From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-15.0 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, MENTIONS_GIT_HOSTING,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,USER_AGENT_GIT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90C4DC06511 for ; Wed, 3 Jul 2019 12:48:55 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 653BB218A4 for ; Wed, 3 Jul 2019 12:48:55 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="c1Ga63pN" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727086AbfGCMsu (ORCPT ); Wed, 3 Jul 2019 08:48:50 -0400 Received: from mail-wr1-f67.google.com ([209.85.221.67]:37116 "EHLO mail-wr1-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727222AbfGCMr3 (ORCPT ); Wed, 3 Jul 2019 08:47:29 -0400 Received: by mail-wr1-f67.google.com with SMTP id v14so2673509wrr.4; Wed, 03 Jul 2019 05:47:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=RI/DgxnmV4iAu3TqAUK19hxYZSHJoXYPEmLHYgwhdLA=; b=c1Ga63pN8WYFieikwxkbf/j423IvTHFuSlIWFWoTlXzmbMyVCj/V5HPbjJtMtPaSox JXzV1xpnA4AnTfx3cbV1jhdJxv3GoEAGIgjDjWMgcRxVYSixIAVMwS+/Ll2dGBE68C5z V5wmptPuovuxeHUQr67RVFYN3PKyJPa8Sji8IOppBcNPREOfIsyEMuO6h9oIy+PMPdVK k4mmxwCWxy5Goxf7xawR/Ofg54YsNVCAeqOtEHHWQFkpZF2Zwn0ow8AtFLOtVKY7oOWF mJPnZH0Zs0Qi/DkPEry6e72WYwXmCXFq4q41ABJ+p/QbIYaBefQnUWQ2nBtgoUwdwUGX 1rWg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=RI/DgxnmV4iAu3TqAUK19hxYZSHJoXYPEmLHYgwhdLA=; b=I1ulqwEmnWcyf/rP2+cMpc67JDPm4hWwcmyAuQKZMlrsZY+D3GDKqY9W8lGgFWKWWI y4wf5LRsQWZsDjD8DoU40ZNtPca8XfC6oHcLBDqrAgCMprHfSoVxnDpy+LKBzeFkrqBX qEqowL7dJQWTOosUMNUk4vRxPRgXE/2L43poNn7DRTEswSzbWHeFAp0Qs2dtMMBMjXqL GkeeABYQ8z8LzusA3eugoC/rwuTPPHIvBAGnGqW0JByEy+cGAEHT5htHVA+rvb3y27Zz BG6dTwzo0qoKNAivdvED22dauZCUA0mniYxT+cQAnGIGbBJXxlLFPIVh6oOGAHzZiBJQ aTtA== X-Gm-Message-State: APjAAAVqo9HsCayU28TELDzoktxvPKjcp6Yz1hib2sQj+AgtAWJZ+ker V+o40bIx5sVEprQLC7tRvRIanGcOXSM= X-Google-Smtp-Source: APXvYqyDSUVMJmoAuLKYvuPltd15RRJwej7+QPAsNgyn4lJ1V+obPuOOc/VMQzvYJYqt7biAFvJz/A== X-Received: by 2002:adf:f591:: with SMTP id f17mr30262141wro.119.1562158047270; Wed, 03 Jul 2019 05:47:27 -0700 (PDT) Received: from heron.blarg.de (p200300DC6F443A000000000000000FD2.dip0.t-ipconnect.de. [2003:dc:6f44:3a00::fd2]) by smtp.gmail.com with ESMTPSA id o24sm5480588wmh.2.2019.07.03.05.47.26 (version=TLS1_3 cipher=AEAD-AES256-GCM-SHA384 bits=256/256); Wed, 03 Jul 2019 05:47:26 -0700 (PDT) From: Max Kellermann To: linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org, trond.myklebust@hammerspace.com, bfields@redhat.com, gregkh@linuxfoundation.org, tytso@mit.edu, adilger.kernel@dilger.ca, hughd@google.com, anna.schumaker@netapp.com Cc: linux-kernel@vger.kernel.org, Max Kellermann Subject: [PATCH 1/4] fs/posix_acl: apply umask if superblock disables ACL support Date: Wed, 3 Jul 2019 14:47:12 +0200 Message-Id: <20190703124715.4319-1-max.kellermann@gmail.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-nfs-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-nfs@vger.kernel.org The function posix_acl_create() applies the umask only if the inode has no ACL (= NULL) or if ACLs are not supported by the filesystem driver (= -EOPNOTSUPP). However, this happens only after after the IS_POSIXACL() check succeeeded. If the superblock doesn't enable ACL support, umask will never be applied. A filesystem which has no ACL support will of course not enable SB_POSIXACL, rendering the umask-applying code path unreachable. This fixes a bug which causes the umask to be ignored with O_TMPFILE on tmpfs: https://github.com/MusicPlayerDaemon/MPD/issues/558 https://bugs.gentoo.org/show_bug.cgi?id=686142#c3 https://bugzilla.kernel.org/show_bug.cgi?id=203625 Signed-off-by: Max Kellermann --- fs/posix_acl.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/fs/posix_acl.c b/fs/posix_acl.c index 2fd0fde16fe1..815f7b36ef94 100644 --- a/fs/posix_acl.c +++ b/fs/posix_acl.c @@ -588,9 +588,14 @@ posix_acl_create(struct inode *dir, umode_t *mode, *acl = NULL; *default_acl = NULL; - if (S_ISLNK(*mode) || !IS_POSIXACL(dir)) + if (S_ISLNK(*mode)) return 0; + if (!IS_POSIXACL(dir)) { + *mode &= ~current_umask(); + return 0; + } + p = get_acl(dir, ACL_TYPE_DEFAULT); if (!p || p == ERR_PTR(-EOPNOTSUPP)) { *mode &= ~current_umask(); -- 2.20.1