From patchwork Tue Aug 4 11:53:21 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: =?utf-8?q?Andreas_Gr=C3=BCnbacher?= X-Patchwork-Id: 6937431 Return-Path: X-Original-To: patchwork-linux-fsdevel@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork1.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.136]) by patchwork1.web.kernel.org (Postfix) with ESMTP id 7A85F9F38B for ; Tue, 4 Aug 2015 12:02:55 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id 9DF8320456 for ; Tue, 4 Aug 2015 12:02:54 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id C593C2045E for ; Tue, 4 Aug 2015 12:02:53 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933721AbbHDLzY (ORCPT ); Tue, 4 Aug 2015 07:55:24 -0400 Received: from mail-wi0-f182.google.com ([209.85.212.182]:37155 "EHLO mail-wi0-f182.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S933695AbbHDLzV (ORCPT ); Tue, 4 Aug 2015 07:55:21 -0400 Received: by wibud3 with SMTP id ud3so20342379wib.0; Tue, 04 Aug 2015 04:55:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=Y52Whbas6UftppVoxtk3hCI12vKP2hZZHeTFCm6HDlM=; b=Ou6+YIcWuGWqxd3BNq2qScuqryR0Haz7gtOzd5leevpDnzCktajnuRmfEsciug2kkG eVPKW5kIJJheJ7FjoiGYymEChSJbsUo1nLFfzpf/2yon4FqlrW8MeMTNzYAghGEw6/qY 6UCAjl/TKX7u7JYMo+7JXcRhvyLx5dUyW6/KWukZxK7rlO3Q7uz1Wf5UF+SKhgbPWBif ApavxaZKtRgidpIjUFcTpJiNF5PTFYQOOaCcqxbUM4mltDBZKtcZEoEwr9yWKAzRmbo4 CEKz6Kea9zsn2rJGqzMGvu144gsVOu8iWv8p4EnKms8OlRJf8ZwQCgwG35zDmuixL7Rs CgGA== X-Received: by 10.194.109.97 with SMTP id hr1mr7387471wjb.38.1438689318885; Tue, 04 Aug 2015 04:55:18 -0700 (PDT) Received: from schleppi.home.com (p54980F84.dip0.t-ipconnect.de. [84.152.15.132]) by smtp.gmail.com with ESMTPSA id u7sm2018458wif.3.2015.08.04.04.55.16 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 04 Aug 2015 04:55:18 -0700 (PDT) From: Andreas Gruenbacher X-Google-Original-From: Andreas Gruenbacher To: linux-kernel@vger.kernel.org Cc: linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org, linux-api@vger.kernel.org, linux-cifs@vger.kernel.org, linux-security-module@vger.kernel.org, Andreas Gruenbacher Subject: [RFC v6 23/40] richacl: Set the owner permissions to the owner mask Date: Tue, 4 Aug 2015 13:53:21 +0200 Message-Id: <1438689218-6921-24-git-send-email-agruenba@redhat.com> X-Mailer: git-send-email 2.5.0 In-Reply-To: <1438689218-6921-1-git-send-email-agruenba@redhat.com> References: <1438689218-6921-1-git-send-email-agruenba@redhat.com> Sender: linux-fsdevel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-fsdevel@vger.kernel.org X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_HI, RP_MATCHES_RCVD, SUSPICIOUS_RECIPS, T_DKIM_INVALID, UNPARSEABLE_RELAY autolearn=unavailable version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Change the acl so that owner@ is granted the permissions set in the owner mask. Signed-off-by: Andreas Gruenbacher --- fs/richacl_compat.c | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) diff --git a/fs/richacl_compat.c b/fs/richacl_compat.c index e9c350e..807372d 100644 --- a/fs/richacl_compat.c +++ b/fs/richacl_compat.c @@ -412,3 +412,49 @@ richacl_propagate_everyone(struct richacl_alloc *alloc) } return 0; } + +/** + * richacl_set_owner_permissions - set the owner permissions to the owner mask + * + * Change the acl so that owner@ is granted the permissions set in the owner + * mask. This leaves at most one efective owner@ allow entry at the beginning + * of the acl. + */ +static int +richacl_set_owner_permissions(struct richacl_alloc *alloc) +{ + unsigned int x = RICHACE_POSIX_ALWAYS_ALLOWED; + unsigned int owner_mask = alloc->acl->a_owner_mask & ~x; + unsigned int denied = 0; + struct richace *ace; + + if (!((alloc->acl->a_flags & RICHACL_WRITE_THROUGH) && + (alloc->acl->a_flags & RICHACL_MASKED))) + return 0; + + richacl_for_each_entry(ace, alloc->acl) { + if (richace_is_owner(ace)) { + if (richace_is_allow(ace) && !(owner_mask & denied)) { + richace_change_mask(alloc, &ace, owner_mask); + owner_mask = 0; + } else + richace_change_mask(alloc, &ace, 0); + } else { + if (richace_is_deny(ace)) + denied |= ace->e_mask; + } + } + + if (owner_mask & (denied | + ~alloc->acl->a_other_mask | + ~alloc->acl->a_group_mask)) { + ace = alloc->acl->a_entries; + if (richacl_insert_entry(alloc, &ace)) + return -1; + ace->e_type = RICHACE_ACCESS_ALLOWED_ACE_TYPE; + ace->e_flags = RICHACE_SPECIAL_WHO; + ace->e_mask = owner_mask; + ace->e_id.special = RICHACE_OWNER_SPECIAL_ID; + } + return 0; +}