2 * Copyright (c) International Business Machines Corp., 2002
3 * Copyright (c) Andreas Gruenbacher, 2001
4 * Copyright (c) Linus Torvalds, 1991, 1992
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See
14 * the GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
21 #include <linux/sched.h>
23 #include "jfs_incore.h"
24 #include "jfs_xattr.h"
27 static struct posix_acl *jfs_get_acl(struct inode *inode, int type)
29 struct posix_acl *acl;
31 struct jfs_inode_info *ji = JFS_IP(inode);
32 struct posix_acl **p_acl;
38 ea_name = XATTR_NAME_ACL_ACCESS;
41 case ACL_TYPE_DEFAULT:
42 ea_name = XATTR_NAME_ACL_DEFAULT;
43 p_acl = &ji->i_default_acl;
46 return ERR_PTR(-EINVAL);
49 if (*p_acl != JFS_ACL_NOT_CACHED)
50 return posix_acl_dup(*p_acl);
52 size = __jfs_getxattr(inode, ea_name, NULL, 0);
55 value = kmalloc(size, GFP_KERNEL);
57 return ERR_PTR(-ENOMEM);
58 size = __jfs_getxattr(inode, ea_name, value, size);
62 if (size == -ENODATA) {
68 acl = posix_acl_from_xattr(value, size);
70 *p_acl = posix_acl_dup(acl);
77 static int jfs_set_acl(struct inode *inode, int type, struct posix_acl *acl)
80 struct jfs_inode_info *ji = JFS_IP(inode);
81 struct posix_acl **p_acl;
86 if (S_ISLNK(inode->i_mode))
91 ea_name = XATTR_NAME_ACL_ACCESS;
94 case ACL_TYPE_DEFAULT:
95 ea_name = XATTR_NAME_ACL_DEFAULT;
96 p_acl = &ji->i_default_acl;
97 if (!S_ISDIR(inode->i_mode))
98 return acl ? -EACCES : 0;
104 size = xattr_acl_size(acl->a_count);
105 value = kmalloc(size, GFP_KERNEL);
108 rc = posix_acl_to_xattr(acl, value, size);
112 rc = __jfs_setxattr(inode, ea_name, value, size, 0);
118 if (*p_acl && (*p_acl != JFS_ACL_NOT_CACHED))
119 posix_acl_release(*p_acl);
120 *p_acl = posix_acl_dup(acl);
128 * modified vfs_permission to check posix acl
130 int jfs_permission(struct inode * inode, int mask, struct nameidata *nd)
132 umode_t mode = inode->i_mode;
133 struct jfs_inode_info *ji = JFS_IP(inode);
135 if (mask & MAY_WRITE) {
137 * Nobody gets write access to a read-only fs.
139 if (IS_RDONLY(inode) &&
140 (S_ISREG(mode) || S_ISDIR(mode) || S_ISLNK(mode)))
144 * Nobody gets write access to an immutable file.
146 if (IS_IMMUTABLE(inode))
150 if (current->fsuid == inode->i_uid) {
155 * ACL can't contain additional permissions if the ACL_MASK entry
158 if (!(mode & S_IRWXG))
161 if (ji->i_acl == JFS_ACL_NOT_CACHED) {
162 struct posix_acl *acl;
164 acl = jfs_get_acl(inode, ACL_TYPE_ACCESS);
168 posix_acl_release(acl);
172 int rc = posix_acl_permission(inode, ji->i_acl, mask);
174 goto check_capabilities;
179 if (in_group_p(inode->i_gid))
184 * If the DACs are ok we don't need any capability check.
186 if (((mode & mask & (MAY_READ|MAY_WRITE|MAY_EXEC)) == mask))
191 * Read/write DACs are always overridable.
192 * Executable DACs are overridable if at least one exec bit is set.
194 if (!(mask & MAY_EXEC) ||
195 (inode->i_mode & S_IXUGO) || S_ISDIR(inode->i_mode))
196 if (capable(CAP_DAC_OVERRIDE))
200 * Searching includes executable on directories, else just read.
202 if (mask == MAY_READ || (S_ISDIR(inode->i_mode) && !(mask & MAY_WRITE)))
203 if (capable(CAP_DAC_READ_SEARCH))
209 int jfs_init_acl(struct inode *inode, struct inode *dir)
211 struct posix_acl *acl = NULL;
212 struct posix_acl *clone;
216 if (S_ISLNK(inode->i_mode))
219 acl = jfs_get_acl(dir, ACL_TYPE_DEFAULT);
224 if (S_ISDIR(inode->i_mode)) {
225 rc = jfs_set_acl(inode, ACL_TYPE_DEFAULT, acl);
229 clone = posix_acl_clone(acl, GFP_KERNEL);
234 mode = inode->i_mode;
235 rc = posix_acl_create_masq(clone, &mode);
237 inode->i_mode = mode;
239 rc = jfs_set_acl(inode, ACL_TYPE_ACCESS, clone);
241 posix_acl_release(clone);
243 posix_acl_release(acl);
245 inode->i_mode &= ~current->fs->umask;
250 static int jfs_acl_chmod(struct inode *inode)
252 struct posix_acl *acl, *clone;
255 if (S_ISLNK(inode->i_mode))
258 acl = jfs_get_acl(inode, ACL_TYPE_ACCESS);
259 if (IS_ERR(acl) || !acl)
262 clone = posix_acl_clone(acl, GFP_KERNEL);
263 posix_acl_release(acl);
267 rc = posix_acl_chmod_masq(clone, inode->i_mode);
269 rc = jfs_set_acl(inode, ACL_TYPE_ACCESS, clone);
271 posix_acl_release(clone);
275 int jfs_setattr(struct dentry *dentry, struct iattr *iattr)
277 struct inode *inode = dentry->d_inode;
280 rc = inode_change_ok(inode, iattr);
284 rc = inode_setattr(inode, iattr);
286 if (!rc && (iattr->ia_valid & ATTR_MODE))
287 rc = jfs_acl_chmod(inode);