From 3d55c56fe820327be245d1237d10cc2730488101 Mon Sep 17 00:00:00 2001 From: Theodore Ts'o Date: Thu, 28 May 2015 21:39:33 -0400 Subject: ext4 crypto: enforce crypto policy restrictions on cross-renames Thanks to Chao Yu for pointing out the need for this check. Change-Id: I957a4e4be043582972d3c8799f18826fc136d567 Signed-off-by: Theodore Ts'o Signed-off-by: Theodore Ts'o --- fs/ext4/namei.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c index 8608118d2..f557def0e 100644 --- a/fs/ext4/namei.c +++ b/fs/ext4/namei.c @@ -3652,6 +3652,15 @@ static int ext4_cross_rename(struct inode *old_dir, struct dentry *old_dentry, u8 new_file_type; int retval; + if ((ext4_encrypted_inode(old_dir) || + ext4_encrypted_inode(new_dir)) && + (old_dir != new_dir) && + (!ext4_is_child_context_consistent_with_parent(new_dir, + old.inode) || + !ext4_is_child_context_consistent_with_parent(old_dir, + new.inode))) + return -EPERM; + dquot_initialize(old.dir); dquot_initialize(new.dir); -- cgit v1.2.3