]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blame - fs/ncpfs/ioctl.c
ceph: don't improperly set dir complete when holding EXCL cap
[mirror_ubuntu-artful-kernel.git] / fs / ncpfs / ioctl.c
CommitLineData
1da177e4
LT
1/*
2 * ioctl.c
3 *
4 * Copyright (C) 1995, 1996 by Volker Lendecke
5 * Modified 1997 Peter Waltenberg, Bill Hawes, David Woodhouse for 2.1 dcache
6 * Modified 1998, 1999 Wolfram Pienkoss for NLS
7 *
8 */
9
16f7e0fe 10#include <linux/capability.h>
54f67f63 11#include <linux/compat.h>
1da177e4
LT
12#include <linux/errno.h>
13#include <linux/fs.h>
14#include <linux/ioctl.h>
15#include <linux/time.h>
16#include <linux/mm.h>
a761a1c0 17#include <linux/mount.h>
5a0e3ad6 18#include <linux/slab.h>
1da177e4 19#include <linux/highuid.h>
54f67f63 20#include <linux/smp_lock.h>
1da177e4 21#include <linux/vmalloc.h>
e8edc6e0 22#include <linux/sched.h>
93d84b6d 23#include <linux/smp_lock.h>
1da177e4
LT
24
25#include <linux/ncp_fs.h>
26
54f67f63
PV
27#include <asm/uaccess.h>
28
1da177e4
LT
29#include "ncplib_kernel.h"
30
31/* maximum limit for ncp_objectname_ioctl */
32#define NCP_OBJECT_NAME_MAX_LEN 4096
33/* maximum limit for ncp_privatedata_ioctl */
34#define NCP_PRIVATE_DATA_MAX_LEN 8192
35/* maximum negotiable packet size */
36#define NCP_PACKET_SIZE_INTERNAL 65536
37
38static int
8c744fb8
CH
39ncp_get_fs_info(struct ncp_server * server, struct file *file,
40 struct ncp_fs_info __user *arg)
1da177e4 41{
92e5baef 42 struct inode *inode = file->f_path.dentry->d_inode;
1da177e4
LT
43 struct ncp_fs_info info;
44
48937024
DH
45 if (file_permission(file, MAY_WRITE) != 0
46 && current_uid() != server->m.mounted_uid)
1da177e4 47 return -EACCES;
48937024 48
1da177e4
LT
49 if (copy_from_user(&info, arg, sizeof(info)))
50 return -EFAULT;
51
52 if (info.version != NCP_GET_FS_INFO_VERSION) {
53 DPRINTK("info.version invalid: %d\n", info.version);
54 return -EINVAL;
55 }
56 /* TODO: info.addr = server->m.serv_addr; */
57 SET_UID(info.mounted_uid, server->m.mounted_uid);
58 info.connection = server->connection;
59 info.buffer_size = server->buffer_size;
60 info.volume_number = NCP_FINFO(inode)->volNumber;
61 info.directory_id = NCP_FINFO(inode)->DosDirNum;
62
63 if (copy_to_user(arg, &info, sizeof(info)))
64 return -EFAULT;
65 return 0;
66}
67
68static int
8c744fb8
CH
69ncp_get_fs_info_v2(struct ncp_server * server, struct file *file,
70 struct ncp_fs_info_v2 __user * arg)
1da177e4 71{
92e5baef 72 struct inode *inode = file->f_path.dentry->d_inode;
1da177e4
LT
73 struct ncp_fs_info_v2 info2;
74
48937024
DH
75 if (file_permission(file, MAY_WRITE) != 0
76 && current_uid() != server->m.mounted_uid)
1da177e4 77 return -EACCES;
48937024 78
1da177e4
LT
79 if (copy_from_user(&info2, arg, sizeof(info2)))
80 return -EFAULT;
81
82 if (info2.version != NCP_GET_FS_INFO_VERSION_V2) {
83 DPRINTK("info.version invalid: %d\n", info2.version);
84 return -EINVAL;
85 }
