zfs_acl.c revision 8a2f1b9190d1dc288470a1fd2776d79ce82cb129
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * CDDL HEADER START
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * The contents of this file are subject to the terms of the
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock * Common Development and Distribution License (the "License").
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock * You may not use this file except in compliance with the License.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
fa9e4066f08beec538e775443c5be79dd423fcabahrens * or http://www.opensolaris.org/os/licensing.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * See the License for the specific language governing permissions
fa9e4066f08beec538e775443c5be79dd423fcabahrens * and limitations under the License.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * When distributing Covered Code, include this CDDL HEADER in each
fa9e4066f08beec538e775443c5be79dd423fcabahrens * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If applicable, add the following below this CDDL HEADER, with the
fa9e4066f08beec538e775443c5be79dd423fcabahrens * fields enclosed by brackets "[]" replaced with your own identifying
fa9e4066f08beec538e775443c5be79dd423fcabahrens * information: Portions Copyright [yyyy] [name of copyright owner]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * CDDL HEADER END
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
84c5a1550ecbf7356ab4133238160367c507f4fbmarks * Copyright 2006 Sun Microsystems, Inc. All rights reserved.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Use is subject to license terms.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#pragma ident "%Z%%M% %I% %E% SMI"
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/types.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/param.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/time.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/systm.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/sysmacros.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/resource.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/vfs.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/vnode.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/file.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/stat.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/kmem.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/cmn_err.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/errno.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/unistd.h>
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks#include <sys/sdt.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/fs/zfs.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/mode.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/policy.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/zfs_znode.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/zfs_acl.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/zfs_dir.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/zfs_vfsops.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/dmu.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <sys/zap.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <util/qsort.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include "fs/fs_subr.h"
fa9e4066f08beec538e775443c5be79dd423fcabahrens#include <acl/acl_common.h>
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define ALLOW ACE_ACCESS_ALLOWED_ACE_TYPE
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define DENY ACE_ACCESS_DENIED_ACE_TYPE
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define OWNING_GROUP (ACE_GROUP|ACE_IDENTIFIER_GROUP)
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define EVERYONE_ALLOW_MASK (ACE_READ_ACL|ACE_READ_ATTRIBUTES | \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_READ_NAMED_ATTRS|ACE_SYNCHRONIZE)
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define EVERYONE_DENY_MASK (ACE_WRITE_ACL|ACE_WRITE_OWNER | \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_WRITE_ATTRIBUTES|ACE_WRITE_NAMED_ATTRS)
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define OWNER_ALLOW_MASK (ACE_WRITE_ACL | ACE_WRITE_OWNER | \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_WRITE_ATTRIBUTES|ACE_WRITE_NAMED_ATTRS)
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define WRITE_MASK (ACE_WRITE_DATA|ACE_APPEND_DATA|ACE_WRITE_NAMED_ATTRS| \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_WRITE_ATTRIBUTES|ACE_WRITE_ACL|ACE_WRITE_OWNER)
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define OGE_CLEAR (ACE_READ_DATA|ACE_LIST_DIRECTORY|ACE_WRITE_DATA| \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_ADD_FILE|ACE_APPEND_DATA|ACE_ADD_SUBDIRECTORY|ACE_EXECUTE)
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define OKAY_MASK_BITS (ACE_READ_DATA|ACE_LIST_DIRECTORY|ACE_WRITE_DATA| \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_ADD_FILE|ACE_APPEND_DATA|ACE_ADD_SUBDIRECTORY|ACE_EXECUTE)
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define ALL_INHERIT (ACE_FILE_INHERIT_ACE|ACE_DIRECTORY_INHERIT_ACE | \
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_NO_PROPAGATE_INHERIT_ACE|ACE_INHERIT_ONLY_ACE)
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks#define SECURE_CLEAR (ACE_WRITE_ACL|ACE_WRITE_OWNER)
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens#define OGE_PAD 6 /* traditional owner/group/everyone ACES */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int zfs_ace_can_use(znode_t *zp, ace_t *);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic zfs_acl_t *
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_alloc(int slots)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = kmem_zalloc(sizeof (zfs_acl_t), KM_SLEEP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (slots != 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl = kmem_alloc(ZFS_ACL_SIZE(slots), KM_SLEEP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_state = ACL_DATA_ALLOCED;
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_state = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_slots = slots;
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensvoid
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_free(zfs_acl_t *aclp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_state == ACL_DATA_ALLOCED) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens kmem_free(aclp->z_acl, ZFS_ACL_SIZE(aclp->z_slots));
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens kmem_free(aclp, sizeof (zfs_acl_t));
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic uint32_t
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_v4_to_unix(uint32_t access_mask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint32_t new_mask = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks /*
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks * This is used for mapping v4 permissions into permissions
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks * that can be passed to secpolicy_vnode_access()
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks */
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (access_mask & (ACE_READ_DATA | ACE_LIST_DIRECTORY |
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ACE_READ_ATTRIBUTES | ACE_READ_ACL))
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= S_IROTH;
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (access_mask & (ACE_WRITE_DATA | ACE_APPEND_DATA |
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ACE_WRITE_ATTRIBUTES | ACE_ADD_FILE | ACE_WRITE_NAMED_ATTRS))
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= S_IWOTH;
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (access_mask & (ACE_EXECUTE | ACE_READ_NAMED_ATTRS))
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= S_IXOTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (new_mask);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Convert unix access mask to v4 access mask
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic uint32_t
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_unix_to_v4(uint32_t access_mask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint32_t new_mask = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (access_mask & 01)
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= (ACE_EXECUTE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (access_mask & 02) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= (ACE_WRITE_DATA);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } if (access_mask & 04) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens new_mask |= ACE_READ_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (new_mask);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_set_ace(ace_t *zacep, uint32_t access_mask, int access_type,
fa9e4066f08beec538e775443c5be79dd423fcabahrens uid_t uid, int entry_type)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacep->a_access_mask = access_mask;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacep->a_type = access_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacep->a_who = uid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacep->a_flags = entry_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic uint64_t
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_mode_compute(znode_t *zp, zfs_acl_t *aclp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int i;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int entry_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode_t mode = (zp->z_phys->zp_mode &
fa9e4066f08beec538e775443c5be79dd423fcabahrens (S_IFMT | S_ISUID | S_ISGID | S_ISVTX));
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode_t seen = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens for (i = 0, acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens i != aclp->z_acl_count; i++, acep++) {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks entry_type = (acep->a_flags & ACE_TYPE_FLAGS);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (entry_type == ACE_OWNER) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_READ_DATA) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IRUSR))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IRUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IRUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_WRITE_DATA) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IWUSR))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IWUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IWUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_EXECUTE) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IXUSR))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IXUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IXUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else if (entry_type == OWNING_GROUP) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_READ_DATA) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IRGRP))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IRGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IRGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_WRITE_DATA) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IWGRP))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IWGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IWGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_EXECUTE) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!(seen & S_IXGRP))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IXGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IXGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else if (entry_type == ACE_EVERYONE) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_READ_DATA)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IRUSR)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IRUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IRUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IRGRP)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IRGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IRGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IROTH)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IROTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IROTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_WRITE_DATA)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IWUSR)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IWUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IWUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IWGRP)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IWGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IWGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IWOTH)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IWOTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IWOTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_access_mask & ACE_EXECUTE)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IXUSR)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IXUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IXUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IXGRP)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IXGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IXGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(seen & S_IXOTH)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens seen |= S_IXOTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_IXOTH;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic zfs_acl_t *
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_node_read_internal(znode_t *zp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_alloc(0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count = zp->z_phys->zp_acl.z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl = &zp->z_phys->zp_acl.z_ace_data[0];
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Read an external acl object.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrockstatic int
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrockzfs_acl_node_read(znode_t *zp, zfs_acl_t **aclpp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint64_t extacl = zp->z_phys->zp_acl.z_acl_extern_obj;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_acl_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (zp->z_phys->zp_acl.z_acl_extern_obj == 0) {
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock *aclpp = zfs_acl_node_read_internal(zp);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock return (0);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_alloc(zp->z_phys->zp_acl.z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock error = dmu_read(zp->z_zfsvfs->z_os, extacl, 0,
fa9e4066f08beec538e775443c5be79dd423fcabahrens ZFS_ACL_SIZE(zp->z_phys->zp_acl.z_acl_count), aclp->z_acl);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (error != 0) {
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock zfs_acl_free(aclp);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock return (error);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count = zp->z_phys->zp_acl.z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock *aclpp = aclp;
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic boolean_t
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_valid(znode_t *zp, ace_t *uace, int aclcnt, int *inherit)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int i;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens *inherit = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclcnt > MAX_ACL_ENTRIES || aclcnt <= 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens for (i = 0, acep = uace; i != aclcnt; i++, acep++) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * first check type of entry
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks switch (acep->a_flags & ACE_TYPE_FLAGS) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_OWNER:
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_who = -1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens case (ACE_IDENTIFIER_GROUP | ACE_GROUP):
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_IDENTIFIER_GROUP:
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_flags & ACE_GROUP) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_who = -1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_EVERYONE:
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_who = -1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * next check inheritance level flags
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_type != ALLOW && acep->a_type != DENY)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Only directories should have inheritance flags.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (ZTOV(zp)->v_type != VDIR && (acep->a_flags &
fa9e4066f08beec538e775443c5be79dd423fcabahrens (ACE_FILE_INHERIT_ACE|ACE_DIRECTORY_INHERIT_ACE|
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_INHERIT_ONLY_ACE|ACE_NO_PROPAGATE_INHERIT_ACE))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_flags &
fa9e4066f08beec538e775443c5be79dd423fcabahrens (ACE_FILE_INHERIT_ACE|ACE_DIRECTORY_INHERIT_ACE))
fa9e4066f08beec538e775443c5be79dd423fcabahrens *inherit = 1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep->a_flags &
fa9e4066f08beec538e775443c5be79dd423fcabahrens (ACE_INHERIT_ONLY_ACE|ACE_NO_PROPAGATE_INHERIT_ACE)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep->a_flags & (ACE_FILE_INHERIT_ACE|
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_DIRECTORY_INHERIT_ACE)) == 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_TRUE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * common code for setting acl's.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * This function is called from zfs_mode_update, zfs_perm_init, and zfs_setacl.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * zfs_setacl passes a non-NULL inherit pointer (ihp) to indicate that it's
fa9e4066f08beec538e775443c5be79dd423fcabahrens * already checked the acl and knows whether to inherit.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_aclset_common(znode_t *zp, zfs_acl_t *aclp, dmu_tx_t *tx, int *ihp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int inherit = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens znode_phys_t *zphys = zp->z_phys;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_znode_acl_t *zacl = &zphys->zp_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint32_t acl_phys_size = ZFS_ACL_SIZE(aclp->z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfsvfs_t *zfsvfs = zp->z_zfsvfs;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint64_t aoid = zphys->zp_acl.z_acl_extern_obj;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_acl_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (ihp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens inherit = *ihp; /* already determined by caller */
