Lines Matching +full:flags +full:- +full:mask
1 // SPDX-License-Identifier: GPL-2.0
99 * All flags that may be specified in parameter event_f_flags of fanotify_init.
101 * Internal and external open flags are stored together in field f_flags of
102 * struct file. Only external open flags shall be allowed in event_f_flags.
103 * Internal flags like FMODE_EXEC shall be excluded.
148 info->name_len); in fanotify_dir_name_info_len()
151 info->name2_len); in fanotify_dir_name_info_len()
163 if (fanotify_is_error_event(event->mask)) in fanotify_event_len()
169 (event->mask & FAN_ONDIR)) { in fanotify_event_len()
197 assert_spin_locked(&group->notification_lock); in fanotify_unhash_event()
202 if (WARN_ON_ONCE(hlist_unhashed(&event->merge_list))) in fanotify_unhash_event()
205 hlist_del_init(&event->merge_list); in fanotify_unhash_event()
224 spin_lock(&group->notification_lock); in get_one_event()
233 event = ERR_PTR(-EINVAL); in get_one_event()
242 if (fanotify_is_perm_event(event->mask)) in get_one_event()
243 FANOTIFY_PERM(event)->state = FAN_EVENT_REPORTED; in get_one_event()
244 if (fanotify_is_hashed_event(event->mask)) in get_one_event()
247 spin_unlock(&group->notification_lock); in get_one_event()
257 client_fd = get_unused_fd_flags(group->fanotify_data.f_flags); in create_fd()
265 new_file = dentry_open_nonotify(path, group->fanotify_data.f_flags, in create_fd()
282 return -EINVAL; in process_access_response_info()
285 return -EFAULT; in process_access_response_info()
287 if (friar->hdr.type != FAN_RESPONSE_INFO_AUDIT_RULE) in process_access_response_info()
288 return -EINVAL; in process_access_response_info()
289 if (friar->hdr.pad != 0) in process_access_response_info()
290 return -EINVAL; in process_access_response_info()
291 if (friar->hdr.len != sizeof(*friar)) in process_access_response_info()
292 return -EINVAL; in process_access_response_info()
299 * drop group->notification_lock.
304 __releases(&group->notification_lock) in finish_permission_event()
308 assert_spin_locked(&group->notification_lock); in finish_permission_event()
309 event->response = response & ~FAN_INFO; in finish_permission_event()
311 memcpy(&event->audit_rule, friar, sizeof(*friar)); in finish_permission_event()
313 if (event->state == FAN_EVENT_CANCELED) in finish_permission_event()
316 event->state = FAN_EVENT_ANSWERED; in finish_permission_event()
317 spin_unlock(&group->notification_lock); in finish_permission_event()
319 fsnotify_destroy_event(group, &event->fae.fse); in finish_permission_event()
328 int fd = response_struct->fd; in process_access_response()
329 u32 response = response_struct->response; in process_access_response()
342 return -EINVAL; in process_access_response()
347 return -EINVAL; in process_access_response()
350 /* Custom errno is supported only for pre-content groups */ in process_access_response()
351 if (errno && group->priority != FSNOTIFY_PRIO_PRE_CONTENT) in process_access_response()
352 return -EINVAL; in process_access_response()
369 return -EINVAL; in process_access_response()
373 return -EINVAL; in process_access_response()
377 return -EINVAL; in process_access_response()
390 return -EINVAL; in process_access_response()
392 spin_lock(&group->notification_lock); in process_access_response()
393 list_for_each_entry(event, &group->fanotify_data.access_list, in process_access_response()
395 if (event->fd != fd) in process_access_response()
398 list_del_init(&event->fae.fse.list); in process_access_response()
400 wake_up(&group->fanotify_data.access_waitq); in process_access_response()
