Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1219503
| From | Andreas Gruenbacher <agruenba@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces |
| Date | 2015-09-05 12:40 +0200 |
| Message-ID | <q5j36-6jH-69@gated-at.bofh.it> (permalink) |
| References | <q5iTn-686-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
The trailing everyone@ allow ace can grant permissions to all file
classes including the owner and group class. Before we can apply the
other mask to this entry to turn it into an "other class" entry, we need
to ensure that members of the owner or group class will not lose any
permissions from that ace.
Conceptually, we do this by inserting additional <who>:<allow>::allow
entries before the trailing everyone@ allow ace with the same
permissions as the trailing everyone@ allow ace for owner@, group@, and
all explicitly mentioned users and groups. (In practice, we will rarely
need to insert any additional aces in this step.)
Signed-off-by: Andreas Gruenbacher <agruen@kernel.org>
---
fs/richacl_compat.c | 195 ++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 195 insertions(+)
diff --git a/fs/richacl_compat.c b/fs/richacl_compat.c
index 4f0acf5..9b76fc0 100644
--- a/fs/richacl_compat.c
+++ b/fs/richacl_compat.c
@@ -218,3 +218,198 @@ richacl_move_everyone_aces_down(struct richacl_alloc *alloc)
}
return 0;
}
+
+/**
+ * __richacl_propagate_everyone - propagate everyone@ permissions up for @who
+ * @alloc: acl and number of allocated entries
+ * @who: identifier to propagate permissions for
+ * @allow: permissions to propagate up
+ *
+ * Propagate the permissions in @allow up from the end of the acl to the start
+ * for the specified principal @who.
+ *
+ * The simplest possible approach to achieve this would be to insert a
+ * "<who>:<allow>::allow" ace before the final everyone@ allow ace. Since this
+ * would often result in aces which are not needed or which could be merged
+ * with an existing ace, we make the following optimizations:
+ *
+ * - We go through the acl and determine which permissions are already
+ * allowed or denied to @who, and we remove those permissions from
+ * @allow.
+ *
+ * - If the acl contains an allow ace for @who and no aces after this entry
+ * deny permissions in @allow, we add the permissions in @allow to this
+ * ace. (Propagating permissions across a deny ace which can match the
+ * process can elevate permissions.)
+ *
+ * This transformation does not alter the permissions that the acl grants.
+ */
+static int
+__richacl_propagate_everyone(struct richacl_alloc *alloc, struct richace *who,
+ unsigned int allow)
+{
+ struct richace *allow_last = NULL, *ace;
+ struct richacl *acl = alloc->acl;
+
+ /*
+ * Remove the permissions from allow that are already determined for
+ * this who value, and figure out if there is an allow entry for
+ * this who value that is "reachable" from the trailing everyone@
+ * allow ace.
+ */
+ richacl_for_each_entry(ace, acl) {
+ if (richace_is_inherit_only(ace))
+ continue;
+ if (richace_is_allow(ace)) {
+ if (richace_is_same_identifier(ace, who)) {
+ allow &= ~ace->e_mask;
+ allow_last = ace;
+ }
+ } else if (richace_is_deny(ace)) {
+ if (richace_is_same_identifier(ace, who))
+ allow &= ~ace->e_mask;
+ else if (allow & ace->e_mask)
+ allow_last = NULL;
+ }
+ }
+ ace--;
+
+ /*
+ * If for group class entries, all the remaining permissions will
+ * remain granted by the trailing everyone@ ace, no additional entry is
+ * needed.
+ */
+ if (!richace_is_owner(who) &&
+ richace_is_everyone(ace) && richace_is_allow(ace) &&
+ !(allow & ~(ace->e_mask & acl->a_other_mask)))
+ allow = 0;
+
+ if (allow) {
+ if (allow_last)
+ return richace_change_mask(alloc, &allow_last,
+ allow_last->e_mask | allow);
+ else {
+ struct richace who_copy;
+
+ richace_copy(&who_copy, who);
+ ace = acl->a_entries + acl->a_count - 1;
+ if (richacl_insert_entry(alloc, &ace))
+ return -1;
+ richace_copy(ace, &who_copy);
+ ace->e_type = RICHACE_ACCESS_ALLOWED_ACE_TYPE;
+ ace->e_flags &= ~RICHACE_INHERITANCE_FLAGS;
+ ace->e_mask = allow;
+ }
+ }
+ return 0;
+}
+
+/**
+ * richacl_propagate_everyone - propagate everyone@ permissions up the acl
+ * @alloc: acl and number of allocated entries
+ *
+ * Make sure that group@ and all other users and groups mentioned in the acl
+ * will not lose any permissions when finally applying the other mask to the
+ * everyone@ allow ace at the end of the acl. We modify the permissions of
+ * existing entries or add new entries before the final everyone@ allow ace to
+ * achieve that.
