xfs
[Top] [All Lists]

Re: [PATCH 00/25] move handling of setuid/gid bits from VFS into individ

To: Trond Myklebust <trond.myklebust@xxxxxxxxxx>
Subject: Re: [PATCH 00/25] move handling of setuid/gid bits from VFS into individual setattr functions (RESEND)
From: Jeff Layton <jlayton@xxxxxxxxxx>
Date: Fri, 10 Aug 2007 16:47:52 -0400
Cc: Andrew Morton <akpm@xxxxxxxxxxxxxxxxxxxx>, Jeff Layton <jlayton@xxxxxxxxxx>, linux-kernel@xxxxxxxxxxxxxxx, linux-fsdevel@xxxxxxxxxxxxxxx, v9fs-developer@xxxxxxxxxxxxxxxxxxxxx, zippel@xxxxxxxxxxxxxx, dhowells@xxxxxxxxxx, linux-cifs-client@xxxxxxxxxxxxxxx, codalist@xxxxxxxxxxxxxxxxxxxxxxxx, joel.becker@xxxxxxxxxx, linux-ext4@xxxxxxxxxxxxxxx, fuse-devel@xxxxxxxxxxxxxxxxxxxxx, cluster-devel@xxxxxxxxxx, user-mode-linux-user@xxxxxxxxxxxxxxxxxxxxx, mikulas@xxxxxxxxxxxxxxxxxxxxxxxx, wli@xxxxxxxxxxxxxx, jffs-dev@xxxxxxxx, jfs-discussion@xxxxxxxxxxxxxxxxxxxxx, ocfs2-devel@xxxxxxxxxxxxxx, reiserfs-devel@xxxxxxxxxxxxxxx, bfennema@xxxxxxxxxxxxxxxxxxxxxx, xfs@xxxxxxxxxxx
In-reply-to: <1186533934.6625.91.camel@heimdal.trondhjem.org>
References: <200708061354.l76Ds3mU002255@dantu.rdu.redhat.com> <20070807171501.e31c4a97.akpm@linux-foundation.org> <1186533934.6625.91.camel@heimdal.trondhjem.org>
Sender: xfs-bounce@xxxxxxxxxxx
On Tue, 07 Aug 2007 20:45:34 -0400
Trond Myklebust <trond.myklebust@xxxxxxxxxx> wrote:
> > - rename something so that unconverted filesystems will reliably fail to
> >   compile?
> > 
> > - leave existing filesystems alone, but add a new
> >   inode_operations.setattr_jeff, which the networked filesytems can
> >   implement, and teach core vfs to call setattr_jeff in preference to
> >   setattr?
> 
> If you really need to know that the filesystem is handling the flags,
> then how about instead having ->setattr() return something which
> indicates which flags it actually handled? That is likely to be a far
> more intrusive change, but it is one which is future-proof.
> 

One thing that we could do here is have notify_change check
attr->ia_valid after the setattr operation returns. If either ATTR_KILL_*
bit is set then BUG(). The helper function already clears those bits
so anything using it should automatically be ok. We'd have to fix
up NFS and a few others that don't implement suid/sgid.

This is not as certain as changing the name of the inode operation. It
would only pop when someone is attempting to change a setuid/setgid
file on these filesystems. Still, it should conceivably catch most if
not all offenders. Would that be sufficient to take care of everyone's
concerns?

-- 
Jeff Layton <jlayton@xxxxxxxxxx>


<Prev in Thread] Current Thread [Next in Thread>