403 spin_unlock(&group->notification_lock); in process_access_response()
405 return -ENOENT; in process_access_response()
418 return -EFAULT; in copy_error_info_to_user()
420 info.error = fee->error; in copy_error_info_to_user()
421 info.error_count = fee->err_count; in copy_error_info_to_user()
424 return -EFAULT; in copy_error_info_to_user()
437 size_t fh_len = fh ? fh->len : 0; in copy_fid_info_to_user()
445 return -EFAULT; in copy_fid_info_to_user()
455 return -EFAULT; in copy_fid_info_to_user()
461 return -EFAULT; in copy_fid_info_to_user()
464 return -EFAULT; in copy_fid_info_to_user()
471 return -EFAULT; in copy_fid_info_to_user()
474 len -= sizeof(info); in copy_fid_info_to_user()
476 return -EFAULT; in copy_fid_info_to_user()
478 handle.handle_type = fh->type; in copy_fid_info_to_user()
486 return -EFAULT; in copy_fid_info_to_user()
489 len -= sizeof(handle); in copy_fid_info_to_user()
491 return -EFAULT; in copy_fid_info_to_user()
503 return -EFAULT; in copy_fid_info_to_user()
506 len -= fh_len; in copy_fid_info_to_user()
512 return -EFAULT; in copy_fid_info_to_user()
515 return -EFAULT; in copy_fid_info_to_user()
518 len -= name_len; in copy_fid_info_to_user()
524 return -EFAULT; in copy_fid_info_to_user()
537 return -EFAULT; in copy_pidfd_info_to_user()
544 return -EFAULT; in copy_pidfd_info_to_user()
557 return -EFAULT; in copy_range_info_to_user()
559 if (WARN_ON_ONCE(!pevent->ppos)) in copy_range_info_to_user()
560 return -EINVAL; in copy_range_info_to_user()
564 info.offset = *(pevent->ppos); in copy_range_info_to_user()
565 info.count = pevent->count; in copy_range_info_to_user()
568 return -EFAULT; in copy_range_info_to_user()
589 info_type = info->name_len ? FAN_EVENT_INFO_TYPE_DFID_NAME : in copy_info_records_to_user()
593 if (event->mask & FAN_RENAME) in copy_info_records_to_user()
600 info->name_len, buf, count); in copy_info_records_to_user()
605 count -= ret; in copy_info_records_to_user()
616 info->name2_len, buf, count); in copy_info_records_to_user()
621 count -= ret; in copy_info_records_to_user()
636 (event->mask & FAN_ONDIR)) { in copy_info_records_to_user()
645 } else if ((event->mask & ALL_FSNOTIFY_DIRENT_EVENTS) || in copy_info_records_to_user()
646 (event->mask & FAN_ONDIR)) { in copy_info_records_to_user()
655 * With group flags FAN_REPORT_DIR_FID|FAN_REPORT_FID, in copy_info_records_to_user()
657 * non-directory, when there is no directory to report. in copy_info_records_to_user()
671 count -= ret; in copy_info_records_to_user()
681 count -= ret; in copy_info_records_to_user()
685 if (fanotify_is_error_event(event->mask)) { in copy_info_records_to_user()
690 count -= ret; in copy_info_records_to_user()
699 count -= ret; in copy_info_records_to_user()
716 int ret, pidfd = -ESRCH, fd = -EBADF; in copy_event_to_user()
724 metadata.mask = event->mask & FANOTIFY_OUTGOING_EVENTS; in copy_event_to_user()
725 metadata.pid = pid_vnr(event->pid); in copy_event_to_user()
727 * For an unprivileged listener, event->pid can be used to identify the in copy_event_to_user()
732 task_tgid(current) != event->pid) in copy_event_to_user()
742 path && path->mnt && path->dentry) { in copy_event_to_user()
759 path->dentry, fd); in copy_event_to_user()
767 if (fd == -EOPENSTALE) in copy_event_to_user()
783 * creation of pidfds for thread-group leaders. in copy_event_to_user()
788 * The PIDTYPE_TGID check for an event->pid is performed in copy_event_to_user()
792 * report either -ESRCH or FAN_NOPIDFD to the event listener in in copy_event_to_user()
796 if (metadata.pid && pid_has_task(event->pid, PIDTYPE_TGID)) in copy_event_to_user()
