From patchwork Wed May 4 14:26:51 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Djalal Harouni X-Patchwork-Id: 9014701 Return-Path: X-Original-To: patchwork-linux-fsdevel@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork1.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.136]) by patchwork1.web.kernel.org (Postfix) with ESMTP id B63279F39D for ; Wed, 4 May 2016 14:31:50 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id BC125203AA for ; Wed, 4 May 2016 14:31:49 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 96173203A1 for ; Wed, 4 May 2016 14:31:48 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752798AbcEDOba (ORCPT ); Wed, 4 May 2016 10:31:30 -0400 Received: from mail-wm0-f43.google.com ([74.125.82.43]:35114 "EHLO mail-wm0-f43.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752686AbcEDO3t (ORCPT ); Wed, 4 May 2016 10:29:49 -0400 Received: by mail-wm0-f43.google.com with SMTP id e201so190634512wme.0; Wed, 04 May 2016 07:29:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=xsoShJb5EcCztvoNhILCoi7Wu6ifKoH9yP1QyFtvhgw=; b=W6Erxrt+sJFybNtcu1C+rnOP3CoQ8KKO36Bsxo9i9ddNKVwrBAnMy3UD96ws+hvXoC wAWMnWb59xCvywisksN0i7Ox5V7oHeyVYRjY7SBQKxXy67SoTteHzV/Iy8aOVIf2cHiy 0fSN2w+w5Fjehm4oHz+ICRq4IKGDPI2VzC3ML/h9u1WjIDVKERwCc9mBKhx6UroLeICB y1uArqqPjsyzhWYtIHeBmeDXPn68mYznsPJLpa6E2uxsmRS5T0hhsVw6f6mEFOpKsE7m 4WCF0p/TlmDjmOu2l+QEJV3mTkxjNiLIbSky8t1ROzEaCXNDqwjDcOGmZYXWGosn7/p7 xINw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=xsoShJb5EcCztvoNhILCoi7Wu6ifKoH9yP1QyFtvhgw=; b=Z/7np5AmaCGbtzDHtdqcbErBW448PmmAxYeSj1Lv6J8EpjCcK7OyS+zcbjnYa7NRHM XUqOB+nEWWvb9rnRzGOr6eyPMdguTUUAqLkvo1eSiY1Ja/YGqrt8FuEXswz146KZFPK1 Yxvla+kfAdueMAHyguVxZGFNUOd6oS1+va7RqUe5+wabioLHC9tWiklPZPvvk/9Spoca JPbZHg37hbJJY/X5UmrZW3vTOTppD030/5IWCNOvtG7906eVA+KJ9jnx7H1fT3p3mue/ +Dc/W6DG2sNwyIGGamBpX+mTVOXdhUKdSr1EUNnaq2BXVqwaUSDLsL1g5vK4ifC9RrhN A/EQ== X-Gm-Message-State: AOPr4FWfdMCei62TTTtWyPWTqbLHDf7eO/vZo7cRiUZGHPOCFnr6Md1hZ7XUczyd5ZzlQg== X-Received: by 10.194.231.104 with SMTP id tf8mr8822212wjc.5.1462372187506; Wed, 04 May 2016 07:29:47 -0700 (PDT) Received: from dztty2.localdomain (ip5b42f9c9.dynamic.kabel-deutschland.de. [91.66.249.201]) by smtp.gmail.com with ESMTPSA id a75sm4615505wme.18.2016.05.04.07.29.45 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 04 May 2016 07:29:46 -0700 (PDT) From: Djalal Harouni To: Alexander Viro , Chris Mason , , Serge Hallyn , Josh Triplett , "Eric W. Biederman" , Andy Lutomirski , Seth Forshee , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Dongsu Park , David Herrmann , Miklos Szeredi , Alban Crequy Cc: Djalal Harouni , Djalal Harouni Subject: [RFC v2 PATCH 5/8] VFS:userns: add helpers to shift UIDs and GIDs into on-disk view Date: Wed, 4 May 2016 16:26:51 +0200 Message-Id: <1462372014-3786-6-git-send-email-tixxdz@gmail.com> X-Mailer: git-send-email 2.5.5 In-Reply-To: <1462372014-3786-1-git-send-email-tixxdz@gmail.com> References: <1462372014-3786-1-git-send-email-tixxdz@gmail.com> Sender: linux-fsdevel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-fsdevel@vger.kernel.org X-Spam-Status: No, score=-8.9 required=5.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_HI, RP_MATCHES_RCVD, T_DKIM_INVALID, UNPARSEABLE_RELAY autolearn=unavailable version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Add helpers to allow the VFS to shift UIDs and GIDs into on-disk view according to the user namespace of the containing mount namespace. All decisions are taken by VFS. This is a preparation patch for the next one where we convert kuid and kgid to be written into disk. To allow the shift of UID and GID, filesystems when mounted must set "vfs_shift_uids" and "vfs_shift_gids" options, otherwise no shift is performed at all. vfs_shift_kuid_to_disk() and vfs_shift_kgid_to_disk() take two arugments, the inode that we are trying to update on-disk and the corresponding kuid and kgid that should be used to update inode->{i_uid|i_gid} values. To convert to on-disk value we perform: 1) First check if UID/GID shift is enabled on the inode which means the filesystem and current mount namespace. 