Re: RFC: BUG: overlayfs getxattr recursion leaves a poison sid.

2019-07-09 Thread Mark Salyzyn
On 7/9/19 9:33 AM, Casey Schaufler wrote: On 7/9/2019 9:23 AM, Mark Salyzyn wrote: For EACCES return for getxattr, sid appears to be expected updated in parent node. For some accesses purely cosmetic for correct avc logging, and depending on kernel vintage for others (older than 4.4) the lack

Re: RFC: BUG: overlayfs getxattr recursion leaves a poison sid.

2019-07-09 Thread Casey Schaufler
On 7/9/2019 9:23 AM, Mark Salyzyn wrote: > For EACCES return for getxattr, sid appears to be expected updated in parent > node. For some accesses purely cosmetic for correct avc logging, and > depending on kernel vintage for others (older than 4.4) the lack of the > corrected sid in the parent o

RFC: BUG: overlayfs getxattr recursion leaves a poison sid.

2019-07-09 Thread Mark Salyzyn
For EACCES return for getxattr, sid appears to be expected updated in parent node. For some accesses purely cosmetic for correct avc logging, and depending on kernel vintage for others (older than 4.4) the lack of the corrected sid in the parent overlay inode poisons the security cache and resu