Re: [PATCH] ceph: use the mount idmap for the owner checks in the SET_LAYOUT ioctls

Ilya Dryomov <[email protected]>
Newsgroups org.kernel.vger.ceph-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <CAOi1vP-xdpg8KFiW93bhwtP6+8f5DB961afu42bebii5SQ3cNQ@mail.gmail.com>
On Wed, Aug 12, 2026 at 1:32 PM Xiubo Li <[email protected]> wrote:
>
> Hi Ilya,
>
> I'm not sure why I couldn't find the original email of this. I checked
> the changes on lore.kernel.org.
>
> The fix looks correct to me.
>
> On an idmapped mount, using &nop_mnt_idmap compares the caller's fsuid
> against the unmapped on-disk uid directly, which would wrongly deny
> the actual mapped owner and potentially allow an unrelated caller.
> Both functions already have the struct file, so switching to
> file_mnt_idmap(file) is the right thing to do.
>
> Reviewed-by: Xiubo Li <[email protected]>

Applied.

Thanks,

                Ilya

>
> Thanks
> Xiubo Li
>
> On Sun, 9 Aug 2026 at 10:33, Ilya Dryomov <[email protected]> wrote:
> >
> > On Sat, Aug 8, 2026 at 8:31 AM Max Kellermann <[email protected]> wrote:
> > >
> > > On Tue, Jul 28, 2026 at 1:31 PM Ilya Dryomov <[email protected]> wrote:
> > > > Was there any specific reason you used nop_mnt_idmap for these checks?
> > >
> > > No, I copied that check from another filesystem, probably ext2. I had
> > > no idea what this parameter means (and I have never used idmappings).
> > > I guess the amended parameter in this patch is correct.
> >
> > Hi Xiubo,
> >
> > You reviewed Max's "ceph: add owner/capability checks for
> > CEPH_IOC_SET_LAYOUT*" patch.  Would you be able to review this fixup as
> > well?
> >
> > Thanks,
> >
> >                 Ilya
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.