From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 393D736A02E for ; Tue, 21 Jul 2026 06:20:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784614858; cv=none; b=OaTwI/UCgDamAwfTXTdTaFEiMHInwb3QCWNOUMR28V3aaP16Ir3qoWoJ+/Y+UvvOZ1cpRafbW+h/COW/wmze6XH9P3d0clH2vfMlHhZpNZtBuoNQnR2MHTTANO1SAO9PcNcMiG6fmW4eIr/0qxALZcaLZ6Yn2Y9FSV6spfmXvKg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784614858; c=relaxed/simple; bh=0Tj3LFCBAm+Dh1IEtEUuQKH6g+6N7pgBfSJCYkAPS+8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dkxy5RUdUL5zh+QAcsaiEGF8ejf/RiUROvvWOpXOm2O2JuSub9585aP0LpDdNh1s10r51W6eruulE0aKItBkZei3gZHVF84m8QdJoAMbGdobyC8BjkOFPwj2TR0+AyupydAD25TQo7Z0EoWkNHuMR5oki95sv8l2kG358XqS8sg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com; spf=pass smtp.mailfrom=ionos.com; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b=FLtXprgE; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ionos.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b="FLtXprgE" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49555a0e68bso12135595e9.2 for ; Mon, 20 Jul 2026 23:20:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ionos.com; s=google; t=1784614854; x=1785219654; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=C7FP3MNblmlu5NslE4mpBL3j8Z5Uszv4ETHx5WOrkF4=; b=FLtXprgEM4az8nM7wvkDS8KQxb3drFztE/mRMcJ0vE84aaYzVKM1dcz9aVz9Z6Sspr sBKnXX4hAzUA4tOB4V78/nkdJLXo+tk9KHgquKxy7JrMZj3pRHH3awrxhtUgFOQtTHwc Jpa+rZGbc2YyrIeZWrv+jqIeWLn4t+KIe3AVFV3nEmsNgnehWs9P08Q/avRFw8RNkfv9 RIxQfE29nf9P7GxcYid24RoahOXtZKwInJ8gcuR9ruk9r3SaH2WgxZ0FCYSz9J+KB5Sb Bt6IpzGfTjN7/89V7wGAqXEAxH44ks4c1V8mGZpSZsm5/hq7EjLj3YBMPLQyonGkTE/Y pYHw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784614854; x=1785219654; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=C7FP3MNblmlu5NslE4mpBL3j8Z5Uszv4ETHx5WOrkF4=; b=d6u5Rz4WL7eXXyxQgDXkHnchMNBzk8Ee7BeVQOJfqfR/hUWEYaQvJ9bIBLLjdZq31q OSTX7nRnLn+wfrXbRcJgzDPxIbN/XWa5lBC1fv0TF8bjj5rVJrXTmebtAcgv7GKn4Tww SJqfUBOE4Ew6WniN7/Vpdr1VOh/EIcP6cFZf55kQ1b67hdq7JNkNKRJ+5JdavxJpBO6Q yV9cw5rlY+p/8SLVyzRvfusWQo0xK7JIImul1tRvNlsMoIl5K9oRJdBYhmPreKPRQVi2 Q+ybRfAqaJKljdSRtHalcGIrQG2C5lTK5ve58Lz5nx1PsK8lyisOIZ8LNFqCqLbJvE5v 7OSg== X-Forwarded-Encrypted: i=1; AHgh+RpofEKA8iCy4a0CWQzYoOr4KXThOcp/fwiCgt38/OpMnGyYFLQd/BCEBhz1r6FPDfZ+8Piy1l2bIrKcjbg=@vger.kernel.org X-Gm-Message-State: AOJu0YwRRe8toV5o37JaIXSQHQZ4+3R5vi/Ob4BVmziHl7ymfeTpJRGa rloe5sIEg6lDdNzmRNS8ySzwe+zaORwP48bWWhpZLNybbxHtbUBnPp1s2I3HXYOhUF4= X-Gm-Gg: AfdE7ckHPxTR8RTt6CWaR17SFi9SdjIBgqgZAd4OOkjqICCe9ZmyklemEmdbv4A5cEz JWNk7VQuqeGORUZrx+bMXHoT4g8Kq6XX+CNCBcWnq4JV7Q3FcUzqo3gy3GfScRpBiimLxJm/FV/ /2LuLiwP/b6WUBbc8DWzyYOnmU/q7JGNUCw3cPrNlXM4oviohAmKk+C/slaYV9hvnHQV6EhSPdn