|
@@ -340,22 +340,14 @@ int generic_permission(struct inode *inode, int mask)
|
|
|
|
|
|
|
|
if (S_ISDIR(inode->i_mode)) {
|
|
if (S_ISDIR(inode->i_mode)) {
|
|
|
/* DACs are overridable for directories */
|
|
/* DACs are overridable for directories */
|
|
|
- if (capable_wrt_inode_uidgid(inode, CAP_DAC_OVERRIDE))
|
|
|
|
|
- return 0;
|
|
|
|
|
if (!(mask & MAY_WRITE))
|
|
if (!(mask & MAY_WRITE))
|
|
|
if (capable_wrt_inode_uidgid(inode,
|
|
if (capable_wrt_inode_uidgid(inode,
|
|
|
CAP_DAC_READ_SEARCH))
|
|
CAP_DAC_READ_SEARCH))
|
|
|
return 0;
|
|
return 0;
|
|
|
- return -EACCES;
|
|
|
|
|
- }
|
|
|
|
|
- /*
|
|
|
|
|
- * Read/write DACs are always overridable.
|
|
|
|
|
- * Executable DACs are overridable when there is
|
|
|
|
|
- * at least one exec bit set.
|
|
|
|
|
- */
|
|
|
|
|
- if (!(mask & MAY_EXEC) || (inode->i_mode & S_IXUGO))
|
|
|
|
|
if (capable_wrt_inode_uidgid(inode, CAP_DAC_OVERRIDE))
|
|
if (capable_wrt_inode_uidgid(inode, CAP_DAC_OVERRIDE))
|
|
|
return 0;
|
|
return 0;
|
|
|
|
|
+ return -EACCES;
|
|
|
|
|
+ }
|
|
|
|
|
|
|
|
/*
|
|
/*
|
|
|
* Searching includes executable on directories, else just read.
|
|
* Searching includes executable on directories, else just read.
|
|
@@ -364,6 +356,14 @@ int generic_permission(struct inode *inode, int mask)
|
|
|
if (mask == MAY_READ)
|
|
if (mask == MAY_READ)
|
|
|
if (capable_wrt_inode_uidgid(inode, CAP_DAC_READ_SEARCH))
|
|
if (capable_wrt_inode_uidgid(inode, CAP_DAC_READ_SEARCH))
|
|
|
return 0;
|
|
return 0;
|
|
|
|
|
+ /*
|
|
|
|
|
+ * Read/write DACs are always overridable.
|
|
|
|
|
+ * Executable DACs are overridable when there is
|
|
|
|
|
+ * at least one exec bit set.
|
|
|
|
|
+ */
|
|
|
|
|
+ if (!(mask & MAY_EXEC) || (inode->i_mode & S_IXUGO))
|
|
|
|
|
+ if (capable_wrt_inode_uidgid(inode, CAP_DAC_OVERRIDE))
|
|
|
|
|
+ return 0;
|
|
|
|
|
|
|
|
return -EACCES;
|
|
return -EACCES;
|
|
|
}
|
|
}
|