summaryrefslogtreecommitdiffstats
path: root/fs/jbd2
diff options
context:
space:
mode:
authorWang Shilong2018-10-03 16:33:32 +0200
committerTheodore Ts'o2018-10-03 16:33:32 +0200
commitdc7ac6c4cae3b58724c2f1e21a7c05ce19ecd5a8 (patch)
tree332457b7a5a12fdc8231bfa3f962ab88dbfaebda /fs/jbd2
parentdocs: make ext4 readme tables readable (diff)
downloadkernel-qcow2-linux-dc7ac6c4cae3b58724c2f1e21a7c05ce19ecd5a8.tar.gz
kernel-qcow2-linux-dc7ac6c4cae3b58724c2f1e21a7c05ce19ecd5a8.tar.xz
kernel-qcow2-linux-dc7ac6c4cae3b58724c2f1e21a7c05ce19ecd5a8.zip
ext4: fix setattr project check in fssetxattr ioctl
Currently, project quota could be changed by fssetxattr ioctl, and existed permission check inode_owner_or_capable() is obviously not enough, just think that common users could change project id of file, that could make users to break project quota easily. This patch try to follow same regular of xfs project quota: "Project Quota ID state is only allowed to change from within the init namespace. Enforce that restriction only if we are trying to change the quota ID state. Everything else is allowed in user namespaces." Besides that, check and set project id'state should be an atomic operation, protect whole operation with inode lock, ext4_ioctl_setproject() is only used for ioctl EXT4_IOC_FSSETXATTR, we have held mnt_want_write_file() before ext4_ioctl_setflags(), and ext4_ioctl_setproject() is called after ext4_ioctl_setflags(), we could share codes, so remove it inside ext4_ioctl_setproject(). Signed-off-by: Wang Shilong <wshilong@ddn.com> Signed-off-by: Theodore Ts'o <tytso@mit.edu> Reviewed-by: Andreas Dilger <adilger@dilger.ca> Cc: stable@kernel.org
Diffstat (limited to 'fs/jbd2')
0 files changed, 0 insertions, 0 deletions