797 pidfd = pidfd_prepare(event->pid, 0, &pidfd_file); in copy_event_to_user()
800 pidfd = pidfd == -ESRCH ? FAN_NOPIDFD : FAN_EPIDFD; in copy_event_to_user()
803 ret = -EFAULT; in copy_event_to_user()
815 count -= FAN_EVENT_METADATA_LEN; in copy_event_to_user()
828 if (fanotify_is_perm_event(event->mask)) in copy_event_to_user()
829 FANOTIFY_PERM(event)->fd = fd; in copy_event_to_user()
850 struct fsnotify_group *group = file->private_data; in fanotify_poll()
853 poll_wait(file, &group->notification_waitq, wait); in fanotify_poll()
854 spin_lock(&group->notification_lock); in fanotify_poll()
857 spin_unlock(&group->notification_lock); in fanotify_poll()
872 group = file->private_data; in fanotify_read()
876 add_wait_queue(&group->notification_waitq, &wait); in fanotify_read()
890 ret = -EAGAIN; in fanotify_read()
891 if (file->f_flags & O_NONBLOCK) in fanotify_read()
894 ret = -ERESTARTSYS; in fanotify_read()
911 if (!fanotify_is_perm_event(event->mask)) { in fanotify_read()
912 fsnotify_destroy_event(group, &event->fse); in fanotify_read()
914 if (ret <= 0 || FANOTIFY_PERM(event)->fd < 0) { in fanotify_read()
915 spin_lock(&group->notification_lock); in fanotify_read()
918 wake_up(&group->fanotify_data.access_waitq); in fanotify_read()
920 spin_lock(&group->notification_lock); in fanotify_read()
921 list_add_tail(&event->fse.list, in fanotify_read()
922 &group->fanotify_data.access_list); in fanotify_read()
923 spin_unlock(&group->notification_lock); in fanotify_read()
929 count -= ret; in fanotify_read()
931 remove_wait_queue(&group->notification_waitq, &wait); in fanotify_read()
933 if (start != buf && ret != -EFAULT) in fanotify_read()
934 ret = buf - start; in fanotify_read()
947 return -EINVAL; in fanotify_write()
949 group = file->private_data; in fanotify_write()
954 return -EINVAL; in fanotify_write()
957 return -EFAULT; in fanotify_write()
959 info_len = count - sizeof(response); in fanotify_write()
972 struct fsnotify_group *group = file->private_data; in fanotify_release()
986 spin_lock(&group->notification_lock); in fanotify_release()
987 while (!list_empty(&group->fanotify_data.access_list)) { in fanotify_release()
990 event = list_first_entry(&group->fanotify_data.access_list, in fanotify_release()
992 list_del_init(&event->fae.fse.list); in fanotify_release()
994 spin_lock(&group->notification_lock); in fanotify_release()
998 * Destroy all non-permission events. For permission events just in fanotify_release()
1005 if (!(event->mask & FANOTIFY_PERM_EVENTS)) { in fanotify_release()
1006 spin_unlock(&group->notification_lock); in fanotify_release()
1012 spin_lock(&group->notification_lock); in fanotify_release()
1014 spin_unlock(&group->notification_lock); in fanotify_release()
1017 wake_up(&group->fanotify_data.access_waitq); in fanotify_release()
1019 /* matches the fanotify_init->fsnotify_alloc_group */ in fanotify_release()
1030 int ret = -ENOTTY; in fanotify_ioctl()
1033 group = file->private_data; in fanotify_ioctl()
1039 spin_lock(&group->notification_lock); in fanotify_ioctl()
1040 list_for_each_entry(fsn_event, &group->notification_list, list) in fanotify_ioctl()
1042 spin_unlock(&group->notification_lock); in fanotify_ioctl()
1063 struct path *path, unsigned int flags, __u64 mask, in fanotify_find_path() argument
1068 pr_debug("%s: dfd=%d filename=%p flags=%x\n", __func__, in fanotify_find_path()
1069 dfd, filename, flags); in fanotify_find_path()
1075 return -EBADF; in fanotify_find_path()
1077 if ((flags & FAN_MARK_ONLYDIR) && in fanotify_find_path()
