From c2faccaff6a16d331df832135ede6d4774c2d2a0 Mon Sep 17 00:00:00 2001 From: Theodore Ts'o Date: Sun, 31 May 2015 13:35:09 -0400 Subject: ext4 crypto: enforce crypto policy restrictions on cross-renames Thanks to Chao Yu for pointing out the need for this check. Signed-off-by: Theodore Ts'o --- fs/ext4/namei.c | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'fs/ext4/namei.c') diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c index 1e7d65d7e6d7..401b099e3af3 100644 --- a/fs/ext4/namei.c +++ b/fs/ext4/namei.c @@ -3647,6 +3647,15 @@ static int ext4_cross_rename(struct inode *old_dir, struct dentry *old_dentry, u8 new_file_type; int retval; + if ((ext4_encrypted_inode(old_dir) || + ext4_encrypted_inode(new_dir)) && + (old_dir != new_dir) && + (!ext4_is_child_context_consistent_with_parent(new_dir, + old.inode) || + !ext4_is_child_context_consistent_with_parent(old_dir, + new.inode))) + return -EPERM; + dquot_initialize(old.dir); dquot_initialize(new.dir); -- cgit v1.2.1