]>
Commit | Line | Data |
---|---|---|
f0c8bd16 | 1 | /* |
f0c8bd16 AG |
2 | * (C) 2005 Andreas Gruenbacher <[email protected]> |
3 | * | |
4 | * This file is released under the GPL. | |
1c7c474c CH |
5 | * |
6 | * Generic ACL support for in-memory filesystems. | |
f0c8bd16 AG |
7 | */ |
8 | ||
9 | #include <linux/sched.h> | |
5a0e3ad6 | 10 | #include <linux/gfp.h> |
f0c8bd16 AG |
11 | #include <linux/fs.h> |
12 | #include <linux/generic_acl.h> | |
1c7c474c CH |
13 | #include <linux/posix_acl.h> |
14 | #include <linux/posix_acl_xattr.h> | |
f0c8bd16 | 15 | |
1c7c474c CH |
16 | |
17 | static size_t | |
18 | generic_acl_list(struct dentry *dentry, char *list, size_t list_size, | |
19 | const char *name, size_t name_len, int type) | |
f0c8bd16 AG |
20 | { |
21 | struct posix_acl *acl; | |
1c7c474c | 22 | const char *xname; |
f0c8bd16 AG |
23 | size_t size; |
24 | ||
1c7c474c | 25 | acl = get_cached_acl(dentry->d_inode, type); |
f0c8bd16 AG |
26 | if (!acl) |
27 | return 0; | |
28 | posix_acl_release(acl); | |
29 | ||
1c7c474c CH |
30 | switch (type) { |
31 | case ACL_TYPE_ACCESS: | |
32 | xname = POSIX_ACL_XATTR_ACCESS; | |
33 | break; | |
34 | case ACL_TYPE_DEFAULT: | |
35 | xname = POSIX_ACL_XATTR_DEFAULT; | |
36 | break; | |
37 | default: | |
38 | return 0; | |
f0c8bd16 | 39 | } |
1c7c474c | 40 | size = strlen(xname) + 1; |
f0c8bd16 | 41 | if (list && size <= list_size) |
1c7c474c | 42 | memcpy(list, xname, size); |
f0c8bd16 AG |
43 | return size; |
44 | } | |
45 | ||
1c7c474c CH |
46 | static int |
47 | generic_acl_get(struct dentry *dentry, const char *name, void *buffer, | |
48 | size_t size, int type) | |
f0c8bd16 AG |
49 | { |
50 | struct posix_acl *acl; | |
51 | int error; | |
52 | ||
1c7c474c CH |
53 | if (strcmp(name, "") != 0) |
54 | return -EINVAL; | |
55 | ||
56 | acl = get_cached_acl(dentry->d_inode, type); | |
f0c8bd16 AG |
57 | if (!acl) |
58 | return -ENODATA; | |
59 | error = posix_acl_to_xattr(acl, buffer, size); | |
60 | posix_acl_release(acl); | |
61 | ||
62 | return error; | |
63 | } | |
64 | ||
1c7c474c CH |
65 | static int |
66 | generic_acl_set(struct dentry *dentry, const char *name, const void *value, | |
67 | size_t size, int flags, int type) | |
f0c8bd16 | 68 | { |
1c7c474c | 69 | struct inode *inode = dentry->d_inode; |
f0c8bd16 AG |
70 | struct posix_acl *acl = NULL; |
71 | int error; | |
72 | ||
1c7c474c CH |
73 | if (strcmp(name, "") != 0) |
74 | return -EINVAL; | |
f0c8bd16 AG |
75 | if (S_ISLNK(inode->i_mode)) |
76 | return -EOPNOTSUPP; | |
3bd858ab | 77 | if (!is_owner_or_cap(inode)) |
f0c8bd16 AG |
78 | return -EPERM; |
79 | if (value) { | |
80 | acl = posix_acl_from_xattr(value, size); | |
81 | if (IS_ERR(acl)) | |
82 | return PTR_ERR(acl); | |
83 | } | |
84 | if (acl) { | |
85 | mode_t mode; | |
86 | ||
87 | error = posix_acl_valid(acl); | |
88 | if (error) | |
89 | goto failed; | |
1c7c474c CH |
90 | switch (type) { |
91 | case ACL_TYPE_ACCESS: | |
92 | mode = inode->i_mode; | |
93 | error = posix_acl_equiv_mode(acl, &mode); | |
94 | if (error < 0) | |
95 | goto failed; | |
96 | inode->i_mode = mode; | |
dad5eb6d | 97 | inode->i_ctime = CURRENT_TIME; |
1c7c474c CH |
98 | if (error == 0) { |
99 | posix_acl_release(acl); | |
100 | acl = NULL; | |
101 | } | |
102 | break; | |
103 | case ACL_TYPE_DEFAULT: | |
104 | if (!S_ISDIR(inode->i_mode)) { | |
105 | error = -EINVAL; | |
106 | goto failed; | |
107 | } | |
108 | break; | |
f0c8bd16 AG |
109 | } |
110 | } | |
1c7c474c | 111 | set_cached_acl(inode, type, acl); |
f0c8bd16 AG |
112 | error = 0; |
113 | failed: | |
