[patch 1/4] vfs: utimes: move owner check into inode_change_ok()
[deliverable/linux.git] / fs / utimes.c
1 #include <linux/compiler.h>
2 #include <linux/file.h>
3 #include <linux/fs.h>
4 #include <linux/linkage.h>
5 #include <linux/mount.h>
6 #include <linux/namei.h>
7 #include <linux/sched.h>
8 #include <linux/stat.h>
9 #include <linux/utime.h>
10 #include <linux/syscalls.h>
11 #include <asm/uaccess.h>
12 #include <asm/unistd.h>
13
14 #ifdef __ARCH_WANT_SYS_UTIME
15
16 /*
17 * sys_utime() can be implemented in user-level using sys_utimes().
18 * Is this for backwards compatibility? If so, why not move it
19 * into the appropriate arch directory (for those architectures that
20 * need it).
21 */
22
23 /* If times==NULL, set access and modification to current time,
24 * must be owner or have write permission.
25 * Else, update from *times, must be owner or super user.
26 */
27 asmlinkage long sys_utime(char __user *filename, struct utimbuf __user *times)
28 {
29 struct timespec tv[2];
30
31 if (times) {
32 if (get_user(tv[0].tv_sec, &times->actime) ||
33 get_user(tv[1].tv_sec, &times->modtime))
34 return -EFAULT;
35 tv[0].tv_nsec = 0;
36 tv[1].tv_nsec = 0;
37 }
38 return do_utimes(AT_FDCWD, filename, times ? tv : NULL, 0);
39 }
40
41 #endif
42
43 static bool nsec_valid(long nsec)
44 {
45 if (nsec == UTIME_OMIT || nsec == UTIME_NOW)
46 return true;
47
48 return nsec >= 0 && nsec <= 999999999;
49 }
50
51 /* If times==NULL, set access and modification to current time,
52 * must be owner or have write permission.
53 * Else, update from *times, must be owner or super user.
54 */
55 long do_utimes(int dfd, char __user *filename, struct timespec *times, int flags)
56 {
57 int error;
58 struct nameidata nd;
59 struct dentry *dentry;
60 struct inode *inode;
61 struct iattr newattrs;
62 struct file *f = NULL;
63 struct vfsmount *mnt;
64
65 error = -EINVAL;
66 if (times && (!nsec_valid(times[0].tv_nsec) ||
67 !nsec_valid(times[1].tv_nsec))) {
68 goto out;
69 }
70
71 if (flags & ~AT_SYMLINK_NOFOLLOW)
72 goto out;
73
74 if (filename == NULL && dfd != AT_FDCWD) {
75 error = -EINVAL;
76 if (flags & AT_SYMLINK_NOFOLLOW)
77 goto out;
78
79 error = -EBADF;
80 f = fget(dfd);
81 if (!f)
82 goto out;
83 dentry = f->f_path.dentry;
84 mnt = f->f_path.mnt;
85 } else {
86 error = __user_walk_fd(dfd, filename, (flags & AT_SYMLINK_NOFOLLOW) ? 0 : LOOKUP_FOLLOW, &nd);
87 if (error)
88 goto out;
89
90 dentry = nd.path.dentry;
91 mnt = nd.path.mnt;
92 }
93
94 inode = dentry->d_inode;
95
96 error = mnt_want_write(mnt);
97 if (error)
98 goto dput_and_out;
99
100 if (times && times[0].tv_nsec == UTIME_NOW &&
101 times[1].tv_nsec == UTIME_NOW)
102 times = NULL;
103
104 newattrs.ia_valid = ATTR_CTIME | ATTR_MTIME | ATTR_ATIME;
105 if (times) {
106 error = -EPERM;
107 if (IS_APPEND(inode) || IS_IMMUTABLE(inode))
108 goto mnt_drop_write_and_out;
109
110 if (times[0].tv_nsec == UTIME_OMIT)
111 newattrs.ia_valid &= ~ATTR_ATIME;
112 else if (times[0].tv_nsec != UTIME_NOW) {
113 newattrs.ia_atime.tv_sec = times[0].tv_sec;
114 newattrs.ia_atime.tv_nsec = times[0].tv_nsec;
115 newattrs.ia_valid |= ATTR_ATIME_SET;
116 }
117
118 if (times[1].tv_nsec == UTIME_OMIT)
119 newattrs.ia_valid &= ~ATTR_MTIME;
120 else if (times[1].tv_nsec != UTIME_NOW) {
121 newattrs.ia_mtime.tv_sec = times[1].tv_sec;
122 newattrs.ia_mtime.tv_nsec = times[1].tv_nsec;
123 newattrs.ia_valid |= ATTR_MTIME_SET;
124 }
125 /*
126 * Tell inode_change_ok(), that this is an explicit time
127 * update, even if neither ATTR_ATIME_SET nor ATTR_MTIME_SET
128 * were used.
