]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blob - fs/ceph/quota.c
ceph: quota: don't allow cross-quota renames
[mirror_ubuntu-bionic-kernel.git] / fs / ceph / quota.c
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * quota.c - CephFS quota
4 *
5 * Copyright (C) 2017-2018 SUSE
6 *
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License
9 * as published by the Free Software Foundation; either version 2
10 * of the License, or (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, see <http://www.gnu.org/licenses/>.
19 */
20
21 #include "super.h"
22 #include "mds_client.h"
23
24 static inline bool ceph_has_quota(struct ceph_inode_info *ci)
25 {
26 return (ci && (ci->i_max_files || ci->i_max_bytes));
27 }
28
29 void ceph_handle_quota(struct ceph_mds_client *mdsc,
30 struct ceph_mds_session *session,
31 struct ceph_msg *msg)
32 {
33 struct super_block *sb = mdsc->fsc->sb;
34 struct ceph_mds_quota *h = msg->front.iov_base;
35 struct ceph_vino vino;
36 struct inode *inode;
37 struct ceph_inode_info *ci;
38
39 if (msg->front.iov_len != sizeof(*h)) {
40 pr_err("%s corrupt message mds%d len %d\n", __func__,
41 session->s_mds, (int)msg->front.iov_len);
42 ceph_msg_dump(msg);
43 return;
44 }
45
46 /* increment msg sequence number */
47 mutex_lock(&session->s_mutex);
48 session->s_seq++;
49 mutex_unlock(&session->s_mutex);
50
51 /* lookup inode */
52 vino.ino = le64_to_cpu(h->ino);
53 vino.snap = CEPH_NOSNAP;
54 inode = ceph_find_inode(sb, vino);
55 if (!inode) {
56 pr_warn("Failed to find inode %llu\n", vino.ino);
57 return;
58 }
59 ci = ceph_inode(inode);
60
61 spin_lock(&ci->i_ceph_lock);
62 ci->i_rbytes = le64_to_cpu(h->rbytes);
63 ci->i_rfiles = le64_to_cpu(h->rfiles);
64 ci->i_rsubdirs = le64_to_cpu(h->rsubdirs);
65 ci->i_max_bytes = le64_to_cpu(h->max_bytes);
66 ci->i_max_files = le64_to_cpu(h->max_files);
67 spin_unlock(&ci->i_ceph_lock);
68
69 iput(inode);
70 }
71
72 /*
73 * This function walks through the snaprealm for an inode and returns the
74 * ceph_snap_realm for the first snaprealm that has quotas set (either max_files
75 * or max_bytes). If the root is reached, return the root ceph_snap_realm
76 * instead.
77 *
78 * Note that the caller is responsible for calling ceph_put_snap_realm() on the
79 * returned realm.
80 */
81 static struct ceph_snap_realm *get_quota_realm(struct ceph_mds_client *mdsc,
82 struct inode *inode)
83 {
84 struct ceph_inode_info *ci = NULL;
85 struct ceph_snap_realm *realm, *next;
86 struct ceph_vino vino;
87 struct inode *in;
88
89 realm = ceph_inode(inode)->i_snap_realm;
90 ceph_get_snap_realm(mdsc, realm);
91 while (realm) {
92 vino.ino = realm->ino;
93 vino.snap = CEPH_NOSNAP;
94 in = ceph_find_inode(inode->i_sb, vino);
95 if (!in) {
96 pr_warn("Failed to find inode for %llu\n", vino.ino);
97 break;
98 }
99 ci = ceph_inode(in);
100 if (ceph_has_quota(ci) || (ci->i_vino.ino == CEPH_INO_ROOT)) {
101 iput(in);
102 return realm;
103 }
104 iput(in);
105 next = realm->parent;
106 ceph_get_snap_realm(mdsc, next);
107 ceph_put_snap_realm(mdsc, realm);
108 realm = next;
109 }
110 if (realm)
111 ceph_put_snap_realm(mdsc, realm);
112
113 return NULL;
114 }
115
116 bool ceph_quota_is_same_realm(struct inode *old, struct inode *new)
117 {
118 struct ceph_mds_client *mdsc = ceph_inode_to_client(old)->mdsc;
119 struct ceph_snap_realm *old_realm, *new_realm;
120 bool is_same;
121
122 down_read(&mdsc->snap_rwsem);
123 old_realm = get_quota_realm(mdsc, old);
124 new_realm = get_quota_realm(mdsc, new);
125 is_same = (old_realm == new_realm);
126 up_read(&mdsc->snap_rwsem);
127
128 if (old_realm)
129 ceph_put_snap_realm(mdsc, old_realm);
130 if (new_realm)
131 ceph_put_snap_realm(mdsc, new_realm);
132
133 return is_same;
134 }
135
136 enum quota_check_op {
137 QUOTA_CHECK_MAX_FILES_OP /* check quota max_files limit */
138 };
139
140 /*
141 * check_quota_exceeded() will walk up the snaprealm hierarchy and, for each
142 * realm, it will execute quota check operation defined by the 'op' parameter.
