2005-04-17 02:20:36 +04:00
/*
* linux / fs / ext2 / acl . c
*
* Copyright ( C ) 2001 - 2003 Andreas Gruenbacher , < agruen @ suse . de >
*/
2006-01-11 23:17:46 +03:00
# include <linux/capability.h>
2005-04-17 02:20:36 +04:00
# include <linux/init.h>
# include <linux/sched.h>
# include <linux/slab.h>
# include <linux/fs.h>
# include "ext2.h"
# include "xattr.h"
# include "acl.h"
/*
* Convert from filesystem to in - memory representation .
*/
static struct posix_acl *
ext2_acl_from_disk ( const void * value , size_t size )
{
const char * end = ( char * ) value + size ;
int n , count ;
struct posix_acl * acl ;
if ( ! value )
return NULL ;
if ( size < sizeof ( ext2_acl_header ) )
return ERR_PTR ( - EINVAL ) ;
if ( ( ( ext2_acl_header * ) value ) - > a_version ! =
cpu_to_le32 ( EXT2_ACL_VERSION ) )
return ERR_PTR ( - EINVAL ) ;
value = ( char * ) value + sizeof ( ext2_acl_header ) ;
count = ext2_acl_count ( size ) ;
if ( count < 0 )
return ERR_PTR ( - EINVAL ) ;
if ( count = = 0 )
return NULL ;
acl = posix_acl_alloc ( count , GFP_KERNEL ) ;
if ( ! acl )
return ERR_PTR ( - ENOMEM ) ;
for ( n = 0 ; n < count ; n + + ) {
ext2_acl_entry * entry =
( ext2_acl_entry * ) value ;
if ( ( char * ) value + sizeof ( ext2_acl_entry_short ) > end )
goto fail ;
acl - > a_entries [ n ] . e_tag = le16_to_cpu ( entry - > e_tag ) ;
acl - > a_entries [ n ] . e_perm = le16_to_cpu ( entry - > e_perm ) ;
switch ( acl - > a_entries [ n ] . e_tag ) {
case ACL_USER_OBJ :
case ACL_GROUP_OBJ :
case ACL_MASK :
case ACL_OTHER :
value = ( char * ) value +
sizeof ( ext2_acl_entry_short ) ;
acl - > a_entries [ n ] . e_id = ACL_UNDEFINED_ID ;
break ;
case ACL_USER :
case ACL_GROUP :
value = ( char * ) value + sizeof ( ext2_acl_entry ) ;
if ( ( char * ) value > end )
goto fail ;
acl - > a_entries [ n ] . e_id =
le32_to_cpu ( entry - > e_id ) ;
break ;
default :
goto fail ;
}
}
if ( value ! = end )
goto fail ;
return acl ;
fail :
posix_acl_release ( acl ) ;
return ERR_PTR ( - EINVAL ) ;
}
/*
* Convert from in - memory to filesystem representation .
*/
static void *
ext2_acl_to_disk ( const struct posix_acl * acl , size_t * size )
{
ext2_acl_header * ext_acl ;
char * e ;
size_t n ;
* size = ext2_acl_size ( acl - > a_count ) ;
2006-09-27 12:49:39 +04:00
ext_acl = kmalloc ( sizeof ( ext2_acl_header ) + acl - > a_count *
sizeof ( ext2_acl_entry ) , GFP_KERNEL ) ;
2005-04-17 02:20:36 +04:00
if ( ! ext_acl )
return ERR_PTR ( - ENOMEM ) ;
ext_acl - > a_version = cpu_to_le32 ( EXT2_ACL_VERSION ) ;
e = ( char * ) ext_acl + sizeof ( ext2_acl_header ) ;
for ( n = 0 ; n < acl - > a_count ; n + + ) {
ext2_acl_entry * entry = ( ext2_acl_entry * ) e ;
entry - > e_tag = cpu_to_le16 ( acl - > a_entries [ n ] . e_tag ) ;
entry - > e_perm = cpu_to_le16 ( acl - > a_entries [ n ] . e_perm ) ;
switch ( acl - > a_entries [ n ] . e_tag ) {
case ACL_USER :
case ACL_GROUP :
entry - > e_id =
cpu_to_le32 ( acl - > a_entries [ n ] . e_id ) ;
e + = sizeof ( ext2_acl_entry ) ;
break ;
case ACL_USER_OBJ :
case ACL_GROUP_OBJ :