fa9e4066f08beec538e775443c5be79dd423fcabahrens else if (!zfs_acl_valid(zp, aclp->z_acl,
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count, &inherit)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EINVAL);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_buf_will_dirty(zp->z_dbuf, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Will ACL fit internally?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_acl_count > ACE_SLOT_CNT) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aoid == 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens aoid = dmu_object_alloc(zfsvfs->z_os,
fa9e4066f08beec538e775443c5be79dd423fcabahrens DMU_OT_ACL, acl_phys_size, DMU_OT_NONE, 0, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens (void) dmu_object_set_blocksize(zfsvfs->z_os, aoid,
fa9e4066f08beec538e775443c5be79dd423fcabahrens acl_phys_size, 0, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens zphys->zp_acl.z_acl_extern_obj = aoid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zphys->zp_acl.z_acl_count = aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_write(zfsvfs->z_os, aoid, 0,
fa9e4066f08beec538e775443c5be79dd423fcabahrens acl_phys_size, aclp->z_acl, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Migrating back embedded?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zphys->zp_acl.z_acl_extern_obj) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = dmu_object_free(zfsvfs->z_os,
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_acl.z_acl_extern_obj, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zphys->zp_acl.z_acl_extern_obj = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens bcopy(aclp->z_acl, zacl->z_ace_data,
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count * sizeof (ace_t));
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacl->z_acl_count = aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
de122929e7c37df60cbea70616404e22d20e025bmarks
de122929e7c37df60cbea70616404e22d20e025bmarks zp->z_phys->zp_flags &= ~(ZFS_ACL_TRIVIAL|ZFS_INHERIT_ACE);
de122929e7c37df60cbea70616404e22d20e025bmarks if (inherit) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_flags |= ZFS_INHERIT_ACE;
de122929e7c37df60cbea70616404e22d20e025bmarks } else if (ace_trivial(zacl->z_ace_data, zacl->z_acl_count) == 0) {
de122929e7c37df60cbea70616404e22d20e025bmarks zp->z_phys->zp_flags |= ZFS_ACL_TRIVIAL;
de122929e7c37df60cbea70616404e22d20e025bmarks }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zphys->zp_mode = zfs_mode_compute(zp, aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_time_stamper_locked(zp, STATE_CHANGED, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Create space for slots_needed ACEs to be append
fa9e4066f08beec538e775443c5be79dd423fcabahrens * to aclp.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_append(zfs_acl_t *aclp, int slots_needed)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *newacep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *oldaclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int slot_cnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int slots_left = aclp->z_slots - aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_state == ACL_DATA_ALLOCED)
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(aclp->z_slots >= aclp->z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (slots_left < slots_needed || aclp->z_state != ACL_DATA_ALLOCED) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens slot_cnt = aclp->z_slots + 1 + (slots_needed - slots_left);
fa9e4066f08beec538e775443c5be79dd423fcabahrens newacep = kmem_alloc(ZFS_ACL_SIZE(slot_cnt), KM_SLEEP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens bcopy(aclp->z_acl, newacep,
fa9e4066f08beec538e775443c5be79dd423fcabahrens ZFS_ACL_SIZE(aclp->z_acl_count));
fa9e4066f08beec538e775443c5be79dd423fcabahrens oldaclp = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_state == ACL_DATA_ALLOCED)
fa9e4066f08beec538e775443c5be79dd423fcabahrens kmem_free(oldaclp, ZFS_ACL_SIZE(aclp->z_slots));
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl = newacep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_slots = slot_cnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_state = ACL_DATA_ALLOCED;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Remove "slot" ACE from aclp
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_ace_remove(zfs_acl_t *aclp, int slot)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_acl_count > 1) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens (void) memmove(&aclp->z_acl[slot],
fa9e4066f08beec538e775443c5be79dd423fcabahrens &aclp->z_acl[slot +1], sizeof (ace_t) *
fa9e4066f08beec538e775443c5be79dd423fcabahrens (--aclp->z_acl_count - slot));
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count--;
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Update access mask for prepended ACE
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * This applies the "groupmask" value for aclmode property.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_prepend_fixup(ace_t *acep, ace_t *origacep, mode_t mode, uid_t owner)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens int rmask, wmask, xmask;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int user_ace;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens user_ace = (!(acep->a_flags &
fa9e4066f08beec538e775443c5be79dd423fcabahrens (ACE_OWNER|ACE_GROUP|ACE_IDENTIFIER_GROUP)));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (user_ace && (acep->a_who == owner)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens rmask = S_IRUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens wmask = S_IWUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens xmask = S_IXUSR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens rmask = S_IRGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens wmask = S_IWGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens xmask = S_IXGRP;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (origacep->a_access_mask & ACE_READ_DATA) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & rmask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask &= ~ACE_READ_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask |= ACE_READ_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (origacep->a_access_mask & ACE_WRITE_DATA) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & wmask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask &= ~ACE_WRITE_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask |= ACE_WRITE_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (origacep->a_access_mask & ACE_APPEND_DATA) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & wmask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask &= ~ACE_APPEND_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask |= ACE_APPEND_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (origacep->a_access_mask & ACE_EXECUTE) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & xmask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask &= ~ACE_EXECUTE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep->a_access_mask |= ACE_EXECUTE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Apply mode to canonical six ACEs.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_fixup_canonical_six(zfs_acl_t *aclp, mode_t mode)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int cnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens cnt = aclp->z_acl_count -1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Fixup final ACEs to match the mode
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(cnt >= 5);
fa9e4066f08beec538e775443c5be79dd423fcabahrens adjust_ace_pair(&acep[cnt - 1], mode); /* everyone@ */
fa9e4066f08beec538e775443c5be79dd423fcabahrens adjust_ace_pair(&acep[cnt - 3], (mode & 0070) >> 3); /* group@ */
fa9e4066f08beec538e775443c5be79dd423fcabahrens adjust_ace_pair(&acep[cnt - 5], (mode & 0700) >> 6); /* owner@ */
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_ace_match(ace_t *acep, int allow_deny, int type, int mask)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (acep->a_access_mask == mask && acep->a_type == allow_deny &&
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ((acep->a_flags & ACE_TYPE_FLAGS) == type));
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Can prepended ACE be reused?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_reuse_deny(ace_t *acep, int i)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int okay_masks;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (i < 1)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep[i-1].a_type != DENY)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep[i-1].a_flags != (acep[i].a_flags & ACE_IDENTIFIER_GROUP))
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens okay_masks = (acep[i].a_access_mask & OKAY_MASK_BITS);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep[i-1].a_access_mask & ~okay_masks)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_FALSE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (B_TRUE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Create space to prepend an ACE
