From patchwork Wed Feb 23 13:51:49 2011 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Aneesh Kumar K.V" X-Patchwork-Id: 584911 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by demeter1.kernel.org (8.14.4/8.14.3) with ESMTP id p1NE2BH1029727 for ; Wed, 23 Feb 2011 14:02:34 GMT Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755399Ab1BWOBl (ORCPT ); Wed, 23 Feb 2011 09:01:41 -0500 Received: from e28smtp03.in.ibm.com ([122.248.162.3]:36677 "EHLO e28smtp03.in.ibm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755294Ab1BWNw5 (ORCPT ); Wed, 23 Feb 2011 08:52:57 -0500 Received: from d28relay01.in.ibm.com (d28relay01.in.ibm.com [9.184.220.58]) by e28smtp03.in.ibm.com (8.14.4/8.13.1) with ESMTP id p1NDqsXM005215; Wed, 23 Feb 2011 19:22:54 +0530 Received: from d28av05.in.ibm.com (d28av05.in.ibm.com [9.184.220.67]) by d28relay01.in.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id p1NDqqx94051056; Wed, 23 Feb 2011 19:22:53 +0530 Received: from d28av05.in.ibm.com (loopback [127.0.0.1]) by d28av05.in.ibm.com (8.14.4/8.13.1/NCO v10.0 AVout) with ESMTP id p1NDqnYE016416; Thu, 24 Feb 2011 00:52:51 +1100 Received: from skywalker.ibm.com ([9.77.68.27]) by d28av05.in.ibm.com (8.14.4/8.13.1/NCO v10.0 AVin) with ESMTP id p1NDqS1t014791; Thu, 24 Feb 2011 00:52:46 +1100 From: "Aneesh Kumar K.V" To: sfrench@us.ibm.com, agruen@linbit.com, dilger.kernel@dilger.ca, sandeen@redhat.com, tytso@mit.edu, bfields@fieldses.org, jlayton@redhat.com Cc: aneesh.kumar@linux.vnet.ibm.com, linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org, linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org, Andreas Gruenbacher Subject: [PATCH -V5 02/24] vfs: Pass all mask flags down to iop->check_acl Date: Wed, 23 Feb 2011 19:21:49 +0530 Message-Id: <1298469131-16555-3-git-send-email-aneesh.kumar@linux.vnet.ibm.com> X-Mailer: git-send-email 1.7.1 In-Reply-To: <1298469131-16555-1-git-send-email-aneesh.kumar@linux.vnet.ibm.com> References: <1298469131-16555-1-git-send-email-aneesh.kumar@linux.vnet.ibm.com> Sender: linux-nfs-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-nfs@vger.kernel.org X-Greylist: IP, sender and recipient auto-whitelisted, not delayed by milter-greylist-4.2.6 (demeter1.kernel.org [140.211.167.41]); Wed, 23 Feb 2011 14:02:34 +0000 (UTC) diff --git a/fs/namei.c b/fs/namei.c index b01eab8..f09ab1f 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -174,8 +174,6 @@ static int acl_permission_check(struct inode *inode, int mask, unsigned int flag { umode_t mode = inode->i_mode; - mask &= MAY_READ | MAY_WRITE | MAY_EXEC; - if (current_fsuid() == inode->i_uid) mode >>= 6; else { @@ -192,7 +190,7 @@ static int acl_permission_check(struct inode *inode, int mask, unsigned int flag /* * If the DACs are ok we don't need any capability check. */ - if ((mask & ~mode) == 0) + if ((mask & (MAY_READ | MAY_WRITE | MAY_EXEC) & ~mode) == 0) return 0; return -EACCES; } diff --git a/fs/posix_acl.c b/fs/posix_acl.c index b1cf6bf..ad40df2 100644 --- a/fs/posix_acl.c +++ b/fs/posix_acl.c @@ -222,6 +222,8 @@ posix_acl_permission(struct inode *inode, const struct posix_acl *acl, int want) const struct posix_acl_entry *pa, *pe, *mask_obj; int found = 0; + want &= MAY_READ | MAY_WRITE | MAY_EXEC; + FOREACH_ACL_ENTRY(pa, acl, pe) { switch(pa->e_tag) { case ACL_USER_OBJ: