Linux/linux b5fed47kernel audit_watch.c

audit: Receive unmount event

Although audit_watch_handle_event() can handle FS_UNMOUNT event, it is
not part of AUDIT_FS_WATCH mask and thus such event never gets to
audit_watch_handle_event(). Thus fsnotify marks are deleted by fsnotify
subsystem on unmount without audit being notified about that which leads
to a strange state of existing audit rules with dead fsnotify marks.

Add FS_UNMOUNT to the mask of events to be received so that audit can
clean up its state accordingly.

Signed-off-by: Jan Kara <jack at suse.cz>
Signed-off-by: Paul Moore <paul at paul-moore.com>
DeltaFile
+1-1kernel/audit_watch.c
+1-11 files

UnifiedSplitRaw