mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* CAP_DAC_OVERRIDE
@ 2004-06-22  1:34 Andries.Brouwer
  2004-06-22  8:05 ` CAP_DAC_OVERRIDE Chris Wright
  0 siblings, 1 reply; 2+ messages in thread
From: Andries.Brouwer @ 2004-06-22  1:34 UTC (permalink / raw)
  To: akpm, linux-kernel, torvalds

It seems that CAP_DAC_OVERRIDE is treated inconsistently.
In fs/namei.c:vfs_permission() it allows one to search in
a directory with zero permissions:

        if (!(mask & MAY_EXEC) ||
            (inode->i_mode & S_IXUGO) || S_ISDIR(inode->i_mode))
                if (capable(CAP_DAC_OVERRIDE))
                        return 0;

while in fs/namei.c:exec_permission_lite() it does not.
Maybe the patch below would be appropriate.

Andries

--- /linux/2.6/linux-2.6.6/linux/fs/namei.c     2004-05-28 20:53
+++ ./namei.c   2004-06-22 03:33
@@ -316,7 +316,7 @@
 {
        umode_t mode = inode->i_mode;
 
-       if ((inode->i_op && inode->i_op->permission))
+       if (inode->i_op && inode->i_op->permission)
                return -EAGAIN;
 
        if (current->fsuid == inode->i_uid)
@@ -330,6 +330,9 @@
        if ((inode->i_mode & S_IXUGO) && capable(CAP_DAC_OVERRIDE))
                goto ok;
 
+       if (S_ISDIR(inode->i_mode) && capable(CAP_DAC_OVERRIDE))
+               goto ok;
+
        if (S_ISDIR(inode->i_mode) && capable(CAP_DAC_READ_SEARCH))
                goto ok;
 

[not compiled, not tested, whitespace damaged]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2004-06-22  8:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-06-22  1:34 CAP_DAC_OVERRIDE Andries.Brouwer
2004-06-22  8:05 ` CAP_DAC_OVERRIDE Chris Wright

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®