114 | posix_acl_release(acl); | |
115 | return error; | |
116 | } | |
117 | ||
118 | /** | |
119 | * generic_acl_init - Take care of acl inheritance at @inode create time | |
f0c8bd16 AG |
120 | * |
121 | * Files created inside a directory with a default ACL inherit the | |
122 | * directory's default ACL. | |
123 | */ | |
124 | int | |
1c7c474c | 125 | generic_acl_init(struct inode *inode, struct inode *dir) |
f0c8bd16 AG |
126 | { |
127 | struct posix_acl *acl = NULL; | |
128 | mode_t mode = inode->i_mode; | |
129 | int error; | |
130 | ||
ce3b0f8d | 131 | inode->i_mode = mode & ~current_umask(); |
f0c8bd16 | 132 | if (!S_ISLNK(inode->i_mode)) |
1c7c474c | 133 | acl = get_cached_acl(dir, ACL_TYPE_DEFAULT); |
f0c8bd16 AG |
134 | if (acl) { |
135 | struct posix_acl *clone; | |
136 | ||
137 | if (S_ISDIR(inode->i_mode)) { | |
138 | clone = posix_acl_clone(acl, GFP_KERNEL); | |
139 | error = -ENOMEM; | |
140 | if (!clone) | |
141 | goto cleanup; | |
1c7c474c | 142 | set_cached_acl(inode, ACL_TYPE_DEFAULT, clone); |
f0c8bd16 AG |
143 | posix_acl_release(clone); |
144 | } | |
145 | clone = posix_acl_clone(acl, GFP_KERNEL); | |
146 | error = -ENOMEM; | |
147 | if (!clone) | |
148 | goto cleanup; | |
149 | error = posix_acl_create_masq(clone, &mode); | |
150 | if (error >= 0) { | |
151 | inode->i_mode = mode; | |
152 | if (error > 0) | |
1c7c474c | 153 | set_cached_acl(inode, ACL_TYPE_ACCESS, clone); |
f0c8bd16 AG |
154 | } |
155 | posix_acl_release(clone); | |
156 | } | |
157 | error = 0; | |
158 | ||
159 | cleanup: | |
160 | posix_acl_release(acl); | |
161 | return error; | |
162 | } | |
163 | ||
164 | /** | |
165 | * generic_acl_chmod - change the access acl of @inode upon chmod() | |
f0c8bd16 AG |
166 | * |
167 | * A chmod also changes the permissions of the owner, group/mask, and | |
168 | * other ACL entries. | |
169 | */ | |
170 | int | |
1c7c474c | 171 | generic_acl_chmod(struct inode *inode) |
f0c8bd16 AG |
172 | { |
173 | struct posix_acl *acl, *clone; | |
174 | int error = 0; | |
175 | ||
176 | if (S_ISLNK(inode->i_mode)) | |
177 | return -EOPNOTSUPP; | |
1c7c474c | 178 | acl = get_cached_acl(inode, ACL_TYPE_ACCESS); |
f0c8bd16 AG |
179 | if (acl) { |
180 | clone = posix_acl_clone(acl, GFP_KERNEL); | |
181 | posix_acl_release(acl); | |
182 | if (!clone) | |
183 | return -ENOMEM; | |
184 | error = posix_acl_chmod_masq(clone, inode->i_mode); | |
185 | if (!error) | |
1c7c474c | 186 | set_cached_acl(inode, ACL_TYPE_ACCESS, clone); |
f0c8bd16 AG |
187 | posix_acl_release(clone); |
188 | } | |
189 | return error; | |
190 | } | |
1c7c474c CH |
191 | |
192 | int | |
193 | generic_check_acl(struct inode *inode, int mask) | |
194 | { | |
195 | struct posix_acl *acl = get_cached_acl(inode, ACL_TYPE_ACCESS); | |
196 | ||
197 | if (acl) { | |
198 | int error = posix_acl_permission(inode, acl, mask); | |
199 | posix_acl_release(acl); | |
200 | return error; | |
201 | } | |
202 | return -EAGAIN; | |
203 | } | |
204 | ||
bb435453 | 205 | const struct xattr_handler generic_acl_access_handler = { |
1c7c474c CH |
206 | .prefix = POSIX_ACL_XATTR_ACCESS, |
207 | .flags = ACL_TYPE_ACCESS, | |
208 | .list = generic_acl_list, | |
209 | .get = generic_acl_get, | |
210 | .set = generic_acl_set, | |
211 | }; | |
212 | ||
bb435453 | 213 | const struct xattr_handler generic_acl_default_handler = { |
1c7c474c CH |
214 | .prefix = POSIX_ACL_XATTR_DEFAULT, |
215 | .flags = ACL_TYPE_DEFAULT, | |
216 | .list = generic_acl_list, | |
217 | .get = generic_acl_get, | |
218 | .set = generic_acl_set, | |
219 | }; |