case ACL_MASK :
case ACL_OTHER :
e + = sizeof ( ext2_acl_entry_short ) ;
break ;
default :
goto fail ;
}
}
return ( char * ) ext_acl ;
fail :
kfree ( ext_acl ) ;
return ERR_PTR ( - EINVAL ) ;
}
/*
2006-01-10 02:59:24 +03:00
* inode - > i_mutex : don ' t care
2005-04-17 02:20:36 +04:00
*/
2011-07-23 19:37:31 +04:00
struct posix_acl *
2005-04-17 02:20:36 +04:00
ext2_get_acl ( struct inode * inode , int type )
{
int name_index ;
char * value = NULL ;
struct posix_acl * acl ;
int retval ;
if ( ! test_opt ( inode - > i_sb , POSIX_ACL ) )
return NULL ;
2009-06-09 20:11:54 +04:00
acl = get_cached_acl ( inode , type ) ;
if ( acl ! = ACL_NOT_CACHED )
return acl ;
switch ( type ) {
case ACL_TYPE_ACCESS :
name_index = EXT2_XATTR_INDEX_POSIX_ACL_ACCESS ;
break ;
case ACL_TYPE_DEFAULT :
name_index = EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT ;
break ;
default :
BUG ( ) ;
2005-04-17 02:20:36 +04:00
}
retval = ext2_xattr_get ( inode , name_index , " " , NULL , 0 ) ;
if ( retval > 0 ) {
value = kmalloc ( retval , GFP_KERNEL ) ;
if ( ! value )
return ERR_PTR ( - ENOMEM ) ;
retval = ext2_xattr_get ( inode , name_index , " " , value , retval ) ;
}
if ( retval > 0 )
acl = ext2_acl_from_disk ( value , retval ) ;
else if ( retval = = - ENODATA | | retval = = - ENOSYS )
acl = NULL ;
else
acl = ERR_PTR ( retval ) ;
2005-11-07 12:01:34 +03:00
kfree ( value ) ;
2005-04-17 02:20:36 +04:00
2009-06-09 20:11:54 +04:00
if ( ! IS_ERR ( acl ) )
set_cached_acl ( inode , type , acl ) ;
2005-04-17 02:20:36 +04:00
return acl ;
}
/*
2006-01-10 02:59:24 +03:00
* inode - > i_mutex : down
2005-04-17 02:20:36 +04:00
*/
static int
ext2_set_acl ( struct inode * inode , int type , struct posix_acl * acl )
{
int name_index ;
void * value = NULL ;
2006-02-03 14:04:13 +03:00
size_t size = 0 ;
2005-04-17 02:20:36 +04:00
int error ;
if ( S_ISLNK ( inode - > i_mode ) )
return - EOPNOTSUPP ;
if ( ! test_opt ( inode - > i_sb , POSIX_ACL ) )
return 0 ;
switch ( type ) {
case ACL_TYPE_ACCESS :
name_index = EXT2_XATTR_INDEX_POSIX_ACL_ACCESS ;
if ( acl ) {
2011-07-24 02:56:36 +04:00
error = posix_acl_equiv_mode ( acl , & inode - > i_mode ) ;
2005-04-17 02:20:36 +04:00
if ( error < 0 )
return error ;
else {
2010-06-02 18:26:51 +04:00
inode - > i_ctime = CURRENT_TIME_SEC ;
2005-04-17 02:20:36 +04:00
mark_inode_dirty ( inode ) ;
if ( error = = 0 )
acl = NULL ;
}
}
break ;
case ACL_TYPE_DEFAULT :
name_index = EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT ;
if ( ! S_ISDIR ( inode - > i_mode ) )
return acl ? - EACCES : 0 ;
break ;
default :
return - EINVAL ;
}
if ( acl ) {
value = ext2_acl_to_disk ( acl , & size ) ;
if ( IS_ERR ( value ) )
return ( int ) PTR_ERR ( value ) ;
}
error = ext2_xattr_set ( inode , name_index , " " , value , size , 0 ) ;
2005-11-07 12:01:34 +03:00
kfree ( value ) ;
2009-06-09 20:11:54 +04:00
if ( ! error )
set_cached_acl ( inode , type , acl ) ;
2005-04-17 02:20:36 +04:00
return error ;
}
/*
* Initialize the ACLs of a new inode . Called from ext2_new_inode .
