xfs_ioctl.c 39.3 KB
Newer Older
L
Linus Torvalds 已提交
1
/*
2 3
 * Copyright (c) 2000-2005 Silicon Graphics, Inc.
 * All Rights Reserved.
L
Linus Torvalds 已提交
4
 *
5 6
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
L
Linus Torvalds 已提交
7 8
 * published by the Free Software Foundation.
 *
9 10 11 12
 * This program is distributed in the hope that it would be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
L
Linus Torvalds 已提交
13
 *
14 15 16
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write the Free Software Foundation,
 * Inc.,  51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
L
Linus Torvalds 已提交
17 18 19
 */
#include "xfs.h"
#include "xfs_fs.h"
20
#include "xfs_shared.h"
21 22 23
#include "xfs_format.h"
#include "xfs_log_format.h"
#include "xfs_trans_resv.h"
L
Linus Torvalds 已提交
24 25 26
#include "xfs_sb.h"
#include "xfs_mount.h"
#include "xfs_inode.h"
27
#include "xfs_ioctl.h"
28
#include "xfs_alloc.h"
L
Linus Torvalds 已提交
29 30
#include "xfs_rtalloc.h"
#include "xfs_itable.h"
31
#include "xfs_error.h"
L
Linus Torvalds 已提交
32
#include "xfs_attr.h"
33
#include "xfs_bmap.h"
D
Dave Chinner 已提交
34
#include "xfs_bmap_util.h"
L
Linus Torvalds 已提交
35
#include "xfs_fsops.h"
C
Christoph Hellwig 已提交
36
#include "xfs_discard.h"
37
#include "xfs_quota.h"
38
#include "xfs_export.h"
C
Christoph Hellwig 已提交
39
#include "xfs_trace.h"
40
#include "xfs_icache.h"
D
Dave Chinner 已提交
41
#include "xfs_symlink.h"
42
#include "xfs_trans.h"
L
Linus Torvalds 已提交
43

44
#include <linux/capability.h>
L
Linus Torvalds 已提交
45 46 47 48
#include <linux/dcache.h>
#include <linux/mount.h>
#include <linux/namei.h>
#include <linux/pagemap.h>
49
#include <linux/slab.h>
50
#include <linux/exportfs.h>
L
Linus Torvalds 已提交
51 52 53 54 55 56 57 58 59 60 61 62

/*
 * xfs_find_handle maps from userspace xfs_fsop_handlereq structure to
 * a file or fs handle.
 *
 * XFS_IOC_PATH_TO_FSHANDLE
 *    returns fs handle for a mount point or path within that mount point
 * XFS_IOC_FD_TO_HANDLE
 *    returns full handle for a FD opened in user space
 * XFS_IOC_PATH_TO_HANDLE
 *    returns full handle for a path
 */
63
int
L
Linus Torvalds 已提交
64 65
xfs_find_handle(
	unsigned int		cmd,
66
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
67 68 69 70
{
	int			hsize;
	xfs_handle_t		handle;
	struct inode		*inode;
71
	struct fd		f = {NULL};
C
Christoph Hellwig 已提交
72
	struct path		path;
73
	int			error;
C
Christoph Hellwig 已提交
74
	struct xfs_inode	*ip;
L
Linus Torvalds 已提交
75

C
Christoph Hellwig 已提交
76
	if (cmd == XFS_IOC_FD_TO_HANDLE) {
77 78
		f = fdget(hreq->fd);
		if (!f.file)
C
Christoph Hellwig 已提交
79
			return -EBADF;
A
Al Viro 已提交
80
		inode = file_inode(f.file);
C
Christoph Hellwig 已提交
81 82 83 84 85
	} else {
		error = user_lpath((const char __user *)hreq->path, &path);
		if (error)
			return error;
		inode = path.dentry->d_inode;
L
Linus Torvalds 已提交
86
	}
C
Christoph Hellwig 已提交
87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112
	ip = XFS_I(inode);

	/*
	 * We can only generate handles for inodes residing on a XFS filesystem,
	 * and only for regular files, directories or symbolic links.
	 */
	error = -EINVAL;
	if (inode->i_sb->s_magic != XFS_SB_MAGIC)
		goto out_put;

	error = -EBADF;
	if (!S_ISREG(inode->i_mode) &&
	    !S_ISDIR(inode->i_mode) &&
	    !S_ISLNK(inode->i_mode))
		goto out_put;


	memcpy(&handle.ha_fsid, ip->i_mount->m_fixedfsid, sizeof(xfs_fsid_t));

	if (cmd == XFS_IOC_PATH_TO_FSHANDLE) {
		/*
		 * This handle only contains an fsid, zero the rest.
		 */
		memset(&handle.ha_fid, 0, sizeof(handle.ha_fid));
		hsize = sizeof(xfs_fsid_t);
	} else {
C
Christoph Hellwig 已提交
113 114 115 116 117
		handle.ha_fid.fid_len = sizeof(xfs_fid_t) -
					sizeof(handle.ha_fid.fid_len);
		handle.ha_fid.fid_pad = 0;
		handle.ha_fid.fid_gen = ip->i_d.di_gen;
		handle.ha_fid.fid_ino = ip->i_ino;
L
Linus Torvalds 已提交
118 119 120 121

		hsize = XFS_HSIZE(handle);
	}

C
Christoph Hellwig 已提交
122
	error = -EFAULT;
123
	if (copy_to_user(hreq->ohandle, &handle, hsize) ||
C
Christoph Hellwig 已提交
124 125
	    copy_to_user(hreq->ohandlen, &hsize, sizeof(__s32)))
		goto out_put;
L
Linus Torvalds 已提交
126

C
Christoph Hellwig 已提交
127 128 129 130
	error = 0;

 out_put:
	if (cmd == XFS_IOC_FD_TO_HANDLE)
131
		fdput(f);
C
Christoph Hellwig 已提交
132 133 134
	else
		path_put(&path);
	return error;
L
Linus Torvalds 已提交
135 136 137
}

/*
138 139
 * No need to do permission checks on the various pathname components
 * as the handle operations are privileged.
L
Linus Torvalds 已提交
140 141
 */
STATIC int
142 143 144 145 146 147 148 149 150 151 152 153 154 155 156
xfs_handle_acceptable(
	void			*context,
	struct dentry		*dentry)
{
	return 1;
}

/*
 * Convert userspace handle data into a dentry.
 */
struct dentry *
xfs_handle_to_dentry(
	struct file		*parfilp,
	void __user		*uhandle,
	u32			hlen)
L
Linus Torvalds 已提交
157 158
{
	xfs_handle_t		handle;
159
	struct xfs_fid64	fid;
L
Linus Torvalds 已提交
160 161 162 163

	/*
	 * Only allow handle opens under a directory.
	 */
A
Al Viro 已提交
164
	if (!S_ISDIR(file_inode(parfilp)->i_mode))
165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182
		return ERR_PTR(-ENOTDIR);

	if (hlen != sizeof(xfs_handle_t))
		return ERR_PTR(-EINVAL);
	if (copy_from_user(&handle, uhandle, hlen))
		return ERR_PTR(-EFAULT);
	if (handle.ha_fid.fid_len !=
	    sizeof(handle.ha_fid) - sizeof(handle.ha_fid.fid_len))
		return ERR_PTR(-EINVAL);

	memset(&fid, 0, sizeof(struct fid));
	fid.ino = handle.ha_fid.fid_ino;
	fid.gen = handle.ha_fid.fid_gen;

	return exportfs_decode_fh(parfilp->f_path.mnt, (struct fid *)&fid, 3,
			FILEID_INO32_GEN | XFS_FILEID_TYPE_64FLAG,
			xfs_handle_acceptable, NULL);
}
L
Linus Torvalds 已提交
183

184 185 186 187 188 189
STATIC struct dentry *
xfs_handlereq_to_dentry(
	struct file		*parfilp,
	xfs_fsop_handlereq_t	*hreq)
{
	return xfs_handle_to_dentry(parfilp, hreq->ihandle, hreq->ihandlen);
L
Linus Torvalds 已提交
190 191
}

192
int
L
Linus Torvalds 已提交
193 194
xfs_open_by_handle(
	struct file		*parfilp,
195
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
196
{
197
	const struct cred	*cred = current_cred();
L
Linus Torvalds 已提交
198
	int			error;
199
	int			fd;
L
Linus Torvalds 已提交
200 201 202 203
	int			permflag;
	struct file		*filp;
	struct inode		*inode;
	struct dentry		*dentry;
204
	fmode_t			fmode;
205
	struct path		path;
L
Linus Torvalds 已提交
206 207

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
208
		return -EPERM;
L
Linus Torvalds 已提交
209

210 211 212 213
	dentry = xfs_handlereq_to_dentry(parfilp, hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
	inode = dentry->d_inode;
L
Linus Torvalds 已提交
214 215 216

	/* Restrict xfs_open_by_handle to directories & regular files. */
	if (!(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode))) {
E
Eric Sandeen 已提交
217
		error = -EPERM;
218
		goto out_dput;
L
Linus Torvalds 已提交
219 220 221
	}

#if BITS_PER_LONG != 32
222
	hreq->oflags |= O_LARGEFILE;
L
Linus Torvalds 已提交
223
#endif
224

225
	permflag = hreq->oflags;
226
	fmode = OPEN_FMODE(permflag);
L
Linus Torvalds 已提交
227
	if ((!(permflag & O_APPEND) || (permflag & O_TRUNC)) &&
228
	    (fmode & FMODE_WRITE) && IS_APPEND(inode)) {
E
Eric Sandeen 已提交
229
		error = -EPERM;
230
		goto out_dput;
L
Linus Torvalds 已提交
231 232
	}

233
	if ((fmode & FMODE_WRITE) && IS_IMMUTABLE(inode)) {
E
Eric Sandeen 已提交
234
		error = -EACCES;
235
		goto out_dput;
L
Linus Torvalds 已提交
236 237 238
	}

