diff options
author | Shirish Pargaonkar <shirishpargaonkar@gmail.com> | 2011-09-26 10:56:44 -0400 |
---|---|---|
committer | Steve French <smfrench@gmail.com> | 2011-10-13 00:42:17 -0400 |
commit | 3d3ea8e64efbeb3e4289675dbbfab82333395642 (patch) | |
tree | 3f7c52039dceefeae2abf010a1a3ec8abef0c459 /fs/cifs/cifsacl.c | |
parent | 8bc4392a1e50f346e97f8777aaefd9cfc3d45c9f (diff) |
cifs: Add mount options for backup intent (try #6)
Add mount options backupuid and backugid.
It allows an authenticated user to access files with the intent to back them
up including their ACLs, who may not have access permission but has
"Backup files and directories user right" on them (by virtue of being part
of the built-in group Backup Operators.
When mount options backupuid is specified, cifs client restricts the
use of backup intents to the user whose effective user id is specified
along with the mount option.
When mount options backupgid is specified, cifs client restricts the
use of backup intents to the users whose effective user id belongs to the
group id specified along with the mount option.
If an authenticated user is not part of the built-in group Backup Operators
at the server, access to such files is denied, even if allowed by the client.
Signed-off-by: Shirish Pargaonkar <shirishpargaonkar@gmail.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <smfrench@gmail.com>
Diffstat (limited to 'fs/cifs/cifsacl.c')
-rw-r--r-- | fs/cifs/cifsacl.c | 18 |
1 files changed, 12 insertions, 6 deletions
diff --git a/fs/cifs/cifsacl.c b/fs/cifs/cifsacl.c index d0f59faefb78..b244e07c3048 100644 --- a/fs/cifs/cifsacl.c +++ b/fs/cifs/cifsacl.c | |||
@@ -945,7 +945,7 @@ static struct cifs_ntsd *get_cifs_acl_by_path(struct cifs_sb_info *cifs_sb, | |||
945 | { | 945 | { |
946 | struct cifs_ntsd *pntsd = NULL; | 946 | struct cifs_ntsd *pntsd = NULL; |
947 | int oplock = 0; | 947 | int oplock = 0; |
948 | int xid, rc; | 948 | int xid, rc, create_options = 0; |
949 | __u16 fid; | 949 | __u16 fid; |
950 | struct cifs_tcon *tcon; | 950 | struct cifs_tcon *tcon; |
951 | struct tcon_link *tlink = cifs_sb_tlink(cifs_sb); | 951 | struct tcon_link *tlink = cifs_sb_tlink(cifs_sb); |
@@ -956,9 +956,12 @@ static struct cifs_ntsd *get_cifs_acl_by_path(struct cifs_sb_info *cifs_sb, | |||
956 | tcon = tlink_tcon(tlink); | 956 | tcon = tlink_tcon(tlink); |
957 | xid = GetXid(); | 957 | xid = GetXid(); |
958 | 958 | ||
959 | rc = CIFSSMBOpen(xid, tcon, path, FILE_OPEN, READ_CONTROL, 0, | 959 | if (backup_cred(cifs_sb)) |
960 | &fid, &oplock, NULL, cifs_sb->local_nls, | 960 | create_options |= CREATE_OPEN_BACKUP_INTENT; |
961 | cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MAP_SPECIAL_CHR); | 961 | |
962 | rc = CIFSSMBOpen(xid, tcon, path, FILE_OPEN, READ_CONTROL, | ||
963 | create_options, &fid, &oplock, NULL, cifs_sb->local_nls, | ||
964 | cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MAP_SPECIAL_CHR); | ||
962 | if (!rc) { | 965 | if (!rc) { |
963 | rc = CIFSSMBGetCIFSACL(xid, tcon, fid, &pntsd, pacllen); | 966 | rc = CIFSSMBGetCIFSACL(xid, tcon, fid, &pntsd, pacllen); |
964 | CIFSSMBClose(xid, tcon, fid); | 967 | CIFSSMBClose(xid, tcon, fid); |
@@ -995,7 +998,7 @@ static int set_cifs_acl_by_path(struct cifs_sb_info *cifs_sb, const char *path, | |||
995 | struct cifs_ntsd *pnntsd, u32 acllen) | 998 | struct cifs_ntsd *pnntsd, u32 acllen) |
996 | { | 999 | { |
997 | int oplock = 0; | 1000 | int oplock = 0; |
998 | int xid, rc; | 1001 | int xid, rc, create_options = 0; |
999 | __u16 fid; | 1002 | __u16 fid; |
1000 | struct cifs_tcon *tcon; | 1003 | struct cifs_tcon *tcon; |
1001 | struct tcon_link *tlink = cifs_sb_tlink(cifs_sb); | 1004 | struct tcon_link *tlink = cifs_sb_tlink(cifs_sb); |
@@ -1006,7 +1009,10 @@ static int set_cifs_acl_by_path(struct cifs_sb_info *cifs_sb, const char *path, | |||
1006 | tcon = tlink_tcon(tlink); | 1009 | tcon = tlink_tcon(tlink); |
1007 | xid = GetXid(); | 1010 | xid = GetXid(); |
1008 | 1011 | ||
1009 | rc = CIFSSMBOpen(xid, tcon, path, FILE_OPEN, WRITE_DAC, 0, | 1012 | if (backup_cred(cifs_sb)) |
1013 | create_options |= CREATE_OPEN_BACKUP_INTENT; | ||
1014 | |||
1015 | rc = CIFSSMBOpen(xid, tcon, path, FILE_OPEN, WRITE_DAC, create_options, | ||
1010 | &fid, &oplock, NULL, cifs_sb->local_nls, | 1016 | &fid, &oplock, NULL, cifs_sb->local_nls, |
1011 | cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MAP_SPECIAL_CHR); | 1017 | cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MAP_SPECIAL_CHR); |
1012 | if (rc) { | 1018 | if (rc) { |