Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1385303

[PATCH v3 11/21] cred: Reject inodes with invalid ids in set_create_file_as()

From Seth Forshee <seth.forshee@canonical.com>
Newsgroups linux.kernel
Subject [PATCH v3 11/21] cred: Reject inodes with invalid ids in set_create_file_as()
Date 2016-04-22 17:50 +0200
Message-ID <rqLvc-49a-29@gated-at.bofh.it> (permalink)
References <rqLlw-44Z-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Using INVALID_[UG]ID for the LSM file creation context doesn't
make sense, so return an error if the inode passed to
set_create_file_as() has an invalid id.

Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
Acked-by: Serge Hallyn <serge.hallyn@canonical.com>
---
 kernel/cred.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/kernel/cred.c b/kernel/cred.c
index 0c0cd8a62285..5f264fb5737d 100644
--- a/kernel/cred.c
+++ b/kernel/cred.c
@@ -689,6 +689,8 @@ EXPORT_SYMBOL(set_security_override_from_ctx);
  */
 int set_create_files_as(struct cred *new, struct inode *inode)
 {
+	if (!uid_valid(inode->i_uid) || !gid_valid(inode->i_gid))
+		return -EINVAL;
 	new->fsuid = inode->i_uid;
 	new->fsgid = inode->i_gid;
 	return security_kernel_create_files_as(new, inode);
-- 
1.9.1

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v3 00/21] Support fuse mounts in user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
  [PATCH v3 17/21] capabilities: Allow privileged user in s_user_ns to set security.* xattrs Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
  [PATCH v3 01/21] fs: fix a posible leak of allocated superblock Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
  [PATCH v3 15/21] fs: Don't remove suid for CAP_FSETID in s_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
  [PATCH v3 16/21] fs: Allow superblock owner to access do_remount_sb() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 05/21] block_dev: Check permissions towards block device inode when mounting Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 04/21] block_dev: Support checking inode permissions in lookup_bdev() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 12/21] fs: Refuse uid/gid changes which don't map into s_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
    Re: [PATCH v3 14/21] fs: Allow superblock owner to change ownership  of inodes with unmappable ids "Serge E. Hallyn" <serge@hallyn.com> - 2016-04-25 22:40 +0200
      Re: [PATCH v3 14/21] fs: Allow superblock owner to change ownership  of inodes with unmappable ids Seth Forshee <seth.forshee@canonical.com> - 2016-04-26 21:50 +0200
  [PATCH v3 11/21] cred: Reject inodes with invalid ids in set_create_file_as() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 19/21] fuse: Support fuse filesystems outside of init_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 21/21] fuse: Allow user namespace mounts Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 20/21] fuse: Restrict allow_other to the superblock's namespace or a descendant Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 10/21] fs: Check for invalid i_uid in may_follow_link() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 09/21] Smack: Handle labels consistently in untrusted mounts Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 18/21] fuse: Add support for pid namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 08/21] userns: Replace in_userns with current_in_userns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
  [PATCH v3 06/21] fs: Treat foreign mounts as nosuid Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
  [PATCH v3 07/21] selinux: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
  [PATCH v3 03/21] fs: Allow sysfs and cgroupfs to share super blocks between user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
    Re: [PATCH v3 03/21] fs: Allow sysfs and cgroupfs to share super  blocks between user namespaces "Serge E. Hallyn" <serge@hallyn.com> - 2016-04-25 21:10 +0200
  [PATCH v3 02/21] fs: Remove check of s_user_ns for existing mounts in fs_fully_visible() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200

csiph-web