*
2006-01-10 02:59:24 +03:00
* dir - > i_mutex : down
* inode - > i_mutex : up ( access to inode is still exclusive )
2005-04-17 02:20:36 +04:00
*/
int
ext2_init_acl ( struct inode * inode , struct inode * dir )
{
struct posix_acl * acl = NULL ;
int error = 0 ;
if ( ! S_ISLNK ( inode - > i_mode ) ) {
if ( test_opt ( dir - > i_sb , POSIX_ACL ) ) {
acl = ext2_get_acl ( dir , ACL_TYPE_DEFAULT ) ;
if ( IS_ERR ( acl ) )
return PTR_ERR ( acl ) ;
}
if ( ! acl )
2009-03-30 03:08:22 +04:00
inode - > i_mode & = ~ current_umask ( ) ;
2005-04-17 02:20:36 +04:00
}
if ( test_opt ( inode - > i_sb , POSIX_ACL ) & & acl ) {
if ( S_ISDIR ( inode - > i_mode ) ) {
error = ext2_set_acl ( inode , ACL_TYPE_DEFAULT , acl ) ;
if ( error )
goto cleanup ;
}
2011-07-24 02:37:50 +04:00
error = posix_acl_create ( & acl , GFP_KERNEL , & inode - > i_mode ) ;
2011-07-23 11:10:32 +04:00
if ( error < 0 )
return error ;
if ( error > 0 ) {
/* This is an extended ACL */
error = ext2_set_acl ( inode , ACL_TYPE_ACCESS , acl ) ;
2005-04-17 02:20:36 +04:00
}
}
cleanup :
posix_acl_release ( acl ) ;
return error ;
}
/*
* Does chmod for an inode that may have an Access Control List . The
* inode - > i_mode field must be updated to the desired value by the caller
* before calling this function .
* Returns 0 on success , or a negative error number .
*
* We change the ACL rather than storing some ACL entries in the file
* mode permission bits ( which would be more efficient ) , because that
* would break once additional permissions ( like ACL_APPEND , ACL_DELETE
* for directories ) are added . There are no more bits available in the
* file mode .
*
2006-01-10 02:59:24 +03:00
* inode - > i_mutex : down
2005-04-17 02:20:36 +04:00
*/
int
ext2_acl_chmod ( struct inode * inode )
{
2011-07-23 08:18:02 +04:00
struct posix_acl * acl ;
2005-04-17 02:20:36 +04:00
int error ;
if ( ! test_opt ( inode - > i_sb , POSIX_ACL ) )
return 0 ;
if ( S_ISLNK ( inode - > i_mode ) )
return - EOPNOTSUPP ;
acl = ext2_get_acl ( inode , ACL_TYPE_ACCESS ) ;
if ( IS_ERR ( acl ) | | ! acl )
return PTR_ERR ( acl ) ;
2011-07-23 08:18:02 +04:00
error = posix_acl_chmod ( & acl , GFP_KERNEL , inode - > i_mode ) ;
if ( error )
return error ;
error = ext2_set_acl ( inode , ACL_TYPE_ACCESS , acl ) ;
2005-04-17 02:20:36 +04:00
posix_acl_release ( acl ) ;
return error ;
}
/*
* Extended attribut handlers
*/
static size_t
2009-11-13 12:52:56 +03:00
ext2_xattr_list_acl_access ( struct dentry * dentry , char * list , size_t list_size ,
const char * name , size_t name_len , int type )
2005-04-17 02:20:36 +04:00
{
2005-06-23 11:10:19 +04:00
const size_t size = sizeof ( POSIX_ACL_XATTR_ACCESS ) ;
2005-04-17 02:20:36 +04:00
2009-11-13 12:52:56 +03:00
if ( ! test_opt ( dentry - > d_sb , POSIX_ACL ) )
2005-04-17 02:20:36 +04:00
return 0 ;
if ( list & & size < = list_size )
2005-06-23 11:10:19 +04:00
memcpy ( list , POSIX_ACL_XATTR_ACCESS , size ) ;
2005-04-17 02:20:36 +04:00
return size ;
}
static size_t
