[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20110519145004.GA15698@mail.hallyn.com>
Date: Thu, 19 May 2011 09:50:04 -0500
From: "Serge E. Hallyn" <serge@...lyn.com>
To: samsonov@...sta.ru
Cc: linux-kernel@...r.kernel.org
Subject: Re: fs/attr.c patch
But you're removing the ability for a process with CAP_CHOWN to
chgrp all files.
You also change behavior (which may be wrong) when doing chgrp to
which would cause no change but the group is not in_group_p(),
which might break current users.
Quoting samsonov@...sta.ru (samsonov@...sta.ru):
> --- ./linux-2.6.33.4.orig/fs/attr.c 2010-05-13 02:04:27.000000000 +0400
> +++ ./linux-2.6.33.4/fs/attr.c 2011-05-19 15:43:14.533672804 +0400
> @@ -35,9 +35,7 @@
>
> /* Make sure caller can chgrp. */
> if ((ia_valid & ATTR_GID) &&
> - (current_fsuid() != inode->i_uid ||
> - (!in_group_p(attr->ia_gid) && attr->ia_gid != inode->i_gid)) &&
> - !capable(CAP_CHOWN))
> + !(in_group_p(attr->ia_gid) && is_owner_or_cap(inode)))
> goto error;
>
> /* Make sure a caller can chmod. */
>
> I think that fileowner can change group of file.
>
>
>
>
> --
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@...r.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists