On Tue, Nov 4, 2014 at 5:27 AM, Miklos Szeredi <miklos(a)szeredi.hu> wrote:
From: Miklos Szeredi <mszeredi(a)suse.cz>
Audit rules disappear when an inode they watch is evicted from the cache.
This is likely not what we want.
The guilty commit is "fsnotify: allow marks to not pin inodes in core",
which didn't take into account that audit_tree adds watches with a zero
mask.
Adding any mask should fix this.
Fixes: 90b1e7a57880 ("fsnotify: allow marks to not pin inodes in core")
Signed-off-by: Miklos Szeredi <mszeredi(a)suse.cz>
Cc: stable(a)vger.kernel.org # 2.6.36+
---
kernel/audit_tree.c | 1 +
1 file changed, 1 insertion(+)
Thanks for your help on this, I've merged this into the audit
stable-3.18 branch; I plan on pushing this to Linus later this week.
*
git://git.infradead.org/users/pcmoore/audit stable-3.18
--- a/kernel/audit_tree.c
+++ b/kernel/audit_tree.c
@@ -154,6 +154,7 @@ static struct audit_chunk *alloc_chunk(i
chunk->owners[i].index = i;
}
fsnotify_init_mark(&chunk->mark, audit_tree_destroy_watch);
+ chunk->mark.mask = FS_IN_IGNORED;
return chunk;
}
--
paul moore
www.paul-moore.com