chown, chgrp: decide --from on the file that is changed - #15029
Open
abendrothj wants to merge 1 commit into
Open
abendrothj wants to merge 1 commit into
abendrothj wants to merge 1 commit into
Conversation
--from was checked on a stat of the name, and the change was then made by name, so a rename landing in between changed a file that never had the required owner. Under -R -H a symlink met in the tree was also checked itself while the change went to the file it points to. Hold the file open and change it through that descriptor: O_PATH and fchownat(AT_EMPTY_PATH) on Linux and FreeBSD, a read-only open and fchown elsewhere, with O_SYMLINK for -h on macOS. A file found to have been replaced after passing --from is left alone; as GNU does, that fails without a message, and -v reports the change that was not made. For a -R entry under -P, the file now under the name is judged in its place instead, as GNU does. Where a file cannot be held that way (a socket or device node, a symlink under -h, or a file the caller cannot read), an unprivileged caller, which can only change its own files, still changes it by name; root gets an error for it. The descriptor-based -R walk now runs on every platform safe_traversal supports instead of only Linux, and a directory operand that cannot be read is no longer skipped.
Merging this PR will degrade performance by 12.16%
Warning Please fix the performance issues or acknowledge them on CodSpeed. Performance Changes
Tip Investigate this regression by commenting Comparing Footnotes
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
--from was checked on a stat of the name and the change was made by name, so a rename in between sent the change to a file that never had the required owner. Under -R -H, symlinks in the tree were also judged by the link but changed through it.
The file is now held open and its owner read and changed through that descriptor: O_PATH with fchownat(AT_EMPTY_PATH) on Linux and FreeBSD, a read-only open and fchown elsewhere (O_SYMLINK for -h on macOS). A file found replaced after passing --from is left alone and, as with GNU, counts as a failure that only -v reports; for -R entries under -P the new file is judged in its place, also as GNU does. Sockets and device nodes, which can't be held without O_PATH, are still changed by name for an unprivileged caller; root gets an error for them. The descriptor-based -R walk now runs on all platforms safe_traversal supports, which also fixes a directory operand that can't be read being skipped silently.
Closes #15027