2009-11-13 12:52:56 +03:00
ext2_xattr_list_acl_default ( struct dentry * dentry , char * list , size_t list_size ,
const char * name , size_t name_len , int type )
2005-04-17 02:20:36 +04:00
{
2005-06-23 11:10:19 +04:00
const size_t size = sizeof ( POSIX_ACL_XATTR_DEFAULT ) ;
2005-04-17 02:20:36 +04:00
2009-11-13 12:52:56 +03:00
if ( ! test_opt ( dentry - > d_sb , POSIX_ACL ) )
2005-04-17 02:20:36 +04:00
return 0 ;
if ( list & & size < = list_size )
2005-06-23 11:10:19 +04:00
memcpy ( list , POSIX_ACL_XATTR_DEFAULT , size ) ;
2005-04-17 02:20:36 +04:00
return size ;
}
static int
2009-11-13 12:52:56 +03:00
ext2_xattr_get_acl ( struct dentry * dentry , const char * name , void * buffer ,
size_t size , int type )
2005-04-17 02:20:36 +04:00
{
struct posix_acl * acl ;
int error ;
2009-11-13 12:52:56 +03:00
if ( strcmp ( name , " " ) ! = 0 )
return - EINVAL ;
if ( ! test_opt ( dentry - > d_sb , POSIX_ACL ) )
2005-04-17 02:20:36 +04:00
return - EOPNOTSUPP ;
2009-11-13 12:52:56 +03:00
acl = ext2_get_acl ( dentry - > d_inode , type ) ;
2005-04-17 02:20:36 +04:00
if ( IS_ERR ( acl ) )
return PTR_ERR ( acl ) ;
if ( acl = = NULL )
return - ENODATA ;
error = posix_acl_to_xattr ( acl , buffer , size ) ;
posix_acl_release ( acl ) ;
return error ;
}
static int
2009-11-13 12:52:56 +03:00
ext2_xattr_set_acl ( struct dentry * dentry , const char * name , const void * value ,
size_t size , int flags , int type )
2005-04-17 02:20:36 +04:00
{
struct posix_acl * acl ;
int error ;
2009-11-13 12:52:56 +03:00
if ( strcmp ( name , " " ) ! = 0 )
return - EINVAL ;
if ( ! test_opt ( dentry - > d_sb , POSIX_ACL ) )
2005-04-17 02:20:36 +04:00
return - EOPNOTSUPP ;
2011-03-24 02:43:26 +03:00
if ( ! inode_owner_or_capable ( dentry - > d_inode ) )
2005-04-17 02:20:36 +04:00
return - EPERM ;
if ( value ) {
acl = posix_acl_from_xattr ( value , size ) ;
if ( IS_ERR ( acl ) )
return PTR_ERR ( acl ) ;
else if ( acl ) {
error = posix_acl_valid ( acl ) ;
if ( error )
goto release_and_out ;
}
} else
acl = NULL ;
2009-11-13 12:52:56 +03:00
error = ext2_set_acl ( dentry - > d_inode , type , acl ) ;
2005-04-17 02:20:36 +04:00
release_and_out :
posix_acl_release ( acl ) ;
return error ;
}
2010-05-14 04:53:16 +04:00
const struct xattr_handler ext2_xattr_acl_access_handler = {
2005-06-23 11:10:19 +04:00
. prefix = POSIX_ACL_XATTR_ACCESS ,
2009-11-13 12:52:56 +03:00
. flags = ACL_TYPE_ACCESS ,
2005-04-17 02:20:36 +04:00
. list = ext2_xattr_list_acl_access ,
2009-11-13 12:52:56 +03:00
. get = ext2_xattr_get_acl ,
. set = ext2_xattr_set_acl ,
2005-04-17 02:20:36 +04:00
} ;
2010-05-14 04:53:16 +04:00
const struct xattr_handler ext2_xattr_acl_default_handler = {
2005-06-23 11:10:19 +04:00
. prefix = POSIX_ACL_XATTR_DEFAULT ,
2009-11-13 12:52:56 +03:00
. flags = ACL_TYPE_DEFAULT ,
2005-04-17 02:20:36 +04:00
. list = ext2_xattr_list_acl_default ,
2009-11-13 12:52:56 +03:00
. get = ext2_xattr_get_acl ,
. set = ext2_xattr_set_acl ,
2005-04-17 02:20:36 +04:00
} ;