diff options
| author | Steven Whitehouse <swhiteho@redhat.com> | 2010-05-24 09:36:48 -0400 |
|---|---|---|
| committer | Steven Whitehouse <swhiteho@redhat.com> | 2010-05-24 09:36:48 -0400 |
| commit | 7df0e0397b9a18358573274db9fdab991941062f (patch) | |
| tree | 2cfad1129b631ade909dc75e32a0ea48f3899a28 | |
| parent | f72f2d2e2f3238e4dedf4afb5f9945b3227dd87e (diff) | |
GFS2: Fix permissions checking for setflags ioctl()
We should be checking for the ownership of the file for which
flags are being set, rather than just for write access.
Reported-by: Dan Rosenberg <dan.j.rosenberg@gmail.com>
Signed-off-by: Steven Whitehouse <swhiteho@redhat.com>
| -rw-r--r-- | fs/gfs2/file.c | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/fs/gfs2/file.c b/fs/gfs2/file.c index e6dd2aec6f82..b20bfcc9fa2d 100644 --- a/fs/gfs2/file.c +++ b/fs/gfs2/file.c | |||
| @@ -218,6 +218,11 @@ static int do_gfs2_set_flags(struct file *filp, u32 reqflags, u32 mask) | |||
| 218 | if (error) | 218 | if (error) |
| 219 | goto out_drop_write; | 219 | goto out_drop_write; |
| 220 | 220 | ||
| 221 | error = -EACCES; | ||
| 222 | if (!is_owner_or_cap(inode)) | ||
| 223 | goto out; | ||
| 224 | |||
| 225 | error = 0; | ||
| 221 | flags = ip->i_diskflags; | 226 | flags = ip->i_diskflags; |
| 222 | new_flags = (flags & ~mask) | (reqflags & mask); | 227 | new_flags = (flags & ~mask) | (reqflags & mask); |
| 223 | if ((new_flags ^ flags) == 0) | 228 | if ((new_flags ^ flags) == 0) |
| @@ -275,8 +280,10 @@ static int gfs2_set_flags(struct file *filp, u32 __user *ptr) | |||
| 275 | { | 280 | { |
| 276 | struct inode *inode = filp->f_path.dentry->d_inode; | 281 | struct inode *inode = filp->f_path.dentry->d_inode; |
| 277 | u32 fsflags, gfsflags; | 282 | u32 fsflags, gfsflags; |
| 283 | |||
| 278 | if (get_user(fsflags, ptr)) | 284 | if (get_user(fsflags, ptr)) |
| 279 | return -EFAULT; | 285 | return -EFAULT; |
| 286 | |||
| 280 | gfsflags = fsflags_cvt(fsflags_to_gfs2, fsflags); | 287 | gfsflags = fsflags_cvt(fsflags_to_gfs2, fsflags); |
| 281 | if (!S_ISDIR(inode->i_mode)) { | 288 | if (!S_ISDIR(inode->i_mode)) { |
| 282 | if (gfsflags & GFS2_DIF_INHERIT_JDATA) | 289 | if (gfsflags & GFS2_DIF_INHERIT_JDATA) |