1078 !(S_ISDIR(file_inode(fd_file(f))->i_mode))) in fanotify_find_path()
1079 return -ENOTDIR; in fanotify_find_path()
1081 *path = fd_file(f)->f_path; in fanotify_find_path()
1086 if (!(flags & FAN_MARK_DONT_FOLLOW)) in fanotify_find_path()
1088 if (flags & FAN_MARK_ONLYDIR) in fanotify_find_path()
1103 ret = security_path_notify(path, mask, obj_type); in fanotify_find_path()
1112 __u32 mask, unsigned int flags, in fanotify_mark_remove_from_mask() argument
1118 mask &= ~umask; in fanotify_mark_remove_from_mask()
1119 spin_lock(&fsn_mark->lock); in fanotify_mark_remove_from_mask()
1121 if (!(flags & FANOTIFY_MARK_IGNORE_BITS)) { in fanotify_mark_remove_from_mask()
1122 fsn_mark->mask &= ~mask; in fanotify_mark_remove_from_mask()
1124 fsn_mark->ignore_mask &= ~mask; in fanotify_mark_remove_from_mask()
1128 * We need to keep the mark around even if remaining mask cannot in fanotify_mark_remove_from_mask()
1129 * result in any events (e.g. mask == FAN_ONDIR) to support incremenal in fanotify_mark_remove_from_mask()
1130 * changes to the mask. in fanotify_mark_remove_from_mask()
1133 *destroy = !((fsn_mark->mask | fsn_mark->ignore_mask) & ~umask); in fanotify_mark_remove_from_mask()
1134 spin_unlock(&fsn_mark->lock); in fanotify_mark_remove_from_mask()
1140 void *obj, unsigned int obj_type, __u32 mask, in fanotify_remove_mark() argument
1141 unsigned int flags, __u32 umask) in fanotify_remove_mark() argument
1151 return -ENOENT; in fanotify_remove_mark()
1154 removed = fanotify_mark_remove_from_mask(fsn_mark, mask, flags, in fanotify_remove_mark()
1156 if (removed & fsnotify_conn_mask(fsn_mark->connector)) in fanotify_remove_mark()
1157 fsnotify_recalc_mask(fsn_mark->connector); in fanotify_remove_mark()
1178 * independent event flags in ignore mask. After that, trying to in fanotify_mark_update_flags()
1179 * update the ignore mask with the old FAN_MARK_IGNORED_MASK API in fanotify_mark_update_flags()
1183 fsn_mark->flags |= FSNOTIFY_MARK_FLAG_HAS_IGNORE_FLAGS; in fanotify_mark_update_flags()
1187 * the removal of the FS_MODIFY bit in calculated mask if it was set in fanotify_mark_update_flags()
1188 * because of an ignore mask that is now going to survive FS_MODIFY. in fanotify_mark_update_flags()
1191 !(fsn_mark->flags & FSNOTIFY_MARK_FLAG_IGNORED_SURV_MODIFY)) { in fanotify_mark_update_flags()
1192 fsn_mark->flags |= FSNOTIFY_MARK_FLAG_IGNORED_SURV_MODIFY; in fanotify_mark_update_flags()
1193 if (!(fsn_mark->mask & FS_MODIFY)) in fanotify_mark_update_flags()
1197 if (fsn_mark->connector->type != FSNOTIFY_OBJ_TYPE_INODE || in fanotify_mark_update_flags()
1198 want_iref == !(fsn_mark->flags & FSNOTIFY_MARK_FLAG_NO_IREF)) in fanotify_mark_update_flags()
1206 fsn_mark->flags &= ~FSNOTIFY_MARK_FLAG_NO_IREF; in fanotify_mark_update_flags()
1212 __u32 mask, unsigned int fan_flags) in fanotify_mark_add_to_mask() argument
1216 spin_lock(&fsn_mark->lock); in fanotify_mark_add_to_mask()
1218 fsn_mark->mask |= mask; in fanotify_mark_add_to_mask()
1220 fsn_mark->ignore_mask |= mask; in fanotify_mark_add_to_mask()
1223 ~fsnotify_conn_mask(fsn_mark->connector); in fanotify_mark_add_to_mask()
1226 spin_unlock(&fsn_mark->lock); in fanotify_mark_add_to_mask()
1245 FANOTIFY_MARK(mark)->fsid = fsid->id; in fanotify_set_mark_fsid()
1246 mark->flags |= FSNOTIFY_MARK_FLAG_HAS_FSID; in fanotify_set_mark_fsid()
1247 if (fsid->weak) in fanotify_set_mark_fsid()
1248 mark->flags |= FSNOTIFY_MARK_FLAG_WEAK_FSID; in fanotify_set_mark_fsid()
1251 if (list_empty(&group->marks_list)) in fanotify_set_mark_fsid()