143 * The snaprealm walk is interrupted if the quota check detects that the quota
144 * is exceeded or if the root inode is reached.
145 */
146 static bool check_quota_exceeded(struct inode *inode, enum quota_check_op op,
147 loff_t delta)
148 {
149 struct ceph_mds_client *mdsc = ceph_inode_to_client(inode)->mdsc;
150 struct ceph_inode_info *ci;
151 struct ceph_snap_realm *realm, *next;
152 struct ceph_vino vino;
153 struct inode *in;
154 u64 max, rvalue;
155 bool is_root;
156 bool exceeded = false;
157
158 down_read(&mdsc->snap_rwsem);
159 realm = ceph_inode(inode)->i_snap_realm;
160 ceph_get_snap_realm(mdsc, realm);
161 while (realm) {
162 vino.ino = realm->ino;
163 vino.snap = CEPH_NOSNAP;
164 in = ceph_find_inode(inode->i_sb, vino);
165 if (!in) {
166 pr_warn("Failed to find inode for %llu\n", vino.ino);
167 break;
168 }
169 ci = ceph_inode(in);
170 spin_lock(&ci->i_ceph_lock);
171 if (op == QUOTA_CHECK_MAX_FILES_OP) {
172 max = ci->i_max_files;
173 rvalue = ci->i_rfiles + ci->i_rsubdirs;
174 }
175 is_root = (ci->i_vino.ino == CEPH_INO_ROOT);
176 spin_unlock(&ci->i_ceph_lock);
177 switch (op) {
178 case QUOTA_CHECK_MAX_FILES_OP:
179 exceeded = (max && (rvalue >= max));
180 break;
181 default:
182 /* Shouldn't happen */
183 pr_warn("Invalid quota check op (%d)\n", op);
184 exceeded = true; /* Just break the loop */
185 }
186 iput(in);
187
188 if (is_root || exceeded)
189 break;
190 next = realm->parent;
191 ceph_get_snap_realm(mdsc, next);
192 ceph_put_snap_realm(mdsc, realm);
193 realm = next;
194 }
195 ceph_put_snap_realm(mdsc, realm);
196 up_read(&mdsc->snap_rwsem);
197
198 return exceeded;
199 }
200
201 /*
202 * ceph_quota_is_max_files_exceeded - check if we can create a new file
203 * @inode: directory where a new file is being created
204 *
205 * This functions returns true is max_files quota allows a new file to be
206 * created. It is necessary to walk through the snaprealm hierarchy (until the
207 * FS root) to check all realms with quotas set.
208 */
209 bool ceph_quota_is_max_files_exceeded(struct inode *inode)
210 {
211 WARN_ON(!S_ISDIR(inode->i_mode));
212
213 return check_quota_exceeded(inode, QUOTA_CHECK_MAX_FILES_OP, 0);
214 }