Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1359417
| From | Andreas Gruenbacher <agruenba@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH v20 21/23] vfs: Add richacl permission checking |
| Date | 2016-03-16 23:30 +0100 |
| Message-ID | <rds72-6Wr-53@gated-at.bofh.it> (permalink) |
| References | <rdrXj-6Sv-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hook the richacl permission checking function into the vfs.
Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
---
fs/namei.c | 51 +++++++++++++++++++++++++++++++++++++++++++++++++--
fs/posix_acl.c | 6 +++---
2 files changed, 52 insertions(+), 5 deletions(-)
diff --git a/fs/namei.c b/fs/namei.c
index 28707ae..b55cee6 100644
--- a/fs/namei.c
+++ b/fs/namei.c
@@ -35,6 +35,7 @@
#include <linux/fs_struct.h>
#include <linux/posix_acl.h>
#include <linux/hash.h>
+#include <linux/richacl.h>
#include <asm/uaccess.h>
#include "internal.h"
@@ -255,7 +256,40 @@ void putname(struct filename *name)
__putname(name);
}
-static int check_acl(struct inode *inode, int mask)
+static int check_richacl(struct inode *inode, int mask)
+{
+#ifdef CONFIG_FS_RICHACL
+ struct richacl *acl;
+
+ if (mask & MAY_NOT_BLOCK) {
+ acl = get_cached_richacl_rcu(inode);
+ if (!acl)
+ goto no_acl;
+ /* no ->get_richacl() calls in RCU mode... */
+ if (acl == ACL_NOT_CACHED)
+ return -ECHILD;
+ return richacl_permission(inode, acl, mask & ~MAY_NOT_BLOCK);
+ }
+
+ acl = get_richacl(inode);
+ if (IS_ERR(acl))
+ return PTR_ERR(acl);
+ if (acl) {
+ int error = richacl_permission(inode, acl, mask);
+ richacl_put(acl);
+ return error;
+ }
+no_acl:
+#endif
+ if (mask & (MAY_DELETE_SELF | MAY_TAKE_OWNERSHIP |
+ MAY_CHMOD | MAY_SET_TIMES)) {
+ /* File permission bits cannot grant this. */
+ return -EACCES;
+ }
+ return -EAGAIN;
+}
+
+static int check_posix_acl(struct inode *inode, int mask)
{
#ifdef CONFIG_FS_POSIX_ACL
struct posix_acl *acl;
@@ -290,11 +324,24 @@ static int acl_permission_check(struct inode *inode, int mask)
{
unsigned int mode = inode->i_mode;
+ /*
+ * With POSIX ACLs, the (mode & S_IRWXU) bits exactly match the owner
+ * permissions, and we can skip checking posix acls for the owner.
+ * With richacls, the owner may be granted fewer permissions than the
+ * mode bits seem to suggest (for example, append but not write), and
+ * we always need to check the richacl.
+ */
+
+ if (IS_RICHACL(inode)) {
+ int error = check_richacl(inode, mask);
+ if (error != -EAGAIN)
+ return error;
+ }
if (likely(uid_eq(current_fsuid(), inode->i_uid)))
mode >>= 6;
else {
if (IS_POSIXACL(inode) && (mode & S_IRWXG)) {
- int error = check_acl(inode, mask);
+ int error = check_posix_acl(inode, mask);
if (error != -EAGAIN)
return error;
}
diff --git a/fs/posix_acl.c b/fs/posix_acl.c
index f24646e..7810c6f 100644
--- a/fs/posix_acl.c
+++ b/fs/posix_acl.c
@@ -100,13 +100,13 @@ struct posix_acl *get_acl(struct inode *inode, int type)
{
struct posix_acl *acl;
+ if (!IS_POSIXACL(inode))
+ return NULL;
+
acl = get_cached_acl(inode, type);
if (acl != ACL_NOT_CACHED)
return acl;
- if (!IS_POSIXACL(inode))
- return NULL;
-
/*
* A filesystem can force a ACL callback by just never filling the
* ACL cache. But normally you'd fill the cache either at inode
--
2.5.0
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v20 00/23] Richacls (Core and Ext4) Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:20 +0100 [PATCH v20 03/23] vfs: Add MAY_DELETE_SELF and MAY_DELETE_CHILD permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:20 +0100 [PATCH v20 01/23] vfs: Add IS_ACL() and IS_RICHACL() tests Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:20 +0100 [PATCH v20 11/23] posix_acl: Improve xattr fixup code Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 13/23] vfs: Add get_richacl and set_richacl inode operations Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 05/23] vfs: Add permission flags for setting file attributes Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 09/23] richacl: Permission check algorithm Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 14/23] vfs: Cache richacl in struct inode Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 23/23] ext4: Add richacl feature flag Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 10/23] posix_acl: Unexport acl_by_type and make it static Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 04/23] vfs: Make the inode passed to inode_change_ok non-const Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 02/23] vfs: Add MAY_CREATE_FILE and MAY_CREATE_DIR permission flags Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 22/23] ext4: Add richacl support Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 08/23] richacl: Compute maximum file masks from an acl Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 16/23] richacl: Check if an acl is equivalent to a file mode Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 19/23] richacl: xattr mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 06/23] richacl: In-memory representation and helper functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 21/23] vfs: Add richacl permission checking Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 07/23] richacl: Permission mapping functions Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 12/23] vfs: Cache base_acl objects in inodes Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 20/23] richacl: Add richacl xattr handler Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 18/23] richacl: Automatic Inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 15/23] richacl: Update the file masks in chmod() Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100 [PATCH v20 17/23] richacl: Create-time inheritance Andreas Gruenbacher <agruenba@redhat.com> - 2016-03-16 23:30 +0100
csiph-web