	/* Can't write directories. */
239
	if (S_ISDIR(inode->i_mode) && (fmode & FMODE_WRITE)) {
E
Eric Sandeen 已提交
240
		error = -EISDIR;
241
		goto out_dput;
L
Linus Torvalds 已提交
242 243
	}

244
	fd = get_unused_fd_flags(0);
245 246 247
	if (fd < 0) {
		error = fd;
		goto out_dput;
L
Linus Torvalds 已提交
248 249
	}

250 251 252 253
	path.mnt = parfilp->f_path.mnt;
	path.dentry = dentry;
	filp = dentry_open(&path, hreq->oflags, cred);
	dput(dentry);
L
Linus Torvalds 已提交
254
	if (IS_ERR(filp)) {
255 256
		put_unused_fd(fd);
		return PTR_ERR(filp);
L
Linus Torvalds 已提交
257
	}
258

A
Al Viro 已提交
259
	if (S_ISREG(inode->i_mode)) {
260
		filp->f_flags |= O_NOATIME;
261
		filp->f_mode |= FMODE_NOCMTIME;
262
	}
L
Linus Torvalds 已提交
263

264 265 266 267 268 269
	fd_install(fd, filp);
	return fd;

 out_dput:
	dput(dentry);
	return error;
L
Linus Torvalds 已提交
270 271
}

272
int
L
Linus Torvalds 已提交
273
xfs_readlink_by_handle(
274 275
	struct file		*parfilp,
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
276
{
277
	struct dentry		*dentry;
L
Linus Torvalds 已提交
278
	__u32			olen;
279 280
	void			*link;
	int			error;
L
Linus Torvalds 已提交
281 282

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
283
		return -EPERM;
L
Linus Torvalds 已提交
284

285 286 287
	dentry = xfs_handlereq_to_dentry(parfilp, hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
288 289

	/* Restrict this handle operation to symlinks only. */
290
	if (!S_ISLNK(dentry->d_inode->i_mode)) {
E
Eric Sandeen 已提交
291
		error = -EINVAL;
292
		goto out_dput;
L
Linus Torvalds 已提交
293 294
	}

295
	if (copy_from_user(&olen, hreq->ohandlen, sizeof(__u32))) {
E
Eric Sandeen 已提交
296
		error = -EFAULT;
297
		goto out_dput;
L
Linus Torvalds 已提交
298 299
	}

300
	link = kmalloc(MAXPATHLEN+1, GFP_KERNEL);
301
	if (!link) {
E
Eric Sandeen 已提交
302
		error = -ENOMEM;
303 304
		goto out_dput;
	}
L
Linus Torvalds 已提交
305

D
Dave Chinner 已提交
306
	error = xfs_readlink(XFS_I(dentry->d_inode), link);
307
	if (error)
308
		goto out_kfree;
A
Al Viro 已提交
309
	error = readlink_copy(hreq->ohandle, olen, link);
310 311
	if (error)
		goto out_kfree;
312

313 314
 out_kfree:
	kfree(link);
315 316
 out_dput:
	dput(dentry);
317
	return error;
L
Linus Torvalds 已提交
318 319
}

D
Dave Chinner 已提交
320 321 322 323 324 325 326 327 328 329 330
int
xfs_set_dmattrs(
	xfs_inode_t     *ip,
	u_int		evmask,
	u_int16_t	state)
{
	xfs_mount_t	*mp = ip->i_mount;
	xfs_trans_t	*tp;
	int		error;

	if (!capable(CAP_SYS_ADMIN))
D
Dave Chinner 已提交
331
		return -EPERM;
D
Dave Chinner 已提交
332 333

	if (XFS_FORCED_SHUTDOWN(mp))
D
Dave Chinner 已提交
334
		return -EIO;
D
Dave Chinner 已提交
335 336

	tp = xfs_trans_alloc(mp, XFS_TRANS_SET_DMATTRS);
337
	error = xfs_trans_reserve(tp, &M_RES(mp)->tr_ichange, 0, 0);
D
Dave Chinner 已提交
338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353
	if (error) {
		xfs_trans_cancel(tp, 0);
		return error;
	}
	xfs_ilock(ip, XFS_ILOCK_EXCL);
	xfs_trans_ijoin(tp, ip, XFS_ILOCK_EXCL);

	ip->i_d.di_dmevmask = evmask;
	ip->i_d.di_dmstate  = state;

	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
	error = xfs_trans_commit(tp, 0);

	return error;
}

L
Linus Torvalds 已提交
354 355
STATIC int
xfs_fssetdm_by_handle(
356 357
	struct file		*parfilp,
	void			__user *arg)
L
Linus Torvalds 已提交
358 359 360 361
{
	int			error;
	struct fsdmidata	fsd;
	xfs_fsop_setdm_handlereq_t dmhreq;
362
	struct dentry		*dentry;
L
Linus Torvalds 已提交
363 364

	if (!capable(CAP_MKNOD))
E
Eric Sandeen 已提交
365
		return -EPERM;
L
Linus Torvalds 已提交
366
	if (copy_from_user(&dmhreq, arg, sizeof(xfs_fsop_setdm_handlereq_t)))
E
Eric Sandeen 已提交
367
		return -EFAULT;
L
Linus Torvalds 已提交
368

J
Jan Kara 已提交
369 370 371 372
	error = mnt_want_write_file(parfilp);
	if (error)
		return error;

373
	dentry = xfs_handlereq_to_dentry(parfilp, &dmhreq.hreq);
J
Jan Kara 已提交
374 375
	if (IS_ERR(dentry)) {
		mnt_drop_write_file(parfilp);
376
		return PTR_ERR(dentry);
J
Jan Kara 已提交
377
	}
L
Linus Torvalds 已提交
378

379
	if (IS_IMMUTABLE(dentry->d_inode) || IS_APPEND(dentry->d_inode)) {
E
Eric Sandeen 已提交
380
		error = -EPERM;
381
		goto out;
L
Linus Torvalds 已提交
382 383 384
	}

	if (copy_from_user(&fsd, dmhreq.data, sizeof(fsd))) {
E
Eric Sandeen 已提交
385
		error = -EFAULT;
386
		goto out;
L
Linus Torvalds 已提交
387 388
	}

D
Dave Chinner 已提交
389
	error = xfs_set_dmattrs(XFS_I(dentry->d_inode), fsd.fsd_dmevmask,
390
				 fsd.fsd_dmstate);
L
Linus Torvalds 已提交
391

392
 out:
J
Jan Kara 已提交
393
	mnt_drop_write_file(parfilp);
394
	dput(dentry);
395
	return error;
L
Linus Torvalds 已提交
396 397 398 399
}

STATIC int
xfs_attrlist_by_handle(
400 401
	struct file		*parfilp,
	void			__user *arg)
L
Linus Torvalds 已提交
402
{
403
	int			error = -ENOMEM;
L
Linus Torvalds 已提交
404 405
	attrlist_cursor_kern_t	*cursor;
	xfs_fsop_attrlist_handlereq_t al_hreq;
406
	struct dentry		*dentry;
L
Linus Torvalds 已提交
407 408 409
	char			*kbuf;

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
410
		return -EPERM;
L
Linus Torvalds 已提交
411
	if (copy_from_user(&al_hreq, arg, sizeof(xfs_fsop_attrlist_handlereq_t)))
E
Eric Sandeen 已提交
412
		return -EFAULT;
413 414
	if (al_hreq.buflen < sizeof(struct attrlist) ||
	    al_hreq.buflen > XATTR_LIST_MAX)
E
Eric Sandeen 已提交
415
		return -EINVAL;
L
Linus Torvalds 已提交
416

417 418 419 420
	/*
	 * Reject flags, only allow namespaces.
	 */
	if (al_hreq.flags & ~(ATTR_ROOT | ATTR_SECURE))
E
Eric Sandeen 已提交
421
		return -EINVAL;
422

423 424 425
	dentry = xfs_handlereq_to_dentry(parfilp, &al_hreq.hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
426

427 428 429
	kbuf = kmem_zalloc_large(al_hreq.buflen, KM_SLEEP);
	if (!kbuf)
		goto out_dput;
L
Linus Torvalds 已提交
430 431

	cursor = (attrlist_cursor_kern_t *)&al_hreq.pos;
D
Dave Chinner 已提交
432
	error = xfs_attr_list(XFS_I(dentry->d_inode), kbuf, al_hreq.buflen,
433
					al_hreq.flags, cursor);
L
Linus Torvalds 已提交
434 435 436 437 438 439
	if (error)
		goto out_kfree;

	if (copy_to_user(al_hreq.buffer, kbuf, al_hreq.buflen))
		error = -EFAULT;

440 441 442
out_kfree:
	kmem_free(kbuf);
out_dput:
443 444
	dput(dentry);
	return error;
L
Linus Torvalds 已提交
445 446
}

447
int
L
Linus Torvalds 已提交
448
xfs_attrmulti_attr_get(
449
	struct inode		*inode,
450 451
	unsigned char		*name,
	unsigned char		__user *ubuf,
L
Linus Torvalds 已提交
452 453 454
	__uint32_t		*len,
	__uint32_t		flags)
{
455
	unsigned char		*kbuf;
D
Dave Chinner 已提交
456
	int			error = -EFAULT;
457

L
Linus Torvalds 已提交
458
	if (*len > XATTR_SIZE_MAX)
D
Dave Chinner 已提交
459
		return -EINVAL;
460 461
	kbuf = kmem_zalloc_large(*len, KM_SLEEP);
	if (!kbuf)
D
Dave Chinner 已提交
462
		return -ENOMEM;
L
Linus Torvalds 已提交
463

464
	error = xfs_attr_get(XFS_I(inode), name, kbuf, (int *)len, flags);
L
Linus Torvalds 已提交
465 466 467 468
	if (error)
		goto out_kfree;

	if (copy_to_user(ubuf, kbuf, *len))
D
Dave Chinner 已提交
469
		error = -EFAULT;
L
Linus Torvalds 已提交
470