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_prepend(zfs_acl_t *aclp, int i)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *oldaclp = NULL;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *to, *from;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int slots_left = aclp->z_slots - aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int oldslots;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int need_free = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_state == ACL_DATA_ALLOCED)
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(aclp->z_slots >= aclp->z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (slots_left == 0 || aclp->z_state != ACL_DATA_ALLOCED) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens to = kmem_alloc(ZFS_ACL_SIZE(aclp->z_acl_count +
fa9e4066f08beec538e775443c5be79dd423fcabahrens OGE_PAD), KM_SLEEP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_state == ACL_DATA_ALLOCED)
fa9e4066f08beec538e775443c5be79dd423fcabahrens need_free++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens from = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens oldaclp = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens (void) memmove(to, from,
fa9e4066f08beec538e775443c5be79dd423fcabahrens sizeof (ace_t) * aclp->z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_state = ACL_DATA_ALLOCED;
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens from = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens to = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens (void) memmove(&to[i + 1], &from[i],
fa9e4066f08beec538e775443c5be79dd423fcabahrens sizeof (ace_t) * (aclp->z_acl_count - i));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (oldaclp) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl = to;
fa9e4066f08beec538e775443c5be79dd423fcabahrens oldslots = aclp->z_slots;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_slots = aclp->z_acl_count + OGE_PAD;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (need_free)
fa9e4066f08beec538e775443c5be79dd423fcabahrens kmem_free(oldaclp, ZFS_ACL_SIZE(oldslots));
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Prepend deny ACE
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_prepend_deny(znode_t *zp, zfs_acl_t *aclp, int i,
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode_t mode)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_prepend(aclp, i);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i], 0, DENY, acep[i + 1].a_who,
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks (acep[i + 1].a_flags & ACE_TYPE_FLAGS));
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_prepend_fixup(&acep[i], &acep[i+1], mode, zp->z_phys->zp_uid);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Split an inherited ACE into inherit_only ACE
fa9e4066f08beec538e775443c5be79dd423fcabahrens * and original ACE with inheritance flags stripped off.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_split_ace(zfs_acl_t *aclp, int i)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_prepend(aclp, i);
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[i] = acep[i + 1];
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[i].a_flags |= ACE_INHERIT_ONLY_ACE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[i + 1].a_flags &= ~ALL_INHERIT;
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Are ACES started at index i, the canonical six ACES?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_have_canonical_six(zfs_acl_t *aclp, int i)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((zfs_acl_ace_match(&acep[i],
fa9e4066f08beec538e775443c5be79dd423fcabahrens DENY, ACE_OWNER, 0) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_ace_match(&acep[i + 1], ALLOW, ACE_OWNER,
fa9e4066f08beec538e775443c5be79dd423fcabahrens OWNER_ALLOW_MASK) && zfs_acl_ace_match(&acep[i + 2],
fa9e4066f08beec538e775443c5be79dd423fcabahrens DENY, OWNING_GROUP, 0) && zfs_acl_ace_match(&acep[i + 3],
fa9e4066f08beec538e775443c5be79dd423fcabahrens ALLOW, OWNING_GROUP, 0) && zfs_acl_ace_match(&acep[i + 4],
fa9e4066f08beec538e775443c5be79dd423fcabahrens DENY, ACE_EVERYONE, EVERYONE_DENY_MASK) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_ace_match(&acep[i + 5], ALLOW, ACE_EVERYONE,
fa9e4066f08beec538e775443c5be79dd423fcabahrens EVERYONE_ALLOW_MASK))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (1);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Apply step 1g, to group entries
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Need to deal with corner case where group may have
fa9e4066f08beec538e775443c5be79dd423fcabahrens * greater permissions than owner. If so then limit
fa9e4066f08beec538e775443c5be79dd423fcabahrens * group permissions, based on what extra permissions
fa9e4066f08beec538e775443c5be79dd423fcabahrens * group has.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_fixup_group_entries(ace_t *acep, mode_t mode)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode_t extramode = (mode >> 3) & 07;
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode_t ownermode = (mode >> 6);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep[0].a_flags & ACE_IDENTIFIER_GROUP) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens extramode &= ~ownermode;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (extramode) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (extramode & 04) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[0].a_access_mask &= ~ACE_READ_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[1].a_access_mask &= ~ACE_READ_DATA;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (extramode & 02) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[0].a_access_mask &=
fa9e4066f08beec538e775443c5be79dd423fcabahrens ~(ACE_WRITE_DATA|ACE_APPEND_DATA);
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[1].a_access_mask &=
fa9e4066f08beec538e775443c5be79dd423fcabahrens ~(ACE_WRITE_DATA|ACE_APPEND_DATA);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (extramode & 01) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[0].a_access_mask &= ~ACE_EXECUTE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[1].a_access_mask &= ~ACE_EXECUTE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Apply the chmod algorithm as described
fa9e4066f08beec538e775443c5be79dd423fcabahrens * in PSARC/2002/240
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_chmod(znode_t *zp, uint64_t mode, zfs_acl_t *aclp,
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_t *tx)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfsvfs_t *zfsvfs = zp->z_zfsvfs;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int i;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int entry_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int reuse_deny;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int need_canonical_six = 1;
de122929e7c37df60cbea70616404e22d20e025bmarks int inherit = 0;
de122929e7c37df60cbea70616404e22d20e025bmarks int iflags;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_acl_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens i = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens while (i < aclp->z_acl_count) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks entry_type = (acep[i].a_flags & ACE_TYPE_FLAGS);
de122929e7c37df60cbea70616404e22d20e025bmarks iflags = (acep[i].a_flags & ALL_INHERIT);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((acep[i].a_type != ALLOW && acep[i].a_type != DENY) ||
de122929e7c37df60cbea70616404e22d20e025bmarks (iflags & ACE_INHERIT_ONLY_ACE)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens i++;
de122929e7c37df60cbea70616404e22d20e025bmarks if (iflags)
de122929e7c37df60cbea70616404e22d20e025bmarks inherit = 1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_acl_mode == DISCARD) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_ace_remove(aclp, i);
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Need to split ace into two?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
de122929e7c37df60cbea70616404e22d20e025bmarks if ((iflags & (ACE_FILE_INHERIT_ACE|
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_DIRECTORY_INHERIT_ACE)) &&
de122929e7c37df60cbea70616404e22d20e025bmarks (!(iflags & ACE_INHERIT_ONLY_ACE))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_split_ace(aclp, i);
fa9e4066f08beec538e775443c5be79dd423fcabahrens i++;
de122929e7c37df60cbea70616404e22d20e025bmarks inherit = 1;
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (entry_type == ACE_OWNER || entry_type == ACE_EVERYONE ||
fa9e4066f08beec538e775443c5be79dd423fcabahrens (entry_type == OWNING_GROUP)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[i].a_access_mask &= ~OGE_CLEAR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens i++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (acep[i].a_type == ALLOW) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Check preceding ACE if any, to see
fa9e4066f08beec538e775443c5be79dd423fcabahrens * if we need to prepend a DENY ACE.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * This is only applicable when the acl_mode
fa9e4066f08beec538e775443c5be79dd423fcabahrens * property == groupmask.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_acl_mode == GROUPMASK) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens reuse_deny = zfs_reuse_deny(acep, i);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (reuse_deny == B_FALSE) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_prepend_deny(zp, aclp,
