From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Aneesh Kumar K.V" Subject: [PATCH -V1 09/22] vfs: Make acl_permission_check() work for richacls Date: Sun, 27 Apr 2014 21:44:40 +0530 Message-ID: <1398615293-22931-10-git-send-email-aneesh.kumar@linux.vnet.ibm.com> References: <1398615293-22931-1-git-send-email-aneesh.kumar@linux.vnet.ibm.com> Cc: aneesh.kumar@linux.vnet.ibm.com, linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org To: agruen@kernel.org, bfields@fieldses.org, akpm@linux-foundation.org, viro@zeniv.linux.org.uk, dhowells@redhat.com Return-path: In-Reply-To: <1398615293-22931-1-git-send-email-aneesh.kumar@linux.vnet.ibm.com> Sender: linux-kernel-owner@vger.kernel.org List-Id: linux-fsdevel.vger.kernel.org From: Andreas Gruenbacher Signed-off-by: Andreas Gruenbacher Signed-off-by: Aneesh Kumar K.V --- fs/namei.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/fs/namei.c b/fs/namei.c index 26b9a8212837..06474553c08d 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -284,6 +284,19 @@ static int acl_permission_check(struct inode *inode, int mask) { unsigned int mode = inode->i_mode; + if (IS_RICHACL(inode)) { + int error = check_acl(inode, mask); + if (error != -EAGAIN) + return error; + if (mask & (MAY_DELETE_SELF | MAY_TAKE_OWNERSHIP | + MAY_CHMOD | MAY_SET_TIMES)) { + /* + * The file permission bit cannot grant these + * permissions. + */ + return -EACCES; + } + } if (likely(uid_eq(current_fsuid(), inode->i_uid))) mode >>= 6; else { -- 1.9.1