471 472
out_kfree:
	kmem_free(kbuf);
L
Linus Torvalds 已提交
473 474 475
	return error;
}

476
int
L
Linus Torvalds 已提交
477
xfs_attrmulti_attr_set(
478
	struct inode		*inode,
479 480
	unsigned char		*name,
	const unsigned char	__user *ubuf,
L
Linus Torvalds 已提交
481 482 483
	__uint32_t		len,
	__uint32_t		flags)
{
484
	unsigned char		*kbuf;
L
Linus Torvalds 已提交
485

486
	if (IS_IMMUTABLE(inode) || IS_APPEND(inode))
D
Dave Chinner 已提交
487
		return -EPERM;
L
Linus Torvalds 已提交
488
	if (len > XATTR_SIZE_MAX)
D
Dave Chinner 已提交
489
		return -EINVAL;
L
Linus Torvalds 已提交
490

L
Li Zefan 已提交
491 492 493
	kbuf = memdup_user(ubuf, len);
	if (IS_ERR(kbuf))
		return PTR_ERR(kbuf);
494

D
Dave Chinner 已提交
495
	return xfs_attr_set(XFS_I(inode), name, kbuf, len, flags);
L
Linus Torvalds 已提交
496 497
}

498
int
L
Linus Torvalds 已提交
499
xfs_attrmulti_attr_remove(
500
	struct inode		*inode,
501
	unsigned char		*name,
L
Linus Torvalds 已提交
502 503
	__uint32_t		flags)
{
504
	if (IS_IMMUTABLE(inode) || IS_APPEND(inode))
D
Dave Chinner 已提交
505
		return -EPERM;
506
	return xfs_attr_remove(XFS_I(inode), name, flags);
L
Linus Torvalds 已提交
507 508 509 510
}

STATIC int
xfs_attrmulti_by_handle(
511
	struct file		*parfilp,
512
	void			__user *arg)
L
Linus Torvalds 已提交
513 514 515 516
{
	int			error;
	xfs_attr_multiop_t	*ops;
	xfs_fsop_attrmulti_handlereq_t am_hreq;
517
	struct dentry		*dentry;
L
Linus Torvalds 已提交
518
	unsigned int		i, size;
519
	unsigned char		*attr_name;
L
Linus Torvalds 已提交
520 521

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
522
		return -EPERM;
L
Linus Torvalds 已提交
523
	if (copy_from_user(&am_hreq, arg, sizeof(xfs_fsop_attrmulti_handlereq_t)))
E
Eric Sandeen 已提交
524
		return -EFAULT;
L
Linus Torvalds 已提交
525

526 527 528 529
	/* overflow check */
	if (am_hreq.opcount >= INT_MAX / sizeof(xfs_attr_multiop_t))
		return -E2BIG;

530 531 532
	dentry = xfs_handlereq_to_dentry(parfilp, &am_hreq.hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
533

D
Dave Chinner 已提交
534
	error = -E2BIG;
C
Christoph Hellwig 已提交
535
	size = am_hreq.opcount * sizeof(xfs_attr_multiop_t);
L
Linus Torvalds 已提交
536
	if (!size || size > 16 * PAGE_SIZE)
537
		goto out_dput;
L
Linus Torvalds 已提交
538

L
Li Zefan 已提交
539 540
	ops = memdup_user(am_hreq.ops, size);
	if (IS_ERR(ops)) {
D
Dave Chinner 已提交
541
		error = PTR_ERR(ops);
542
		goto out_dput;
L
Li Zefan 已提交
543
	}
L
Linus Torvalds 已提交
544

D
Dave Chinner 已提交
545
	error = -ENOMEM;
L
Linus Torvalds 已提交
546 547 548 549 550 551
	attr_name = kmalloc(MAXNAMELEN, GFP_KERNEL);
	if (!attr_name)
		goto out_kfree_ops;

	error = 0;
	for (i = 0; i < am_hreq.opcount; i++) {
552
		ops[i].am_error = strncpy_from_user((char *)attr_name,
L
Linus Torvalds 已提交
553 554
				ops[i].am_attrname, MAXNAMELEN);
		if (ops[i].am_error == 0 || ops[i].am_error == MAXNAMELEN)
D
Dave Chinner 已提交
555
			error = -ERANGE;
L
Linus Torvalds 已提交
556 557 558 559 560
		if (ops[i].am_error < 0)
			break;

		switch (ops[i].am_opcode) {
		case ATTR_OP_GET:
561 562 563 564
			ops[i].am_error = xfs_attrmulti_attr_get(
					dentry->d_inode, attr_name,
					ops[i].am_attrvalue, &ops[i].am_length,
					ops[i].am_flags);
L
Linus Torvalds 已提交
565 566
			break;
		case ATTR_OP_SET:
567
			ops[i].am_error = mnt_want_write_file(parfilp);
568 569
			if (ops[i].am_error)
				break;
570 571 572 573
			ops[i].am_error = xfs_attrmulti_attr_set(
					dentry->d_inode, attr_name,
					ops[i].am_attrvalue, ops[i].am_length,
					ops[i].am_flags);
A
Al Viro 已提交
574
			mnt_drop_write_file(parfilp);
L
Linus Torvalds 已提交
575 576
			break;
		case ATTR_OP_REMOVE:
577
			ops[i].am_error = mnt_want_write_file(parfilp);
578 579
			if (ops[i].am_error)
				break;
580 581 582
			ops[i].am_error = xfs_attrmulti_attr_remove(
					dentry->d_inode, attr_name,
					ops[i].am_flags);
A
Al Viro 已提交
583
			mnt_drop_write_file(parfilp);
L
Linus Torvalds 已提交
584 585
			break;
		default:
D
Dave Chinner 已提交
586
			ops[i].am_error = -EINVAL;
L
Linus Torvalds 已提交
587 588 589 590
		}
	}

	if (copy_to_user(am_hreq.ops, ops, size))
D
Dave Chinner 已提交
591
		error = -EFAULT;
L
Linus Torvalds 已提交
592 593 594 595

	kfree(attr_name);
 out_kfree_ops:
	kfree(ops);
596 597
 out_dput:
	dput(dentry);
D
Dave Chinner 已提交
598
	return error;
L
Linus Torvalds 已提交
599 600
}

601
int
L
Linus Torvalds 已提交
602
xfs_ioc_space(
603
	struct xfs_inode	*ip,
604
	struct inode		*inode,
L
Linus Torvalds 已提交
605 606 607
	struct file		*filp,
	int			ioflags,
	unsigned int		cmd,
608
	xfs_flock64_t		*bf)
L
Linus Torvalds 已提交
609
{
610 611 612 613 614
	struct xfs_mount	*mp = ip->i_mount;
	struct xfs_trans	*tp;
	struct iattr		iattr;
	bool			setprealloc = false;
	bool			clrprealloc = false;
L
Linus Torvalds 已提交
615 616
	int			error;

617 618 619 620 621 622
	/*
	 * Only allow the sys admin to reserve space unless
	 * unwritten extents are enabled.
	 */
	if (!xfs_sb_version_hasextflgbit(&ip->i_mount->m_sb) &&
	    !capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
623
		return -EPERM;
624

625
	if (inode->i_flags & (S_IMMUTABLE|S_APPEND))
E
Eric Sandeen 已提交
626
		return -EPERM;
L
Linus Torvalds 已提交
627

628
	if (!(filp->f_mode & FMODE_WRITE))
E
Eric Sandeen 已提交
629
		return -EBADF;
L
Linus Torvalds 已提交
630

631
	if (!S_ISREG(inode->i_mode))
E
Eric Sandeen 已提交
632
		return -EINVAL;
L
Linus Torvalds 已提交
633

J
Jan Kara 已提交
634 635 636
	error = mnt_want_write_file(filp);
	if (error)
		return error;
637

638
	xfs_ilock(ip, XFS_IOLOCK_EXCL);
639 640 641 642 643 644 645 646 647 648 649

	switch (bf->l_whence) {
	case 0: /*SEEK_SET*/
		break;
	case 1: /*SEEK_CUR*/
		bf->l_start += filp->f_pos;
		break;
	case 2: /*SEEK_END*/
		bf->l_start += XFS_ISIZE(ip);
		break;
	default:
D
Dave Chinner 已提交
650
		error = -EINVAL;
651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666
		goto out_unlock;
	}

	/*
	 * length of <= 0 for resv/unresv/zero is invalid.  length for
	 * alloc/free is ignored completely and we have no idea what userspace
	 * might have set it to, so set it to zero to allow range
	 * checks to pass.
	 */
	switch (cmd) {
	case XFS_IOC_ZERO_RANGE:
	case XFS_IOC_RESVSP:
	case XFS_IOC_RESVSP64:
	case XFS_IOC_UNRESVSP:
	case XFS_IOC_UNRESVSP64:
		if (bf->l_len <= 0) {
D
Dave Chinner 已提交
667
			error = -EINVAL;
668 669 670 671 672 673 674 675 676 677 678 679
			goto out_unlock;
		}
		break;
	default:
		bf->l_len = 0;
		break;
	}

	if (bf->l_start < 0 ||
	    bf->l_start > mp->m_super->s_maxbytes ||
	    bf->l_start + bf->l_len < 0 ||
	    bf->l_start + bf->l_len >= mp->m_super->s_maxbytes) {
D
Dave Chinner 已提交
680
		error = -EINVAL;
681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720
		goto out_unlock;
	}

	switch (cmd) {
	case XFS_IOC_ZERO_RANGE:
		error = xfs_zero_file_space(ip, bf->l_start, bf->l_len);
		if (!error)
			setprealloc = true;
		break;
	case XFS_IOC_RESVSP:
	case XFS_IOC_RESVSP64:
		error = xfs_alloc_file_space(ip, bf->l_start, bf->l_len,
						XFS_BMAPI_PREALLOC);
		if (!error)
			setprealloc = true;
		break;
	case XFS_IOC_UNRESVSP:
	case XFS_IOC_UNRESVSP64:
		error = xfs_free_file_space(ip, bf->l_start, bf->l_len);
		break;
	case XFS_IOC_ALLOCSP:
	case XFS_IOC_ALLOCSP64:
	case XFS_IOC_FREESP:
	case XFS_IOC_FREESP64:
		if (bf->l_start > XFS_ISIZE(ip)) {
			error = xfs_alloc_file_space(ip, XFS_ISIZE(ip),
					bf->l_start - XFS_ISIZE(ip), 0);
			if (error)
				goto out_unlock;
		}

		iattr.ia_valid = ATTR_SIZE;
		iattr.ia_size = bf->l_start;

		error = xfs_setattr_size(ip, &iattr);
		if (!error)
			clrprealloc = true;
		break;
	default:
		ASSERT(0);
D
Dave Chinner 已提交
721
		error = -EINVAL;
722 723 724 725 726 727 728 729 730 731 732 733 734 735 736
	}

	if (error)
		goto out_unlock;

	tp = xfs_trans_alloc(mp, XFS_TRANS_WRITEID);
	error = xfs_trans_reserve(tp, &M_RES(mp)->tr_writeid, 0, 0);
	if (error) {
		xfs_trans_cancel(tp, 0);
		goto out_unlock;
	}

	xfs_ilock(ip, XFS_ILOCK_EXCL);
	xfs_trans_ijoin(tp, ip, XFS_ILOCK_EXCL);

