From patchwork Wed Oct 10 00:11:06 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darrick J. Wong" X-Patchwork-Id: 10633457 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id A291717E3 for ; Wed, 10 Oct 2018 00:11:13 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 9215529C8B for ; Wed, 10 Oct 2018 00:11:13 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 905CB29BED; Wed, 10 Oct 2018 00:11:13 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.0 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE, UNPARSEABLE_RELAY autolearn=ham version=3.3.1 Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 2323529C8A for ; Wed, 10 Oct 2018 00:11:13 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id E67156B0269; Tue, 9 Oct 2018 20:11:11 -0400 (EDT) Delivered-To: linux-mm-outgoing@kvack.org Received: by kanga.kvack.org (Postfix, from userid 40) id DC7876B026A; Tue, 9 Oct 2018 20:11:11 -0400 (EDT) X-Original-To: int-list-linux-mm@kvack.org X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id C67346B026B; Tue, 9 Oct 2018 20:11:11 -0400 (EDT) X-Original-To: linux-mm@kvack.org X-Delivered-To: linux-mm@kvack.org Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) by kanga.kvack.org (Postfix) with ESMTP id 8759B6B0269 for ; Tue, 9 Oct 2018 20:11:11 -0400 (EDT) Received: by mail-pl1-f199.google.com with SMTP id f5-v6so2630943plf.11 for ; Tue, 09 Oct 2018 17:11:11 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:dkim-signature:subject:from:to:cc:date :message-id:in-reply-to:references:user-agent:mime-version :content-transfer-encoding; bh=dLeY25XICiLWqckKMrtV3v59Uk72O343BuPWK8wy/8U=; b=oOn1RgdM8TZQKujpn7N7alaABzsilQojPeCnCt0aenPLCw1/Qa4Ng1gz4ftC+PH4U6 dUxLgnTlk+q5S0vSXb8iqC0bJrJGLf1+/FLtPIm15LSLpCnx8oNoMm5W78507NoPZC4N lhfQWKE4Gm1NSoIKP44uq5d5z5t1oKZ3X8qAOySeXSsg9yfZ8fEKR7C6ae2tX50WDCvQ UTRgBi+WXTA4lL3PuzJhvMpYZCn5WXLIWPwO1N2/JZY/+GV0QvU9ZUfIUQKsoLjo4ubU jiNPhDsFqGfj6tndKzx9yYvxrAqYVIN/1THIS3NsFChjr1lePwTCaiumU/QEJV9DSmgg mlpw== X-Gm-Message-State: ABuFfoie3VT29i7iUtFjTd4Ox+Mg+wNtYXELUi4fqzFySMEizqwr0/i3 CP8cetsmDYGH5U+RJj8Ze5k14p+5XhBZ7/0fwbFFru4mLRTlilfp4QyjSVhUsbV2ONWoVOkLha9 7NYE2aD7WoY1GRfE9uF2W1NWGquU06PiaJG3ybFi3EpYJVtUseEE9nXtbO1xlz/UMbg== X-Received: by 2002:a17:902:bb96:: with SMTP id m22-v6mr30672382pls.117.1539130271227; Tue, 09 Oct 2018 17:11:11 -0700 (PDT) X-Google-Smtp-Source: ACcGV622BF5q4gwLZRDbkzTGoXuTBggj1PYSauro+MCf1iJgHSzgM9l2aqH9dbIB1TrE/p8j9/Or X-Received: by 2002:a17:902:bb96:: with SMTP id m22-v6mr30672344pls.117.1539130270515; Tue, 09 Oct 2018 17:11:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1539130270; cv=none; d=google.com; s=arc-20160816; b=E+0fOOfYxx8TZL+grltmU9Sn8ohqhVzBPCadzv5/5JnGczIINDBwLH89Jmr+Xko2BA EG1TSw2AvqJ7BAwzUVZGTX4ZQQ+lSMG7/Ks9NpoL5SJVBzEehC7sDGeibGqZ+y8FkyX2 IwC1vIJO4eE6hXufxWXVpDEUhCWO6xxkofpFqWhnAWnz8nJHk7OC3K5oezPD/lBaigAf kz8xJ0xh9Bzxnf5tCd0nY6kyI7QRBe77iHLVT2ZiDtPaXX84gE008v7+3ctGoSsNM9YK N3GHPe+aa7wQysVSUrF87u+0ZNJnj4fYy5/QaJ5Eel5WY3p7QqKxglR/8kyrdiRhv/64 ZkGg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:user-agent:references :in-reply-to:message-id:date:cc:to:from:subject:dkim-signature; bh=dLeY25XICiLWqckKMrtV3v59Uk72O343BuPWK8wy/8U=; b=feXqJcc+IXPZHqWQYUGUsIeWu1cFpVcsjqwCiLb656Nh7zOWXAyaxe+pJL1ycnAsUx 5aMKO37IKRvp8bT08DQg4YPIUNdWE/ZogZop1fK9jfcDsdDiNP6HWDFJUjVrOAxO8ShX KF2rUj5kmvvZCXTh8eOH1dO9U4QIthcPFrMDENv/0gGYj+85KK0bCOPvMdoMRYFlMbQn QiJJ9JnZhibyh21zUfIj+vweJCj8/nLfxr+tg7u0cILuaonf6GoJdHT4UX7gdrLd9iOl 0Dm1Guy0VGnanVW6RCCdJwjCzIJMka/VoGB9w7LkTSY54sSTwKydgpNz97dqdCikJQle DqCw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2018-07-02 header.b=4ROg8HLc; spf=pass (google.com: domain of darrick.wong@oracle.com designates 156.151.31.86 as permitted sender) smtp.mailfrom=darrick.wong@oracle.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Received: from userp2130.oracle.com (userp2130.oracle.com. [156.151.31.86]) by mx.google.com with ESMTPS id z1-v6si22516285plo.59.2018.10.09.17.11.10 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 09 Oct 2018 17:11:10 -0700 (PDT) Received-SPF: pass (google.com: domain of darrick.wong@oracle.com designates 156.151.31.86 as permitted sender) client-ip=156.151.31.86; Authentication-Results: mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2018-07-02 header.b=4ROg8HLc; spf=pass (google.com: domain of darrick.wong@oracle.com designates 156.151.31.86 as permitted sender) smtp.mailfrom=darrick.wong@oracle.