86 info2.mounted_uid = server->m.mounted_uid;
87 info2.connection = server->connection;
88 info2.buffer_size = server->buffer_size;
89 info2.volume_number = NCP_FINFO(inode)->volNumber;
90 info2.directory_id = NCP_FINFO(inode)->DosDirNum;
91 info2.dummy1 = info2.dummy2 = info2.dummy3 = 0;
92
93 if (copy_to_user(arg, &info2, sizeof(info2)))
94 return -EFAULT;
95 return 0;
96}
97
54f67f63
PV
98#ifdef CONFIG_COMPAT
99struct compat_ncp_objectname_ioctl
100{
101 s32 auth_type;
102 u32 object_name_len;
0211a9c8 103 compat_caddr_t object_name; /* a userspace data, in most cases user name */
54f67f63
PV
104};
105
106struct compat_ncp_fs_info_v2 {
107 s32 version;
108 u32 mounted_uid;
109 u32 connection;
110 u32 buffer_size;
111
112 u32 volume_number;
113 u32 directory_id;
114
115 u32 dummy1;
116 u32 dummy2;
117 u32 dummy3;
118};
119
120struct compat_ncp_ioctl_request {
121 u32 function;
122 u32 size;
123 compat_caddr_t data;
124};
125
126struct compat_ncp_privatedata_ioctl
127{
128 u32 len;
129 compat_caddr_t data; /* ~1000 for NDS */
130};
131
132#define NCP_IOC_GET_FS_INFO_V2_32 _IOWR('n', 4, struct compat_ncp_fs_info_v2)
133#define NCP_IOC_NCPREQUEST_32 _IOR('n', 1, struct compat_ncp_ioctl_request)
134#define NCP_IOC_GETOBJECTNAME_32 _IOWR('n', 9, struct compat_ncp_objectname_ioctl)
135#define NCP_IOC_SETOBJECTNAME_32 _IOR('n', 9, struct compat_ncp_objectname_ioctl)
136#define NCP_IOC_GETPRIVATEDATA_32 _IOWR('n', 10, struct compat_ncp_privatedata_ioctl)
137#define NCP_IOC_SETPRIVATEDATA_32 _IOR('n', 10, struct compat_ncp_privatedata_ioctl)
138
139static int
140ncp_get_compat_fs_info_v2(struct ncp_server * server, struct file *file,
141 struct compat_ncp_fs_info_v2 __user * arg)
142{
92e5baef 143 struct inode *inode = file->f_path.dentry->d_inode;
54f67f63
PV
144 struct compat_ncp_fs_info_v2 info2;
145
48937024
DH
146 if (file_permission(file, MAY_WRITE) != 0
147 && current_uid() != server->m.mounted_uid)
54f67f63 148 return -EACCES;
48937024 149
54f67f63
PV
150 if (copy_from_user(&info2, arg, sizeof(info2)))
151 return -EFAULT;
152
153 if (info2.version != NCP_GET_FS_INFO_VERSION_V2) {
154 DPRINTK("info.version invalid: %d\n", info2.version);
155 return -EINVAL;
156 }
157 info2.mounted_uid = server->m.mounted_uid;
158 info2.connection = server->connection;
159 info2.buffer_size = server->buffer_size;
160 info2.volume_number = NCP_FINFO(inode)->volNumber;
161 info2.directory_id = NCP_FINFO(inode)->DosDirNum;
162 info2.dummy1 = info2.dummy2 = info2.dummy3 = 0;
163
164 if (copy_to_user(arg, &info2, sizeof(info2)))
165 return -EFAULT;
166 return 0;
167}
168#endif
169
170#define NCP_IOC_GETMOUNTUID16 _IOW('n', 2, u16)
171#define NCP_IOC_GETMOUNTUID32 _IOW('n', 2, u32)
172#define NCP_IOC_GETMOUNTUID64 _IOW('n', 2, u64)
173
1da177e4
LT
174#ifdef CONFIG_NCPFS_NLS
175/* Here we are select the iocharset and the codepage for NLS.
176 * Thanks Petr Vandrovec for idea and many hints.