D
Dave Chinner 已提交
737
	if (!(ioflags & XFS_IO_INVIS)) {
738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754
		ip->i_d.di_mode &= ~S_ISUID;
		if (ip->i_d.di_mode & S_IXGRP)
			ip->i_d.di_mode &= ~S_ISGID;
		xfs_trans_ichgtime(tp, ip, XFS_ICHGTIME_MOD | XFS_ICHGTIME_CHG);
	}

	if (setprealloc)
		ip->i_d.di_flags |= XFS_DIFLAG_PREALLOC;
	else if (clrprealloc)
		ip->i_d.di_flags &= ~XFS_DIFLAG_PREALLOC;

	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
	if (filp->f_flags & O_DSYNC)
		xfs_trans_set_sync(tp);
	error = xfs_trans_commit(tp, 0);

out_unlock:
755
	xfs_iunlock(ip, XFS_IOLOCK_EXCL);
J
Jan Kara 已提交
756
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
757
	return error;
L
Linus Torvalds 已提交
758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778
}

STATIC int
xfs_ioc_bulkstat(
	xfs_mount_t		*mp,
	unsigned int		cmd,
	void			__user *arg)
{
	xfs_fsop_bulkreq_t	bulkreq;
	int			count;	/* # of records returned */
	xfs_ino_t		inlast;	/* last inode number */
	int			done;
	int			error;

	/* done = 1 if there are more stats to get and if bulkstat */
	/* should be called again (unused here, but used in dmapi) */

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (XFS_FORCED_SHUTDOWN(mp))
E
Eric Sandeen 已提交
779
		return -EIO;
L
Linus Torvalds 已提交
780 781

	if (copy_from_user(&bulkreq, arg, sizeof(xfs_fsop_bulkreq_t)))
E
Eric Sandeen 已提交
782
		return -EFAULT;
L
Linus Torvalds 已提交
783 784

	if (copy_from_user(&inlast, bulkreq.lastip, sizeof(__s64)))
E
Eric Sandeen 已提交
785
		return -EFAULT;
L
Linus Torvalds 已提交
786 787

	if ((count = bulkreq.icount) <= 0)
E
Eric Sandeen 已提交
788
		return -EINVAL;
L
Linus Torvalds 已提交
789

790
	if (bulkreq.ubuffer == NULL)
E
Eric Sandeen 已提交
791
		return -EINVAL;
792

L
Linus Torvalds 已提交
793 794
	if (cmd == XFS_IOC_FSINUMBERS)
		error = xfs_inumbers(mp, &inlast, &count,
795
					bulkreq.ubuffer, xfs_inumbers_fmt);
L
Linus Torvalds 已提交
796
	else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE)
797 798
		error = xfs_bulkstat_one(mp, inlast, bulkreq.ubuffer,
					sizeof(xfs_bstat_t), NULL, &done);
799
	else	/* XFS_IOC_FSBULKSTAT */
800 801 802
		error = xfs_bulkstat(mp, &inlast, &count, xfs_bulkstat_one,
				     sizeof(xfs_bstat_t), bulkreq.ubuffer,
				     &done);
L
Linus Torvalds 已提交
803 804

	if (error)
D
Dave Chinner 已提交
805
		return error;
L
Linus Torvalds 已提交
806 807 808 809

	if (bulkreq.ocount != NULL) {
		if (copy_to_user(bulkreq.lastip, &inlast,
						sizeof(xfs_ino_t)))
E
Eric Sandeen 已提交
810
			return -EFAULT;
L
Linus Torvalds 已提交
811 812

		if (copy_to_user(bulkreq.ocount, &count, sizeof(count)))
E
Eric Sandeen 已提交
813
			return -EFAULT;
L
Linus Torvalds 已提交
814 815 816 817 818 819 820 821 822 823
	}

	return 0;
}

STATIC int
xfs_ioc_fsgeometry_v1(
	xfs_mount_t		*mp,
	void			__user *arg)
{
824
	xfs_fsop_geom_t         fsgeo;
L
Linus Torvalds 已提交
825 826
	int			error;

827
	error = xfs_fs_geometry(mp, &fsgeo, 3);
L
Linus Torvalds 已提交
828
	if (error)
D
Dave Chinner 已提交
829
		return error;
L
Linus Torvalds 已提交
830

831 832 833 834 835 836
	/*
	 * Caller should have passed an argument of type
	 * xfs_fsop_geom_v1_t.  This is a proper subset of the
	 * xfs_fsop_geom_t that xfs_fs_geometry() fills in.
	 */
	if (copy_to_user(arg, &fsgeo, sizeof(xfs_fsop_geom_v1_t)))
E
Eric Sandeen 已提交
837
		return -EFAULT;
L
Linus Torvalds 已提交
838 839 840 841 842 843 844 845 846 847 848 849 850
	return 0;
}

STATIC int
xfs_ioc_fsgeometry(
	xfs_mount_t		*mp,
	void			__user *arg)
{
	xfs_fsop_geom_t		fsgeo;
	int			error;

	error = xfs_fs_geometry(mp, &fsgeo, 4);
	if (error)
D
Dave Chinner 已提交
851
		return error;
L
Linus Torvalds 已提交
852 853

	if (copy_to_user(arg, &fsgeo, sizeof(fsgeo)))
E
Eric Sandeen 已提交
854
		return -EFAULT;
L
Linus Torvalds 已提交
855 856 857 858 859 860 861 862 863 864 865 866 867 868
	return 0;
}

/*
 * Linux extended inode flags interface.
 */

STATIC unsigned int
xfs_merge_ioc_xflags(
	unsigned int	flags,
	unsigned int	start)
{
	unsigned int	xflags = start;

869
	if (flags & FS_IMMUTABLE_FL)
L
Linus Torvalds 已提交
870 871 872
		xflags |= XFS_XFLAG_IMMUTABLE;
	else
		xflags &= ~XFS_XFLAG_IMMUTABLE;
873
	if (flags & FS_APPEND_FL)
L
Linus Torvalds 已提交
874 875 876
		xflags |= XFS_XFLAG_APPEND;
	else
		xflags &= ~XFS_XFLAG_APPEND;
877
	if (flags & FS_SYNC_FL)
L
Linus Torvalds 已提交
878 879 880
		xflags |= XFS_XFLAG_SYNC;
	else
		xflags &= ~XFS_XFLAG_SYNC;
881
	if (flags & FS_NOATIME_FL)
L
Linus Torvalds 已提交
882 883 884
		xflags |= XFS_XFLAG_NOATIME;
	else
		xflags &= ~XFS_XFLAG_NOATIME;
885
	if (flags & FS_NODUMP_FL)
L
Linus Torvalds 已提交
886 887 888 889 890 891 892 893 894 895 896 897 898 899
		xflags |= XFS_XFLAG_NODUMP;
	else
		xflags &= ~XFS_XFLAG_NODUMP;

	return xflags;
}

STATIC unsigned int
xfs_di2lxflags(
	__uint16_t	di_flags)
{
	unsigned int	flags = 0;

	if (di_flags & XFS_DIFLAG_IMMUTABLE)
900
		flags |= FS_IMMUTABLE_FL;
L
Linus Torvalds 已提交
901
	if (di_flags & XFS_DIFLAG_APPEND)
902
		flags |= FS_APPEND_FL;
L
Linus Torvalds 已提交
903
	if (di_flags & XFS_DIFLAG_SYNC)
904
		flags |= FS_SYNC_FL;
L
Linus Torvalds 已提交
905
	if (di_flags & XFS_DIFLAG_NOATIME)
906
		flags |= FS_NOATIME_FL;
L
Linus Torvalds 已提交
907
	if (di_flags & XFS_DIFLAG_NODUMP)
908
		flags |= FS_NODUMP_FL;
L
Linus Torvalds 已提交
909 910 911
	return flags;
}

912 913 914 915 916 917 918 919
STATIC int
xfs_ioc_fsgetxattr(
	xfs_inode_t		*ip,
	int			attr,
	void			__user *arg)
{
	struct fsxattr		fa;

920 921
	memset(&fa, 0, sizeof(struct fsxattr));