+ *
+ * For example, the following acl implicitly grants everyone rwpx access:
+ *
+ * joe:r::allow
+ * everyone@:rwpx::allow
+ *
+ * When applying mode 0660 to this acl, group@ would lose rwp access, and joe
+ * would lose wp access even though the mode does not exclude those
+ * permissions. After propagating the everyone@ permissions, the result for
+ * applying mode 0660 becomes:
+ *
+ * owner@:rwp::allow
+ * joe:rwp::allow
+ * group@:rwp::allow
+ *
+ * Deny aces complicate the matter. For example, the following acl grants
+ * everyone but joe write access:
+ *
+ * joe:wp::deny
+ * everyone@:rwpx::allow
+ *
+ * When applying mode 0660 to this acl, group@ would lose rwp access, and joe
+ * would lose r access. After propagating the everyone@ permissions, the
+ * result for applying mode 0660 becomes:
+ *
+ * owner@:rwp::allow
+ * joe:w::deny
+ * group@:rwp::allow
+ * joe:r::allow
+ */
+static int
+richacl_propagate_everyone(struct richacl_alloc *alloc)
+{
+ struct richace who = { .e_flags = RICHACE_SPECIAL_WHO };
+ struct richacl *acl = alloc->acl;
+ struct richace *ace;
+ unsigned int owner_allow, group_allow;
+
+ /*
+ * If the owner mask contains permissions which are not in the group
+ * mask, the group mask contains permissions which are not in the other
+ * mask, or the owner class contains permissions which are not in the
+ * other mask, we may need to propagate permissions up from the
+ * everyone@ allow ace. The third condition is implied by the first
+ * two.
+ */
+ if (!((acl->a_owner_mask & ~acl->a_group_mask) ||
+ (acl->a_group_mask & ~acl->a_other_mask)))
+ return 0;
+ if (!acl->a_count)
+ return 0;
+ ace = acl->a_entries + acl->a_count - 1;
+ if (richace_is_inherit_only(ace) || !richace_is_everyone(ace))
+ return 0;
+
+ owner_allow = ace->e_mask & acl->a_owner_mask;
+ group_allow = ace->e_mask & acl->a_group_mask;
+
+ if (owner_allow & ~(acl->a_group_mask & acl->a_other_mask)) {
+ /* Propagate everyone@ permissions through to owner@. */
+ who.e_id.special = RICHACE_OWNER_SPECIAL_ID;
+ if (__richacl_propagate_everyone(alloc, &who, owner_allow))
+ return -1;
+ acl = alloc->acl;
+ }
+
+ if (group_allow & ~acl->a_other_mask) {
+ int n;
+
+ /* Propagate everyone@ permissions through to group@. */
+ who.e_id.special = RICHACE_GROUP_SPECIAL_ID;
+ if (__richacl_propagate_everyone(alloc, &who, group_allow))
+ return -1;
+ acl = alloc->acl;
+
+ /*
+ * Start from the entry before the trailing everyone@ allow
+ * entry. We will not hit everyone@ entries in the loop.
+ */
+ for (n = acl->a_count - 2; n != -1; n--) {
+ ace = acl->a_entries + n;
+
+ if (richace_is_inherit_only(ace) ||
+ richace_is_owner(ace) ||
+ richace_is_group(ace))
+ continue;
+ if (richace_is_allow(ace) || richace_is_deny(ace)) {
+ /*
+ * Any inserted entry will end up below the
+ * current entry
+ */
+ if (__richacl_propagate_everyone(alloc, ace,
+ group_allow))
+ return -1;
+ acl = alloc->acl;
+ }
+ }
+ }
+ return 0;
+}
--
2.4.3
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[RFC v7 00/41] Richacls Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:30 +0200
[RFC v7 21/41] richacl: Move everyone@ aces down the acl Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 21/41] richacl: Move everyone@ aces down the acl bfields@fieldses.org (J. Bruce Fields) - 2015-09-18 21:40 +0200
Re: [RFC v7 21/41] richacl: Move everyone@ aces down the acl Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-21 23:50 +0200
Re: [RFC v7 21/41] richacl: Move everyone@ aces down the acl "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-22 04:00 +0200
[RFC v7 26/41] richacl: Apply the file masks to a richacl Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 33/41] richacl: Add support for unmapped identifiers Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 28/41] nfsd: Keep list of acls to dispose of in compoundargs Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 02/41] vfs: Add MAY_CREATE_FILE and MAY_CREATE_DIR permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 38/41] nfs: Remove unused xdr page offsets in getacl/setacl arguments Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode bfields@fieldses.org (J. Bruce Fields) - 2015-09-17 20:30 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-18 03:00 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode Austin S Hemmelgarn <ahferroin7@gmail.com> - 2015-09-21 16:00 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-21 16:40 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode Austin S Hemmelgarn <ahferroin7@gmail.com> - 2015-09-21 19:10 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-21 19:50 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-21 17:40 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-22 01:30 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-22 01:30 +0200
Re: [RFC v7 13/41] richacl: Check if an acl is equivalent to a file mode bfields@fieldses.org (J. Bruce Fields) - 2015-09-17 20:40 +0200