fa9e4066f08beec538e775443c5be79dd423fcabahrens i, mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens i++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_prepend_fixup(
fa9e4066f08beec538e775443c5be79dd423fcabahrens &acep[i - 1],
fa9e4066f08beec538e775443c5be79dd423fcabahrens &acep[i], mode,
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_uid);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_fixup_group_entries(&acep[i - 1],
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens i++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Check out last six aces, if we have six.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (aclp->z_acl_count >= 6) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens i = aclp->z_acl_count - 6;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfs_have_canonical_six(aclp, i)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens need_canonical_six = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (need_canonical_six) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_append(aclp, 6);
fa9e4066f08beec538e775443c5be79dd423fcabahrens i = aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], 0, DENY, -1, ACE_OWNER);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], OWNER_ALLOW_MASK, ALLOW, -1, ACE_OWNER);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], 0, DENY, -1, OWNING_GROUP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], 0, ALLOW, -1, OWNING_GROUP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], EVERYONE_DENY_MASK,
fa9e4066f08beec538e775443c5be79dd423fcabahrens DENY, -1, ACE_EVERYONE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_set_ace(&acep[i++], EVERYONE_ALLOW_MASK,
fa9e4066f08beec538e775443c5be79dd423fcabahrens ALLOW, -1, ACE_EVERYONE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count += 6;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_fixup_canonical_six(aclp, mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_mode = mode;
de122929e7c37df60cbea70616404e22d20e025bmarks error = zfs_aclset_common(zp, aclp, tx, &inherit);
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_chmod_setattr(znode_t *zp, uint64_t mode, dmu_tx_t *tx)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock zfs_acl_t *aclp = NULL;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(MUTEX_HELD(&zp->z_lock));
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_acl_lock);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock error = zfs_acl_node_read(zp, &aclp);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (error == 0)
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock error = zfs_acl_chmod(zp, mode, aclp, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (aclp)
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * strip off write_owner and write_acl
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic void
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_securemode_update(zfsvfs_t *zfsvfs, ace_t *acep)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((zfsvfs->z_acl_inherit == SECURE) &&
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks (acep->a_type == ALLOW))
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep->a_access_mask &= ~SECURE_CLEAR;
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * inherit inheritable ACEs from parent
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic zfs_acl_t *
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_acl_inherit(znode_t *zp, zfs_acl_t *paclp)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfsvfs_t *zfsvfs = zp->z_zfsvfs;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *pacep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int ace_cnt = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int pace_cnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int i, j;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp = NULL;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens i = j = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens pace_cnt = paclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens pacep = paclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_acl_inherit != DISCARD) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens for (i = 0; i != pace_cnt; i++) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_acl_inherit == NOALLOW &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens pacep[i].a_type == ALLOW)
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfs_ace_can_use(zp, &pacep[i])) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_cnt++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!(pacep[i].a_flags &
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_NO_PROPAGATE_INHERIT_ACE))
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_cnt++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_alloc(ace_cnt + OGE_PAD);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (ace_cnt && zfsvfs->z_acl_inherit != DISCARD) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens pacep = paclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens for (i = 0; i != pace_cnt; i++) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_acl_inherit == NOALLOW &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens pacep[i].a_type == ALLOW)
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfs_ace_can_use(zp, &pacep[i])) {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Now create entry for inherited ace
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep[j] = pacep[i];
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks /*
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks * When AUDIT/ALARM a_types are supported
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks * they should be inherited here.
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if ((pacep[i].a_flags &
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ACE_NO_PROPAGATE_INHERIT_ACE) ||
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks (ZTOV(zp)->v_type != VDIR)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens acep[j].a_flags &= ~ALL_INHERIT;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_securemode_update(zfsvfs, &acep[j]);
fa9e4066f08beec538e775443c5be79dd423fcabahrens j++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(ZTOV(zp)->v_type == VDIR);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If we are inheriting an ACE targeted for
55601ddb0a1b2278559e8e1723ff6e08c0aeb553marks * only files, then make sure inherit_only
55601ddb0a1b2278559e8e1723ff6e08c0aeb553marks * is on for future propagation.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if ((pacep[i].a_flags & (ACE_FILE_INHERIT_ACE |
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ACE_DIRECTORY_INHERIT_ACE)) !=
55601ddb0a1b2278559e8e1723ff6e08c0aeb553marks ACE_FILE_INHERIT_ACE) {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks j++;
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep[j] = acep[j-1];
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep[j-1].a_flags |=
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ACE_INHERIT_ONLY_ACE;
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep[j].a_flags &= ~ALL_INHERIT;
55601ddb0a1b2278559e8e1723ff6e08c0aeb553marks } else {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks acep[j].a_flags |= ACE_INHERIT_ONLY_ACE;
55601ddb0a1b2278559e8e1723ff6e08c0aeb553marks }
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_securemode_update(zfsvfs, &acep[j]);
fa9e4066f08beec538e775443c5be79dd423fcabahrens j++;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count = j;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(aclp->z_slots >= aclp->z_acl_count);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Create file system object initial permissions
fa9e4066f08beec538e775443c5be79dd423fcabahrens * including inheritable ACEs.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensvoid
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_perm_init(znode_t *zp, znode_t *parent, int flag,
fa9e4066f08beec538e775443c5be79dd423fcabahrens vattr_t *vap, dmu_tx_t *tx, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint64_t mode;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uid_t uid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid_t gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int pull_down;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp, *paclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode = MAKEIMODE(vap->va_type, vap->va_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Determine uid and gid.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((flag & (IS_ROOT_NODE | IS_REPLAY)) ||
fa9e4066f08beec538e775443c5be79dd423fcabahrens ((flag & IS_XATTR) && (vap->va_type == VDIR))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens uid = vap->va_uid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid = vap->va_gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens uid = crgetuid(cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((vap->va_mask & AT_GID) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens ((vap->va_gid == parent->z_phys->zp_gid) ||
fa9e4066f08beec538e775443c5be79dd423fcabahrens groupmember(vap->va_gid, cr) ||
d394a7544e3fd35f9cbe064e8d86cdaa85417402xs secpolicy_vnode_create_gid(cr) == 0))
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid = vap->va_gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid = (parent->z_phys->zp_mode & S_ISGID) ?
