diff options
| author | Namjae Jeon <linkinjeon@kernel.org> | 2026-07-05 15:32:06 +0900 |
|---|---|---|
| committer | Namjae Jeon <linkinjeon@kernel.org> | 2026-08-17 15:00:29 +0900 |
| commit | 5d47ebb2795d0dab7bf718ae6665ffdaa7bb880c (patch) | |
| tree | 58c0ed4e36a1b772f52be42c1a61238bccc2b11b /tools/perf/scripts/python/stackcollapse.py | |
| parent | e5f42cb7577221080e4db0498d71e6db7e67f1a5 (diff) | |
ksmbd: honor owner rights ACEs in maximal access
The SMB2 create maximal-access context is currently calculated from
POSIX mode bits when the client does not request MAXIMUM_ALLOWED. This
overwrites the access granted by a stored Windows DACL.
Calculate the create-context result with the DACL permission checker.
Recognize the S-1-3-4 Owner Rights SID as applying to the object owner
and process its allow and deny ACEs in ACL order.
When an Owner Rights ACE is present, do not add the owner implicit
READ_CONTROL and WRITE_DAC rights. The Owner Rights ACE replaces those
implicit grants as required by Windows access-check semantics.
Without an Owner Rights ACE, preserve the existing implicit owner grants,
including FILE_READ_ATTRIBUTES and DELETE.
This fixes smb2.acls.OWNER-RIGHTS and its deny variants without regressing
smb2.acls.GENERIC.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Diffstat (limited to 'tools/perf/scripts/python/stackcollapse.py')
0 files changed, 0 insertions, 0 deletions