922 923 924
	xfs_ilock(ip, XFS_ILOCK_SHARED);
	fa.fsx_xflags = xfs_ip2xflags(ip);
	fa.fsx_extsize = ip->i_d.di_extsize << ip->i_mount->m_sb.sb_blocklog;
925
	fa.fsx_projid = xfs_get_projid(ip);
926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949

	if (attr) {
		if (ip->i_afp) {
			if (ip->i_afp->if_flags & XFS_IFEXTENTS)
				fa.fsx_nextents = ip->i_afp->if_bytes /
							sizeof(xfs_bmbt_rec_t);
			else
				fa.fsx_nextents = ip->i_d.di_anextents;
		} else
			fa.fsx_nextents = 0;
	} else {
		if (ip->i_df.if_flags & XFS_IFEXTENTS)
			fa.fsx_nextents = ip->i_df.if_bytes /
						sizeof(xfs_bmbt_rec_t);
		else
			fa.fsx_nextents = ip->i_d.di_nextents;
	}
	xfs_iunlock(ip, XFS_ILOCK_SHARED);

	if (copy_to_user(arg, &fa, sizeof(fa)))
		return -EFAULT;
	return 0;
}

950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972
STATIC void
xfs_set_diflags(
	struct xfs_inode	*ip,
	unsigned int		xflags)
{
	unsigned int		di_flags;

	/* can't set PREALLOC this way, just preserve it */
	di_flags = (ip->i_d.di_flags & XFS_DIFLAG_PREALLOC);
	if (xflags & XFS_XFLAG_IMMUTABLE)
		di_flags |= XFS_DIFLAG_IMMUTABLE;
	if (xflags & XFS_XFLAG_APPEND)
		di_flags |= XFS_DIFLAG_APPEND;
	if (xflags & XFS_XFLAG_SYNC)
		di_flags |= XFS_DIFLAG_SYNC;
	if (xflags & XFS_XFLAG_NOATIME)
		di_flags |= XFS_DIFLAG_NOATIME;
	if (xflags & XFS_XFLAG_NODUMP)
		di_flags |= XFS_DIFLAG_NODUMP;
	if (xflags & XFS_XFLAG_NODEFRAG)
		di_flags |= XFS_DIFLAG_NODEFRAG;
	if (xflags & XFS_XFLAG_FILESTREAM)
		di_flags |= XFS_DIFLAG_FILESTREAM;
973
	if (S_ISDIR(ip->i_d.di_mode)) {
974 975 976 977 978 979
		if (xflags & XFS_XFLAG_RTINHERIT)
			di_flags |= XFS_DIFLAG_RTINHERIT;
		if (xflags & XFS_XFLAG_NOSYMLINKS)
			di_flags |= XFS_DIFLAG_NOSYMLINKS;
		if (xflags & XFS_XFLAG_EXTSZINHERIT)
			di_flags |= XFS_DIFLAG_EXTSZINHERIT;
980 981
		if (xflags & XFS_XFLAG_PROJINHERIT)
			di_flags |= XFS_DIFLAG_PROJINHERIT;
982
	} else if (S_ISREG(ip->i_d.di_mode)) {
983 984 985 986 987 988 989 990 991
		if (xflags & XFS_XFLAG_REALTIME)
			di_flags |= XFS_DIFLAG_REALTIME;
		if (xflags & XFS_XFLAG_EXTSIZE)
			di_flags |= XFS_DIFLAG_EXTSIZE;
	}

	ip->i_d.di_flags = di_flags;
}

992 993 994 995
STATIC void
xfs_diflags_to_linux(
	struct xfs_inode	*ip)
{
996
	struct inode		*inode = VFS_I(ip);
997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015
	unsigned int		xflags = xfs_ip2xflags(ip);

	if (xflags & XFS_XFLAG_IMMUTABLE)
		inode->i_flags |= S_IMMUTABLE;
	else
		inode->i_flags &= ~S_IMMUTABLE;
	if (xflags & XFS_XFLAG_APPEND)
		inode->i_flags |= S_APPEND;
	else
		inode->i_flags &= ~S_APPEND;
	if (xflags & XFS_XFLAG_SYNC)
		inode->i_flags |= S_SYNC;
	else
		inode->i_flags &= ~S_SYNC;
	if (xflags & XFS_XFLAG_NOATIME)
		inode->i_flags |= S_NOATIME;
	else
		inode->i_flags &= ~S_NOATIME;
}
1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030

#define FSX_PROJID	1
#define FSX_EXTSIZE	2
#define FSX_XFLAGS	4
#define FSX_NONBLOCK	8

STATIC int
xfs_ioctl_setattr(
	xfs_inode_t		*ip,
	struct fsxattr		*fa,
	int			mask)
{
	struct xfs_mount	*mp = ip->i_mount;
	struct xfs_trans	*tp;
	unsigned int		lock_flags = 0;
C
Christoph Hellwig 已提交
1031
	struct xfs_dquot	*udqp = NULL;
1032
	struct xfs_dquot	*pdqp = NULL;
1033 1034 1035
	struct xfs_dquot	*olddquot = NULL;
	int			code;

C
Christoph Hellwig 已提交
1036
	trace_xfs_ioctl_setattr(ip);
1037 1038

	if (mp->m_flags & XFS_MOUNT_RDONLY)
D
Dave Chinner 已提交
1039
		return -EROFS;
1040
	if (XFS_FORCED_SHUTDOWN(mp))
D
Dave Chinner 已提交
1041
		return -EIO;
1042

1043
	/*
1044
	 * Disallow 32bit project ids when projid32bit feature is not enabled.
1045
	 */
1046 1047
	if ((mask & FSX_PROJID) && (fa->fsx_projid > (__uint16_t)-1) &&
			!xfs_sb_version_hasprojid32bit(&ip->i_mount->m_sb))
D
Dave Chinner 已提交
1048
		return -EINVAL;
1049

1050 1051 1052 1053 1054 1055 1056 1057 1058
	/*
	 * If disk quotas is on, we make sure that the dquots do exist on disk,
	 * before we start any other transactions. Trying to do this later
	 * is messy. We don't care to take a readlock to look at the ids
	 * in inode here, because we can't hold it across the trans_reserve.
	 * If the IDs do change before we take the ilock, we're covered
	 * because the i_*dquot fields will get updated anyway.
	 */
	if (XFS_IS_QUOTA_ON(mp) && (mask & FSX_PROJID)) {
C
Christoph Hellwig 已提交
1059
		code = xfs_qm_vop_dqalloc(ip, ip->i_d.di_uid,
1060
					 ip->i_d.di_gid, fa->fsx_projid,
1061
					 XFS_QMOPT_PQUOTA, &udqp, NULL, &pdqp);
1062 1063 1064 1065 1066 1067 1068 1069 1070
		if (code)
			return code;
	}

	/*
	 * For the other attributes, we acquire the inode lock and
	 * first do an error checking pass.
	 */
	tp = xfs_trans_alloc(mp, XFS_TRANS_SETATTR_NOT_SIZE);
1071
	code = xfs_trans_reserve(tp, &M_RES(mp)->tr_ichange, 0, 0);
1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084
	if (code)
		goto error_return;

	lock_flags = XFS_ILOCK_EXCL;
	xfs_ilock(ip, lock_flags);

	/*
	 * CAP_FOWNER overrides the following restrictions:
	 *
	 * The user ID of the calling process must be equal
	 * to the file owner ID, except in cases where the
	 * CAP_FSETID capability is applicable.
	 */
1085
	if (!inode_owner_or_capable(VFS_I(ip))) {
D
Dave Chinner 已提交
1086
		code = -EPERM;
1087 1088 1089 1090 1091
		goto error_return;
	}

	/*
	 * Do a quota reservation only if projid is actually going to change.
1092 1093
	 * Only allow changing of projid from init_user_ns since it is a
	 * non user namespace aware identifier.
1094 1095
	 */
	if (mask & FSX_PROJID) {
1096
		if (current_user_ns() != &init_user_ns) {
D
Dave Chinner 已提交
1097
			code = -EINVAL;
1098 1099 1100
			goto error_return;
		}

C
Christoph Hellwig 已提交
1101 1102
		if (XFS_IS_QUOTA_RUNNING(mp) &&
		    XFS_IS_PQUOTA_ON(mp) &&
1103
		    xfs_get_projid(ip) != fa->fsx_projid) {
1104
			ASSERT(tp);
1105 1106
			code = xfs_qm_vop_chown_reserve(tp, ip, udqp, NULL,
						pdqp, capable(CAP_FOWNER) ?
1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119
						XFS_QMOPT_FORCE_RES : 0);
			if (code)	/* out of quota */
				goto error_return;
		}
	}

	if (mask & FSX_EXTSIZE) {
		/*
		 * Can't change extent size if any extents are allocated.
		 */
		if (ip->i_d.di_nextents &&
		    ((ip->i_d.di_extsize << mp->m_sb.sb_blocklog) !=
		     fa->fsx_extsize)) {
D
Dave Chinner 已提交
1120
			code = -EINVAL;	/* EFBIG? */
1121 1122 1123 1124 1125
			goto error_return;
		}

		/*
		 * Extent size must be a multiple of the appropriate block
1126 1127 1128 1129 1130 1131
		 * size, if set at all. It must also be smaller than the
		 * maximum extent size supported by the filesystem.
		 *
		 * Also, for non-realtime files, limit the extent size hint to
		 * half the size of the AGs in the filesystem so alignment
		 * doesn't result in extents larger than an AG.
1132 1133
		 */
		if (fa->fsx_extsize != 0) {
1134 1135 1136 1137 1138
			xfs_extlen_t    size;
			xfs_fsblock_t   extsize_fsb;

			extsize_fsb = XFS_B_TO_FSB(mp, fa->fsx_extsize);
			if (extsize_fsb > MAXEXTLEN) {
D
Dave Chinner 已提交
1139
				code = -EINVAL;
1140 1141
				goto error_return;
			}
1142 1143 1144 1145 1146 1147 1148 1149

			if (XFS_IS_REALTIME_INODE(ip) ||
			    ((mask & FSX_XFLAGS) &&
			    (fa->fsx_xflags & XFS_XFLAG_REALTIME))) {
				size = mp->m_sb.sb_rextsize <<
				       mp->m_sb.sb_blocklog;
			} else {
				size = mp->m_sb.sb_blocksize;
1150
				if (extsize_fsb > mp->m_sb.sb_agblocks / 2) {
D
Dave Chinner 已提交
1151
					code = -EINVAL;
1152 1153
					goto error_return;
				}
1154 1155 1156
			}

			if (fa->fsx_extsize % size) {
D
Dave Chinner 已提交
1157
				code = -EINVAL;
1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170
				goto error_return;
			}
		}
	}


	if (mask & FSX_XFLAGS) {
		/*
		 * Can't change realtime flag if any extents are allocated.
		 */
		if ((ip->i_d.di_nextents || ip->i_delayed_blks) &&
		    (XFS_IS_REALTIME_INODE(ip)) !=
		    (fa->fsx_xflags & XFS_XFLAG_REALTIME)) {
D
Dave Chinner 已提交
1171
			code = -EINVAL;	/* EFBIG? */
1172 1173 1174 1175 1176 1177 1178 1179 1180 1181
			goto error_return;
		}