1255 list_for_each_entry(old, &group->marks_list, g_list) { in fanotify_set_mark_fsid()
1256 conn = READ_ONCE(old->connector); in fanotify_set_mark_fsid()
1269 if ((mark->flags ^ old->flags) & FSNOTIFY_MARK_FLAG_WEAK_FSID) in fanotify_set_mark_fsid()
1270 return -EXDEV; in fanotify_set_mark_fsid()
1273 if (!fsid->weak) in fanotify_set_mark_fsid()
1277 if (old_sb != fsid->sb) in fanotify_set_mark_fsid()
1278 return -EXDEV; in fanotify_set_mark_fsid()
1280 /* Do not allow mixing marks from different btrfs sub-volumes */ in fanotify_set_mark_fsid()
1281 if (!fanotify_fsid_equal(&FANOTIFY_MARK(old)->fsid, in fanotify_set_mark_fsid()
1282 &FANOTIFY_MARK(mark)->fsid)) in fanotify_set_mark_fsid()
1283 return -EXDEV; in fanotify_set_mark_fsid()
1294 struct ucounts *ucounts = group->fanotify_data.ucounts; in fanotify_add_new_mark()
1305 !inc_ucount(ucounts->ns, ucounts->uid, UCOUNT_FANOTIFY_MARKS)) in fanotify_add_new_mark()
1306 return ERR_PTR(-ENOSPC); in fanotify_add_new_mark()
1310 ret = -ENOMEM; in fanotify_add_new_mark()
1314 mark = &fan_mark->fsn_mark; in fanotify_add_new_mark()
1317 mark->flags |= FSNOTIFY_MARK_FLAG_NO_IREF; in fanotify_add_new_mark()
1325 fan_mark->fsid.val[0] = fan_mark->fsid.val[1] = 0; in fanotify_add_new_mark()
1344 if (mempool_initialized(&group->fanotify_data.error_events_pool)) in fanotify_group_init_error_pool()
1347 return mempool_init_kmalloc_pool(&group->fanotify_data.error_events_pool, in fanotify_group_init_error_pool()
1353 __u32 mask, unsigned int fan_flags) in fanotify_may_update_existing_mark() argument
1359 !(fsn_mark->flags & FSNOTIFY_MARK_FLAG_NO_IREF)) in fanotify_may_update_existing_mark()
1360 return -EEXIST; in fanotify_may_update_existing_mark()
1363 * New ignore mask semantics cannot be downgraded to old semantics. in fanotify_may_update_existing_mark()
1366 fsn_mark->flags & FSNOTIFY_MARK_FLAG_HAS_IGNORE_FLAGS) in fanotify_may_update_existing_mark()
1367 return -EEXIST; in fanotify_may_update_existing_mark()
1370 * An ignore mask that survives modify could never be downgraded to not in fanotify_may_update_existing_mark()
1372 * explicit and return an error when trying to update the ignore mask in fanotify_may_update_existing_mark()
1377 fsn_mark->flags & FSNOTIFY_MARK_FLAG_IGNORED_SURV_MODIFY) in fanotify_may_update_existing_mark()
1378 return -EEXIST; in fanotify_may_update_existing_mark()
1380 /* For now pre-content events are not generated for directories */ in fanotify_may_update_existing_mark()
1381 mask |= fsn_mark->mask; in fanotify_may_update_existing_mark()
1382 if (mask & FANOTIFY_PRE_CONTENT_EVENTS && mask & FAN_ONDIR) in fanotify_may_update_existing_mark()
1383 return -EEXIST; in fanotify_may_update_existing_mark()
1390 __u32 mask, unsigned int fan_flags, in fanotify_add_mark() argument
1409 * Check if requested mark flags conflict with an existing mark flags. in fanotify_add_mark()
1411 ret = fanotify_may_update_existing_mark(fsn_mark, mask, fan_flags); in fanotify_add_mark()
1416 * Error events are pre-allocated per group, only if strictly in fanotify_add_mark()
1420 (mask & FAN_FS_ERROR)) { in fanotify_add_mark()
1426 recalc = fanotify_mark_add_to_mask(fsn_mark, mask, fan_flags); in fanotify_add_mark()
1428 fsnotify_recalc_mask(fsn_mark->connector); in fanotify_add_mark()
1446 oevent->type = FANOTIFY_EVENT_TYPE_OVERFLOW; in fanotify_alloc_overflow_event()
1448 return &oevent->fse; in fanotify_alloc_overflow_event()
1466 SYSCALL_DEFINE2(fanotify_init, unsigned int, flags, unsigned int, event_f_flags) in SYSCALL_DEFINE2() argument