LAx9/QOuW6p1s4MUtB0XGWwPQ83LwLnbMFFszDJ/3VU0/YnS4JSYHC2JeI6RJOm6fMea5yUT/KJ XDac0FA7P8rICtf9UbsPVC0UplK+pPACmdM47mzVyJ0yLsxj570H96R4vIaU/cBRtOwl6aCs7Jv pyw/y4SXqN5Z3nSUP7ZFpenx7avxO+Glqeecoe/5O6NRgwClyujopklgnPs5R/lTtM9mxyFYKH5 OfVYX90mMGYZz1f4Ig/WdQhQuXgG1dQglYDkOfzVA3a3v2XAMos7ju5iy92sLjR+YBtb//t6ho+ YCubA== X-Received: by 2002:a05:600c:1d18:b0:495:515a:dad9 with SMTP id 5b1f17b1804b1-495515adc7fmr142513775e9.37.1784614854456; Mon, 20 Jul 2026 23:20:54 -0700 (PDT) Received: from raven.intern.cm-ag (p200300dc6f484700023064fffe740809.dip0.t-ipconnect.de. [2003:dc:6f48:4700:230:64ff:fe74:809]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956547af7esm47681535e9.8.2026.07.20.23.20.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 23:20:54 -0700 (PDT) From: Max Kellermann To: idryomov@gmail.com, amarkuze@redhat.com, xiubo.li@clyso.com, ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Max Kellermann Subject: [PATCH] fs/ceph/ioctl: add owner/capability checks for CEPH_IOC_SET_LAYOUT* Date: Tue, 21 Jul 2026 08:20:46 +0200 Message-ID: <20260721062047.3162957-1-max.kellermann@ionos.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit These permission checks were already missing in the initial impementation of these ioctls. This Ceph allows any user who owns a file descriptor to manipulate the layout of any file, even if they don't have write permissions. It might be a good idea to guard other ioctls with permission checks as well or even disallow regular users (even if they own the file) to manipulate layout settings completely, as this may be abused to DoS the Ceph servers, but right now, I find it most urgent to have setter checks at all. Fixes: 8f4e91dee2a2 ("ceph: ioctls") Signed-off-by: Max Kellermann --- Note: this is a resend. I had already sent this to security@ceph.io and security@kernel.org on 2024-11-25, but the Ceph maintainers thought it was "not a big problem". It was never merged. --- fs/ceph/ioctl.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/fs/ceph/ioctl.c b/fs/ceph/ioctl.c index 15cde055f3da..de07f19b0caa 100644 --- a/fs/ceph/ioctl.c +++ b/fs/ceph/ioctl.c @@ -72,6 +72,9 @@ static long ceph_ioctl_set_layout(struct file *file, void __user *arg) struct ceph_ioctl_layout nl; int err; + if (!inode_owner_or_capable(&nop_mnt_idmap, inode)) + return -EACCES; + if (copy_from_user(&l, arg, sizeof(l))) return -EFAULT; @@ -142,6 +145,9 @@ static long ceph_ioctl_set_layout_policy (struct file *file, void __user *arg) int err; struct ceph_mds_client *mdsc = ceph_sb_to_fs_client(inode->i_sb)->mdsc; + if (!inode_owner_or_capable(&nop_mnt_idmap, inode)) + return -EACCES; + /* copy and validate */ if (copy_from_user(&l, arg, sizeof(l))) return -EFAULT; -- 2.47.3