Skip to content

chown, chgrp: decide --from on the file that is changed - #15029

Open
abendrothj wants to merge 1 commit into
uutils:mainfrom
abendrothj:chown-from-by-fd
Open

abendrothj wants to merge 1 commit into
uutils:mainfrom
abendrothj:chown-from-by-fd

Conversation

@abendrothj

Copy link
Copy Markdown
Contributor

--from was checked on a stat of the name and the change was made by name, so a rename in between sent the change to a file that never had the required owner. Under -R -H, symlinks in the tree were also judged by the link but changed through it.

The file is now held open and its owner read and changed through that descriptor: O_PATH with fchownat(AT_EMPTY_PATH) on Linux and FreeBSD, a read-only open and fchown elsewhere (O_SYMLINK for -h on macOS). A file found replaced after passing --from is left alone and, as with GNU, counts as a failure that only -v reports; for -R entries under -P the new file is judged in its place, also as GNU does. Sockets and device nodes, which can't be held without O_PATH, are still changed by name for an unprivileged caller; root gets an error for them. The descriptor-based -R walk now runs on all platforms safe_traversal supports, which also fixes a directory operand that can't be read being skipped silently.

Closes #15027

--from was checked on a stat of the name, and the change was then made
by name, so a rename landing in between changed a file that never had
the required owner. Under -R -H a symlink met in the tree was also
checked itself while the change went to the file it points to.

Hold the file open and change it through that descriptor: O_PATH and
fchownat(AT_EMPTY_PATH) on Linux and FreeBSD, a read-only open and
fchown elsewhere, with O_SYMLINK for -h on macOS. A file found to have
been replaced after passing --from is left alone; as GNU does, that
fails without a message, and -v reports the change that was not made.
For a -R entry under -P, the file now under the name is judged in its
place instead, as GNU does.

Where a file cannot be held that way (a socket or device node, a
symlink under -h, or a file the caller cannot read), an unprivileged
caller, which can only change its own files, still changes it by name;
root gets an error for it.

The descriptor-based -R walk now runs on every platform safe_traversal
supports instead of only Linux, and a directory operand that cannot be
read is no longer skipped.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 08:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@codspeed

codspeed Bot commented Oct 2, 2026

Copy link
Copy Markdown

Merging this PR will degrade performance by 12.16%

⚡ 1 improved benchmark
❌ 2 regressed benchmarks
✅ 390 untouched benchmarks
⏩ 54 skipped benchmarks1

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Mode Benchmark BASE HEAD Efficiency
❌ Simulation three_39_bit_primes 533 ms 836.6 ms -36.29%
❌ Simulation thirteen_39_bit_primes 8.9 s 9.4 s -5.11%
⚡ Simulation five_38_bit_primes 1.8 s 1.6 s +12.11%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing abendrothj:chown-from-by-fd (00aa3e0) with main (61a3e74)

Open in CodSpeed

Footnotes

  1. 54 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chown: --from can change a file that doesn't have the given owner

2 participants