[My ISP still seems to be stopping email server :-/]
You can add my:So if I read this correctly, (ATTR_FORCE| ATTR_KILL_SUID|ATTR_MODE) will not return here, since 'ia_valid' will be ATTR_FORCE finally.Whoops, good catch. Fortunately, it doesn't seem to have actual problem,
I think you forgot to clear ATTR_FORCE here...
but it's bug obviously, and sorry for that. Fixed patch was attached.
Acked-by: Stephen Smalley <sds@xxxxxxxxxxxxx>
Thanks.
Amerigo, could you handle that patch with his ack for the remaining work?
BTW, I think [Patch 2/2] of
- newattrs.ia_valid |= should_remove_suid(dentry);
+ ret = should_remove_suid(dentry);
+ newattrs.ia_valid |= ret;
+ if (ret)
+ newattrs.ia_valid |= ATTR_FORCE;
should be
killsuid = should_remove_suid(dentry);
if (killsuid)
newattrs.ia_valid |= killsuid | ATTR_FORCE;