177 */
178static int
179ncp_set_charsets(struct ncp_server* server, struct ncp_nls_ioctl __user *arg)
180{
181 struct ncp_nls_ioctl user;
182 struct nls_table *codepage;
183 struct nls_table *iocharset;
184 struct nls_table *oldset_io;
185 struct nls_table *oldset_cp;
186
187 if (!capable(CAP_SYS_ADMIN))
188 return -EACCES;
189 if (server->root_setuped)
190 return -EBUSY;
191
192 if (copy_from_user(&user, arg, sizeof(user)))
193 return -EFAULT;
194
195 codepage = NULL;
196 user.codepage[NCP_IOCSNAME_LEN] = 0;
197 if (!user.codepage[0] || !strcmp(user.codepage, "default"))
198 codepage = load_nls_default();
199 else {
200 codepage = load_nls(user.codepage);
201 if (!codepage) {
202 return -EBADRQC;
203 }
204 }
205
206 iocharset = NULL;
207 user.iocharset[NCP_IOCSNAME_LEN] = 0;
208 if (!user.iocharset[0] || !strcmp(user.iocharset, "default")) {
209 iocharset = load_nls_default();
210 NCP_CLR_FLAG(server, NCP_FLAG_UTF8);
211 } else if (!strcmp(user.iocharset, "utf8")) {
212 iocharset = load_nls_default();
213 NCP_SET_FLAG(server, NCP_FLAG_UTF8);
214 } else {
215 iocharset = load_nls(user.iocharset);
216 if (!iocharset) {
217 unload_nls(codepage);
218 return -EBADRQC;
219 }
220 NCP_CLR_FLAG(server, NCP_FLAG_UTF8);
221 }
222
223 oldset_cp = server->nls_vol;
224 server->nls_vol = codepage;
225 oldset_io = server->nls_io;
226 server->nls_io = iocharset;
227
6d729e44
TG
228 unload_nls(oldset_cp);
229 unload_nls(oldset_io);
1da177e4
LT
230
231 return 0;
232}
233
234static int
235ncp_get_charsets(struct ncp_server* server, struct ncp_nls_ioctl __user *arg)
236{
237 struct ncp_nls_ioctl user;
238 int len;
239
240 memset(&user, 0, sizeof(user));
241 if (server->nls_vol && server->nls_vol->charset) {
242 len = strlen(server->nls_vol->charset);
243 if (len > NCP_IOCSNAME_LEN)
244 len = NCP_IOCSNAME_LEN;
245 strncpy(user.codepage, server->nls_vol->charset, len);
246 user.codepage[len] = 0;
247 }
248
249 if (NCP_IS_FLAG(server, NCP_FLAG_UTF8))
250 strcpy(user.iocharset, "utf8");
251 else if (server->nls_io && server->nls_io->charset) {
252 len = strlen(server->nls_io->charset);
253 if (len > NCP_IOCSNAME_LEN)
254 len = NCP_IOCSNAME_LEN;
255 strncpy(user.iocharset, server->nls_io->charset, len);
256 user.iocharset[len] = 0;
257 }
258
259 if (copy_to_user(arg, &user, sizeof(user)))
260 return -EFAULT;
261 return 0;
262}
263#endif /* CONFIG_NCPFS_NLS */
264
93d84b6d 265static long __ncp_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
1da177e4 266{
93d84b6d 267 struct inode *inode = filp->f_dentry->d_inode;
1da177e4
LT
268 struct ncp_server *server = NCP_SERVER(inode);
269 int result;
270 struct ncp_ioctl_request request;
271 char* bouncebuffer;
272 void __user *argp = (void __user *)arg;
48937024 273 uid_t uid = current_uid();
1da177e4
LT
274
275 switch (cmd) {
54f67f63
PV
276#ifdef CONFIG_COMPAT
277 case NCP_IOC_NCPREQUEST_32:
278#endif
1da177e4 279 case NCP_IOC_NCPREQUEST:
48937024
DH
280 if (file_permission(filp, MAY_WRITE) != 0
281 && uid != server->m.mounted_uid)
1da177e4 282 return -EACCES;
48937024 283
54f67f63
PV
284#ifdef CONFIG_COMPAT
285 if (cmd == NCP_IOC_NCPREQUEST_32) {
286 struct compat_ncp_ioctl_request request32;
287 if (copy_from_user(&request32, argp, sizeof(request32)))
288 return -EFAULT;
289 request.function = request32.function;
