struct *tty)
 	spin_unlock_irqrestore(&current->sighand->siglock, flags);
 
 	if (buf) {
-		int major, minor;
-
-		major = tty->driver->major;
-		minor = tty->driver->minor_start + tty->index;
 		mutex_lock(&buf->mutex);
-		if (buf->major == major && buf->minor == minor)
-			tty_audit_buf_push(buf);
+		tty_audit_buf_push(buf);
 		mutex_unlock(&buf->mutex);
 		tty_audit_buf_put(buf);
 	}
diff --git a/include/linux/tty.h b/include/linux/tty.h
index c1d1f08..21e3722 100644
--- a/include/linux/tty.h
+++ b/include/linux/tty.h
@@ -608,7 +608,7 @@ extern void tty_audit_add_data(struct tty_struct *tty, const void *data,
 extern void tty_audit_exit(void);
 extern void tty_audit_fork(struct signal_struct *sig);
 extern void tty_audit_tiocsti(struct tty_struct *tty, char ch);
-extern void tty_audit_push(struct tty_struct *tty);
+extern void tty_audit_push(void);
 extern int tty_audit_push_current(void);
 #else
 static inline void tty_audit_add_data(struct tty_struct *tty, const void *data,
-- 
2.7.0

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[RESEND][PATCH 00/15] Rework tty audit Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 02/15] tty: audit: Never audit packet mode Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 04/15] tty: audit: Defer audit buffer association Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
    Re: [RESEND][PATCH 06/15] tty: audit: Ignore current association for  audit push kbuild test robot <lkp@intel.com> - 2016-01-10 06:40 +0100
      Re: [RESEND][PATCH 06/15] tty: audit: Ignore current association for  audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
  [RESEND][PATCH 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 05/15] tty: audit: Take siglock directly Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 13/15] tty: audit: Check audit enable first Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 12/15] tty: audit: Simplify first-use allocation Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 08/15] tty: audit: Track tty association with dev_t Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 07/15] tty: audit: Combine push functions Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [RESEND][PATCH 10/15] tty: audit: Remove false memory optimization Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
  [PATCH v2 12/15] tty: audit: Simplify first-use allocation Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
  [PATCH v2 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
  [PATCH v2 00/15] Rework tty audit Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 02/15] tty: audit: Never audit packet mode Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 10/15] tty: audit: Remove false memory optimization Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 13/15] tty: audit: Check audit enable first Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 08/15] tty: audit: Track tty association with dev_t Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
    [PATCH v2 04/15] tty: audit: Defer audit buffer association Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
    [PATCH v2 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
    [PATCH v2 05/15] tty: audit: Take siglock directly Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
    [PATCH v2 07/15] tty: audit: Combine push functions Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
    [PATCH v2 06/15] tty: audit: Ignore current association for audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100

csiph-web