From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Joakim Sindholt <opensource@zhasha.com>,
Eric Van Hensbergen <ericvh@kernel.org>,
Sasha Levin <sashal@kernel.org>,
lucho@ionkov.net, asmadeus@codewreck.org, v9fs@lists.linux.dev
Subject: [PATCH AUTOSEL 5.10 1/9] fs/9p: only translate RWX permissions for plain 9P2000
Date: Tue, 23 Apr 2024 07:02:39 -0400 [thread overview]
Message-ID: <20240423110249.1659263-1-sashal@kernel.org> (raw)
From: Joakim Sindholt <opensource@zhasha.com>
[ Upstream commit cd25e15e57e68a6b18dc9323047fe9c68b99290b ]
Garbage in plain 9P2000's perm bits is allowed through, which causes it
to be able to set (among others) the suid bit. This was presumably not
the intent since the unix extended bits are handled explicitly and
conditionally on .u.
Signed-off-by: Joakim Sindholt <opensource@zhasha.com>
Signed-off-by: Eric Van Hensbergen <ericvh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/9p/vfs_inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c
index 0791480bf922b..88ca5015f987e 100644
--- a/fs/9p/vfs_inode.c
+++ b/fs/9p/vfs_inode.c
@@ -86,7 +86,7 @@ static int p9mode2perm(struct v9fs_session_info *v9ses,
int res;
int mode = stat->mode;
- res = mode & S_IALLUGO;
+ res = mode & 0777; /* S_IRWXUGO */
if (v9fs_proto_dotu(v9ses)) {
if ((mode & P9_DMSETUID) == P9_DMSETUID)
res |= S_ISUID;
--
2.43.0
next reply other threads:[~2024-04-23 11:41 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-04-23 11:02 Sasha Levin [this message]
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 2/9] fs/9p: translate O_TRUNC into OTRUNC Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 3/9] 9p: explicitly deny setlease attempts Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 4/9] gpio: wcove: Use -ENOTSUPP consistently Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 5/9] gpio: crystalcove: " Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 6/9] clk: Don't hold prepare_lock when calling kref_put() Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 7/9] fs/9p: drop inodes immediately on non-.L too Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 8/9] drm/nouveau/dp: Don't probe eDP ports twice harder Sasha Levin
2024-04-23 11:02 ` [PATCH AUTOSEL 5.10 9/9] net:usb:qmi_wwan: support Rolling modules Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240423110249.1659263-1-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=asmadeus@codewreck.org \
--cc=ericvh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lucho@ionkov.net \
--cc=opensource@zhasha.com \
--cc=stable@vger.kernel.org \
--cc=v9fs@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox