On 2018/9/9 17:15, Wang Shilong wrote: > From: Wang Shilong <wangshilong1991@xxxxxxxxx> > > Currently, project quota could be changed by fssetxattr > ioctl, and existed permission check inode_owner_or_capable() > is obviously not enough, just think that common users could > change project id of file, that could make users to > break project quota easily. > > This patch try to follow same regular of xfs project > quota: > > "Project Quota ID state is only allowed to change from > within the init namespace. Enforce that restriction only > if we are trying to change the quota ID state. > Everything else is allowed in user namespaces." > > Besides that, check and set project id'state should > be an atomic operation, protect whole operation with > inode lock. > > Signed-off-by: Wang Shilong <wshilong@xxxxxxx> It looks good to me, thanks for the patch, Shilong. :) Reviewed-by: Chao Yu <yuchao0@xxxxxxxxxx> Thanks,