fscrypto: lock inode while setting encryption policy
authorEric Biggers <ebiggers@google.com>
Sat, 15 Oct 2016 13:48:50 +0000 (09:48 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 28 Oct 2016 07:45:30 +0000 (03:45 -0400)
commitdeb197e9992f4b8d0af491b062fff602c68eaff3
tree5c884ea44a15223573b103776e83936b3770ac13
parent8b722a45b3e2cc10dee3bb96e4fae0b2267607ce
fscrypto: lock inode while setting encryption policy

commit 8906a8223ad4909b391c5628f7991ebceda30e52 upstream.

i_rwsem needs to be acquired while setting an encryption policy so that
concurrent calls to FS_IOC_SET_ENCRYPTION_POLICY are correctly
serialized (especially the ->get_context() + ->set_context() pair), and
so that new files cannot be created in the directory during or after the
->empty_dir() check.

Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Reviewed-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/crypto/policy.c