diff options
author | Ben Hutchings <ben@decadent.org.uk> | 2017-10-06 03:18:40 +0100 |
---|---|---|
committer | Ben Hutchings <ben@decadent.org.uk> | 2017-10-12 15:27:17 +0100 |
commit | 6b49d3b542cc262009a4d3f878bc003d59b2c304 (patch) | |
tree | 705823f33fab41cb42734a275df627b31d2d6583 /fs | |
parent | 507e6875a25c495191deb089cf0dd47766808a0b (diff) |
ext3: Don't clear SGID when inheriting ACLs
Based on Jan Kara's fix for ext2 (commit a992f2d38e4c), from which the
following description is taken:
> When new directory 'DIR1' is created in a directory 'DIR0' with SGID bit
> set, DIR1 is expected to have SGID bit set (and owning group equal to
> the owning group of 'DIR0'). However when 'DIR0' also has some default
> ACLs that 'DIR1' inherits, setting these ACLs will result in SGID bit on
> 'DIR1' to get cleared if user is not member of the owning group.
>
> Fix the problem by creating __ext2_set_acl() function that does not call
> posix_acl_update_mode() and use it when inheriting ACLs. That prevents
> SGID bit clearing and the mode has been properly set by
> posix_acl_create() anyway.
Fixes: 073931017b49 ("posix_acl: Clear SGID bit when setting file permissions")
Cc: linux-ext4@vger.kernel.org
Cc: Jan Kara <jack@suse.cz>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Diffstat (limited to 'fs')
-rw-r--r-- | fs/ext3/acl.c | 43 |
1 files changed, 26 insertions, 17 deletions
diff --git a/fs/ext3/acl.c b/fs/ext3/acl.c index 880d3d64bb14..0a6db91b556e 100644 --- a/fs/ext3/acl.c +++ b/fs/ext3/acl.c @@ -178,14 +178,9 @@ ext3_get_acl(struct inode *inode, int type) return acl; } -/* - * Set the access or default ACL of an inode. - * - * inode->i_mutex: down unless called from ext3_new_inode - */ static int -ext3_set_acl(handle_t *handle, struct inode *inode, int type, - struct posix_acl *acl) +__ext3_set_acl(handle_t *handle, struct inode *inode, int type, + struct posix_acl *acl) { int name_index; void *value = NULL; @@ -198,13 +193,6 @@ ext3_set_acl(handle_t *handle, struct inode *inode, int type, switch(type) { case ACL_TYPE_ACCESS: name_index = EXT3_XATTR_INDEX_POSIX_ACL_ACCESS; - if (acl) { - error = posix_acl_update_mode(inode, &inode->i_mode, &acl); - if (error) - return error; - inode->i_ctime = CURRENT_TIME_SEC; - ext3_mark_inode_dirty(handle, inode); - } break; case ACL_TYPE_DEFAULT: @@ -234,6 +222,27 @@ ext3_set_acl(handle_t *handle, struct inode *inode, int type, } /* + * Set the access or default ACL of an inode. + * + * inode->i_mutex: down + */ +static int +ext3_set_acl(handle_t *handle, struct inode *inode, int type, + struct posix_acl *acl) +{ + int error; + + if (type == ACL_TYPE_ACCESS && acl) { + error = posix_acl_update_mode(inode, &inode->i_mode, &acl); + if (error) + return error; + inode->i_ctime = CURRENT_TIME_SEC; + ext3_mark_inode_dirty(handle, inode); + } + return __ext3_set_acl(handle, inode, type, acl); +} + +/* * Initialize the ACLs of a new inode. Called from ext3_new_inode. * * dir->i_mutex: down @@ -256,8 +265,8 @@ ext3_init_acl(handle_t *handle, struct inode *inode, struct inode *dir) } if (test_opt(inode->i_sb, POSIX_ACL) && acl) { if (S_ISDIR(inode->i_mode)) { - error = ext3_set_acl(handle, inode, - ACL_TYPE_DEFAULT, acl); + error = __ext3_set_acl(handle, inode, + ACL_TYPE_DEFAULT, acl); if (error) goto cleanup; } @@ -267,7 +276,7 @@ ext3_init_acl(handle_t *handle, struct inode *inode, struct inode *dir) if (error > 0) { /* This is an extended ACL */ - error = ext3_set_acl(handle, inode, ACL_TYPE_ACCESS, acl); + error = __ext3_set_acl(handle, inode, ACL_TYPE_ACCESS, acl); } } cleanup: |