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Received: from pps.filterd (userp2130.oracle.com [127.0.0.1]) by userp2130.oracle.com (8.16.0.22/8.16.0.22) with SMTP id w9A08q9u119807; Wed, 10 Oct 2018 00:11:09 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=subject : from : to : cc : date : message-id : in-reply-to : references : mime-version : content-type : content-transfer-encoding; s=corp-2018-07-02; bh=dLeY25XICiLWqckKMrtV3v59Uk72O343BuPWK8wy/8U=; b=4ROg8HLcuay622FiB2cbzs3fYCaZnJhJaTMZVRcW7v8/0zwxlOpwHytxs00L9lzLifjE OamRxAeyzCAxQhCkOCjqXuI7pq8n46HK/tch2QaJhDAHbvbYV+zUzwPpsAxc39jRuaEl 6yodviYMrdbDVtv5EiShuPD9EgsoWsNV5kSxAydV4ahN6x4mbi8hx4aWizmNBynFt4Rd c4l26TMz4xNHg+4SLTwtNElTanXzNNWpATmX8H7Zm/SndmKvswecUPWNezWF2AprL+Wb Q7U77nyhAlJuridLWR6Z0PJTsSp+VTc9KauPB5vyP08G+K94/4kT7AlOnaXce/2aImqR Ig== Received: from userv0021.oracle.com (userv0021.oracle.com [156.151.31.71]) by userp2130.oracle.com with ESMTP id 2mxmftrvg6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 10 Oct 2018 00:11:09 +0000 Received: from userv0122.oracle.com (userv0122.oracle.com [156.151.31.75]) by userv0021.oracle.com (8.14.4/8.14.4) with ESMTP id w9A0B88S031503 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 10 Oct 2018 00:11:09 GMT Received: from abhmp0013.oracle.com (abhmp0013.oracle.com [141.146.116.19]) by userv0122.oracle.com (8.14.4/8.14.4) with ESMTP id w9A0B8hu002889; Wed, 10 Oct 2018 00:11:08 GMT Received: from localhost (/10.159.249.114) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Wed, 10 Oct 2018 00:11:08 +0000 Subject: [PATCH 04/25] xfs: update ctime and remove suid before cloning files From: "Darrick J. Wong" To: david@fromorbit.com, darrick.wong@oracle.com Cc: sandeen@redhat.com, linux-nfs@vger.kernel.org, linux-cifs@vger.kernel.org, linux-unionfs@vger.kernel.org, linux-xfs@vger.kernel.org, linux-mm@kvack.org, linux-btrfs@vger.kernel.org, Dave Chinner , linux-fsdevel@vger.kernel.org, ocfs2-devel@oss.oracle.com Date: Tue, 09 Oct 2018 17:11:06 -0700 Message-ID: <153913026644.32295.612141018276176517.stgit@magnolia> In-Reply-To: <153913023835.32295.13962696655740190941.stgit@magnolia> References: <153913023835.32295.13962696655740190941.stgit@magnolia> User-Agent: StGit/0.17.1-dirty MIME-Version: 1.0 X-Proofpoint-Virus-Version: vendor=nai engine=5900 definitions=9041 signatures=668706 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1807170000 definitions=main-1810100000 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: X-Virus-Scanned: ClamAV using ClamSMTP From: Darrick J. Wong Before cloning into a file, update the ctime and remove sensitive attributes like suid, just like we'd do for a regular file write. Signed-off-by: Darrick J. Wong Reviewed-by: Dave Chinner --- fs/xfs/xfs_reflink.c | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/fs/xfs/xfs_reflink.c b/fs/xfs/xfs_reflink.c index cbb359e68a72..d4feaeba8542 100644 --- a/fs/xfs/xfs_reflink.c +++ b/fs/xfs/xfs_reflink.c @@ -1264,6 +1264,7 @@ xfs_reflink_zero_posteof( * Prepare two files for range cloning. Upon a successful return both inodes * will have the iolock and mmaplock held, the page cache of the out file * will be truncated, and any leases on the out file will have been broken. + * This function borrows heavily from xfs_file_aio_write_checks. * Returns negative for error, 0 for nothing to do, and 1 for success. */ STATIC int @@ -1328,6 +1329,30 @@ xfs_reflink_remap_prep( /* Zap any page cache for the destination file's range. */ truncate_inode_pages_range(&inode_out->i_data, pos_out, PAGE_ALIGN(pos_out + *len) - 1); + + /* If we're altering the file contents... */ + if (!is_dedupe) { + /* + * ...update the timestamps (which will grab the ilock again + * from xfs_fs_dirty_inode, so we have to call it before we + * take the ilock). + */ + if (!(file_out->f_mode & FMODE_NOCMTIME)) { + ret = file_update_time(file_out); + if (ret) + goto out_unlock; + } + + /* + * ...clear the security bits if the process is not being run + * by root. This keeps people from modifying setuid and setgid + * binaries. + */ + ret = file_remove_privs(file_out); + if (ret) + goto out_unlock; + } + return 1; out_unlock: xfs_reflink_remap_unlock(file_in, file_out);