fa9e4066f08beec538e775443c5be79dd423fcabahrens parent->z_phys->zp_gid : crgetgid(cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If we're creating a directory, and the parent directory has the
fa9e4066f08beec538e775443c5be79dd423fcabahrens * set-GID bit set, set in on the new directory.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Otherwise, if the user is neither privileged nor a member of the
fa9e4066f08beec538e775443c5be79dd423fcabahrens * file's new group, clear the file's set-GID bit.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((parent->z_phys->zp_mode & S_ISGID) && (vap->va_type == VDIR))
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= S_ISGID;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((mode & S_ISGID) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens secpolicy_vnode_setids_setgids(cr, gid) != 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode &= ~S_ISGID;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_uid = uid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_gid = gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_mode = mode;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&parent->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens pull_down = (parent->z_phys->zp_flags & ZFS_INHERIT_ACE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (pull_down) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&parent->z_acl_lock);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock VERIFY(0 == zfs_acl_node_read(parent, &paclp));
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&parent->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_inherit(zp, paclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(paclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else {
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_alloc(6);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&parent->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = zfs_acl_chmod(zp, mode, aclp, tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT3U(error, ==, 0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
0a787dc5d2d96ab63f180c8895835c584db505f2marks * Should ACE be inherited?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_ace_can_use(znode_t *zp, ace_t *acep)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int vtype = ZTOV(zp)->v_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens int iflags = (acep->a_flags & 0xf);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((vtype == VDIR) && (iflags & ACE_DIRECTORY_INHERIT_ACE))
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (1);
fa9e4066f08beec538e775443c5be79dd423fcabahrens else if (iflags & ACE_FILE_INHERIT_ACE)
0a787dc5d2d96ab63f180c8895835c584db505f2marks return (!((vtype == VDIR) &&
0a787dc5d2d96ab63f180c8895835c584db505f2marks (iflags & ACE_NO_PROPAGATE_INHERIT_ACE)));
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Retrieve a files ACL
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_getacl(znode_t *zp, vsecattr_t *vsecp, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ulong_t mask = vsecp->vsa_mask & (VSA_ACE | VSA_ACECNT);
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error = zfs_zaccess(zp, ACE_READ_ACL, cr)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If owner of file then allow reading of the
fa9e4066f08beec538e775443c5be79dd423fcabahrens * ACL.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (crgetuid(cr) != zp->z_phys->zp_uid)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mask == 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (ENOSYS);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock error = zfs_acl_node_read(zp, &aclp);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (error != 0) {
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock mutex_exit(&zp->z_acl_lock);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock return (error);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock }
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mask & VSA_ACECNT) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens vsecp->vsa_aclcnt = aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mask & VSA_ACE) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens vsecp->vsa_aclentp = kmem_alloc(aclp->z_acl_count *
fa9e4066f08beec538e775443c5be79dd423fcabahrens sizeof (ace_t), KM_SLEEP);
fa9e4066f08beec538e775443c5be79dd423fcabahrens bcopy(aclp->z_acl, vsecp->vsa_aclentp,
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count * sizeof (ace_t));
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Set a files ACL
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_setacl(znode_t *zp, vsecattr_t *vsecp, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfsvfs_t *zfsvfs = zp->z_zfsvfs;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zilog_t *zilog = zfsvfs->z_log;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *acep = vsecp->vsa_aclentp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int aclcnt = vsecp->vsa_aclcnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ulong_t mask = vsecp->vsa_mask & (VSA_ACE | VSA_ACECNT);
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_t *tx;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int inherit;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint64_t seq = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mask == 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EINVAL);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (!zfs_acl_valid(zp, acep, aclcnt, &inherit))
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EINVAL);
fa9e4066f08beec538e775443c5be79dd423fcabahrenstop:
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = zfs_zaccess_v4_perm(zp, ACE_WRITE_ACL, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error == EACCES || error == ACCESS_UNDETERMINED) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((error = secpolicy_vnode_setdac(cr,
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_uid)) != 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else if (error) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error == EROFS ? error : EPERM);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens tx = dmu_tx_create(zfsvfs->z_os);
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_hold_bonus(tx, zp->z_id);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zp->z_phys->zp_acl.z_acl_extern_obj) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_hold_write(tx, zp->z_phys->zp_acl.z_acl_extern_obj,
fa9e4066f08beec538e775443c5be79dd423fcabahrens 0, ZFS_ACL_SIZE(aclcnt));
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else if (aclcnt > ACE_SLOT_CNT) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_hold_write(tx, DMU_NEW_OBJECT, 0, ZFS_ACL_SIZE(aclcnt));
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = dmu_tx_assign(tx, zfsvfs->z_assign);
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error == ERESTART && zfsvfs->z_assign == TXG_NOWAIT) {
8a2f1b9190d1dc288470a1fd2776d79ce82cb129ahrens dmu_tx_wait(tx);
8a2f1b9190d1dc288470a1fd2776d79ce82cb129ahrens dmu_tx_abort(tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens goto top;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
8a2f1b9190d1dc288470a1fd2776d79ce82cb129ahrens dmu_tx_abort(tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp = zfs_acl_alloc(aclcnt);
fa9e4066f08beec538e775443c5be79dd423fcabahrens bcopy(acep, aclp->z_acl, sizeof (ace_t) * aclcnt);
fa9e4066f08beec538e775443c5be79dd423fcabahrens aclp->z_acl_count = aclcnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = zfs_aclset_common(zp, aclp, tx, &inherit);
fa9e4066f08beec538e775443c5be79dd423fcabahrens ASSERT(error == 0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens seq = zfs_log_acl(zilog, tx, TX_ACL, zp, aclcnt, acep);
fa9e4066f08beec538e775443c5be79dd423fcabahrens dmu_tx_commit(tx);
fa9e4066f08beec538e775443c5be79dd423fcabahrensdone:
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zil_commit(zilog, seq, 0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarkszfs_ace_access(ace_t *zacep, int *working_mode)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (*working_mode == 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (zacep->a_access_mask & *working_mode) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zacep->a_type == ALLOW) {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks *working_mode &=
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ~(*working_mode & zacep->a_access_mask);
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (*working_mode == 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens } else if (zacep->a_type == DENY) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EACCES);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * haven't been specifcally denied at this point
fa9e4066f08beec538e775443c5be79dd423fcabahrens * so return UNDETERMINED.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (ACCESS_UNDETERMINED);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensstatic int
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess_common(znode_t *zp, int v4_mode, int *working_mode, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_t *aclp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfsvfs_t *zfsvfs = zp->z_zfsvfs;
fa9e4066f08beec538e775443c5be79dd423fcabahrens ace_t *zacep;
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid_t gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int cnt;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int i;
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int access_deny = ACCESS_UNDETERMINED;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uint_t entry_type;
