Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1305495
| From | Peter Hurley <peter@hurleysoftware.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH v2 04/15] tty: audit: Defer audit buffer association |
| Date | 2016-01-10 08:10 +0100 |
| Message-ID | <qPiiu-XG-1@gated-at.bofh.it> (permalink) |
| References | <qPgql-84a-1@gated-at.bofh.it> <qPi8O-Fk-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
The tty audit buffer used to audit/record tty input is allocated on
the process's first call to tty_audit_add_data(), and not freed until
the process exits. On each call to tty_audit_add_data(), the current
tty is compared (by major:minor) with the last tty associated with
the audit buffer, and if the tty has changed the existing data is
logged to the audit log. The audit buffer is then re-associated with
the new tty.
Currently, the audit buffer is immediately associated with the tty;
however, the association must be re-checked when the buffer is locked
prior to copying the tty input. This extra step is always necessary,
since a concurrent read of a different tty by another thread of the
process may have used the buffer in between allocation and buffer
lock.
Rather than associate the audit buffer with the tty at allocation,
leave the buffer initially un-associated (null dev_t); simply let the
re-association check also perform the initial association.
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
---
drivers/tty/tty_audit.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/tty/tty_audit.c b/drivers/tty/tty_audit.c
index d2a004a..9effa81 100644
--- a/drivers/tty/tty_audit.c
+++ b/drivers/tty/tty_audit.c
@@ -22,7 +22,7 @@ struct tty_audit_buf {
unsigned char *data; /* Allocated size N_TTY_BUF_SIZE */
};
-static struct tty_audit_buf *tty_audit_buf_alloc(struct tty_struct *tty)
+static struct tty_audit_buf *tty_audit_buf_alloc(void)
{
struct tty_audit_buf *buf;
@@ -34,9 +34,9 @@ static struct tty_audit_buf *tty_audit_buf_alloc(struct tty_struct *tty)
goto err_buf;
atomic_set(&buf->count, 1);
mutex_init(&buf->mutex);
- buf->major = tty->driver->major;
- buf->minor = tty->driver->minor_start + tty->index;
- buf->icanon = !!L_ICANON(tty);
+ buf->major = 0;
+ buf->minor = 0;
+ buf->icanon = 0;
buf->valid = 0;
return buf;
@@ -211,11 +211,11 @@ int tty_audit_push_current(void)
/**
* tty_audit_buf_get - Get an audit buffer.
*
- * Get an audit buffer for @tty, allocate it if necessary. Return %NULL
+ * Get an audit buffer, allocate it if necessary. Return %NULL
* if TTY auditing is disabled or out of memory. Otherwise, return a new
* reference to the buffer.
*/
-static struct tty_audit_buf *tty_audit_buf_get(struct tty_struct *tty)
+static struct tty_audit_buf *tty_audit_buf_get(void)
{
struct tty_audit_buf *buf, *buf2;
unsigned long flags;
@@ -232,7 +232,7 @@ static struct tty_audit_buf *tty_audit_buf_get(struct tty_struct *tty)
}
spin_unlock_irqrestore(¤t->sighand->siglock, flags);
- buf2 = tty_audit_buf_alloc(tty);
+ buf2 = tty_audit_buf_alloc();
if (buf2 == NULL) {
audit_log_lost("out of memory in TTY auditing");
return NULL;
@@ -282,7 +282,7 @@ void tty_audit_add_data(struct tty_struct *tty, const void *data, size_t size)
if (!audit_log_tty_passwd && icanon && !L_ECHO(tty))
return;
- buf = tty_audit_buf_get(tty);
+ buf = tty_audit_buf_get();
if (!buf)
return;
--
2.7.0
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[RESEND][PATCH 00/15] Rework tty audit Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 02/15] tty: audit: Never audit packet mode Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 04/15] tty: audit: Defer audit buffer association Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
Re: [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push kbuild test robot <lkp@intel.com> - 2016-01-10 06:40 +0100
Re: [RESEND][PATCH 06/15] tty: audit: Ignore current association for audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
[RESEND][PATCH 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 05/15] tty: audit: Take siglock directly Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 13/15] tty: audit: Check audit enable first Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 12/15] tty: audit: Simplify first-use allocation Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 08/15] tty: audit: Track tty association with dev_t Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 07/15] tty: audit: Combine push functions Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[RESEND][PATCH 10/15] tty: audit: Remove false memory optimization Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 06:10 +0100
[PATCH v2 12/15] tty: audit: Simplify first-use allocation Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 11/15] tty: audit: Remove tty_audit_buf reference counting Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 00/15] Rework tty audit Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 02/15] tty: audit: Never audit packet mode Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 15/15] tty: audit: Poison tty_audit_buf while process exits Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 10/15] tty: audit: Remove false memory optimization Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 09/15] tty: audit: Handle tty audit enable atomically Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 14/15] tty: audit: Always push audit buffer before TIOCSTI Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 13/15] tty: audit: Check audit enable first Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 01/15] tty: audit: Early-out pty master reads earlier Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 08/15] tty: audit: Track tty association with dev_t Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:00 +0100
[PATCH v2 04/15] tty: audit: Defer audit buffer association Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
[PATCH v2 03/15] tty: audit: Remove icanon mode from call chain Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
[PATCH v2 05/15] tty: audit: Take siglock directly Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
[PATCH v2 07/15] tty: audit: Combine push functions Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
[PATCH v2 06/15] tty: audit: Ignore current association for audit push Peter Hurley <peter@hurleysoftware.com> - 2016-01-10 08:10 +0100
csiph-web