2) If the passed kuid has a mapping in the user namespace of the containing mount namespace, then get the correspondig uid_t value otherwise we fallback to init_user_ns 3) Finally construct the kuid from the pair init_user_ns and uid_t values, this will always reflects what should be put into inode->{i_uid|i_gid} on the disk. If a mount supports VFS UID/GID shifts shows up in a mount namespace that allows UID/GID shifts, these helpers will handle the shift to on-disk view and perform the translation accordingly. Signed-off-by: Dongsu Park Signed-off-by: Djalal Harouni --- fs/namespace.c | 93 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ include/linux/fs.h | 3 ++ 2 files changed, 96 insertions(+) diff --git a/fs/namespace.c b/fs/namespace.c index a8820fb..7df896b 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -1726,6 +1726,99 @@ kgid_t vfs_shift_i_gid_to_virtual(const struct inode *inode) return i_gid; } +/* + * Returns the on-disk UID view of the passed kuid that is supposed to be + * used to update the inode's uid. + * If UID shifts are enabled on the mount namespace and the filesystem, + * the VFS will return the on-disk view of the passed kuid. If no shift is + * performed, kuid is returned without any change. + */ +kuid_t vfs_shift_kuid_to_disk(const struct inode *inode, kuid_t kuid) +{ + uid_t uid; + struct mnt_namespace *ns; + + if (!current->mm) + return kuid; + + ns = current->nsproxy->mnt_ns; + + /* Nothing to do */ + if (!vfs_mount_shift_i_uid(ns, inode)) + return kuid; + + /* + * If kuid has a mapping in the mountns get its uid_t otherwise get it + * from init_user_ns + */ + if (kuid_has_mapping(ns->user_ns, kuid)) + uid = from_kuid(ns->user_ns, kuid); + else + uid = from_kuid(&init_user_ns, kuid); + + if (uid == (uid_t) -1) + return kuid; + + /* Get the final kuid that will be used for on-disk writes */ + return make_kuid(&init_user_ns, uid); +} + +/* + * Returns the on-disk GID view of the passed kgid that is supposed to be + * used to update the inode's gid. + * If GID shifts are enabled on the mount namespace and the filesystem, + * the VFS will return the on-disk view of the passed kgid. If no shift is + * performed, kgid is returned without any change. + */ +kgid_t vfs_shift_kgid_to_disk(const struct inode *inode, kgid_t kgid) +{ + gid_t gid; + struct mnt_namespace *ns; + + if (!current->mm) + return kgid; + + ns = current->nsproxy->mnt_ns; + + /* Nothing to do ? */ + if (!vfs_mount_shift_i_gid(ns, inode)) + return kgid; + + /* + * If kgid has a mapping in the mountns get its gid_t otherwise get it + * from init_user_ns + */ + if (kgid_has_mapping(ns->user_ns, kgid)) + gid = from_kgid(ns->user_ns, kgid); + else + gid = from_kgid(&init_user_ns, kgid); + + if (gid == (gid_t) -1) + return kgid; + + /* Get the final kgid that will be used for on-disk writes */ + return make_kgid(&init_user_ns, gid); +} + +/* + * Converts the passed kgid from on-disk view into the virtual one and returns it. + * It takes two arguments, the inode where the related kgid is supposed to be + * used, and the kgid. + */ +kgid_t vfs_kgid_disk_to_virtual(const struct inode *inode, kgid_t kgid) +{ + struct mnt_namespace *ns = current->nsproxy->mnt_ns; + + /* shift kgid if necessary */ + if (!vfs_mount_shift_i_gid(ns, inode)) + return kgid; + + if (!kgid_has_mapping(ns->user_ns, kgid)) + return make_kgid(ns->user_ns, kgid.val); + + return kgid; +} + static bool mnt_ns_loop(struct dentry *dentry) { /* Could bind mounting the mount namespace inode cause a diff --git a/include/linux/fs.h b/include/linux/fs.h index a9efc5a..e957474 100644 --- a/include/linux/fs.h +++ b/include/linux/fs.h @@ -1573,6 +1573,9 @@ extern void inode_init_owner(struct inode *inode, const struct inode *dir, */ extern kuid_t vfs_shift_i_uid_to_virtual(const struct inode *inode); extern kgid_t vfs_shift_i_gid_to_virtual(const struct inode *inode); +extern kgid_t vfs_kgid_disk_to_virtual(const struct inode *inode, kgid_t kgid); +extern kuid_t vfs_shift_kuid_to_disk(const struct inode *inode, kuid_t kuid); +extern kgid_t vfs_shift_kgid_to_disk(const struct inode *inode, kgid_t kgid); /* * VFS FS_IOC_FIEMAP helper definitions.