fa9e4066f08beec538e775443c5be79dd423fcabahrens uid_t uid = crgetuid(cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks *working_mode = v4_mode;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zfsvfs->z_assign >= TXG_INITIAL) /* ZIL replay */
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((v4_mode & WRITE_MASK) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (zp->z_zfsvfs->z_vfs->vfs_flag & VFS_RDONLY) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (!IS_DEVVP(ZTOV(zp)))) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EROFS);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_enter(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock error = zfs_acl_node_read(zp, &aclp);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock if (error != 0) {
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock mutex_exit(&zp->z_acl_lock);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock return (error);
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock }
ea8dc4b6d2251b437950c0056bc626b311c73c27eschrock
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens zacep = aclp->z_acl;
fa9e4066f08beec538e775443c5be79dd423fcabahrens cnt = aclp->z_acl_count;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens for (i = 0; i != cnt; i++) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks DTRACE_PROBE2(zfs__access__common,
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ace_t *, &zacep[i], int, *working_mode);
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (zacep[i].a_flags & ACE_INHERIT_ONLY_ACE)
fa9e4066f08beec538e775443c5be79dd423fcabahrens continue;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks entry_type = (zacep[i].a_flags & ACE_TYPE_FLAGS);
fa9e4066f08beec538e775443c5be79dd423fcabahrens switch (entry_type) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_OWNER:
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (uid == zp->z_phys->zp_uid) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens access_deny = zfs_ace_access(&zacep[i],
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks working_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens case (ACE_IDENTIFIER_GROUP | ACE_GROUP):
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_IDENTIFIER_GROUP:
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Owning group gid is in znode not ACL
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (entry_type == (ACE_IDENTIFIER_GROUP | ACE_GROUP))
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid = zp->z_phys->zp_gid;
fa9e4066f08beec538e775443c5be79dd423fcabahrens else
fa9e4066f08beec538e775443c5be79dd423fcabahrens gid = zacep[i].a_who;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (groupmember(gid, cr)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens access_deny = zfs_ace_access(&zacep[i],
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks working_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens case ACE_EVERYONE:
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks access_deny = zfs_ace_access(&zacep[i], working_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /* USER Entry */
fa9e4066f08beec538e775443c5be79dd423fcabahrens default:
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (entry_type == 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (uid == zacep[i].a_who) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens access_deny = zfs_ace_access(&zacep[i],
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks working_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (EIO);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (access_deny != ACCESS_UNDETERMINED)
fa9e4066f08beec538e775443c5be79dd423fcabahrens break;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens mutex_exit(&zp->z_acl_lock);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zfs_acl_free(aclp);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (access_deny);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Determine whether Access should be granted/denied, invoking least
fa9e4066f08beec538e775443c5be79dd423fcabahrens * priv subsytem when a deny is determined.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess(znode_t *zp, int mode, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks int working_mode;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int is_attr;
fa9e4066f08beec538e775443c5be79dd423fcabahrens znode_t *xzp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens znode_t *check_zp = zp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens is_attr = ((zp->z_phys->zp_flags & ZFS_XATTR) &&
fa9e4066f08beec538e775443c5be79dd423fcabahrens (ZTOV(zp)->v_type == VDIR));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If attribute then validate against base file
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (is_attr) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if ((error = zfs_zget(zp->z_zfsvfs,
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp->z_phys->zp_parent, &xzp)) != 0) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens check_zp = xzp;
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * fixup mode to map to xattr perms
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & (ACE_WRITE_DATA|ACE_APPEND_DATA)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode &= ~(ACE_WRITE_DATA|ACE_APPEND_DATA);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= ACE_WRITE_NAMED_ATTRS;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (mode & (ACE_READ_DATA|ACE_EXECUTE)) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode &= ~(ACE_READ_DATA|ACE_EXECUTE);
fa9e4066f08beec538e775443c5be79dd423fcabahrens mode |= ACE_READ_NAMED_ATTRS;
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = zfs_zaccess_common(check_zp, mode, &working_mode, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error == EROFS) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (is_attr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens VN_RELE(ZTOV(xzp));
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (error || working_mode) {
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks working_mode = (zfs_v4_to_unix(working_mode) << 6);
fa9e4066f08beec538e775443c5be79dd423fcabahrens error = secpolicy_vnode_access(cr, ZTOV(check_zp),
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks check_zp->z_phys->zp_uid, working_mode);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (is_attr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens VN_RELE(ZTOV(xzp));
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Special zaccess function to check for special nfsv4 perm.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * doesn't call secpolicy_vnode_access() for failure, since that
fa9e4066f08beec538e775443c5be79dd423fcabahrens * would probably be the wrong policy function to call.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * instead its up to the caller to handle that situation.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess_v4_perm(znode_t *zp, int mode, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int working_mode = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (zfs_zaccess_common(zp, mode, &working_mode, cr));
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Translate tradition unix VREAD/VWRITE/VEXEC mode into
fa9e4066f08beec538e775443c5be79dd423fcabahrens * native ACL format and call zfs_zaccess()
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess_rwx(znode_t *zp, mode_t mode, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int v4_mode = zfs_unix_to_v4(mode >> 6);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (zfs_zaccess(zp, v4_mode, cr));
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens/*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Determine whether Access should be granted/deny, without
fa9e4066f08beec538e775443c5be79dd423fcabahrens * consulting least priv subsystem.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * The following chart is the recommended NFSv4 enforcement for
fa9e4066f08beec538e775443c5be79dd423fcabahrens * ability to delete an object.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | Parent Dir | Target Object Permissions |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | permissions | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | | ACL Allows | ACL Denies| Delete |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | | Delete | Delete | unspecified|
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | ACL Allows | Permit | Permit | Permit |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | DELETE_CHILD | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | ACL Denies | Permit | Deny | Deny |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | DELETE_CHILD | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | ACL specifies | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | only allow | Permit | Permit | Permit |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | write and | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | execute | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | ACL denies | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | write and | Permit | Deny | Deny |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * | execute | | | |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * -------------------------------------------------------
fa9e4066f08beec538e775443c5be79dd423fcabahrens * ^
fa9e4066f08beec538e775443c5be79dd423fcabahrens * |
fa9e4066f08beec538e775443c5be79dd423fcabahrens * No search privilege, can't even look up file?
