[PATCH openEuler-1.0-LTS] nfsd: gate nfs3 setacl by argp->mask
From: Chris Mason <clm@meta.com> stable inclusion from stable-6.6.157 commit 3be1d8611dae4829e4608007db29f4a8748c37b2 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18934 CVE: CVE-2026-89671 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=... ------------------------------ commit 453d7198a0ab07a12d46e0575861ac7b932da17e upstream. nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl_default verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set: nfs3svc_decode_setaclargs() if (args->mask & NFS_ACL) decode into acl_access if (args->mask & NFS_DFACL) decode into acl_default /* otherwise the pointer stays NULL (pc_argzero) */ nfsd3_proc_setacl() set_posix_acl(.., ACL_TYPE_ACCESS, argp->acl_access) set_posix_acl(.., ACL_TYPE_DEFAULT, argp->acl_default) set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFS_ACL silently drops the directory's default ACL; mask=0 drops both. The sibling nfsd3_proc_getacl() already consults argp->mask before touching each arm; mirror that in setacl. Fix by wrapping each set_posix_acl() call in the matching mask bit check and initializing error to 0 before inode_lock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfs_ok. The out_drop_lock path and the unconditional posix_acl_release() at out: are preserved; both NULL-tolerate the skipped arms. Fixes: a257cdd0e217 ("[PATCH] NFSD: Add server support for NFSv3 ACLs.") Cc: stable@vger.kernel.org Assisted-by: kres:claude-opus-4-7 Reported-by: Chris Mason <clm@meta.com> Signed-off-by: Chris Mason <clm@meta.com> Link: https://patch.msgid.link/20260530-nfsd-fixes-v2-5-f27e8eb4d974@kernel.org Signed-off-by: Chuck Lever <chuck.lever@oracle.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Conflicts: fs/nfsd/nfs3acl.c [Context differences, commit bb4d53d66e4b ("NFSD: use (un)lock_inode instead of fh_(un)lock for file operations") has not been merged, so fh_lock/fh_unlock are kept. And set_posix_acl() in this tree takes (inode, type, acl) without the mnt_idmap/dentry arguments, so the calls are rewritten to the local signature instead of the upstream (&nop_mnt_idmap, fh->fh_dentry, ...) form.] Signed-off-by: Gaosheng Cui <cuigaosheng1@huawei.com> --- fs/nfsd/nfs3acl.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/fs/nfsd/nfs3acl.c b/fs/nfsd/nfs3acl.c index 04cc86a520ca..027a0fb0f142 100644 --- a/fs/nfsd/nfs3acl.c +++ b/fs/nfsd/nfs3acl.c @@ -106,10 +106,17 @@ static __be32 nfsd3_proc_setacl(struct svc_rqst *rqstp) fh_lock(fh); - error = set_posix_acl(inode, ACL_TYPE_ACCESS, argp->acl_access); - if (error) - goto out_drop_lock; - error = set_posix_acl(inode, ACL_TYPE_DEFAULT, argp->acl_default); + error = 0; + if (argp->mask & NFS_ACL) { + error = set_posix_acl(inode, ACL_TYPE_ACCESS, + argp->acl_access); + if (error) + goto out_drop_lock; + } + if (argp->mask & NFS_DFACL) { + error = set_posix_acl(inode, ACL_TYPE_DEFAULT, + argp->acl_default); + } out_drop_lock: fh_unlock(fh); -- 2.43.0
反馈: 您发送到kernel@openeuler.org的补丁/补丁集,已成功转换为PR! PR链接地址: https://gitcode.com/openeuler/kernel/merge_requests/29143 邮件列表地址:https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/EZA... FeedBack: The patch(es) which you have sent to kernel@openeuler.org mailing list has been converted to a pull request successfully! Pull request link: https://gitcode.com/openeuler/kernel/merge_requests/29143 Mailing list address: https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/EZA...
participants (2)
-
Gaosheng Cui -
patchwork bot