290 request.size = request32.size;
291 request.data = compat_ptr(request32.data);
292 } else
293#endif
1da177e4
LT
294 if (copy_from_user(&request, argp, sizeof(request)))
295 return -EFAULT;
296
297 if ((request.function > 255)
298 || (request.size >
299 NCP_PACKET_SIZE - sizeof(struct ncp_request_header))) {
300 return -EINVAL;
301 }
302 bouncebuffer = vmalloc(NCP_PACKET_SIZE_INTERNAL);
303 if (!bouncebuffer)
304 return -ENOMEM;
305 if (copy_from_user(bouncebuffer, request.data, request.size)) {
306 vfree(bouncebuffer);
307 return -EFAULT;
308 }
309 ncp_lock_server(server);
310
311 /* FIXME: We hack around in the server's structures
312 here to be able to use ncp_request */
313
314 server->has_subfunction = 0;
315 server->current_size = request.size;
316 memcpy(server->packet, bouncebuffer, request.size);
317
318 result = ncp_request2(server, request.function,
319 bouncebuffer, NCP_PACKET_SIZE_INTERNAL);
320 if (result < 0)
321 result = -EIO;
322 else
323 result = server->reply_size;
324 ncp_unlock_server(server);
325 DPRINTK("ncp_ioctl: copy %d bytes\n",
326 result);
327 if (result >= 0)
328 if (copy_to_user(request.data, bouncebuffer, result))
329 result = -EFAULT;
330 vfree(bouncebuffer);
331 return result;
332
333 case NCP_IOC_CONN_LOGGED_IN:
334
335 if (!capable(CAP_SYS_ADMIN))
336 return -EACCES;
337 if (!(server->m.int_flags & NCP_IMOUNT_LOGGEDIN_POSSIBLE))
338 return -EINVAL;
339 if (server->root_setuped)
340 return -EBUSY;
341 server->root_setuped = 1;
342 return ncp_conn_logged_in(inode->i_sb);
343
344 case NCP_IOC_GET_FS_INFO:
8c744fb8 345 return ncp_get_fs_info(server, filp, argp);
1da177e4
LT
346
347 case NCP_IOC_GET_FS_INFO_V2:
8c744fb8 348 return ncp_get_fs_info_v2(server, filp, argp);
1da177e4 349
54f67f63
PV
350#ifdef CONFIG_COMPAT
351 case NCP_IOC_GET_FS_INFO_V2_32:
352 return ncp_get_compat_fs_info_v2(server, filp, argp);
353#endif
354 /* we have too many combinations of CONFIG_COMPAT,
355 * CONFIG_64BIT and CONFIG_UID16, so just handle
356 * any of the possible ioctls */
357 case NCP_IOC_GETMOUNTUID16:
358 case NCP_IOC_GETMOUNTUID32:
359 case NCP_IOC_GETMOUNTUID64:
48937024
DH
360 if (file_permission(filp, MAY_READ) != 0
361 && uid != server->m.mounted_uid)
54f67f63 362 return -EACCES;
48937024 363
54f67f63
PV
364 if (cmd == NCP_IOC_GETMOUNTUID16) {
365 u16 uid;
366 SET_UID(uid, server->m.mounted_uid);
367 if (put_user(uid, (u16 __user *)argp))
368 return -EFAULT;
369 } else if (cmd == NCP_IOC_GETMOUNTUID32) {
370 if (put_user(server->m.mounted_uid,
371 (u32 __user *)argp))
372 return -EFAULT;
373 } else {
374 if (put_user(server->m.mounted_uid,
375 (u64 __user *)argp))
1da177e4 376 return -EFAULT;
1da177e4 377 }
54f67f63 378 return 0;
1da177e4
LT
379
380 case NCP_IOC_GETROOT:
381 {
382 struct ncp_setroot_ioctl sr;
383
48937024
DH
384 if (file_permission(filp, MAY_READ) != 0
385 && uid != server->m.mounted_uid)
1da177e4 386 return -EACCES;
48937024 387
1da177e4
LT
388 if (server->m.mounted_vol[0]) {
389 struct dentry* dentry = inode->i_sb->s_root;
390
391 if (dentry) {
305787e4 392 struct inode* s_inode = dentry->d_inode;
1da177e4 393
305787e4
HH
394 if (s_inode) {
395 sr.volNumber = NCP_FINFO(s_inode)->volNumber;
396 sr.dirEntNum = NCP_FINFO(s_inode)->dirEntNum;
1da177e4
LT
397 sr.namespace = server->name_space[sr.volNumber];
