]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blame - fs/nfsd/nfs4recover.c
[PATCH] r/o bind mounts: elevate write count for rmdir and unlink.
[mirror_ubuntu-zesty-kernel.git] / fs / nfsd / nfs4recover.c
CommitLineData
a55370a3
N
1/*
2* linux/fs/nfsd/nfs4recover.c
3*
4* Copyright (c) 2004 The Regents of the University of Michigan.
5* All rights reserved.
6*
7* Andy Adamson <andros@citi.umich.edu>
8*
9* Redistribution and use in source and binary forms, with or without
10* modification, are permitted provided that the following conditions
11* are met:
12*
13* 1. Redistributions of source code must retain the above copyright
14* notice, this list of conditions and the following disclaimer.
15* 2. Redistributions in binary form must reproduce the above copyright
16* notice, this list of conditions and the following disclaimer in the
17* documentation and/or other materials provided with the distribution.
18* 3. Neither the name of the University nor the names of its
19* contributors may be used to endorse or promote products derived
20* from this software without specific prior written permission.
21*
22* THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
23* WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
24* MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
25* DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
29* BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
30* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
31* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
32* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
33*
34*/
35
35058687 36#include <linux/err.h>
a55370a3
N
37#include <linux/sunrpc/svc.h>
38#include <linux/nfsd/nfsd.h>
39#include <linux/nfs4.h>
40#include <linux/nfsd/state.h>
41#include <linux/nfsd/xdr4.h>
190e4fbf
N
42#include <linux/param.h>
43#include <linux/file.h>
44#include <linux/namei.h>
a55370a3 45#include <asm/uaccess.h>
87ae9afd 46#include <linux/scatterlist.h>
a55370a3 47#include <linux/crypto.h>
e8edc6e0 48#include <linux/sched.h>
0622753b 49#include <linux/mount.h>
a55370a3
N
50
51#define NFSDDBG_FACILITY NFSDDBG_PROC
52
190e4fbf 53/* Globals */
190e4fbf
N
54static struct nameidata rec_dir;
55static int rec_dir_init = 0;
56
57static void
58nfs4_save_user(uid_t *saveuid, gid_t *savegid)
59{
60 *saveuid = current->fsuid;
61 *savegid = current->fsgid;
62 current->fsuid = 0;
63 current->fsgid = 0;
64}
65
66static void
67nfs4_reset_user(uid_t saveuid, gid_t savegid)
68{
69 current->fsuid = saveuid;
70 current->fsgid = savegid;
71}
72
a55370a3
N
73static void
74md5_to_hex(char *out, char *md5)
75{
76 int i;
77
78 for (i=0; i<16; i++) {
79 unsigned char c = md5[i];
80
81 *out++ = '0' + ((c&0xf0)>>4) + (c>=0xa0)*('a'-'9'-1);
82 *out++ = '0' + (c&0x0f) + ((c&0x0f)>=0x0a)*('a'-'9'-1);
83 }
84 *out = '\0';
85}
86
b37ad28b 87__be32
a55370a3
N
88nfs4_make_rec_clidname(char *dname, struct xdr_netobj *clname)
89{
90 struct xdr_netobj cksum;
35058687 91 struct hash_desc desc;
60c74f81 92 struct scatterlist sg;
b37ad28b 93 __be32 status = nfserr_resource;
a55370a3
N
94
95 dprintk("NFSD: nfs4_make_rec_clidname for %.*s\n",
96 clname->len, clname->data);
35058687
HX
97 desc.flags = CRYPTO_TFM_REQ_MAY_SLEEP;
98 desc.tfm = crypto_alloc_hash("md5", 0, CRYPTO_ALG_ASYNC);
99 if (IS_ERR(desc.tfm))
100 goto out_no_tfm;
101 cksum.len = crypto_hash_digestsize(desc.tfm);
a55370a3
N
102 cksum.data = kmalloc(cksum.len, GFP_KERNEL);
103 if (cksum.data == NULL)
104 goto out;
a55370a3 105
60c74f81 106 sg_init_one(&sg, clname->data, clname->len);
a55370a3 107
60c74f81 108 if (crypto_hash_digest(&desc, &sg, sg.length, cksum.data))
35058687 109 goto out;
a55370a3
N
110
111 md5_to_hex(dname, cksum.data);
112
113 kfree(cksum.data);
114 status = nfs_ok;
115out:
35058687
HX
116 crypto_free_hash(desc.tfm);
117out_no_tfm:
a55370a3
N
118 return status;
119}
190e4fbf 120
a6ccbbb8
N
121static void
122nfsd4_sync_rec_dir(void)
c7b9a459 123{
4ac91378
JB
124 mutex_lock(&rec_dir.path.dentry->d_inode->i_mutex);
125 nfsd_sync_dir(rec_dir.path.dentry);
126 mutex_unlock(&rec_dir.path.dentry->d_inode->i_mutex);
c7b9a459
N
127}
128
129int
130nfsd4_create_clid_dir(struct nfs4_client *clp)
131{
132 char *dname = clp->cl_recdir;
133 struct dentry *dentry;
134 uid_t uid;
135 gid_t gid;
136 int status;
137
138 dprintk("NFSD: nfsd4_create_clid_dir for \"%s\"\n", dname);
139
140 if (!rec_dir_init || clp->cl_firststate)
141 return 0;
142
143 nfs4_save_user(&uid, &gid);
144
145 /* lock the parent */
4ac91378 146 mutex_lock(&rec_dir.path.dentry->d_inode->i_mutex);
c7b9a459 147
4ac91378 148 dentry = lookup_one_len(dname, rec_dir.path.dentry, HEXDIR_LEN-1);
c7b9a459
N
149 if (IS_ERR(dentry)) {
150 status = PTR_ERR(dentry);
151 goto out_unlock;
152 }
153 status = -EEXIST;
154 if (dentry->d_inode) {
155 dprintk("NFSD: nfsd4_create_clid_dir: DIRECTORY EXISTS\n");
156 goto out_put;
157 }
4ac91378 158 status = vfs_mkdir(rec_dir.path.dentry->d_inode, dentry, S_IRWXU);
c7b9a459
N
159out_put:
160 dput(dentry);
161out_unlock:
4ac91378 162 mutex_unlock(&rec_dir.path.dentry->d_inode->i_mutex);
c7b9a459
N
163 if (status == 0) {
164 clp->cl_firststate = 1;
a6ccbbb8 165 nfsd4_sync_rec_dir();
c7b9a459
N
166 }
167 nfs4_reset_user(uid, gid);
168 dprintk("NFSD: nfsd4_create_clid_dir returns %d\n", status);
169 return status;
170}
171
190e4fbf
N
172typedef int (recdir_func)(struct dentry *, struct dentry *);
173
174struct dentry_list {
175 struct dentry *dentry;
176 struct list_head list;
177};
178
179struct dentry_list_arg {
180 struct list_head dentries;
181 struct dentry *parent;
182};
183
184static int
185nfsd4_build_dentrylist(void *arg, const char *name, int namlen,
afefdbb2 186 loff_t offset, u64 ino, unsigned int d_type)
190e4fbf
N
187{
188 struct dentry_list_arg *dla = arg;
189 struct list_head *dentries = &dla->dentries;
190 struct dentry *parent = dla->parent;
191 struct dentry *dentry;
192 struct dentry_list *child;
193
194 if (name && isdotent(name, namlen))
b37ad28b 195 return 0;
190e4fbf
N
196 dentry = lookup_one_len(name, parent, namlen);
197 if (IS_ERR(dentry))
198 return PTR_ERR(dentry);
199 child = kmalloc(sizeof(*child), GFP_KERNEL);