1470 unsigned int fid_mode = flags & FANOTIFY_FID_BITS; in SYSCALL_DEFINE2()
1471 unsigned int class = flags & FANOTIFY_CLASS_BITS; in SYSCALL_DEFINE2()
1475 pr_debug("%s: flags=%x event_f_flags=%x\n", in SYSCALL_DEFINE2()
1476 __func__, flags, event_f_flags); in SYSCALL_DEFINE2()
1481 * limited functionality - an unprivileged group is limited to in SYSCALL_DEFINE2()
1485 if ((flags & FANOTIFY_ADMIN_INIT_FLAGS) || !fid_mode) in SYSCALL_DEFINE2()
1486 return -EPERM; in SYSCALL_DEFINE2()
1497 if (flags & ~(FANOTIFY_INIT_FLAGS | FAN_ENABLE_AUDIT)) in SYSCALL_DEFINE2()
1499 if (flags & ~FANOTIFY_INIT_FLAGS) in SYSCALL_DEFINE2()
1501 return -EINVAL; in SYSCALL_DEFINE2()
1504 * A pidfd can only be returned for a thread-group leader; thus in SYSCALL_DEFINE2()
1508 if ((flags & FAN_REPORT_PIDFD) && (flags & FAN_REPORT_TID)) in SYSCALL_DEFINE2()
1509 return -EINVAL; in SYSCALL_DEFINE2()
1512 return -EINVAL; in SYSCALL_DEFINE2()
1520 return -EINVAL; in SYSCALL_DEFINE2()
1524 return -EINVAL; in SYSCALL_DEFINE2()
1531 return -EINVAL; in SYSCALL_DEFINE2()
1540 return -EINVAL; in SYSCALL_DEFINE2()
1543 if (flags & FAN_CLOEXEC) in SYSCALL_DEFINE2()
1545 if (flags & FAN_NONBLOCK) in SYSCALL_DEFINE2()
1556 group->fanotify_data.ucounts = inc_ucount(current_user_ns(), in SYSCALL_DEFINE2()
1559 if (!group->fanotify_data.ucounts) { in SYSCALL_DEFINE2()
1560 fd = -EMFILE; in SYSCALL_DEFINE2()
1564 group->fanotify_data.flags = flags | internal_flags; in SYSCALL_DEFINE2()
1565 group->memcg = get_mem_cgroup_from_mm(current->mm); in SYSCALL_DEFINE2()
1567 group->fanotify_data.merge_hash = fanotify_alloc_merge_hash(); in SYSCALL_DEFINE2()
1568 if (!group->fanotify_data.merge_hash) { in SYSCALL_DEFINE2()
1569 fd = -ENOMEM; in SYSCALL_DEFINE2()
1573 group->overflow_event = fanotify_alloc_overflow_event(); in SYSCALL_DEFINE2()
1574 if (unlikely(!group->overflow_event)) { in SYSCALL_DEFINE2()
1575 fd = -ENOMEM; in SYSCALL_DEFINE2()
1581 group->fanotify_data.f_flags = event_f_flags; in SYSCALL_DEFINE2()
1582 init_waitqueue_head(&group->fanotify_data.access_waitq); in SYSCALL_DEFINE2()
1583 INIT_LIST_HEAD(&group->fanotify_data.access_list); in SYSCALL_DEFINE2()
1586 group->priority = FSNOTIFY_PRIO_NORMAL; in SYSCALL_DEFINE2()
1589 group->priority = FSNOTIFY_PRIO_CONTENT; in SYSCALL_DEFINE2()
1592 group->priority = FSNOTIFY_PRIO_PRE_CONTENT; in SYSCALL_DEFINE2()
1595 fd = -EINVAL; in SYSCALL_DEFINE2()
1599 if (flags & FAN_UNLIMITED_QUEUE) { in SYSCALL_DEFINE2()
1600 fd = -EPERM; in SYSCALL_DEFINE2()
1603 group->max_events = UINT_MAX; in SYSCALL_DEFINE2()
1605 group->max_events = fanotify_max_queued_events; in SYSCALL_DEFINE2()
1608 if (flags & FAN_UNLIMITED_MARKS) { in SYSCALL_DEFINE2()
1609 fd = -EPERM; in SYSCALL_DEFINE2()
1614 if (flags & FAN_ENABLE_AUDIT) { in SYSCALL_DEFINE2()
1615 fd = -EPERM; in SYSCALL_DEFINE2()
1639 static int fanotify_test_fsid(struct dentry *dentry, unsigned int flags, in fanotify_test_fsid() argument
1642 unsigned int mark_type = flags & FANOTIFY_MARK_TYPE_BITS; in fanotify_test_fsid()
1649 err = vfs_get_fsid(dentry, &fsid->id); in fanotify_test_fsid()
1653 fsid->sb = dentry->d_sb; in fanotify_test_fsid()
1654 if (!fsid->id.val[0] && !fsid->id.val[1]) { in fanotify_test_fsid()
1655 err = -ENODEV; in fanotify_test_fsid()
1663 err = vfs_get_fsid(dentry->d_sb->s_root, &root_fsid); in fanotify_test_fsid()
1667 if (!fanotify_fsid_equal(&root_fsid, &fsid->id)) { in fanotify_test_fsid()
1668 err = -EXDEV; in fanotify_test_fsid()
1672 fsid->weak = false; in fanotify_test_fsid()
1677 fsid->weak = true; in fanotify_test_fsid()