398 } else
399 DPRINTK("ncpfs: s_root->d_inode==NULL\n");
400 } else
401 DPRINTK("ncpfs: s_root==NULL\n");
402 } else {
403 sr.volNumber = -1;
404 sr.namespace = 0;
405 sr.dirEntNum = 0;
406 }
407 if (copy_to_user(argp, &sr, sizeof(sr)))
408 return -EFAULT;
409 return 0;
410 }
48937024 411
1da177e4
LT
412 case NCP_IOC_SETROOT:
413 {
414 struct ncp_setroot_ioctl sr;
415 __u32 vnum;
416 __le32 de;
417 __le32 dosde;
418 struct dentry* dentry;
419
420 if (!capable(CAP_SYS_ADMIN))
421 {
422 return -EACCES;
423 }
424 if (server->root_setuped) return -EBUSY;
425 if (copy_from_user(&sr, argp, sizeof(sr)))
426 return -EFAULT;
427 if (sr.volNumber < 0) {
428 server->m.mounted_vol[0] = 0;
429 vnum = NCP_NUMBER_OF_VOLUMES;
430 de = 0;
431 dosde = 0;
432 } else if (sr.volNumber >= NCP_NUMBER_OF_VOLUMES) {
433 return -EINVAL;
434 } else if (ncp_mount_subdir(server, sr.volNumber,
435 sr.namespace, sr.dirEntNum,
436 &vnum, &de, &dosde)) {
437 return -ENOENT;
438 }
439
440 dentry = inode->i_sb->s_root;
441 server->root_setuped = 1;
442 if (dentry) {
305787e4 443 struct inode* s_inode = dentry->d_inode;
1da177e4 444
8b2feb10 445 if (s_inode) {
305787e4
HH
446 NCP_FINFO(s_inode)->volNumber = vnum;
447 NCP_FINFO(s_inode)->dirEntNum = de;
448 NCP_FINFO(s_inode)->DosDirNum = dosde;
1da177e4
LT
449 } else
450 DPRINTK("ncpfs: s_root->d_inode==NULL\n");
451 } else
452 DPRINTK("ncpfs: s_root==NULL\n");
453
454 return 0;
455 }
456
457#ifdef CONFIG_NCPFS_PACKET_SIGNING
458 case NCP_IOC_SIGN_INIT:
48937024
DH
459 if (file_permission(filp, MAY_WRITE) != 0
460 && uid != server->m.mounted_uid)
1da177e4 461 return -EACCES;
48937024 462
1da177e4
LT
463 if (argp) {
464 if (server->sign_wanted)
465 {
466 struct ncp_sign_init sign;
467
468 if (copy_from_user(&sign, argp, sizeof(sign)))
469 return -EFAULT;
470 memcpy(server->sign_root,sign.sign_root,8);
471 memcpy(server->sign_last,sign.sign_last,16);
472 server->sign_active = 1;
473 }
474 /* ignore when signatures not wanted */
475 } else {
476 server->sign_active = 0;
477 }
478 return 0;
479
480 case NCP_IOC_SIGN_WANTED:
48937024
DH
481 if (file_permission(filp, MAY_READ) != 0
482 && uid != server->m.mounted_uid)
1da177e4 483 return -EACCES;
1da177e4
LT
484
485 if (put_user(server->sign_wanted, (int __user *)argp))
486 return -EFAULT;
487 return 0;
48937024 488
1da177e4
LT
489 case NCP_IOC_SET_SIGN_WANTED:
490 {
491 int newstate;
492
48937024
DH
493 if (file_permission(filp, MAY_WRITE) != 0
494 && uid != server->m.mounted_uid)
1da177e4 495 return -EACCES;
48937024 496
1da177e4
LT
497 /* get only low 8 bits... */
498 if (get_user(newstate, (unsigned char __user *)argp))
499 return -EFAULT;
500 if (server->sign_active) {
501 /* cannot turn signatures OFF when active */
502 if (!newstate) return -EINVAL;
503 } else {
504 server->sign_wanted = newstate != 0;
505 }
506 return 0;
507 }
508
509#endif /* CONFIG_NCPFS_PACKET_SIGNING */
510
511#ifdef CONFIG_NCPFS_IOCTL_LOCKING
512 case NCP_IOC_LOCKUNLOCK:
48937024
DH
513 if (file_permission(filp, MAY_WRITE) != 0
514 && uid != server->m.mounted_uid)
1da177e4 515 return -EACCES;
48937024 516
1da177e4
LT
517 {
518 struct ncp_lock_ioctl rqdata;
1da177e4
LT
519
520 if (copy_from_user(&rqdata, argp, sizeof(rqdata)))
521 return -EFAULT;
522 if (rqdata.origin != 0)
523 return -EINVAL;
