From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f177.google.com (mail-qt1-f177.google.com [209.85.160.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F8E9345CDC for ; Mon, 27 Jul 2026 01:47:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785116880; cv=none; b=l80M43rITDb92mSZudOuqF+jwiQiaupBFSjAQPbOkSYxE7VpfLtHwr8Ip1+Uz/Lxgj8ZP4GHVY1yGWf9hpLXsq88XB+mMRPVwwNYmhPlx/wkMwz1IUXAkY0Srfz8NTK7BPpWMTMSau1XVLgmfrptt+CsYvTzJ82xGAUoaiDk5E0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785116880; c=relaxed/simple; bh=AVsuJJQRTTWoyOJkTSi6fUKZFteb6ITubarU8DpDMps=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=rD9OicIIQclWU67vbjHKQ00dU4ShATi+8fXe/Kka9BFnTTLo51Kw5MK4hO+J522CLIMy516Myza3sOzTvKx9KgJVTA0iU787mE6WpqV/vM3AbNl9F/LaGrTR+TWhoziv6+F4RJfgdHUeCJ4KXNdFJq9VdtL9vSS/f2qG0Shf71Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TjuZaRBu; arc=none smtp.client-ip=209.85.160.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TjuZaRBu" Received: by mail-qt1-f177.google.com with SMTP id d75a77b69052e-51c2a818fc4so14690711cf.2 for ; Sun, 26 Jul 2026 18:47:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785116876; x=1785721676; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=VSqmJSe12HqDp26C3dw3gZtstJOdYyHd5Hf+ohShs7o=; b=TjuZaRBuWsTSZDd6LYUBMIpVpjNpnd6zTAqOA5T3UJjkqYIO9524K0741hhEW6aK7F pnVJqHJrpgO99cjFOdMCx0DEHMcWmS8dRptuXvTSjDV8pgmVTp95TTJ/hqqiGEhk83zp s5bABNdRTUlasmZ1CISct27u80dzq83AFg3wnPuLZGhoXRFs4UsMqgsWI7VKiB5ZeJcI joxIvnrp5ik4PmItocdIkAKKoaouIL8qaWFVL3fCPsh4wPCd9x9KXaVEBCH/hMCrEBUu RxxlmE1rEEvMEkzcgJ7hxbmbKs151lozoFfY2146XfcugnYsTFn0tLgnmv7GMLjclgrF tfrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785116876; x=1785721676; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VSqmJSe12HqDp26C3dw3gZtstJOdYyHd5Hf+ohShs7o=; b=ZKeHdLFCklGcY2wzXLgoDlr3a/TyADTs0aPCRjmBOcFX9VS5pVr4do0YGpistOFpR4 QoAPjqHa+Jr0zuMogsoGiFQ/iM15zMHQPi7rHlEdF2wsHxC5t+mHUATAYhAQbflGFN2L WwA5OM/N12SRfjhGM4RC4lJwvNpaNy1P0ZsYcJAQjvEw+1Nsq+3/UbJNAO/HBSy0lOQN nN53IT5AqLFKEM/+e8XVfzzzKGGz2NZl4fdqKnBq+kfqrXIxf4O/Rv/GANJipbVT50Lw RZniQyDzSJm0a5dwoSmVcDFNtWmYuF+/s0fH4W42ALC2I8uXLFn7DuOlNKd05sYjUOWS pxaA== X-Forwarded-Encrypted: i=1; AHgh+Rr/zQ8bmmnanJnJoy49KAUqpgMhwgNB1qP1f54xyMyciFRGC0HyDxvLDBSVUjeeCy37Zyyd0olatxL8DY0=@vger.kernel.org X-Gm-Message-State: AOJu0YxxHihryRjYkufTKrh9waur6uKP29nX3cKGcisCzF8/xnk6ufnz XarrT8m1kGcyAP7LwAjY0B1TTYi5Tl+gAambWPFYwfSM9ATwbh61/5qc X-Gm-Gg: AR+sD10bSJ9J5aSdvDxBRI1v9H4OihfJfxwndqZiB98osE3+3ZlvFccTcNiafvEGuz6 lRv66FxV8q/Lx3aWKQuZo7yBPgYIkZZ7w0pH8/hNuJBioDPHBZBZ2JJXctyDQE3iYcVVP/ORp30 eVfAE0FWiBynq7wmuIFFbAgQRa7crJYQ4p4W8SiM6OkU2HsISnA8UIWFUwKkW5MRhlnmL55nAvt be82fzdOaWw7klOdQ8OCu3nieQvbnTErfp6ZjnqPlB7I8NetWx5bPJE29sDG96gwuvXr3lu1f6Q rW7h3yZeQh/RX76kfNaa2l/POyn3KTmYJe6Z0WEFw4GwYX81bI5MEQNqyVfnyVmxBVmAypBjaLY HqTg84RgjjUwG0aYnnYHEC+j45c/SaXzg3WVObtQx7txKUq+LaXHbQB+cvAQ66TiHT9zQqZbTQz 3a0yeccrzEUDPM7VvbUA== X-Received: by 2002:ac8:5941:0:b0:51c:a8:51cd with SMTP id d75a77b69052e-529a8314aa2mr63874141cf.1.1785116876145; Sun, 26 Jul 2026 18:47:56 -0700 (PDT) Received: from osman.mioffice.cn ([43.224.245.178]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529a2989b24sm44064281cf.15.2026.07.26.18.47.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 18:47:55 -0700 (PDT) From: Zhan Xusheng To: Ilya Dryomov Cc: Alex Markuze , Viacheslav Dubeyko , Max Kellermann , ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Zhan Xusheng , stable@vger.kernel.org Subject: [PATCH] ceph: use the mount idmap for the owner checks in the SET_LAYOUT ioctls Date: Mon, 27 Jul 2026 09:47:44 +0800 Message-ID: <20260727014745.1304657-1-zhanxusheng1024@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Zhan Xusheng ceph_ioctl_set_layout() and ceph_ioctl_set_layout_policy() call inode_owner_or_capable() with &nop_mnt_idmap instead of the idmap of the mount the ioctl was issued on. CephFS supports idmapped mounts (FS_ALLOW_IDMAP), so on such a mount this compares the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EACCES and an unrelated caller wrongly allowed. Both functions already have the struct file, so use file_mnt_idmap(file) instead. Fixes: cee38bbf5556 ("ceph: add owner/capability checks for CEPH_IOC_SET_LAYOUT*") Cc: stable@vger.kernel.org Signed-off-by: Zhan Xusheng --- fs/ceph/ioctl.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/ceph/ioctl.c b/fs/ceph/ioctl.c index de07f19b0caa..12cb50e0a166 100644 --- a/fs/ceph/ioctl.c +++ b/fs/ceph/ioctl.c @@ -72,7 +72,7 @@ static long ceph_ioctl_set_layout(struct file *file, void __user *arg) struct ceph_ioctl_layout nl; int err; - if (!inode_owner_or_capable(&nop_mnt_idmap, inode)) + if (!inode_owner_or_capable(file_mnt_idmap(file), inode)) return -EACCES; if (copy_from_user(&l, arg, sizeof(l))) @@ -145,7 +145,7 @@ static long ceph_ioctl_set_layout_policy (struct file *file, void __user *arg) int err; struct ceph_mds_client *mdsc = ceph_sb_to_fs_client(inode->i_sb)->mdsc; - if (!inode_owner_or_capable(&nop_mnt_idmap, inode)) + if (!inode_owner_or_capable(file_mnt_idmap(file), inode)) return -EACCES; /* copy and validate */ -- 2.43.0