2 * Copyright (C) Sistina Software, Inc. 1997-2003 All rights reserved.
3 * Copyright (C) 2004-2006 Red Hat, Inc. All rights reserved.
5 * This copyrighted material is made available to anyone wishing to use,
6 * modify, copy, or redistribute it subject to the terms and conditions
7 * of the GNU General Public License version 2.
10 #include <linux/sched.h>
11 #include <linux/slab.h>
12 #include <linux/spinlock.h>
13 #include <linux/completion.h>
14 #include <linux/buffer_head.h>
15 #include <linux/xattr.h>
16 #include <linux/posix_acl.h>
17 #include <linux/posix_acl_xattr.h>
18 #include <linux/gfs2_ondisk.h>
30 static const char *gfs2_acl_name(int type
)
34 return GFS2_POSIX_ACL_ACCESS
;
35 case ACL_TYPE_DEFAULT
:
36 return GFS2_POSIX_ACL_DEFAULT
;
41 static struct posix_acl
*gfs2_acl_get(struct gfs2_inode
*ip
, int type
)
43 struct posix_acl
*acl
;
51 acl
= get_cached_acl(&ip
->i_inode
, type
);
52 if (acl
!= ACL_NOT_CACHED
)
55 name
= gfs2_acl_name(type
);
57 return ERR_PTR(-EINVAL
);
59 len
= gfs2_xattr_acl_get(ip
, name
, &data
);
65 acl
= posix_acl_from_xattr(data
, len
);
71 * gfs2_check_acl - Check an ACL to see if we're allowed to do something
72 * @inode: the file we want to do something to
73 * @mask: what we want to do
78 int gfs2_check_acl(struct inode
*inode
, int mask
, unsigned int flags
)
80 struct posix_acl
*acl
;
83 if (flags
& IPERM_FLAG_RCU
) {
84 if (!negative_cached_acl(inode
, ACL_TYPE_ACCESS
))
89 acl
= gfs2_acl_get(GFS2_I(inode
), ACL_TYPE_ACCESS
);
94 error
= posix_acl_permission(inode
, acl
, mask
);
95 posix_acl_release(acl
);
102 static int gfs2_set_mode(struct inode
*inode
, mode_t mode
)
106 if (mode
!= inode
->i_mode
) {
109 iattr
.ia_valid
= ATTR_MODE
;
110 iattr
.ia_mode
= mode
;
112 error
= gfs2_setattr_simple(GFS2_I(inode
), &iattr
);
118 static int gfs2_acl_set(struct inode
*inode
, int type
, struct posix_acl
*acl
)
123 const char *name
= gfs2_acl_name(type
);
125 BUG_ON(name
== NULL
);
126 len
= posix_acl_to_xattr(acl
, NULL
, 0);
129 data
= kmalloc(len
, GFP_NOFS
);
132 error
= posix_acl_to_xattr(acl
, data
, len
);
135 error
= __gfs2_xattr_set(inode
, name
, data
, len
, 0, GFS2_EATYPE_SYS
);
137 set_cached_acl(inode
, type
, acl
);
143 int gfs2_acl_create(struct gfs2_inode
*dip
, struct inode
*inode
)
145 struct gfs2_sbd
*sdp
= GFS2_SB(&dip
->i_inode
);
146 struct posix_acl
*acl
, *clone
;
147 mode_t mode
= inode
->i_mode
;
150 if (!sdp
->sd_args
.ar_posix_acl
)
152 if (S_ISLNK(inode
->i_mode
))
155 acl
= gfs2_acl_get(dip
, ACL_TYPE_DEFAULT
);
159 mode
&= ~current_umask();
160 if (mode
!= inode
->i_mode
)
161 error
= gfs2_set_mode(inode
, mode
);
165 if (S_ISDIR(inode
->i_mode
)) {
166 error
= gfs2_acl_set(inode
, ACL_TYPE_DEFAULT
, acl
);
171 clone
= posix_acl_clone(acl
, GFP_NOFS
);
175 posix_acl_release(acl
);
178 error