200 if (child == NULL)
201 return -ENOMEM;
202 child->dentry = dentry;
203 list_add(&child->list, dentries);
204 return 0;
205}
206
207static int
208nfsd4_list_rec_dir(struct dentry *dir, recdir_func *f)
209{
210 struct file *filp;
211 struct dentry_list_arg dla = {
212 .parent = dir,
213 };
214 struct list_head *dentries = &dla.dentries;
215 struct dentry_list *child;
216 uid_t uid;
217 gid_t gid;
218 int status;
219
220 if (!rec_dir_init)
221 return 0;
222
223 nfs4_save_user(&uid, &gid);
224
4ac91378 225 filp = dentry_open(dget(dir), mntget(rec_dir.path.mnt), O_RDONLY);
190e4fbf
N
226 status = PTR_ERR(filp);
227 if (IS_ERR(filp))
228 goto out;
229 INIT_LIST_HEAD(dentries);
230 status = vfs_readdir(filp, nfsd4_build_dentrylist, &dla);
231 fput(filp);
232 while (!list_empty(dentries)) {
233 child = list_entry(dentries->next, struct dentry_list, list);
234 status = f(dir, child->dentry);
235 if (status)
236 goto out;
237 list_del(&child->list);
238 dput(child->dentry);
239 kfree(child);
240 }
241out:
242 while (!list_empty(dentries)) {
243 child = list_entry(dentries->next, struct dentry_list, list);
244 list_del(&child->list);
245 dput(child->dentry);
246 kfree(child);
247 }
248 nfs4_reset_user(uid, gid);
249 return status;
250}
251
c7b9a459
N
252static int
253nfsd4_remove_clid_file(struct dentry *dir, struct dentry *dentry)
254{
255 int status;
256
257 if (!S_ISREG(dir->d_inode->i_mode)) {
258 printk("nfsd4: non-file found in client recovery directory\n");
259 return -EINVAL;
260 }
4b75f78e 261 mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
c7b9a459 262 status = vfs_unlink(dir->d_inode, dentry);
1b1dcc1b 263 mutex_unlock(&dir->d_inode->i_mutex);
c7b9a459
N
264 return status;
265}
266
267static int
268nfsd4_clear_clid_dir(struct dentry *dir, struct dentry *dentry)
269{
270 int status;
271
272 /* For now this directory should already be empty, but we empty it of
273 * any regular files anyway, just in case the directory was created by
274 * a kernel from the future.... */
275 nfsd4_list_rec_dir(dentry, nfsd4_remove_clid_file);
7ef55b8a 276 mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
c7b9a459 277 status = vfs_rmdir(dir->d_inode, dentry);
1b1dcc1b 278 mutex_unlock(&dir->d_inode->i_mutex);
c7b9a459
N
279 return status;
280}
281
282static int
283nfsd4_unlink_clid_dir(char *name, int namlen)
284{
285 struct dentry *dentry;
286 int status;
287
288 dprintk("NFSD: nfsd4_unlink_clid_dir. name %.*s\n", namlen, name);
289
4ac91378
JB
290 mutex_lock(&rec_dir.path.dentry->d_inode->i_mutex);
291 dentry = lookup_one_len(name, rec_dir.path.dentry, namlen);
292 mutex_unlock(&rec_dir.path.dentry->d_inode->i_mutex);
c7b9a459
N
293 if (IS_ERR(dentry)) {
294 status = PTR_ERR(dentry);
295 return status;
296 }
297 status = -ENOENT;
298 if (!dentry->d_inode)
299 goto out;
300
4ac91378 301 status = nfsd4_clear_clid_dir(rec_dir.path.dentry, dentry);
c7b9a459
N
302out:
303 dput(dentry);
304 return status;
305}
306
307void
308nfsd4_remove_clid_dir(struct nfs4_client *clp)
309{
310 uid_t uid;
311 gid_t gid;
312 int status;
313
