ioctl.c 27.9 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0
2
/*
3
 * linux/fs/ext4/ioctl.c
4 5 6 7 8 9 10 11 12 13 14
 *
 * Copyright (C) 1993, 1994, 1995
 * Remy Card (card@masi.ibp.fr)
 * Laboratoire MASI - Institut Blaise Pascal
 * Universite Pierre et Marie Curie (Paris VI)
 */

#include <linux/fs.h>
#include <linux/capability.h>
#include <linux/time.h>
#include <linux/compat.h>
15
#include <linux/mount.h>
16
#include <linux/file.h>
17
#include <linux/quotaops.h>
18
#include <linux/random.h>
19
#include <linux/uuid.h>
20
#include <linux/uaccess.h>
21
#include <linux/delay.h>
J
Jeff Layton 已提交
22
#include <linux/iversion.h>
23 24
#include "ext4_jbd2.h"
#include "ext4.h"
D
Darrick J. Wong 已提交
25 26 27
#include <linux/fsmap.h>
#include "fsmap.h"
#include <trace/events/ext4.h>
28

29 30 31 32 33 34 35 36 37 38 39 40 41 42 43
/**
 * Swap memory between @a and @b for @len bytes.
 *
 * @a:          pointer to first memory area
 * @b:          pointer to second memory area
 * @len:        number of bytes to swap
 *
 */
static void memswap(void *a, void *b, size_t len)
{
	unsigned char *ap, *bp;

	ap = (unsigned char *)a;
	bp = (unsigned char *)b;
	while (len-- > 0) {
F
Fabian Frederick 已提交
44
		swap(*ap, *bp);
45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69
		ap++;
		bp++;
	}
}

/**
 * Swap i_data and associated attributes between @inode1 and @inode2.
 * This function is used for the primary swap between inode1 and inode2
 * and also to revert this primary swap in case of errors.
 *
 * Therefore you have to make sure, that calling this method twice
 * will revert all changes.
 *
 * @inode1:     pointer to first inode
 * @inode2:     pointer to second inode
 */
static void swap_inode_data(struct inode *inode1, struct inode *inode2)
{
	loff_t isize;
	struct ext4_inode_info *ei1;
	struct ext4_inode_info *ei2;

	ei1 = EXT4_I(inode1);
	ei2 = EXT4_I(inode2);

70 71 72 73 74
	swap(inode1->i_version, inode2->i_version);
	swap(inode1->i_blocks, inode2->i_blocks);
	swap(inode1->i_bytes, inode2->i_bytes);
	swap(inode1->i_atime, inode2->i_atime);
	swap(inode1->i_mtime, inode2->i_mtime);
75 76

	memswap(ei1->i_data, ei2->i_data, sizeof(ei1->i_data));
77 78
	swap(ei1->i_flags, ei2->i_flags);
	swap(ei1->i_disksize, ei2->i_disksize);
79 80
	ext4_es_remove_extent(inode1, 0, EXT_MAX_BLOCKS);
	ext4_es_remove_extent(inode2, 0, EXT_MAX_BLOCKS);
81 82 83 84 85 86

	isize = i_size_read(inode1);
	i_size_write(inode1, i_size_read(inode2));
	i_size_write(inode2, isize);
}

T
Theodore Ts'o 已提交
87 88 89 90 91 92 93 94 95 96 97 98 99 100 101
static void reset_inode_seed(struct inode *inode)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	struct ext4_sb_info *sbi = EXT4_SB(inode->i_sb);
	__le32 inum = cpu_to_le32(inode->i_ino);
	__le32 gen = cpu_to_le32(inode->i_generation);
	__u32 csum;

	if (!ext4_has_metadata_csum(inode->i_sb))
		return;

	csum = ext4_chksum(sbi, sbi->s_csum_seed, (__u8 *)&inum, sizeof(inum));
	ei->i_csum_seed = ext4_chksum(sbi, csum, (__u8 *)&gen, sizeof(gen));
}