= posix_acl_create_masq(acl
, &mode
);
184 error
= gfs2_acl_set(inode
, ACL_TYPE_ACCESS
, acl
);
188 error
= gfs2_set_mode(inode
, mode
);
190 posix_acl_release(acl
);
194 int gfs2_acl_chmod(struct gfs2_inode
*ip
, struct iattr
*attr
)
196 struct posix_acl
*acl
, *clone
;
201 acl
= gfs2_acl_get(ip
, ACL_TYPE_ACCESS
);
205 return gfs2_setattr_simple(ip
, attr
);
207 clone
= posix_acl_clone(acl
, GFP_NOFS
);
211 posix_acl_release(acl
);
214 error
= posix_acl_chmod_masq(acl
, attr
->ia_mode
);
216 len
= posix_acl_to_xattr(acl
, NULL
, 0);
217 data
= kmalloc(len
, GFP_NOFS
);
221 posix_acl_to_xattr(acl
, data
, len
);
222 error
= gfs2_xattr_acl_chmod(ip
, attr
, data
);
224 set_cached_acl(&ip
->i_inode
, ACL_TYPE_ACCESS
, acl
);
228 posix_acl_release(acl
);
232 static int gfs2_acl_type(const char *name
)
234 if (strcmp(name
, GFS2_POSIX_ACL_ACCESS
) == 0)
235 return ACL_TYPE_ACCESS
;
236 if (strcmp(name
, GFS2_POSIX_ACL_DEFAULT
) == 0)
237 return ACL_TYPE_DEFAULT
;
241 static int gfs2_xattr_system_get(struct dentry
*dentry
, const char *name
,
242 void *buffer
, size_t size
, int xtype
)
244 struct inode
*inode
= dentry
->d_inode
;
245 struct gfs2_sbd
*sdp
= GFS2_SB(inode
);
246 struct posix_acl
*acl
;
250 if (!sdp
->sd_args
.ar_posix_acl
)
253 type
= gfs2_acl_type(name
);
257 acl
= gfs2_acl_get(GFS2_I(inode
), type
);
263 error
= posix_acl_to_xattr(acl
, buffer
, size
);
264 posix_acl_release(acl
);
269 static int gfs2_xattr_system_set(struct dentry
*dentry
, const char *name
,
270 const void *value
, size_t size
, int flags
,
273 struct inode
*inode
= dentry
->d_inode
;
274 struct gfs2_sbd
*sdp
= GFS2_SB(inode
);
275 struct posix_acl
*acl
= NULL
;
278 if (!sdp
->sd_args
.ar_posix_acl
)
281 type
= gfs2_acl_type(name
);
284 if (flags
& XATTR_CREATE
)
286 if (type
== ACL_TYPE_DEFAULT
&& !S_ISDIR(inode
->i_mode
))
287 return value
? -EACCES
: 0;
288 if ((current_fsuid() != inode
->i_uid
) && !capable(CAP_FOWNER
))
290 if (S_ISLNK(inode
->i_mode
))
296 acl
= posix_acl_from_xattr(value
, size
);
299 * acl_set_file(3) may request that we set default ACLs with
300 * zero length -- defend (gracefully) against that here.
305 error
= PTR_ERR(acl
);
309 error
= posix_acl_valid(acl
);
314 if (acl
->a_count
> GFS2_ACL_MAX_ENTRIES
)
317 if (type
== ACL_TYPE_ACCESS
) {
318 mode_t mode
= inode
->i_mode
;
319 error
= posix_acl_equiv_mode(acl
, &mode
);
322 posix_acl_release(acl
);
329 error
= gfs2_set_mode(inode
, mode
);
335 error
= __gfs2_xattr_set(inode
, name
, value
, size
, 0, GFS2_EATYPE_SYS
);
338 set_cached_acl(inode
, type
, acl
);
340 forget_cached_acl(inode
, type
);
343 posix_acl_release(acl
);
348 const struct xattr_handler gfs2_xattr_system_handler
= {
349 .prefix
= XATTR_SYSTEM_PREFIX
,
350 .flags
= GFS2_EATYPE_SYS
,
351 .get
= gfs2_xattr_system_get
,
352 .set
= gfs2_xattr_system_set
,