BACKPORT: smack: fix cache of access labels
authorJosé Bollo <jobol@nonadev.net>
Tue, 12 Jan 2016 20:23:40 +0000 (21:23 +0100)
committerRafal Krypa <r.krypa@samsung.com>
Tue, 22 Mar 2016 11:49:29 +0000 (12:49 +0100)
Before this commit, removing the access property of
a file, aka, the extended attribute security.SMACK64
was not effictive until the cache had been cleaned.

This patch fixes that problem.

Signed-off-by: José Bollo <jobol@nonadev.net>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
(cherry-picked from upstream 8012495e177bbf67eba8915e266a6f897bedbd53)

security/smack/smack_lsm.c

index 61b317032290c5e6edca8d50e539f93ec4f4d72e..2e6c835c913f9e7101ae5b233957f8d38358d705 100644 (file)
@@ -1444,9 +1444,13 @@ static int smack_inode_removexattr(struct dentry *dentry, const char *name)
         * Don't do anything special for these.
         *      XATTR_NAME_SMACKIPIN
         *      XATTR_NAME_SMACKIPOUT
-        *      XATTR_NAME_SMACKEXEC
         */
-       if (strcmp(name, XATTR_NAME_SMACK) == 0)
+       if (strcmp(name, XATTR_NAME_SMACK) == 0) {
+               struct super_block *sbp = dentry->d_inode->i_sb;
+               struct superblock_smack *sbsp = sbp->s_security;
+
+               isp->smk_inode = sbsp->smk_default;
+       } else if (strcmp(name, XATTR_NAME_SMACKEXEC) == 0)
                isp->smk_task = NULL;
        else if (strcmp(name, XATTR_NAME_SMACKMMAP) == 0)
                isp->smk_mmap = NULL;