2 * Copyright (C) International Business Machines Corp., 2002-2004
3 * Copyright (C) Andreas Gruenbacher, 2001
4 * Copyright (C) Linus Torvalds, 1991, 1992
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See
14 * the GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
21 #include <linux/sched.h>
23 #include <linux/quotaops.h>
24 #include "jfs_incore.h"
25 #include "jfs_xattr.h"
28 static struct posix_acl
*jfs_get_acl(struct inode
*inode
, int type
)
30 struct posix_acl
*acl
;
32 struct jfs_inode_info
*ji
= JFS_IP(inode
);
33 struct posix_acl
**p_acl
;
39 ea_name
= XATTR_NAME_ACL_ACCESS
;
42 case ACL_TYPE_DEFAULT
:
43 ea_name
= XATTR_NAME_ACL_DEFAULT
;
44 p_acl
= &ji
->i_default_acl
;
47 return ERR_PTR(-EINVAL
);
50 if (*p_acl
!= JFS_ACL_NOT_CACHED
)
51 return posix_acl_dup(*p_acl
);
53 size
= __jfs_getxattr(inode
, ea_name
, NULL
, 0);
56 value
= kmalloc(size
, GFP_KERNEL
);
58 return ERR_PTR(-ENOMEM
);
59 size
= __jfs_getxattr(inode
, ea_name
, value
, size
);
63 if (size
== -ENODATA
) {
69 acl
= posix_acl_from_xattr(value
, size
);
71 *p_acl
= posix_acl_dup(acl
);
78 static int jfs_set_acl(struct inode
*inode
, int type
, struct posix_acl
*acl
)
81 struct jfs_inode_info
*ji
= JFS_IP(inode
);
82 struct posix_acl
**p_acl
;
87 if (S_ISLNK(inode
->i_mode
))
92 ea_name
= XATTR_NAME_ACL_ACCESS
;
95 case ACL_TYPE_DEFAULT
:
96 ea_name
= XATTR_NAME_ACL_DEFAULT
;
97 p_acl
= &ji
->i_default_acl
;
98 if (!S_ISDIR(inode
->i_mode
))
99 return acl
? -EACCES
: 0;
105 size
= xattr_acl_size(acl
->a_count
);
106 value
= kmalloc(size
, GFP_KERNEL
);
109 rc
= posix_acl_to_xattr(acl
, value
, size
);
113 rc
= __jfs_setxattr(inode
, ea_name
, value
, size
, 0);
119 if (*p_acl
&& (*p_acl
!= JFS_ACL_NOT_CACHED
))
120 posix_acl_release(*p_acl
);
121 *p_acl
= posix_acl_dup(acl
);
129 * modified vfs_permission to check posix acl
131 int jfs_permission(struct inode
* inode
, int mask
, struct nameidata
*nd
)
133 umode_t mode
= inode
->i_mode
;
134 struct jfs_inode_info
*ji
= JFS_IP(inode
);
136 if (mask
& MAY_WRITE
) {
138 * Nobody gets write access to a read-only fs.
140 if (IS_RDONLY(inode
) &&
141 (S_ISREG(mode
) || S_ISDIR(mode
) || S_ISLNK(mode
)))
145 * Nobody gets write access to an immutable file.
147 if (IS_IMMUTABLE(inode
))
151 if (current
->fsuid
== inode
->i_uid
) {
156 * ACL can't contain additional permissions if the ACL_MASK entry
159 if (!(mode
& S_IRWXG
))
162 if (ji
->i_acl
== JFS_ACL_NOT_CACHED
) {
163 struct posix_acl
*acl
;
165 acl
= jfs_get_acl(inode
, ACL_TYPE_ACCESS
);
169 posix_acl_release(acl
);
173 int rc
= posix_acl_permission(inode
, ji
->i_acl
, mask
);
175 goto check_capabilities
;
180 if (in_group_p(inode
->i_gid
))
185 * If the DACs are ok we don't need any capability check.
187 if (((mode
& mask
& (MAY_READ
|MAY_WRITE
|MAY_EXEC
)) == mask
))
192 * Read/write DACs are always overridable.
193 * Executable DACs are overridable if at least one exec bit is set.
195 if (!(mask
& MAY_EXEC
) ||
196 (inode
->i_mode
& S_IXUGO
) || S_ISDIR(inode
->i_mode
))
197 if (capable(CAP_DAC_OVERRIDE
))
201 * Searching includes executable on directories, else just read.
203 if (mask
== MAY_READ
|| (S_ISDIR(inode
->i_mode
) && !(mask
& MAY_WRITE
)))
204 if (capable(CAP_DAC_READ_SEARCH
))
210 int jfs_init_acl(struct inode
*inode
, struct inode
*dir
)
212 struct posix_acl
*acl
= NULL
;
213 struct posix_acl
*clone
;
217 if (S_ISLNK(inode
->i_mode
))
220 acl
= jfs_get_acl(dir
, ACL_TYPE_DEFAULT
);
225 if (S_ISDIR(inode
->i_mode
)) {
226 rc
= jfs_set_acl(inode
, ACL_TYPE_DEFAULT
, acl
);
230 clone
= posix_acl_clone(acl
, GFP_KERNEL
);
235 mode
= inode
->i_mode
;
236 rc
= posix_acl_create_masq(clone
, &mode
);
238 inode
->i_mode
= mode
;
240 rc
= jfs_set_acl(inode
, ACL_TYPE_ACCESS
, clone
);
242 posix_acl_release(clone
);
244 posix_acl_release(acl
);
246 inode
->i_mode
&= ~current
->fs
->umask
;
251 static int jfs_acl_chmod(struct inode
*inode
)
253 struct posix_acl
*acl
, *clone
;
256 if (S_ISLNK(inode
->i_mode
))
259 acl
= jfs_get_acl(inode
, ACL_TYPE_ACCESS
);
260 if (IS_ERR(acl
) || !acl
)
263 clone
= posix_acl_clone(acl
, GFP_KERNEL
);
264 posix_acl_release(acl
);
268 rc
= posix_acl_chmod_masq(clone
, inode
->i_mode
);
270 rc
= jfs_set_acl(inode
, ACL_TYPE_ACCESS
, clone
);
272 posix_acl_release(clone
);
276 int jfs_setattr(struct dentry
*dentry
, struct iattr
*iattr
)
278 struct inode
*inode
= dentry
->d_inode
;
281 rc
= inode_change_ok(inode
, iattr
);
285 if ((iattr
->ia_valid
& ATTR_UID
&& iattr
->ia_uid
!= inode
->i_uid
) ||
286 (iattr
->ia_valid
& ATTR_GID
&& iattr
->ia_gid
!= inode
->i_gid
)) {
287 if (DQUOT_TRANSFER(inode
, iattr
))
291 rc
= inode_setattr(inode
, iattr
);
293 if (!rc
&& (iattr
->ia_valid
& ATTR_MODE
))
294 rc
= jfs_acl_chmod(inode
);