ima: open a new file instance if no read permissions
authorGoldwyn Rodrigues <rgoldwyn@suse.de>
Tue, 9 Oct 2018 15:12:33 +0000 (10:12 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 16 May 2019 17:42:26 +0000 (19:42 +0200)
commit16be27a5ccfc654a7bd68eb362205362aabbd38b
tree1a06cba975d1d7555fe3299d8cadf038c6f4e6cc
parent19278c44705c608140f9566212ff2610d3a3b838
ima: open a new file instance if no read permissions

[ Upstream commit a408e4a86b36bf98ad15b9ada531cf0e5118ac67 ]

Open a new file instance as opposed to changing file->f_mode when
the file is not readable.  This is done to accomodate overlayfs
stacked file operations change.  The real struct file is hidden
behind the overlays struct file.  So, any file->f_mode manipulations are
not reflected on the real struct file.  Open the file again in read mode
if original file cannot be read, read and calculate the hash.

Signed-off-by: Goldwyn Rodrigues <rgoldwyn@suse.com>
Cc: stable@vger.kernel.org (linux-4.19)
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
security/integrity/ima/ima_crypto.c