524 /* check for cmd */
525 switch (rqdata.cmd) {
526 case NCP_LOCK_EX:
527 case NCP_LOCK_SH:
528 if (rqdata.timeout == 0)
529 rqdata.timeout = NCP_LOCK_DEFAULT_TIMEOUT;
530 else if (rqdata.timeout > NCP_LOCK_MAX_TIMEOUT)
531 rqdata.timeout = NCP_LOCK_MAX_TIMEOUT;
532 break;
533 case NCP_LOCK_LOG:
534 rqdata.timeout = NCP_LOCK_DEFAULT_TIMEOUT; /* has no effect */
535 case NCP_LOCK_CLEAR:
536 break;
537 default:
538 return -EINVAL;
539 }
540 /* locking needs both read and write access */
541 if ((result = ncp_make_open(inode, O_RDWR)) != 0)
542 {
543 return result;
544 }
545 result = -EIO;
546 if (!ncp_conn_valid(server))
547 goto outrel;
548 result = -EISDIR;
549 if (!S_ISREG(inode->i_mode))
550 goto outrel;
551 if (rqdata.cmd == NCP_LOCK_CLEAR)
552 {
553 result = ncp_ClearPhysicalRecord(NCP_SERVER(inode),
554 NCP_FINFO(inode)->file_handle,
555 rqdata.offset,
556 rqdata.length);
557 if (result > 0) result = 0; /* no such lock */
558 }
559 else
560 {
561 int lockcmd;
562
563 switch (rqdata.cmd)
564 {
565 case NCP_LOCK_EX: lockcmd=1; break;
566 case NCP_LOCK_SH: lockcmd=3; break;
567 default: lockcmd=0; break;
568 }
569 result = ncp_LogPhysicalRecord(NCP_SERVER(inode),
570 NCP_FINFO(inode)->file_handle,
571 lockcmd,
572 rqdata.offset,
573 rqdata.length,
574 rqdata.timeout);
575 if (result > 0) result = -EAGAIN;
576 }
577outrel:
578 ncp_inode_close(inode);
579 return result;
580 }
581#endif /* CONFIG_NCPFS_IOCTL_LOCKING */
582
54f67f63
PV
583#ifdef CONFIG_COMPAT
584 case NCP_IOC_GETOBJECTNAME_32:
48937024 585 if (uid != server->m.mounted_uid)
54f67f63 586 return -EACCES;
54f67f63
PV
587 {
588 struct compat_ncp_objectname_ioctl user;
589 size_t outl;
590
591 if (copy_from_user(&user, argp, sizeof(user)))
592 return -EFAULT;
593 user.auth_type = server->auth.auth_type;
594 outl = user.object_name_len;
595 user.object_name_len = server->auth.object_name_len;
596 if (outl > user.object_name_len)
597 outl = user.object_name_len;
598 if (outl) {
599 if (copy_to_user(compat_ptr(user.object_name),
600 server->auth.object_name,
601 outl)) return -EFAULT;
602 }
603 if (copy_to_user(argp, &user, sizeof(user)))
604 return -EFAULT;
605 return 0;
606 }
607#endif
48937024 608
1da177e4 609 case NCP_IOC_GETOBJECTNAME:
48937024 610 if (uid != server->m.mounted_uid)
1da177e4 611 return -EACCES;
1da177e4
LT
612 {
613 struct ncp_objectname_ioctl user;
614 size_t outl;
615
616 if (copy_from_user(&user, argp, sizeof(user)))
617 return -EFAULT;
618 user.auth_type = server->auth.auth_type;
619 outl = user.object_name_len;
620 user.object_name_len = server->auth.object_name_len;
621 if (outl > user.object_name_len)
622 outl = user.object_name_len;
623 if (outl) {
624 if (copy_to_user(user.object_name,
625 server->auth.object_name,
626 outl)) return -EFAULT;
627 }
628 if (copy_to_user(argp, &user, sizeof(user)))
629 return -EFAULT;
630 return 0;
631 }
48937024 632
54f67f63
PV
633#ifdef CONFIG_COMPAT
634 case NCP_IOC_SETOBJECTNAME_32:
635#endif
1da177e4 636 case NCP_IOC_SETOBJECTNAME:
48937024 637 if (uid != server->m.mounted_uid)
1da177e4 638 return -EACCES;
1da177e4
LT
639 {
640 struct ncp_objectname_ioctl user;
641 void* newname;
642 void* oldname;
643 size_t oldnamelen;
644 void* oldprivate;
645 size_t oldprivatelen;
646
54f67f63
PV
647#ifdef CONFIG_COMPAT
