diff options
| author | Raghavendra Bhat <raghavendra@redhat.com> | 2013-02-08 11:44:41 +0530 | 
|---|---|---|
| committer | Vijay Bellur <vbellur@redhat.com> | 2013-03-04 23:44:04 -0800 | 
| commit | b24003342eb707027982599a7bac485fe3b9f465 (patch) | |
| tree | e968205bfbf888c4d0e1709ccdbeecb2db763682 /rpc/rpc-lib/src/rpcsvc-auth.c | |
| parent | cd4736baba8a60d007bff6ed633f9feba9862bfb (diff) | |
rpc: bring in root-squashing behavior in rpc
* requests coming in as root are converted to nfsnobody
* with open-behind some acl checks wont happen and nfsnobody
  can read the file "whose owner is root and other users do not
  have permission to read the file". This is becasue open-behind
  does not send the open to the brick and sends success to the
  application, thus the acl related tests on the file wont happen
  which would have prevented the file from being opened.
Change-Id: I12a3e6b2a12884d00bb81f2779074fed09b1b2e4
BUG: 887145
Signed-off-by: Raghavendra Bhat <raghavendra@redhat.com>
Reviewed-on: http://review.gluster.org/4619
Tested-by: Gluster Build System <jenkins@build.gluster.com>
Reviewed-by: Jeff Darcy <jdarcy@redhat.com>
Diffstat (limited to 'rpc/rpc-lib/src/rpcsvc-auth.c')
| -rw-r--r-- | rpc/rpc-lib/src/rpcsvc-auth.c | 16 | 
1 files changed, 16 insertions, 0 deletions
diff --git a/rpc/rpc-lib/src/rpcsvc-auth.c b/rpc/rpc-lib/src/rpcsvc-auth.c index 3a46cc498..907ae1ec9 100644 --- a/rpc/rpc-lib/src/rpcsvc-auth.c +++ b/rpc/rpc-lib/src/rpcsvc-auth.c @@ -204,6 +204,21 @@ rpcsvc_set_allow_insecure (rpcsvc_t *svc, dict_t *options)  }  int +rpcsvc_set_root_squash (rpcsvc_t *svc, dict_t *options) +{ +        GF_ASSERT (svc); +        GF_ASSERT (options); + +        if (dict_get_str_boolean (options, "root-squash", 0)) +                svc->root_squash = _gf_true; + +        if (svc->root_squash) +                gf_log (GF_RPCSVC, GF_LOG_DEBUG, "root squashing enabled "); + +        return 0; +} + +int  rpcsvc_auth_init (rpcsvc_t *svc, dict_t *options)  {          int             ret = -1; @@ -212,6 +227,7 @@ rpcsvc_auth_init (rpcsvc_t *svc, dict_t *options)                  return -1;          (void) rpcsvc_set_allow_insecure (svc, options); +        (void) rpcsvc_set_root_squash (svc, options);          ret = rpcsvc_auth_add_initers (svc);          if (ret == -1) {                  gf_log (GF_RPCSVC, GF_LOG_ERROR, "Failed to add initers");  | 