[RFC v7 23/41] richacl: Set the owner permissions to the owner mask Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 23/41] richacl: Set the owner permissions to the owner mask bfields@fieldses.org (J. Bruce Fields) - 2015-09-21 23:10 +0200
[RFC v7 11/41] vfs: Cache base_acl objects in inodes Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 10/41] richacl: Permission check algorithm Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 10/41] richacl: Permission check algorithm bfields@fieldses.org (J. Bruce Fields) - 2015-09-11 23:20 +0200
Re: [RFC v7 10/41] richacl: Permission check algorithm Andreas Grünbacher <andreas.gruenbacher@gmail.com> - 2015-09-12 00:20 +0200
Re: [RFC v7 10/41] richacl: Permission check algorithm "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-17 19:40 +0200
[RFC v7 07/41] richacl: Permission mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 34/41] ext4: Don't allow unmapped identifiers in richacls Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 12/41] vfs: Cache richacl in struct inode Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 01/41] vfs: Add IS_ACL() and IS_RICHACL() tests Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 17/41] vfs: Add richacl permission checking Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 18/41] ext4: Add richacl support Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 30/41] nfsd: Add richacl support Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 14/41] richacl: Create-time inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 14/41] richacl: Create-time inheritance bfields@fieldses.org (J. Bruce Fields) - 2015-09-18 20:00 +0200
Re: [RFC v7 14/41] richacl: Create-time inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-21 22:40 +0200
[RFC v7 40/41] nfs: Add support for the v4.1 dacl attribute Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 29/41] nfsd: Use richacls as internal acl representation Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 16/41] richacl: xattr mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 08/41] richacl: Compute maximum file masks from an acl Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 20/41] richacl: acl editing helper functions Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 20/41] richacl: acl editing helper functions bfields@fieldses.org (J. Bruce Fields) - 2015-09-18 21:00 +0200
[RFC v7 05/41] vfs: Add permission flags for setting file attributes Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 24/41] richacl: Set the other permissions to the other mask Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 31/41] nfsd: Add support for the v4.1 dacl attribute Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 39/41] nfs: Add richacl support Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 15/41] richacl: Automatic Inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 15/41] richacl: Automatic Inheritance bfields@fieldses.org (J. Bruce Fields) - 2015-09-18 20:50 +0200
Re: [RFC v7 15/41] richacl: Automatic Inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-21 23:30 +0200
Re: [RFC v7 15/41] richacl: Automatic Inheritance "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-22 04:00 +0200
[RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces bfields@fieldses.org (J. Bruce Fields) - 2015-09-18 23:40 +0200
Re: [RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-22 01:50 +0200
Re: [RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces bfields@fieldses.org (J. Bruce Fields) - 2015-09-19 00:00 +0200
Re: [RFC v7 22/41] richacl: Propagate everyone@ permissions to other aces "J. Bruce Fields" <bfields@fieldses.org> - 2015-09-21 21:30 +0200
[RFC v7 41/41] richacl: uapi header split Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 09/41] richacl: Update the file masks in chmod() Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
Re: [RFC v7 09/41] richacl: Update the file masks in chmod() bfields@fieldses.org (J. Bruce Fields) - 2015-09-11 22:40 +0200
[RFC v7 03/41] vfs: Add MAY_DELETE_SELF and MAY_DELETE_CHILD permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[PATCH] vfs: Add MAY_DELETE_SELF and MAY_DELETE_CHILD permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-06 10:20 +0200
Re: [PATCH] vfs: Add MAY_DELETE_SELF and MAY_DELETE_CHILD permission flags bfields@fieldses.org (J. Bruce Fields) - 2015-09-11 22:40 +0200
[RFC v7 27/41] richacl: Create richacl from mode values Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 25/41] richacl: Isolate the owner and group classes Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 19/41] ext4: Add richacl feature flag Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 32/41] nfsd: Add support for the MAY_CREATE_{FILE,DIR} permissions Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:40 +0200
[RFC v7 37/41] nfs: Fix GETATTR bitmap verification Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:50 +0200
[RFC v7 36/41] sunrpc: Add xdr_init_encode_pages Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:50 +0200
[RFC v7 35/41] sunrpc: Allow to demand-allocate pages to encode into Andreas Gruenbacher <agruenba@redhat.com> - 2015-09-05 12:50 +0200
csiph-web