filelocks: use mount idmapping for setlease permission check
authorSeth Forshee <sforshee@kernel.org>
Thu, 9 Mar 2023 20:39:09 +0000 (14:39 -0600)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 17 Mar 2023 07:50:32 +0000 (08:50 +0100)
commitd663e13ca866d0192869f2b5dc6f92a76cac012e
treef98aaa667b7adb5006e2c5c2b2e71bc46e96c056
parent38327b6cb1fa2bb098bca0db7dd25ee80a6d64b1
filelocks: use mount idmapping for setlease permission check

commit 42d0c4bdf753063b6eec55415003184d3ca24f6e upstream.

A user should be allowed to take out a lease via an idmapped mount if
the fsuid matches the mapped uid of the inode. generic_setlease() is
checking the unmapped inode uid, causing these operations to be denied.

Fix this by comparing against the mapped inode uid instead of the
unmapped uid.

Fixes: 9caccd41541a ("fs: introduce MOUNT_ATTR_IDMAP")
Cc: stable@vger.kernel.org
Signed-off-by: Seth Forshee (DigitalOcean) <sforshee@kernel.org>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/locks.c