		/*
		 * If realtime flag is set then must have realtime data.
		 */
		if ((fa->fsx_xflags & XFS_XFLAG_REALTIME)) {
			if ((mp->m_sb.sb_rblocks == 0) ||
			    (mp->m_sb.sb_rextsize == 0) ||
			    (ip->i_d.di_extsize % mp->m_sb.sb_rextsize)) {
D
Dave Chinner 已提交
1182
				code = -EINVAL;
1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195
				goto error_return;
			}
		}

		/*
		 * Can't modify an immutable/append-only file unless
		 * we have appropriate permission.
		 */
		if ((ip->i_d.di_flags &
				(XFS_DIFLAG_IMMUTABLE|XFS_DIFLAG_APPEND) ||
		     (fa->fsx_xflags &
				(XFS_XFLAG_IMMUTABLE | XFS_XFLAG_APPEND))) &&
		    !capable(CAP_LINUX_IMMUTABLE)) {
D
Dave Chinner 已提交
1196
			code = -EPERM;
1197 1198 1199 1200
			goto error_return;
		}
	}

1201
	xfs_trans_ijoin(tp, ip, 0);
1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213

	/*
	 * Change file ownership.  Must be the owner or privileged.
	 */
	if (mask & FSX_PROJID) {
		/*
		 * CAP_FSETID overrides the following restrictions:
		 *
		 * The set-user-ID and set-group-ID bits of a file will be
		 * cleared upon successful return from chown()
		 */
		if ((ip->i_d.di_mode & (S_ISUID|S_ISGID)) &&
1214
		    !capable_wrt_inode_uidgid(VFS_I(ip), CAP_FSETID))
1215 1216 1217 1218 1219 1220
			ip->i_d.di_mode &= ~(S_ISUID|S_ISGID);

		/*
		 * Change the ownerships and register quota modifications
		 * in the transaction.
		 */
1221
		if (xfs_get_projid(ip) != fa->fsx_projid) {
C
Christoph Hellwig 已提交
1222 1223
			if (XFS_IS_QUOTA_RUNNING(mp) && XFS_IS_PQUOTA_ON(mp)) {
				olddquot = xfs_qm_vop_chown(tp, ip,
1224
							&ip->i_pdquot, pdqp);
1225
			}
1226
			ASSERT(ip->i_d.di_version > 1);
1227
			xfs_set_projid(ip, fa->fsx_projid);
1228 1229 1230 1231
		}

	}

1232
	if (mask & FSX_XFLAGS) {
1233
		xfs_set_diflags(ip, fa->fsx_xflags);
1234 1235
		xfs_diflags_to_linux(ip);
	}
1236

1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250
	/*
	 * Only set the extent size hint if we've already determined that the
	 * extent size hint should be set on the inode. If no extent size flags
	 * are set on the inode then unconditionally clear the extent size hint.
	 */
	if (mask & FSX_EXTSIZE) {
		int	extsize = 0;

		if (ip->i_d.di_flags &
				(XFS_DIFLAG_EXTSIZE | XFS_DIFLAG_EXTSZINHERIT))
			extsize = fa->fsx_extsize >> mp->m_sb.sb_blocklog;
		ip->i_d.di_extsize = extsize;
	}

1251
	xfs_trans_ichgtime(tp, ip, XFS_ICHGTIME_CHG);
1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273
	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);

	XFS_STATS_INC(xs_ig_attrchg);

	/*
	 * If this is a synchronous mount, make sure that the
	 * transaction goes to disk before returning to the user.
	 * This is slightly sub-optimal in that truncates require
	 * two sync transactions instead of one for wsync filesystems.
	 * One for the truncate and one for the timestamps since we
	 * don't want to change the timestamps unless we're sure the
	 * truncate worked.  Truncates are less than 1% of the laddis
	 * mix so this probably isn't worth the trouble to optimize.
	 */
	if (mp->m_flags & XFS_MOUNT_WSYNC)
		xfs_trans_set_sync(tp);
	code = xfs_trans_commit(tp, 0);
	xfs_iunlock(ip, lock_flags);

	/*
	 * Release any dquot(s) the inode had kept before chown.
	 */
C
Christoph Hellwig 已提交
1274 1275
	xfs_qm_dqrele(olddquot);
	xfs_qm_dqrele(udqp);
1276
	xfs_qm_dqrele(pdqp);
1277

C
Christoph Hellwig 已提交
1278
	return code;
1279 1280

 error_return:
C
Christoph Hellwig 已提交
1281
	xfs_qm_dqrele(udqp);
1282
	xfs_qm_dqrele(pdqp);
1283 1284 1285 1286 1287 1288
	xfs_trans_cancel(tp, 0);
	if (lock_flags)
		xfs_iunlock(ip, lock_flags);
	return code;
}

L
Linus Torvalds 已提交
1289
STATIC int
L
Lachlan McIlroy 已提交
1290
xfs_ioc_fssetxattr(
L
Linus Torvalds 已提交
1291 1292 1293 1294 1295
	xfs_inode_t		*ip,
	struct file		*filp,
	void			__user *arg)
{
	struct fsxattr		fa;
1296
	unsigned int		mask;
J
Jan Kara 已提交
1297
	int error;
L
Lachlan McIlroy 已提交
1298 1299 1300

	if (copy_from_user(&fa, arg, sizeof(fa)))
		return -EFAULT;
L
Linus Torvalds 已提交
1301

1302
	mask = FSX_XFLAGS | FSX_EXTSIZE | FSX_PROJID;
L
Lachlan McIlroy 已提交
1303
	if (filp->f_flags & (O_NDELAY|O_NONBLOCK))
1304
		mask |= FSX_NONBLOCK;
L
Linus Torvalds 已提交
1305

J
Jan Kara 已提交
1306 1307 1308 1309 1310
	error = mnt_want_write_file(filp);
	if (error)
		return error;
	error = xfs_ioctl_setattr(ip, &fa, mask);
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1311
	return error;
L
Lachlan McIlroy 已提交
1312
}
L
Linus Torvalds 已提交
1313

L
Lachlan McIlroy 已提交
1314 1315 1316 1317 1318 1319
STATIC int
xfs_ioc_getxflags(
	xfs_inode_t		*ip,
	void			__user *arg)
{
	unsigned int		flags;
L
Linus Torvalds 已提交
1320

L
Lachlan McIlroy 已提交
1321 1322 1323 1324 1325
	flags = xfs_di2lxflags(ip->i_d.di_flags);
	if (copy_to_user(arg, &flags, sizeof(flags)))
		return -EFAULT;
	return 0;
}
L
Linus Torvalds 已提交
1326

L
Lachlan McIlroy 已提交
1327 1328 1329 1330 1331 1332
STATIC int
xfs_ioc_setxflags(
	xfs_inode_t		*ip,
	struct file		*filp,
	void			__user *arg)
{
1333
	struct fsxattr		fa;
L
Lachlan McIlroy 已提交
1334
	unsigned int		flags;
1335
	unsigned int		mask;
J
Jan Kara 已提交
1336
	int error;
L
Linus Torvalds 已提交
1337

L
Lachlan McIlroy 已提交
1338 1339
	if (copy_from_user(&flags, arg, sizeof(flags)))
		return -EFAULT;
L
Linus Torvalds 已提交
1340

L
Lachlan McIlroy 已提交
1341 1342 1343 1344
	if (flags & ~(FS_IMMUTABLE_FL | FS_APPEND_FL | \
		      FS_NOATIME_FL | FS_NODUMP_FL | \
		      FS_SYNC_FL))
		return -EOPNOTSUPP;
L
Linus Torvalds 已提交
1345

1346
	mask = FSX_XFLAGS;
L
Lachlan McIlroy 已提交
1347
	if (filp->f_flags & (O_NDELAY|O_NONBLOCK))
1348 1349
		mask |= FSX_NONBLOCK;
	fa.fsx_xflags = xfs_merge_ioc_xflags(flags, xfs_ip2xflags(ip));
L
Linus Torvalds 已提交
1350

J
Jan Kara 已提交
1351 1352 1353 1354 1355
	error = mnt_want_write_file(filp);
	if (error)
		return error;
	error = xfs_ioctl_setattr(ip, &fa, mask);
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1356
	return error;
L
Linus Torvalds 已提交
1357 1358
}

1359 1360 1361
STATIC int
xfs_getbmap_format(void **ap, struct getbmapx *bmv, int *full)
{
1362
	struct getbmap __user	*base = (struct getbmap __user *)*ap;
1363 1364 1365

	/* copy only getbmap portion (not getbmapx) */
	if (copy_to_user(base, bmv, sizeof(struct getbmap)))
D
Dave Chinner 已提交
1366
		return -EFAULT;
1367 1368 1369 1370 1371

	*ap += sizeof(struct getbmap);
	return 0;
}

L
Linus Torvalds 已提交
1372 1373
STATIC int
xfs_ioc_getbmap(
1374
	struct xfs_inode	*ip,
L
Linus Torvalds 已提交
1375 1376 1377 1378
	int			ioflags,
	unsigned int		cmd,
	void			__user *arg)
{
1379
	struct getbmapx		bmx;
L
Linus Torvalds 已提交
1380 1381
	int			error;