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess_delete(znode_t *dzp, znode_t *zp, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int dzp_working_mode = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int zp_working_mode = 0;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int dzp_error, zp_error;
84c5a1550ecbf7356ab4133238160367c507f4fbmarks int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Arghh, this check is going to require a couple of questions
fa9e4066f08beec538e775443c5be79dd423fcabahrens * to be asked. We want specific DELETE permissions to
fa9e4066f08beec538e775443c5be79dd423fcabahrens * take precedence over WRITE/EXECUTE. We don't
fa9e4066f08beec538e775443c5be79dd423fcabahrens * want an ACL such as this to mess us up.
fa9e4066f08beec538e775443c5be79dd423fcabahrens * user:sloar:write_data:deny,user:sloar:delete:allow
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * However, deny permissions may ultimately be overridden
fa9e4066f08beec538e775443c5be79dd423fcabahrens * by secpolicy_vnode_access().
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens dzp_error = zfs_zaccess_common(dzp, ACE_DELETE_CHILD,
fa9e4066f08beec538e775443c5be79dd423fcabahrens &dzp_working_mode, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens zp_error = zfs_zaccess_common(zp, ACE_DELETE, &zp_working_mode, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (dzp_error == EROFS || zp_error == EROFS)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (dzp_error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * First handle the first row
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if ((dzp_working_mode & ACE_DELETE_CHILD) == 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Second row
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if ((zp_working_mode & ACE_DELETE) == 0)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (0);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Third Row
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens dzp_error = zfs_zaccess_common(dzp, ACE_WRITE_DATA|ACE_EXECUTE,
fa9e4066f08beec538e775443c5be79dd423fcabahrens &dzp_working_mode, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (dzp_error == EROFS)
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (dzp_error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if ((dzp_working_mode & (ACE_WRITE_DATA|ACE_EXECUTE)) == 0)
84c5a1550ecbf7356ab4133238160367c507f4fbmarks goto sticky;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Fourth Row
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks if (((dzp_working_mode & (ACE_WRITE_DATA|ACE_EXECUTE)) != 0) &&
169cdae232f15e542d6af0a9ce30c3f84222bc0fmarks ((zp_working_mode & ACE_DELETE) == 0))
84c5a1550ecbf7356ab4133238160367c507f4fbmarks goto sticky;
84c5a1550ecbf7356ab4133238160367c507f4fbmarks
84c5a1550ecbf7356ab4133238160367c507f4fbmarks error = secpolicy_vnode_access(cr, ZTOV(zp),
84c5a1550ecbf7356ab4133238160367c507f4fbmarks dzp->z_phys->zp_uid, S_IWRITE|S_IEXEC);
84c5a1550ecbf7356ab4133238160367c507f4fbmarks
84c5a1550ecbf7356ab4133238160367c507f4fbmarks if (error)
84c5a1550ecbf7356ab4133238160367c507f4fbmarks return (error);
84c5a1550ecbf7356ab4133238160367c507f4fbmarks
84c5a1550ecbf7356ab4133238160367c507f4fbmarkssticky:
84c5a1550ecbf7356ab4133238160367c507f4fbmarks error = zfs_sticky_remove_access(dzp, zp, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
84c5a1550ecbf7356ab4133238160367c507f4fbmarks return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrensint
fa9e4066f08beec538e775443c5be79dd423fcabahrenszfs_zaccess_rename(znode_t *sdzp, znode_t *szp, znode_t *tdzp,
fa9e4066f08beec538e775443c5be79dd423fcabahrens znode_t *tzp, cred_t *cr)
fa9e4066f08beec538e775443c5be79dd423fcabahrens{
fa9e4066f08beec538e775443c5be79dd423fcabahrens int add_perm;
fa9e4066f08beec538e775443c5be79dd423fcabahrens int error;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens add_perm = (ZTOV(szp)->v_type == VDIR) ?
fa9e4066f08beec538e775443c5be79dd423fcabahrens ACE_ADD_SUBDIRECTORY : ACE_ADD_FILE;
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Rename permissions are combination of delete permission +
fa9e4066f08beec538e775443c5be79dd423fcabahrens * add file/subdir permission.
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * first make sure we do the delete portion.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If that succeeds then check for add_file/add_subdir permissions
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error = zfs_zaccess_delete(sdzp, szp, cr))
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * If we have a tzp, see if we can delete it?
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (tzp) {
fa9e4066f08beec538e775443c5be79dd423fcabahrens if (error = zfs_zaccess_delete(tdzp, tzp, cr))
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens }
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens /*
fa9e4066f08beec538e775443c5be79dd423fcabahrens * Now check for add permissions
fa9e4066f08beec538e775443c5be79dd423fcabahrens */
84c5a1550ecbf7356ab4133238160367c507f4fbmarks error = zfs_zaccess(tdzp, add_perm, cr);
fa9e4066f08beec538e775443c5be79dd423fcabahrens
fa9e4066f08beec538e775443c5be79dd423fcabahrens return (error);
fa9e4066f08beec538e775443c5be79dd423fcabahrens}