648 if (cmd == NCP_IOC_SETOBJECTNAME_32) {
649 struct compat_ncp_objectname_ioctl user32;
650 if (copy_from_user(&user32, argp, sizeof(user32)))
651 return -EFAULT;
652 user.auth_type = user32.auth_type;
653 user.object_name_len = user32.object_name_len;
654 user.object_name = compat_ptr(user32.object_name);
655 } else
656#endif
1da177e4
LT
657 if (copy_from_user(&user, argp, sizeof(user)))
658 return -EFAULT;
54f67f63 659
1da177e4
LT
660 if (user.object_name_len > NCP_OBJECT_NAME_MAX_LEN)
661 return -ENOMEM;
662 if (user.object_name_len) {
a9482ebc
LZ
663 newname = memdup_user(user.object_name,
664 user.object_name_len);
665 if (IS_ERR(newname))
666 return PTR_ERR(newname);
1da177e4
LT
667 } else {
668 newname = NULL;
669 }
670 /* enter critical section */
671 /* maybe that kfree can sleep so do that this way */
672 /* it is at least more SMP friendly (in future...) */
673 oldname = server->auth.object_name;
674 oldnamelen = server->auth.object_name_len;
675 oldprivate = server->priv.data;
676 oldprivatelen = server->priv.len;
677 server->auth.auth_type = user.auth_type;
678 server->auth.object_name_len = user.object_name_len;
679 server->auth.object_name = newname;
680 server->priv.len = 0;
681 server->priv.data = NULL;
682 /* leave critical section */
44db77f3
PE
683 kfree(oldprivate);
684 kfree(oldname);
1da177e4
LT
685 return 0;
686 }
48937024 687
54f67f63
PV
688#ifdef CONFIG_COMPAT
689 case NCP_IOC_GETPRIVATEDATA_32:
690#endif
1da177e4 691 case NCP_IOC_GETPRIVATEDATA:
48937024 692 if (uid != server->m.mounted_uid)
1da177e4 693 return -EACCES;
1da177e4
LT
694 {
695 struct ncp_privatedata_ioctl user;
696 size_t outl;
697
54f67f63
PV
698#ifdef CONFIG_COMPAT
699 if (cmd == NCP_IOC_GETPRIVATEDATA_32) {
700 struct compat_ncp_privatedata_ioctl user32;
701 if (copy_from_user(&user32, argp, sizeof(user32)))
702 return -EFAULT;
703 user.len = user32.len;
704 user.data = compat_ptr(user32.data);
705 } else
706#endif
1da177e4
LT
707 if (copy_from_user(&user, argp, sizeof(user)))
708 return -EFAULT;
54f67f63 709
1da177e4
LT
710 outl = user.len;
711 user.len = server->priv.len;
712 if (outl > user.len) outl = user.len;
713 if (outl) {
714 if (copy_to_user(user.data,
715 server->priv.data,
716 outl)) return -EFAULT;
717 }
54f67f63
PV
718#ifdef CONFIG_COMPAT
719 if (cmd == NCP_IOC_GETPRIVATEDATA_32) {
720 struct compat_ncp_privatedata_ioctl user32;
721 user32.len = user.len;
722 user32.data = (unsigned long) user.data;
5c09d96b 723 if (copy_to_user(argp, &user32, sizeof(user32)))
54f67f63
PV
724 return -EFAULT;
725 } else
726#endif
1da177e4
LT
727 if (copy_to_user(argp, &user, sizeof(user)))
728 return -EFAULT;
54f67f63 729
1da177e4
LT
730 return 0;
731 }
48937024 732
54f67f63
PV
733#ifdef CONFIG_COMPAT
734 case NCP_IOC_SETPRIVATEDATA_32:
735#endif
1da177e4 736 case NCP_IOC_SETPRIVATEDATA:
48937024 737 if (uid != server->m.mounted_uid)
1da177e4 738 return -EACCES;
1da177e4
LT
739 {
740 struct ncp_privatedata_ioctl user;
741 void* new;
742 void* old;
743 size_t oldlen;
744
54f67f63
PV
745#ifdef CONFIG_COMPAT
746 if (cmd == NCP_IOC_SETPRIVATEDATA_32) {
747 struct compat_ncp_privatedata_ioctl user32;
748 if (copy_from_user(&user32, argp, sizeof(user32)))
749 return -EFAULT;
750 user.len = user32.len;
751 user.data = compat_ptr(user32.data);
752 } else
753#endif