1382
	if (copy_from_user(&bmx, arg, sizeof(struct getbmapx)))
E
Eric Sandeen 已提交
1383
		return -EFAULT;
L
Linus Torvalds 已提交
1384

1385
	if (bmx.bmv_count < 2)
E
Eric Sandeen 已提交
1386
		return -EINVAL;
L
Linus Torvalds 已提交
1387

1388
	bmx.bmv_iflags = (cmd == XFS_IOC_GETBMAPA ? BMV_IF_ATTRFORK : 0);
D
Dave Chinner 已提交
1389
	if (ioflags & XFS_IO_INVIS)
1390
		bmx.bmv_iflags |= BMV_IF_NO_DMAPI_READ;
L
Linus Torvalds 已提交
1391

1392
	error = xfs_getbmap(ip, &bmx, xfs_getbmap_format,
1393
			    (__force struct getbmap *)arg+1);
L
Linus Torvalds 已提交
1394
	if (error)
D
Dave Chinner 已提交
1395
		return error;
L
Linus Torvalds 已提交
1396

1397 1398
	/* copy back header - only size of getbmap */
	if (copy_to_user(arg, &bmx, sizeof(struct getbmap)))
E
Eric Sandeen 已提交
1399
		return -EFAULT;
L
Linus Torvalds 已提交
1400 1401 1402
	return 0;
}

1403 1404 1405
STATIC int
xfs_getbmapx_format(void **ap, struct getbmapx *bmv, int *full)
{
1406
	struct getbmapx __user	*base = (struct getbmapx __user *)*ap;
1407 1408

	if (copy_to_user(base, bmv, sizeof(struct getbmapx)))
D
Dave Chinner 已提交
1409
		return -EFAULT;
1410 1411 1412 1413 1414

	*ap += sizeof(struct getbmapx);
	return 0;
}

L
Linus Torvalds 已提交
1415 1416
STATIC int
xfs_ioc_getbmapx(
1417
	struct xfs_inode	*ip,
L
Linus Torvalds 已提交
1418 1419 1420 1421 1422 1423
	void			__user *arg)
{
	struct getbmapx		bmx;
	int			error;

	if (copy_from_user(&bmx, arg, sizeof(bmx)))
E
Eric Sandeen 已提交
1424
		return -EFAULT;
L
Linus Torvalds 已提交
1425 1426

	if (bmx.bmv_count < 2)
E
Eric Sandeen 已提交
1427
		return -EINVAL;
L
Linus Torvalds 已提交
1428

1429
	if (bmx.bmv_iflags & (~BMV_IF_VALID))
E
Eric Sandeen 已提交
1430
		return -EINVAL;
L
Linus Torvalds 已提交
1431

1432
	error = xfs_getbmap(ip, &bmx, xfs_getbmapx_format,
1433
			    (__force struct getbmapx *)arg+1);
L
Linus Torvalds 已提交
1434
	if (error)
D
Dave Chinner 已提交
1435
		return error;
L
Linus Torvalds 已提交
1436

1437 1438
	/* copy back header */
	if (copy_to_user(arg, &bmx, sizeof(struct getbmapx)))
E
Eric Sandeen 已提交
1439
		return -EFAULT;
L
Linus Torvalds 已提交
1440 1441 1442

	return 0;
}
L
Lachlan McIlroy 已提交
1443

D
Dave Chinner 已提交
1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454
int
xfs_ioc_swapext(
	xfs_swapext_t	*sxp)
{
	xfs_inode_t     *ip, *tip;
	struct fd	f, tmp;
	int		error = 0;

	/* Pull information for the target fd */
	f = fdget((int)sxp->sx_fdtarget);
	if (!f.file) {
D
Dave Chinner 已提交
1455
		error = -EINVAL;
D
Dave Chinner 已提交
1456 1457 1458 1459 1460 1461
		goto out;
	}

	if (!(f.file->f_mode & FMODE_WRITE) ||
	    !(f.file->f_mode & FMODE_READ) ||
	    (f.file->f_flags & O_APPEND)) {
D
Dave Chinner 已提交
1462
		error = -EBADF;
D
Dave Chinner 已提交
1463 1464 1465 1466 1467
		goto out_put_file;
	}

	tmp = fdget((int)sxp->sx_fdtmp);
	if (!tmp.file) {
D
Dave Chinner 已提交
1468
		error = -EINVAL;
D
Dave Chinner 已提交
1469 1470 1471 1472 1473 1474
		goto out_put_file;
	}

	if (!(tmp.file->f_mode & FMODE_WRITE) ||
	    !(tmp.file->f_mode & FMODE_READ) ||
	    (tmp.file->f_flags & O_APPEND)) {
D
Dave Chinner 已提交
1475
		error = -EBADF;
D
Dave Chinner 已提交
1476 1477 1478 1479 1480
		goto out_put_tmp_file;
	}

	if (IS_SWAPFILE(file_inode(f.file)) ||
	    IS_SWAPFILE(file_inode(tmp.file))) {
D
Dave Chinner 已提交
1481
		error = -EINVAL;
D
Dave Chinner 已提交
1482 1483 1484 1485 1486 1487 1488
		goto out_put_tmp_file;
	}

	ip = XFS_I(file_inode(f.file));
	tip = XFS_I(file_inode(tmp.file));

	if (ip->i_mount != tip->i_mount) {
D
Dave Chinner 已提交
1489
		error = -EINVAL;
D
Dave Chinner 已提交
1490 1491 1492 1493
		goto out_put_tmp_file;
	}

	if (ip->i_ino == tip->i_ino) {
D
Dave Chinner 已提交
1494
		error = -EINVAL;
D
Dave Chinner 已提交
1495 1496 1497 1498
		goto out_put_tmp_file;
	}

	if (XFS_FORCED_SHUTDOWN(ip->i_mount)) {
D
Dave Chinner 已提交
1499
		error = -EIO;
D
Dave Chinner 已提交
1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512
		goto out_put_tmp_file;
	}

	error = xfs_swap_extents(ip, tip, sxp);

 out_put_tmp_file:
	fdput(tmp);
 out_put_file:
	fdput(f);
 out:
	return error;
}

1513 1514 1515 1516 1517 1518 1519 1520
/*
 * Note: some of the ioctl's return positive numbers as a
 * byte count indicating success, such as readlink_by_handle.
 * So we don't "sign flip" like most other routines.  This means
 * true errors need to be returned as a negative value.
 */
long
xfs_file_ioctl(
L
Lachlan McIlroy 已提交
1521 1522
	struct file		*filp,
	unsigned int		cmd,
1523
	unsigned long		p)
L
Lachlan McIlroy 已提交
1524
{
A
Al Viro 已提交
1525
	struct inode		*inode = file_inode(filp);
1526 1527 1528 1529
	struct xfs_inode	*ip = XFS_I(inode);
	struct xfs_mount	*mp = ip->i_mount;
	void			__user *arg = (void __user *)p;
	int			ioflags = 0;
L
Lachlan McIlroy 已提交
1530 1531
	int			error;

1532
	if (filp->f_mode & FMODE_NOCMTIME)
D
Dave Chinner 已提交
1533
		ioflags |= XFS_IO_INVIS;
L
Lachlan McIlroy 已提交
1534

C
Christoph Hellwig 已提交
1535
	trace_xfs_file_ioctl(ip);
1536 1537

	switch (cmd) {
C
Christoph Hellwig 已提交
1538 1539
	case FITRIM:
		return xfs_ioc_trim(mp, arg);
L
Lachlan McIlroy 已提交
1540 1541 1542 1543 1544 1545 1546
	case XFS_IOC_ALLOCSP:
	case XFS_IOC_FREESP:
	case XFS_IOC_RESVSP:
	case XFS_IOC_UNRESVSP:
	case XFS_IOC_ALLOCSP64:
	case XFS_IOC_FREESP64:
	case XFS_IOC_RESVSP64:
D
Dave Chinner 已提交
1547 1548
	case XFS_IOC_UNRESVSP64:
	case XFS_IOC_ZERO_RANGE: {
1549
		xfs_flock64_t		bf;
L
Lachlan McIlroy 已提交
1550

1551
		if (copy_from_user(&bf, arg, sizeof(bf)))
E
Eric Sandeen 已提交
1552
			return -EFAULT;
1553 1554
		return xfs_ioc_space(ip, inode, filp, ioflags, cmd, &bf);
	}
L
Lachlan McIlroy 已提交
1555 1556 1557 1558 1559 1560
	case XFS_IOC_DIOINFO: {
		struct dioattr	da;
		xfs_buftarg_t	*target =
			XFS_IS_REALTIME_INODE(ip) ?
			mp->m_rtdev_targp : mp->m_ddev_targp;

1561
		da.d_mem =  da.d_miniosz = target->bt_logical_sectorsize;
L
Lachlan McIlroy 已提交
1562 1563 1564
		da.d_maxiosz = INT_MAX & ~(da.d_miniosz - 1);

		if (copy_to_user(arg, &da, sizeof(da)))
E
Eric Sandeen 已提交
1565
			return -EFAULT;
L
Lachlan McIlroy 已提交
1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586
		return 0;
	}

	case XFS_IOC_FSBULKSTAT_SINGLE:
	case XFS_IOC_FSBULKSTAT:
	case XFS_IOC_FSINUMBERS:
		return xfs_ioc_bulkstat(mp, cmd, arg);

	case XFS_IOC_FSGEOMETRY_V1:
		return xfs_ioc_fsgeometry_v1(mp, arg);

	case XFS_IOC_FSGEOMETRY:
		return xfs_ioc_fsgeometry(mp, arg);

	case XFS_IOC_GETVERSION:
		return put_user(inode->i_generation, (int __user *)arg);

	case XFS_IOC_FSGETXATTR:
		return xfs_ioc_fsgetxattr(ip, 0, arg);
	case XFS_IOC_FSGETXATTRA:
		return xfs_ioc_fsgetxattr(ip, 1, arg);
L
Lachlan McIlroy 已提交
1587 1588
	case XFS_IOC_FSSETXATTR:
		return xfs_ioc_fssetxattr(ip, filp, arg);
L
Lachlan McIlroy 已提交
1589
	case XFS_IOC_GETXFLAGS:
L
Lachlan McIlroy 已提交
1590
		return xfs_ioc_getxflags(ip, arg);
L
Lachlan McIlroy 已提交
1591
	case XFS_IOC_SETXFLAGS:
L
Lachlan McIlroy 已提交
1592
		return xfs_ioc_setxflags(ip, filp, arg);
L
Lachlan McIlroy 已提交
1593 1594 1595 1596 1597

	case XFS_IOC_FSSETDM: {
		struct fsdmidata	dmi;

		if (copy_from_user(&dmi, arg, sizeof(dmi)))
E
Eric Sandeen 已提交
1598
			return -EFAULT;
L
Lachlan McIlroy 已提交
1599

