xfs: Check Permissions
Implemented the xfs_access hook and we now check for permissions where required. Change-Id: Idaa71f300e0a73951d13073b66cb9ff37dbfa3ec Reviewed-on: https://review.haiku-os.org/c/haiku/+/3151 Reviewed-by: Adrien Destugues <[email protected]>
This commit is contained in:
committed by
Adrien Destugues
parent
91cbfa855e
commit
4a2870fcf2
@@ -181,6 +181,18 @@ Inode::HasFileTypeField() const
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
status_t
|
||||||
|
Inode::CheckPermissions(int accessMode) const
|
||||||
|
{
|
||||||
|
// you never have write access to a read-only volume
|
||||||
|
if ((accessMode & W_OK) != 0 && fVolume->IsReadOnly())
|
||||||
|
return B_READ_ONLY_DEVICE;
|
||||||
|
|
||||||
|
return check_access_permissions(accessMode, Mode(),
|
||||||
|
(uint32)fNode->GroupId(), (uint32)fNode->UserId());
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
status_t
|
status_t
|
||||||
Inode::GetFromDisk()
|
Inode::GetFromDisk()
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -189,6 +189,7 @@ public:
|
|||||||
void GetAccessTime(struct timespec& timestamp) const
|
void GetAccessTime(struct timespec& timestamp) const
|
||||||
{ fNode->GetAccessTime(timestamp); }
|
{ fNode->GetAccessTime(timestamp); }
|
||||||
|
|
||||||
|
status_t CheckPermissions(int accessMode) const;
|
||||||
uint32 UserId() const { return fNode->UserId(); }
|
uint32 UserId() const { return fNode->UserId(); }
|
||||||
uint32 GroupId() const { return fNode->GroupId(); }
|
uint32 GroupId() const { return fNode->GroupId(); }
|
||||||
bool HasFileTypeField() const;
|
bool HasFileTypeField() const;
|
||||||
|
|||||||
@@ -211,14 +211,16 @@ xfs_lookup(fs_volume *_volume, fs_vnode *_directory, const char *name,
|
|||||||
if (!directory->IsDirectory())
|
if (!directory->IsDirectory())
|
||||||
return B_NOT_A_DIRECTORY;
|
return B_NOT_A_DIRECTORY;
|
||||||
|
|
||||||
//TODO: pretend everything is accessible. We should actually checking
|
status_t status = directory->CheckPermissions(X_OK);
|
||||||
//for permission here.
|
if (status < B_OK)
|
||||||
|
return status;
|
||||||
|
|
||||||
DirectoryIterator* iterator =
|
DirectoryIterator* iterator =
|
||||||
new(std::nothrow) DirectoryIterator(directory);
|
new(std::nothrow) DirectoryIterator(directory);
|
||||||
if (iterator == NULL)
|
if (iterator == NULL)
|
||||||
return B_NO_MEMORY;
|
return B_NO_MEMORY;
|
||||||
|
|
||||||
status_t status = iterator->Init();
|
status = iterator->Init();
|
||||||
if (status != B_OK) {
|
if (status != B_OK) {
|
||||||
delete iterator;
|
delete iterator;
|
||||||
return status;
|
return status;
|
||||||
@@ -308,9 +310,8 @@ xfs_free_cookie(fs_volume *_volume, fs_vnode *_node, void *_cookie)
|
|||||||
static status_t
|
static status_t
|
||||||
xfs_access(fs_volume *_volume, fs_vnode *_node, int accessMode)
|
xfs_access(fs_volume *_volume, fs_vnode *_node, int accessMode)
|
||||||
{
|
{
|
||||||
//TODO: pretend everything is accessible. We should actually checking
|
Inode* inode = (Inode*)_node->private_node;
|
||||||
//for permission here.
|
return inode->CheckPermissions(accessMode);
|
||||||
return B_OK;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -353,6 +354,10 @@ xfs_open_dir(fs_volume * /*_volume*/, fs_vnode *_node, void **_cookie)
|
|||||||
Inode* inode = (Inode*)_node->private_node;
|
Inode* inode = (Inode*)_node->private_node;
|
||||||
TRACE("XFS_OPEN_DIR: (%ld)\n", inode->ID());
|
TRACE("XFS_OPEN_DIR: (%ld)\n", inode->ID());
|
||||||
|
|
||||||
|
status_t status = inode->CheckPermissions(R_OK);
|
||||||
|
if (status < B_OK)
|
||||||
|
return status;
|
||||||
|
|
||||||
if (!inode->IsDirectory())
|
if (!inode->IsDirectory())
|
||||||
return B_NOT_A_DIRECTORY;
|
return B_NOT_A_DIRECTORY;
|
||||||
|
|
||||||
@@ -361,7 +366,7 @@ xfs_open_dir(fs_volume * /*_volume*/, fs_vnode *_node, void **_cookie)
|
|||||||
delete iterator;
|
delete iterator;
|
||||||
return B_NO_MEMORY;
|
return B_NO_MEMORY;
|
||||||
}
|
}
|
||||||
status_t status = iterator->Init();
|
status = iterator->Init();
|
||||||
*_cookie = iterator;
|
*_cookie = iterator;
|
||||||
return status;
|
return status;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user