Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1449513
| From | Andreas Gruenbacher <agruenba@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH v24 18/22] richacl: Add richacl xattr handler |
| Date | 2016-07-25 16:20 +0200 |
| Message-ID | <rYOTD-5Bn-7@gated-at.bofh.it> (permalink) |
| References | <rYOJY-5xo-27@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Add richacl xattr handler implementing the xattr operations based on the
get_richacl and set_richacl inode operations.
Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
---
fs/richacl.c | 22 ++++++++++++++++
fs/richacl_xattr.c | 61 +++++++++++++++++++++++++++++++++++++++++++
include/linux/richacl.h | 1 +
include/linux/richacl_xattr.h | 2 ++
4 files changed, 86 insertions(+)
diff --git a/fs/richacl.c b/fs/richacl.c
index 4edce8b..1945691 100644
--- a/fs/richacl.c
+++ b/fs/richacl.c
@@ -543,6 +543,28 @@ restart:
EXPORT_SYMBOL_GPL(richacl_compute_max_masks);
/**
+ * set_richacl - set the richacl of an inode
+ * @inode: inode whose richacl to set
+ * @acl: access control list
+ */
+int
+set_richacl(struct inode *inode, struct richacl *acl)
+{
+ if (!IS_RICHACL(inode))
+ return -EOPNOTSUPP;
+ if (!inode->i_op->set_richacl)
+ return -EOPNOTSUPP;
+
+ if (!uid_eq(current_fsuid(), inode->i_uid) &&
+ inode_permission(inode, MAY_CHMOD) &&
+ !capable(CAP_FOWNER))
+ return -EPERM;
+
+ return inode->i_op->set_richacl(inode, acl);
+}
+EXPORT_SYMBOL(set_richacl);
+
+/**
* __richacl_chmod - update the file masks to reflect the new mode
* @acl: access control list
* @mode: new file permission bits including the file type
diff --git a/fs/richacl_xattr.c b/fs/richacl_xattr.c
index dc1ad36..5eb4aba 100644
--- a/fs/richacl_xattr.c
+++ b/fs/richacl_xattr.c
@@ -18,7 +18,9 @@
#include <linux/fs.h>
#include <linux/slab.h>
#include <linux/module.h>
+#include <linux/xattr.h>
#include <linux/richacl_xattr.h>
+#include <uapi/linux/xattr.h>
/**
* richacl_from_xattr - convert a richacl xattr into the in-memory representation
@@ -159,3 +161,62 @@ richacl_to_xattr(struct user_namespace *user_ns,
return real_size;
}
EXPORT_SYMBOL_GPL(richacl_to_xattr);
+
+static bool
+richacl_xattr_list(struct dentry *dentry)
+{
+ return IS_RICHACL(d_backing_inode(dentry));
+}
+
+static int
+richacl_xattr_get(const struct xattr_handler *handler,
+ struct dentry *unused, struct inode *inode,
+ const char *name, void *buffer, size_t buffer_size)
+{
+ struct richacl *acl;
+ int error;
+
+ if (*name)
+ return -EINVAL;
+ if (!IS_RICHACL(inode))
+ return -EOPNOTSUPP;
+ if (S_ISLNK(inode->i_mode))
+ return -EOPNOTSUPP;
+ acl = get_richacl(inode);
+ if (IS_ERR(acl))
+ return PTR_ERR(acl);
+ if (acl == NULL)
+ return -ENODATA;
+ error = richacl_to_xattr(current_user_ns(), acl, buffer, buffer_size);
+ richacl_put(acl);
+ return error;
+}
+
+static int
+richacl_xattr_set(const struct xattr_handler *handler,
+ struct dentry *unused, struct inode *inode,
+ const char *name, const void *value, size_t size,
+ int flags)
+{
+ struct richacl *acl = NULL;
+ int ret;
+
+ if (value) {
+ acl = richacl_from_xattr(current_user_ns(), value, size,
+ -EINVAL);
+ if (IS_ERR(acl))
+ return PTR_ERR(acl);
+ }
+
+ ret = set_richacl(inode, acl);
+ richacl_put(acl);
+ return ret;
+}
+
+struct xattr_handler richacl_xattr_handler = {
+ .name = XATTR_NAME_RICHACL,
+ .list = richacl_xattr_list,
+ .get = richacl_xattr_get,
+ .set = richacl_xattr_set,
+};
+EXPORT_SYMBOL(richacl_xattr_handler);
diff --git a/include/linux/richacl.h b/include/linux/richacl.h
index 737513b..7530920 100644
--- a/include/linux/richacl.h
+++ b/include/linux/richacl.h
@@ -205,5 +205,6 @@ extern int richacl_chmod(struct inode *, umode_t);
extern int richacl_equiv_mode(const struct richacl *, umode_t *);
extern struct richacl *richacl_inherit(const struct richacl *, int);
extern struct richacl *richacl_create(umode_t *, struct inode *);
+extern int set_richacl(struct inode *, struct richacl *);
#endif /* __RICHACL_H */
diff --git a/include/linux/richacl_xattr.h b/include/linux/richacl_xattr.h
index 0efa14b..6c6adb1 100644
--- a/include/linux/richacl_xattr.h
+++ b/include/linux/richacl_xattr.h
@@ -26,4 +26,6 @@ extern size_t richacl_xattr_size(const struct richacl *);
extern int richacl_to_xattr(struct user_namespace *, const struct richacl *,
void *, size_t);
+extern struct xattr_handler richacl_xattr_handler;
+
#endif /* __RICHACL_XATTR_H */
--
2.5.5
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v24 00/22] Richacls (Core and Ext4) Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:10 +0200 [PATCH v24 03/22] vfs: Add MAY_DELETE_SELF and MAY_DELETE_CHILD permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 21/22] ext4: Add richacl support Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 22/22] ext4: Add richacl feature flag Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 13/22] richacl: Update the file masks in chmod() Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 18/22] richacl: Add richacl xattr handler Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 19/22] vfs: Add richacl permission checking Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 09/22] richacl: Compute maximum file masks from an acl Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 01/22] vfs: Add IS_ACL() and IS_RICHACL() tests Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 20/22] vfs: Move check_posix_acl and check_richacl out of fs/namei.c Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 04/22] vfs: Make the inode passed to inode_change_ok non-const Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 06/22] richacl: In-memory representation and helper functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 02/22] vfs: Add MAY_CREATE_FILE and MAY_CREATE_DIR permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 15/22] richacl: Create-time inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 17/22] richacl: xattr mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 11/22] vfs: Add get_richacl and set_richacl inode operations Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 12/22] vfs: Cache richacl in struct inode Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 05/22] vfs: Add permission flags for setting file attributes Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 08/22] richacl: Permission check algorithm Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 14/22] richacl: Check if an acl is equivalent to a file mode Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 07/22] richacl: Permission mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 10/22] vfs: Cache base_acl objects in inodes Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200 [PATCH v24 16/22] richacl: Automatic Inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2016-07-25 16:20 +0200
csiph-web