129 */
130 newattrs.ia_valid |= ATTR_TIMES_SET;
131 } else {
132 /*
133 * If times is NULL (or both times are UTIME_NOW),
134 * then we need to check permissions, because
135 * inode_change_ok() won't do it.
136 */
137 error = -EACCES;
138 if (IS_IMMUTABLE(inode))
139 goto mnt_drop_write_and_out;
140
141 if (!is_owner_or_cap(inode)) {
142 error = permission(inode, MAY_WRITE, NULL);
143 if (error)
144 goto mnt_drop_write_and_out;
145 }
146 }
147 mutex_lock(&inode->i_mutex);
148 error = notify_change(dentry, &newattrs);
149 mutex_unlock(&inode->i_mutex);
150 mnt_drop_write_and_out:
151 mnt_drop_write(mnt);
152 dput_and_out:
153 if (f)
154 fput(f);
155 else
156 path_put(&nd.path);
157 out:
158 return error;
159 }
160
161 asmlinkage long sys_utimensat(int dfd, char __user *filename, struct timespec __user *utimes, int flags)
162 {
163 struct timespec tstimes[2];
164
165 if (utimes) {
166 if (copy_from_user(&tstimes, utimes, sizeof(tstimes)))
167 return -EFAULT;
168
169 /* Nothing to do, we must not even check the path. */
170 if (tstimes[0].tv_nsec == UTIME_OMIT &&
171 tstimes[1].tv_nsec == UTIME_OMIT)
172 return 0;
173 }
174
175 return do_utimes(dfd, filename, utimes ? tstimes : NULL, flags);
176 }
177
178 asmlinkage long sys_futimesat(int dfd, char __user *filename, struct timeval __user *utimes)
179 {
180 struct timeval times[2];
181 struct timespec tstimes[2];
182
183 if (utimes) {
184 if (copy_from_user(&times, utimes, sizeof(times)))
185 return -EFAULT;
186
187 /* This test is needed to catch all invalid values. If we
188 would test only in do_utimes we would miss those invalid
189 values truncated by the multiplication with 1000. Note
190 that we also catch UTIME_{NOW,OMIT} here which are only
191 valid for utimensat. */
192 if (times[0].tv_usec >= 1000000 || times[0].tv_usec < 0 ||
193 times[1].tv_usec >= 1000000 || times[1].tv_usec < 0)
194 return -EINVAL;
195
196 tstimes[0].tv_sec = times[0].tv_sec;
197 tstimes[0].tv_nsec = 1000 * times[0].tv_usec;
198 tstimes[1].tv_sec = times[1].tv_sec;
199 tstimes[1].tv_nsec = 1000 * times[1].tv_usec;
200 }
201
202 return do_utimes(dfd, filename, utimes ? tstimes : NULL, 0);
203 }
204
205 asmlinkage long sys_utimes(char __user *filename, struct timeval __user *utimes)
206 {
207 return sys_futimesat(AT_FDCWD, filename, utimes);
208 }
This page took 0.036376 seconds and 6 git commands to generate.