mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Chris Wright <chrisw@osdl.org>
To: Andries.Brouwer@cwi.nl
Cc: akpm@osdl.org, linux-kernel@vger.kernel.org, torvalds@osdl.org
Subject: Re: CAP_DAC_OVERRIDE
Date: Tue, 22 Jun 2004 01:05:07 -0700	[thread overview]
Message-ID: <20040622010505.I22989@build.pdx.osdl.net> (raw)
In-Reply-To: <UTC200406220134.i5M1YxJ20330.aeb@smtp.cwi.nl>; from Andries.Brouwer@cwi.nl on Tue, Jun 22, 2004 at 03:34:59AM +0200

* Andries.Brouwer@cwi.nl (Andries.Brouwer@cwi.nl) wrote:
> It seems that CAP_DAC_OVERRIDE is treated inconsistently.
> In fs/namei.c:vfs_permission() it allows one to search in
> a directory with zero permissions:
> 
>         if (!(mask & MAY_EXEC) ||
>             (inode->i_mode & S_IXUGO) || S_ISDIR(inode->i_mode))
>                 if (capable(CAP_DAC_OVERRIDE))
>                         return 0;
> 
> while in fs/namei.c:exec_permission_lite() it does not.
> Maybe the patch below would be appropriate.

Andries, I agree, it's handled inconsistently.  The typical usage would
never notice this since both caps would be either enabled or disabled.
I believe we could actually simplify the overrides to simply:

	if (capable(CAP_DAC_OVERRIDE) || capable(CAP_DAC_READ_SEARCH))
		goto ok;

Because this is only MAY_EXEC on directories check.  However, that does
hide the override reasoning, so conservative approach below.  I changed
it just slightly from yours to keep in line with code in vfs_permission.

thanks,
-chris

===== fs/namei.c 1.96 vs edited =====
--- 1.96/fs/namei.c	2004-06-20 18:20:57 -07:00
+++ edited/fs/namei.c	2004-06-22 01:02:00 -07:00
@@ -316,7 +316,7 @@
 {
 	umode_t	mode = inode->i_mode;
 
-	if ((inode->i_op && inode->i_op->permission))
+	if (inode->i_op && inode->i_op->permission)
 		return -EAGAIN;
 
 	if (current->fsuid == inode->i_uid)
@@ -327,7 +327,8 @@
 	if (mode & MAY_EXEC)
 		goto ok;
 
-	if ((inode->i_mode & S_IXUGO) && capable(CAP_DAC_OVERRIDE))
+	if (((inode->i_mode & S_IXUGO) || S_ISDIR(inode->i_mode)) &&
+	    capable(CAP_DAC_OVERRIDE))
 		goto ok;
 
 	if (S_ISDIR(inode->i_mode) && capable(CAP_DAC_READ_SEARCH))

      reply	other threads:[~2004-06-22  8:05 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-06-22  1:34 CAP_DAC_OVERRIDE Andries.Brouwer
2004-06-22  8:05 ` Chris Wright [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040622010505.I22989@build.pdx.osdl.net \
    --to=chrisw@osdl.org \
    --cc=Andries.Brouwer@cwi.nl \
    --cc=akpm@osdl.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®