1da177e4
LT
754 if (copy_from_user(&user, argp, sizeof(user)))
755 return -EFAULT;
54f67f63 756
1da177e4
LT
757 if (user.len > NCP_PRIVATE_DATA_MAX_LEN)
758 return -ENOMEM;
759 if (user.len) {
a9482ebc
LZ
760 new = memdup_user(user.data, user.len);
761 if (IS_ERR(new))
762 return PTR_ERR(new);
1da177e4
LT
763 } else {
764 new = NULL;
765 }
766 /* enter critical section */
767 old = server->priv.data;
768 oldlen = server->priv.len;
769 server->priv.len = user.len;
770 server->priv.data = new;
771 /* leave critical section */
44db77f3 772 kfree(old);
1da177e4
LT
773 return 0;
774 }
775
776#ifdef CONFIG_NCPFS_NLS
777 case NCP_IOC_SETCHARSETS:
778 return ncp_set_charsets(server, argp);
779
780 case NCP_IOC_GETCHARSETS:
781 return ncp_get_charsets(server, argp);
782
783#endif /* CONFIG_NCPFS_NLS */
784
785 case NCP_IOC_SETDENTRYTTL:
48937024
DH
786 if (file_permission(filp, MAY_WRITE) != 0 &&
787 uid != server->m.mounted_uid)
1da177e4 788 return -EACCES;
48937024 789
1da177e4
LT
790 {
791 u_int32_t user;
792
793 if (copy_from_user(&user, argp, sizeof(user)))
794 return -EFAULT;
795 /* 20 secs at most... */
796 if (user > 20000)
797 return -EINVAL;
798 user = (user * HZ) / 1000;
799 server->dentry_ttl = user;
800 return 0;
801 }
802
803 case NCP_IOC_GETDENTRYTTL:
804 {
805 u_int32_t user = (server->dentry_ttl * 1000) / HZ;
806 if (copy_to_user(argp, &user, sizeof(user)))
807 return -EFAULT;
808 return 0;
809 }
810
811 }
1da177e4
LT
812 return -EINVAL;
813}
54f67f63 814
a761a1c0
DH
815static int ncp_ioctl_need_write(unsigned int cmd)
816{
817 switch (cmd) {
818 case NCP_IOC_GET_FS_INFO:
819 case NCP_IOC_GET_FS_INFO_V2:
820 case NCP_IOC_NCPREQUEST:
821 case NCP_IOC_SETDENTRYTTL:
822 case NCP_IOC_SIGN_INIT:
823 case NCP_IOC_LOCKUNLOCK:
824 case NCP_IOC_SET_SIGN_WANTED:
825 return 1;
826 case NCP_IOC_GETOBJECTNAME:
827 case NCP_IOC_SETOBJECTNAME:
828 case NCP_IOC_GETPRIVATEDATA:
829 case NCP_IOC_SETPRIVATEDATA:
830 case NCP_IOC_SETCHARSETS:
831 case NCP_IOC_GETCHARSETS:
832 case NCP_IOC_CONN_LOGGED_IN:
833 case NCP_IOC_GETDENTRYTTL:
834 case NCP_IOC_GETMOUNTUID2:
835 case NCP_IOC_SIGN_WANTED:
836 case NCP_IOC_GETROOT:
837 case NCP_IOC_SETROOT:
838 return 0;
839 default:
af901ca1 840 /* unknown IOCTL command, assume write */
a761a1c0
DH
841 return 1;
842 }
843}
844
93d84b6d 845long ncp_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
a761a1c0 846{
93d84b6d 847 long ret;
a761a1c0 848
93d84b6d 849 lock_kernel();
a761a1c0
DH
850 if (ncp_ioctl_need_write(cmd)) {
851 /*
852 * inside the ioctl(), any failures which
853 * are because of file_permission() are
854 * -EACCESS, so it seems consistent to keep
855 * that here.
856 */
93d84b6d
JK
857 if (mnt_want_write(filp->f_path.mnt)) {
858 ret = -EACCES;
859 goto out;
860 }
a761a1c0 861 }
93d84b6d 862 ret = __ncp_ioctl(filp, cmd, arg);
a761a1c0
DH
863 if (ncp_ioctl_need_write(cmd))
864 mnt_drop_write(filp->f_path.mnt);
93d84b6d
JK
865
866out:
867 unlock_kernel();
a761a1c0
DH
868 return ret;
869}
870
54f67f63
PV
871#ifdef CONFIG_COMPAT
872long ncp_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
873{
93d84b6d 874 long ret;
54f67f63
PV
875
876 lock_kernel();
877 arg = (unsigned long) compat_ptr(arg);
93d84b6d 878 ret = ncp_ioctl(file, cmd, arg);
54f67f63
PV
879 unlock_kernel();
880 return ret;
881}
882#endif