314 if (!rec_dir_init || !clp->cl_firststate)
315 return;
316
0622753b
DH
317 status = mnt_want_write(rec_dir.path.mnt);
318 if (status)
319 goto out;
67be4313 320 clp->cl_firststate = 0;
c7b9a459
N
321 nfs4_save_user(&uid, &gid);
322 status = nfsd4_unlink_clid_dir(clp->cl_recdir, HEXDIR_LEN-1);
323 nfs4_reset_user(uid, gid);
324 if (status == 0)
a6ccbbb8 325 nfsd4_sync_rec_dir();
0622753b
DH
326 mnt_drop_write(rec_dir.path.mnt);
327out:
c7b9a459
N
328 if (status)
329 printk("NFSD: Failed to remove expired client state directory"
330 " %.*s\n", HEXDIR_LEN, clp->cl_recdir);
331 return;
332}
333
334static int
335purge_old(struct dentry *parent, struct dentry *child)
336{
337 int status;
338
339 if (nfs4_has_reclaimed_state(child->d_name.name))
b37ad28b 340 return 0;
c7b9a459
N
341
342 status = nfsd4_clear_clid_dir(parent, child);
343 if (status)
344 printk("failed to remove client recovery directory %s\n",
345 child->d_name.name);
346 /* Keep trying, success or failure: */
b37ad28b 347 return 0;
c7b9a459
N
348}
349
350void
351nfsd4_recdir_purge_old(void) {
352 int status;
353
354 if (!rec_dir_init)
355 return;
0622753b
DH
356 status = mnt_want_write(rec_dir.path.mnt);
357 if (status)
358 goto out;
4ac91378 359 status = nfsd4_list_rec_dir(rec_dir.path.dentry, purge_old);
c7b9a459 360 if (status == 0)
a6ccbbb8 361 nfsd4_sync_rec_dir();
0622753b
DH
362 mnt_drop_write(rec_dir.path.mnt);
363out:
c7b9a459
N
364 if (status)
365 printk("nfsd4: failed to purge old clients from recovery"
4ac91378 366 " directory %s\n", rec_dir.path.dentry->d_name.name);
c7b9a459
N
367}
368
190e4fbf
N
369static int
370load_recdir(struct dentry *parent, struct dentry *child)
371{
372 if (child->d_name.len != HEXDIR_LEN - 1) {
373 printk("nfsd4: illegal name %s in recovery directory\n",
374 child->d_name.name);
375 /* Keep trying; maybe the others are OK: */
b37ad28b 376 return 0;
190e4fbf
N
377 }
378 nfs4_client_to_reclaim(child->d_name.name);
b37ad28b 379 return 0;
190e4fbf
N
380}
381
382int
383nfsd4_recdir_load(void) {
384 int status;
385
4ac91378 386 status = nfsd4_list_rec_dir(rec_dir.path.dentry, load_recdir);
190e4fbf
N
387 if (status)
388 printk("nfsd4: failed loading clients from recovery"
4ac91378 389 " directory %s\n", rec_dir.path.dentry->d_name.name);
190e4fbf
N
390 return status;
391}
392
393/*
394 * Hold reference to the recovery directory.
395 */
396
397void
398nfsd4_init_recdir(char *rec_dirname)
399{
400 uid_t uid = 0;
401 gid_t gid = 0;
402 int status;
403
404 printk("NFSD: Using %s as the NFSv4 state recovery directory\n",
405 rec_dirname);
406
407 BUG_ON(rec_dir_init);
408
409 nfs4_save_user(&uid, &gid);
410
c2642ab0
BF
411 status = path_lookup(rec_dirname, LOOKUP_FOLLOW | LOOKUP_DIRECTORY,
412 &rec_dir);
413 if (status)
414 printk("NFSD: unable to find recovery directory %s\n",
190e4fbf
N
415 rec_dirname);
416
417 if (!status)
418 rec_dir_init = 1;
419 nfs4_reset_user(uid, gid);
420}
421
422void
423nfsd4_shutdown_recdir(void)
424{
425 if (!rec_dir_init)
426 return;
427 rec_dir_init = 0;
1d957f9b 428 path_put(&rec_dir.path);
190e4fbf 429}