J
Jan Kara 已提交
1600 1601 1602 1603
		error = mnt_want_write_file(filp);
		if (error)
			return error;

L
Lachlan McIlroy 已提交
1604 1605
		error = xfs_set_dmattrs(ip, dmi.fsd_dmevmask,
				dmi.fsd_dmstate);
J
Jan Kara 已提交
1606
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1607
		return error;
L
Lachlan McIlroy 已提交
1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618
	}

	case XFS_IOC_GETBMAP:
	case XFS_IOC_GETBMAPA:
		return xfs_ioc_getbmap(ip, ioflags, cmd, arg);

	case XFS_IOC_GETBMAPX:
		return xfs_ioc_getbmapx(ip, arg);

	case XFS_IOC_FD_TO_HANDLE:
	case XFS_IOC_PATH_TO_HANDLE:
1619 1620
	case XFS_IOC_PATH_TO_FSHANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
1621

1622
		if (copy_from_user(&hreq, arg, sizeof(hreq)))
E
Eric Sandeen 已提交
1623
			return -EFAULT;
1624 1625 1626 1627
		return xfs_find_handle(cmd, &hreq);
	}
	case XFS_IOC_OPEN_BY_HANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
1628

1629
		if (copy_from_user(&hreq, arg, sizeof(xfs_fsop_handlereq_t)))
E
Eric Sandeen 已提交
1630
			return -EFAULT;
1631
		return xfs_open_by_handle(filp, &hreq);
1632
	}
L
Lachlan McIlroy 已提交
1633
	case XFS_IOC_FSSETDM_BY_HANDLE:
1634
		return xfs_fssetdm_by_handle(filp, arg);
L
Lachlan McIlroy 已提交
1635

1636 1637
	case XFS_IOC_READLINK_BY_HANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
1638

1639
		if (copy_from_user(&hreq, arg, sizeof(xfs_fsop_handlereq_t)))
E
Eric Sandeen 已提交
1640
			return -EFAULT;
1641
		return xfs_readlink_by_handle(filp, &hreq);
1642
	}
L
Lachlan McIlroy 已提交
1643
	case XFS_IOC_ATTRLIST_BY_HANDLE:
1644
		return xfs_attrlist_by_handle(filp, arg);
L
Lachlan McIlroy 已提交
1645 1646

	case XFS_IOC_ATTRMULTI_BY_HANDLE:
1647
		return xfs_attrmulti_by_handle(filp, arg);
L
Lachlan McIlroy 已提交
1648 1649

	case XFS_IOC_SWAPEXT: {
1650 1651 1652
		struct xfs_swapext	sxp;

		if (copy_from_user(&sxp, arg, sizeof(xfs_swapext_t)))
E
Eric Sandeen 已提交
1653
			return -EFAULT;
J
Jan Kara 已提交
1654 1655 1656
		error = mnt_want_write_file(filp);
		if (error)
			return error;
D
Dave Chinner 已提交
1657
		error = xfs_ioc_swapext(&sxp);
J
Jan Kara 已提交
1658
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1659
		return error;
L
Lachlan McIlroy 已提交
1660 1661 1662 1663 1664 1665 1666
	}

	case XFS_IOC_FSCOUNTS: {
		xfs_fsop_counts_t out;

		error = xfs_fs_counts(mp, &out);
		if (error)
D
Dave Chinner 已提交
1667
			return error;
L
Lachlan McIlroy 已提交
1668 1669

		if (copy_to_user(arg, &out, sizeof(out)))
E
Eric Sandeen 已提交
1670
			return -EFAULT;
L
Lachlan McIlroy 已提交
1671 1672 1673 1674 1675 1676 1677 1678 1679 1680
		return 0;
	}

	case XFS_IOC_SET_RESBLKS: {
		xfs_fsop_resblks_t inout;
		__uint64_t	   in;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

E
Eric Sandeen 已提交
1681
		if (mp->m_flags & XFS_MOUNT_RDONLY)
E
Eric Sandeen 已提交
1682
			return -EROFS;
E
Eric Sandeen 已提交
1683

L
Lachlan McIlroy 已提交
1684
		if (copy_from_user(&inout, arg, sizeof(inout)))
E
Eric Sandeen 已提交
1685
			return -EFAULT;
L
Lachlan McIlroy 已提交
1686

J
Jan Kara 已提交
1687 1688 1689 1690
		error = mnt_want_write_file(filp);
		if (error)
			return error;

L
Lachlan McIlroy 已提交
1691 1692 1693
		/* input parameter is passed in resblks field of structure */
		in = inout.resblks;
		error = xfs_reserve_blocks(mp, &in, &inout);
J
Jan Kara 已提交
1694
		mnt_drop_write_file(filp);
L
Lachlan McIlroy 已提交
1695
		if (error)
D
Dave Chinner 已提交
1696
			return error;
L
Lachlan McIlroy 已提交
1697 1698

		if (copy_to_user(arg, &inout, sizeof(inout)))
E
Eric Sandeen 已提交
1699
			return -EFAULT;
L
Lachlan McIlroy 已提交
1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710
		return 0;
	}

	case XFS_IOC_GET_RESBLKS: {
		xfs_fsop_resblks_t out;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		error = xfs_reserve_blocks(mp, NULL, &out);
		if (error)
D
Dave Chinner 已提交
1711
			return error;
L
Lachlan McIlroy 已提交
1712 1713

		if (copy_to_user(arg, &out, sizeof(out)))
E
Eric Sandeen 已提交
1714
			return -EFAULT;
L
Lachlan McIlroy 已提交
1715 1716 1717 1718 1719 1720 1721 1722

		return 0;
	}

	case XFS_IOC_FSGROWFSDATA: {
		xfs_growfs_data_t in;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
1723
			return -EFAULT;
L
Lachlan McIlroy 已提交
1724

J
Jan Kara 已提交
1725 1726 1727
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
1728
		error = xfs_growfs_data(mp, &in);
J
Jan Kara 已提交
1729
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1730
		return error;
L
Lachlan McIlroy 已提交
1731 1732 1733 1734 1735 1736
	}

	case XFS_IOC_FSGROWFSLOG: {
		xfs_growfs_log_t in;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
1737
			return -EFAULT;
L
Lachlan McIlroy 已提交
1738

J
Jan Kara 已提交
1739 1740 1741
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
1742
		error = xfs_growfs_log(mp, &in);
J
Jan Kara 已提交
1743
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1744
		return error;
L
Lachlan McIlroy 已提交
1745 1746 1747 1748 1749 1750
	}

	case XFS_IOC_FSGROWFSRT: {
		xfs_growfs_rt_t in;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
1751
			return -EFAULT;
L
Lachlan McIlroy 已提交
1752

J
Jan Kara 已提交
1753 1754 1755
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
1756
		error = xfs_growfs_rt(mp, &in);
J
Jan Kara 已提交
1757
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1758
		return error;
L
Lachlan McIlroy 已提交
1759 1760 1761 1762 1763 1764 1765 1766 1767
	}

	case XFS_IOC_GOINGDOWN: {
		__uint32_t in;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		if (get_user(in, (__uint32_t __user *)arg))
E
Eric Sandeen 已提交
1768
			return -EFAULT;
L
Lachlan McIlroy 已提交
1769

D
Dave Chinner 已提交
1770
		return xfs_fs_goingdown(mp, in);
L
Lachlan McIlroy 已提交
1771 1772 1773 1774 1775 1776 1777 1778 1779
	}

	case XFS_IOC_ERROR_INJECTION: {
		xfs_error_injection_t in;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
1780
			return -EFAULT;
L
Lachlan McIlroy 已提交
1781

D
Dave Chinner 已提交
1782
		return xfs_errortag_add(in.errtag, mp);
L
Lachlan McIlroy 已提交
1783 1784 1785 1786 1787 1788
	}

	case XFS_IOC_ERROR_CLEARALL:
		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

D
Dave Chinner 已提交
1789
		return xfs_errortag_clearall(mp, 1);
L
Lachlan McIlroy 已提交
1790

1791
	case XFS_IOC_FREE_EOFBLOCKS: {
1792 1793
		struct xfs_fs_eofblocks eofb;
		struct xfs_eofblocks keofb;
1794

1795 1796 1797 1798
		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		if (mp->m_flags & XFS_MOUNT_RDONLY)
E
Eric Sandeen 已提交
1799
			return -EROFS;
1800

1801
		if (copy_from_user(&eofb, arg, sizeof(eofb)))
E
Eric Sandeen 已提交
1802
			return -EFAULT;
1803

1804 1805
		error = xfs_fs_eofblocks_from_user(&eofb, &keofb);
		if (error)
D
Dave Chinner 已提交
1806
			return error;
1807

D
Dave Chinner 已提交
1808
		return xfs_icache_free_eofblocks(mp, &keofb);
1809 1810
	}

L
Lachlan McIlroy 已提交
1811 1812 1813 1814
	default:
		return -ENOTTY;
	}
}