1682 static int fanotify_test_fid(struct dentry *dentry, unsigned int flags) in fanotify_test_fid() argument
1684 unsigned int mark_type = flags & FANOTIFY_MARK_TYPE_BITS; in fanotify_test_fid()
1685 const struct export_operations *nop = dentry->d_sb->s_export_op; in fanotify_test_fid()
1693 return -EOPNOTSUPP; in fanotify_test_fid()
1701 return -EOPNOTSUPP; in fanotify_test_fid()
1707 const struct path *path, __u64 mask, in fanotify_events_supported() argument
1708 unsigned int flags) in fanotify_events_supported() argument
1710 unsigned int mark_type = flags & FANOTIFY_MARK_TYPE_BITS; in fanotify_events_supported()
1711 bool is_dir = d_is_dir(path->dentry); in fanotify_events_supported()
1712 /* Strict validation of events in non-dir inode mask with v5.17+ APIs */ in fanotify_events_supported()
1714 (mask & FAN_RENAME) || in fanotify_events_supported()
1715 (flags & FAN_MARK_IGNORE); in fanotify_events_supported()
1718 * Filesystems need to opt-into pre-content evnets (a.k.a HSM) in fanotify_events_supported()
1721 if (mask & FANOTIFY_PRE_CONTENT_EVENTS) { in fanotify_events_supported()
1722 if (!(path->mnt->mnt_sb->s_iflags & SB_I_ALLOW_HSM)) in fanotify_events_supported()
1723 return -EOPNOTSUPP; in fanotify_events_supported()
1724 if (!is_dir && !d_is_reg(path->dentry)) in fanotify_events_supported()
1725 return -EINVAL; in fanotify_events_supported()
1731 * deadlocking the system - open done when reporting fanotify event in fanotify_events_supported()
1736 if (mask & FANOTIFY_PERM_EVENTS && in fanotify_events_supported()
1737 path->mnt->mnt_sb->s_type->fs_flags & FS_DISALLOW_NOTIFY_PERM) in fanotify_events_supported()
1738 return -EINVAL; in fanotify_events_supported()
1751 path->mnt->mnt_sb->s_flags & SB_NOUSER) in fanotify_events_supported()
1752 return -EINVAL; in fanotify_events_supported()
1756 * flags FAN_ONDIR and FAN_EVENT_ON_CHILD in mask of non-dir inode, in fanotify_events_supported()
1760 !is_dir && (mask & FANOTIFY_DIRONLY_EVENT_BITS)) in fanotify_events_supported()
1761 return -ENOTDIR; in fanotify_events_supported()
1766 static int do_fanotify_mark(int fanotify_fd, unsigned int flags, __u64 mask, in do_fanotify_mark() argument
1775 unsigned int mark_type = flags & FANOTIFY_MARK_TYPE_BITS; in do_fanotify_mark()
1776 unsigned int mark_cmd = flags & FANOTIFY_MARK_CMD_BITS; in do_fanotify_mark()
1777 unsigned int ignore = flags & FANOTIFY_MARK_IGNORE_BITS; in do_fanotify_mark()
1783 pr_debug("%s: fanotify_fd=%d flags=%x dfd=%d pathname=%p mask=%llx\n", in do_fanotify_mark()
1784 __func__, fanotify_fd, flags, dfd, pathname, mask); in do_fanotify_mark()
1787 if (upper_32_bits(mask)) in do_fanotify_mark()
1788 return -EINVAL; in do_fanotify_mark()
1790 if (flags & ~FANOTIFY_MARK_FLAGS) in do_fanotify_mark()
1791 return -EINVAL; in do_fanotify_mark()
1804 return -EINVAL; in do_fanotify_mark()
1810 if (!mask) in do_fanotify_mark()
1811 return -EINVAL; in do_fanotify_mark()
1814 if (flags & ~(FANOTIFY_MARK_TYPE_BITS | FAN_MARK_FLUSH)) in do_fanotify_mark()
1815 return -EINVAL; in do_fanotify_mark()
1818 return -EINVAL; in do_fanotify_mark()
1824 if (mask & ~valid_mask) in do_fanotify_mark()
1825 return -EINVAL; in do_fanotify_mark()
1830 return -EINVAL; in do_fanotify_mark()
1833 * Event flags (FAN_ONDIR, FAN_EVENT_ON_CHILD) have no effect with in do_fanotify_mark()
1837 mask &= ~FANOTIFY_EVENT_FLAGS; in do_fanotify_mark()
1843 return -EBADF; in do_fanotify_mark()
1846 if (unlikely(fd_file(f)->f_op != &fanotify_fops)) in do_fanotify_mark()
1847 return -EINVAL; in do_fanotify_mark()
