Re: [PATCH] ext4: fix reserved group initialization

Ritesh Harjani (IBM) <[email protected]>
Newsgroups org.kernel.vger.linux-ext4,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
guzebing <[email protected]> writes:

> ext4 initializes the in-memory reserved uid and gid from the on-disk
> default reserved id fields during mount. The s_resgid assignment
> accidentally uses ext4_get_resuid(), so the reserved group is initialized
> from the reserved uid instead of the reserved gid.
>
> As a result, members of the configured reserved group can be denied access
> to reserved blocks, while members of a group whose gid matches the
> reserved uid can be incorrectly allowed to use them.
>
> Initialize s_resgid with ext4_get_resgid() instead.
>
> Fixes: 12c84dd4d308 ("ext4: add support for 32-bit default reserved uid and gid values")
> Signed-off-by: guzebing <[email protected]>

This was posted before [1] and looks it already landed in ext4's dev
branch [2].

[1]: https://lore.kernel.org/all/[email protected]/
[2]: https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?h=dev&id=c87abbab6147dcc5aa1fd8f2a61734d58d8b99ec

-ritesh

> ---
>  fs/ext4/super.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/ext4/super.c b/fs/ext4/super.c
> index 245f67d10ded3..63de62a75a543 100644
> --- a/fs/ext4/super.c
> +++ b/fs/ext4/super.c
> @@ -5369,7 +5369,7 @@ static int __ext4_fill_super(struct fs_context *fc, struct super_block *sb)
>  	ext4_set_def_opts(sb, es);
>  
>  	sbi->s_resuid = make_kuid(&init_user_ns, ext4_get_resuid(es));
> -	sbi->s_resgid = make_kgid(&init_user_ns, ext4_get_resuid(es));
> +	sbi->s_resgid = make_kgid(&init_user_ns, ext4_get_resgid(es));
>  	sbi->s_commit_interval = JBD2_DEFAULT_MAX_COMMIT_AGE * HZ;
>  	sbi->s_min_batch_time = EXT4_DEF_MIN_BATCH_TIME;
>  	sbi->s_max_batch_time = EXT4_DEF_MAX_BATCH_TIME;
>
> base-commit: 06cf61899d6498b33e4b7c87d99d5bd471ccc375
> -- 
> 2.20.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.