Skip to content

Commit 06e7696

Browse files
committed
Merge branch 'jc/set-gid-bit-less-aggressively'
The adjust_shared_perm() helper function learned to refrain from setting the "g+s" bit on directories when it is not necessary. * jc/set-gid-bit-less-aggressively: adjust_shared_perm(): leave g+s alone when the group does not matter
2 parents bdd42e3 + 671bbf7 commit 06e7696

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

path.c

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -901,7 +901,13 @@ int adjust_shared_perm(const char *path)
901901
if (S_ISDIR(old_mode)) {
902902
/* Copy read bits to execute bits */
903903
new_mode |= (new_mode & 0444) >> 2;
904-
new_mode |= FORCE_DIR_SET_GID;
904+
905+
/*
906+
* g+s matters only if any extra access is granted
907+
* based on group membership.
908+
*/
909+
if (FORCE_DIR_SET_GID && (new_mode & 060))
910+
new_mode |= FORCE_DIR_SET_GID;
905911
}
906912

907913
if (((old_mode ^ new_mode) & ~S_IFMT) &&

0 commit comments

Comments
 (0)