1848 group = fd_file(f)->private_data; in do_fanotify_mark()
1858 return -EPERM; in do_fanotify_mark()
1862 * Pre-content permission events are not allowed for FAN_CLASS_CONTENT. in do_fanotify_mark()
1864 if (mask & FANOTIFY_PERM_EVENTS && in do_fanotify_mark()
1865 group->priority == FSNOTIFY_PRIO_NORMAL) in do_fanotify_mark()
1866 return -EINVAL; in do_fanotify_mark()
1867 else if (mask & FANOTIFY_PRE_CONTENT_EVENTS && in do_fanotify_mark()
1868 group->priority == FSNOTIFY_PRIO_CONTENT) in do_fanotify_mark()
1869 return -EINVAL; in do_fanotify_mark()
1871 if (mask & FAN_FS_ERROR && in do_fanotify_mark()
1873 return -EINVAL; in do_fanotify_mark()
1879 if (flags & FAN_MARK_EVICTABLE && in do_fanotify_mark()
1881 return -EINVAL; in do_fanotify_mark()
1885 * event->fd require a group that supports reporting fid. Those in do_fanotify_mark()
1891 if (mask & ~(FANOTIFY_FD_EVENTS|FANOTIFY_EVENT_FLAGS) && in do_fanotify_mark()
1893 return -EINVAL; in do_fanotify_mark()
1900 if (mask & FAN_RENAME && !(fid_mode & FAN_REPORT_NAME)) in do_fanotify_mark()
1901 return -EINVAL; in do_fanotify_mark()
1903 /* Pre-content events are not currently generated for directories. */ in do_fanotify_mark()
1904 if (mask & FANOTIFY_PRE_CONTENT_EVENTS && mask & FAN_ONDIR) in do_fanotify_mark()
1905 return -EINVAL; in do_fanotify_mark()
1917 ret = fanotify_find_path(dfd, pathname, &path, flags, in do_fanotify_mark()
1918 (mask & ALL_FSNOTIFY_EVENTS), obj_type); in do_fanotify_mark()
1923 ret = fanotify_events_supported(group, &path, mask, flags); in do_fanotify_mark()
1929 ret = fanotify_test_fsid(path.dentry, flags, &__fsid); in do_fanotify_mark()
1933 ret = fanotify_test_fid(path.dentry, flags); in do_fanotify_mark()
1942 inode = path.dentry->d_inode; in do_fanotify_mark()
1949 obj = mnt->mnt_sb; in do_fanotify_mark()
1954 * an ignore mask, unless that ignore mask is supposed to survive in do_fanotify_mark()
1957 if (mark_cmd == FAN_MARK_ADD && (flags & FANOTIFY_MARK_IGNORE_BITS) && in do_fanotify_mark()
1958 !(flags & FAN_MARK_IGNORED_SURV_MODIFY)) { in do_fanotify_mark()
1959 ret = mnt ? -EINVAL : -EISDIR; in do_fanotify_mark()
1962 (mnt || S_ISDIR(inode->i_mode))) in do_fanotify_mark()
1970 /* Mask out FAN_EVENT_ON_CHILD flag for sb/mount/non-dir marks */ in do_fanotify_mark()
1971 if (mnt || !S_ISDIR(inode->i_mode)) { in do_fanotify_mark()
1972 mask &= ~FAN_EVENT_ON_CHILD; in do_fanotify_mark()
1976 * events with parent/name info for non-directory. in do_fanotify_mark()
1979 (flags & FAN_MARK_ADD) && !ignore) in do_fanotify_mark()
1980 mask |= FAN_EVENT_ON_CHILD; in do_fanotify_mark()
1986 ret = fanotify_add_mark(group, obj, obj_type, mask, flags, in do_fanotify_mark()
1990 ret = fanotify_remove_mark(group, obj, obj_type, mask, flags, in do_fanotify_mark()
1994 ret = -EINVAL; in do_fanotify_mark()
2003 SYSCALL_DEFINE5(fanotify_mark, int, fanotify_fd, unsigned int, flags, in SYSCALL_DEFINE5() argument
2004 __u64, mask, int, dfd, in SYSCALL_DEFINE5() argument
2007 return do_fanotify_mark(fanotify_fd, flags, mask, dfd, pathname); in SYSCALL_DEFINE5()
2013 int, fanotify_fd, unsigned int, flags, in SYSCALL32_DEFINE6() argument
2014 SC_ARG64(mask), int, dfd, in SYSCALL32_DEFINE6() argument
2017 return do_fanotify_mark(fanotify_fd, flags, SC_VAL64(__u64, mask), in SYSCALL32_DEFINE6()
2023 * fanotify_user_setup - Our initialization function. Note that we cannot return
2024 * error because we have compiled-in VFS hooks. So an (unlikely) failure here
2039 max_marks = (((si.totalram - si.totalhigh) / 100) << PAGE_SHIFT) / in fanotify_user_setup()