mv: strip setuid/setgid when the cross-device copy cannot preserve ownership - #13675
Open
sylvestre wants to merge 1 commit into
Open
mv: strip setuid/setgid when the cross-device copy cannot preserve ownership#13675sylvestre wants to merge 1 commit into
sylvestre wants to merge 1 commit into
Conversation
…nership When rename(2) returns EXDEV, mv copies the file and then re-applies the source mode, including setuid and setgid. The chown back to the original owner is best-effort and silently ignored, so an unprivileged user moving a root-owned setuid file across a filesystem boundary ended up owning a file that still carried the bits. preserve_ownership now reports whether the destination ended up with the source's uid and gid, and the single-file fallback masks 0o6000 out of the applied mode when it did not. GNU mv does the same, and uutils cp already does (cp.rs, 'GNU cp strips setuid (04000) and setgid (02000) when...'). Measured in a user namespace with two tmpfs mounts, unprivileged uid moving root-owned files: before: f6755 -> mode=6755, f4755 -> 4755, f2755 -> 2755 (owner mover) after : f6755 -> mode=755, f4755 -> 755, f2755 -> 755 GNU : f6755 -> mode=755, f4755 -> 755, f2755 -> 755 When ownership is preserved the bits survive, matching GNU. The directory recursion path already matched GNU and is unchanged. Reported by zerodaybugs via GHSA-6c4j-6pgg-xgg8.
Merging this PR will improve performance by 22.59%
|
| Mode | Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|---|
| ⚡ | Simulation | df_with_path |
699.4 µs | 570.5 µs | +22.59% |
Tip
Curious why this is faster? Comment @codspeedbot explain why this is faster on this PR, or directly use the CodSpeed MCP with your agent.
Comparing sylvestre:mv-strip-setuid-when-chown-fails (c5dc2b7) with main (fc2dfd6)
Footnotes
-
46 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When rename(2) returns EXDEV, mv copies the file and then re-applies the source mode, including setuid and setgid. The chown back to the original owner is best-effort and silently ignored, so an unprivileged user moving a root-owned setuid file across a filesystem boundary ended up owning a file that still carried the bits.
preserve_ownership now reports whether the destination ended up with the source's uid and gid, and the single-file fallback masks 0o6000 out of the applied mode when it did not. GNU mv does the same, and uutils cp already does (cp.rs, 'GNU cp strips setuid (04000) and setgid (02000) when...').