102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118
/**
 * Swap the information from the given @inode and the inode
 * EXT4_BOOT_LOADER_INO. It will basically swap i_data and all other
 * important fields of the inodes.
 *
 * @sb:         the super block of the filesystem
 * @inode:      the inode to swap with EXT4_BOOT_LOADER_INO
 *
 */
static long swap_inode_boot_loader(struct super_block *sb,
				struct inode *inode)
{
	handle_t *handle;
	int err;
	struct inode *inode_bl;
	struct ext4_inode_info *ei_bl;

T
Theodore Ts'o 已提交
119 120 121
	if (inode->i_nlink != 1 || !S_ISREG(inode->i_mode) ||
	    IS_SWAPFILE(inode) || IS_ENCRYPTED(inode) ||
	    ext4_has_inline_data(inode))
122
		return -EINVAL;
123

T
Theodore Ts'o 已提交
124 125
	if (IS_RDONLY(inode) || IS_APPEND(inode) || IS_IMMUTABLE(inode) ||
	    !inode_owner_or_capable(inode) || !capable(CAP_SYS_ADMIN))
126
		return -EPERM;
127

128
	inode_bl = ext4_iget(sb, EXT4_BOOT_LOADER_INO, EXT4_IGET_SPECIAL);
129 130
	if (IS_ERR(inode_bl))
		return PTR_ERR(inode_bl);
131 132 133 134 135 136 137
	ei_bl = EXT4_I(inode_bl);

	filemap_flush(inode->i_mapping);
	filemap_flush(inode_bl->i_mapping);

	/* Protect orig inodes against a truncate and make sure,
	 * that only 1 swap_inode_boot_loader is running. */
138
	lock_two_nondirectories(inode, inode_bl);
139 140 141 142 143

	/* Wait for all existing dio workers */
	inode_dio_wait(inode);
	inode_dio_wait(inode_bl);

T
Theodore Ts'o 已提交
144 145 146
	truncate_inode_pages(&inode->i_data, 0);
	truncate_inode_pages(&inode_bl->i_data, 0);

147 148 149
	handle = ext4_journal_start(inode_bl, EXT4_HT_MOVE_EXTENTS, 2);
	if (IS_ERR(handle)) {
		err = -EINVAL;
150
		goto journal_err_out;
151 152 153 154 155 156 157 158 159 160 161 162
	}

	/* Protect extent tree against block allocations via delalloc */
	ext4_double_down_write_data_sem(inode, inode_bl);

	if (inode_bl->i_nlink == 0) {
		/* this inode has never been used as a BOOT_LOADER */
		set_nlink(inode_bl, 1);
		i_uid_write(inode_bl, 0);
		i_gid_write(inode_bl, 0);
		inode_bl->i_flags = 0;
		ei_bl->i_flags = 0;
J
Jeff Layton 已提交
163
		inode_set_iversion(inode_bl, 1);
164 165
		i_size_write(inode_bl, 0);
		inode_bl->i_mode = S_IFREG;
166
		if (ext4_has_feature_extents(sb)) {
167 168 169 170 171 172 173 174
			ext4_set_inode_flag(inode_bl, EXT4_INODE_EXTENTS);
			ext4_ext_tree_init(handle, inode_bl);
		} else
			memset(ei_bl->i_data, 0, sizeof(ei_bl->i_data));
	}

	swap_inode_data(inode, inode_bl);

175
	inode->i_ctime = inode_bl->i_ctime = current_time(inode);
176

177 178
	inode->i_generation = prandom_u32();
	inode_bl->i_generation = prandom_u32();
T
Theodore Ts'o 已提交
179 180
	reset_inode_seed(inode);
	reset_inode_seed(inode_bl);
181 182 183 184 185 186 187 188 189 190

	ext4_discard_preallocations(inode);

	err = ext4_mark_inode_dirty(handle, inode);
	if (err < 0) {
		ext4_warning(inode->i_sb,
			"couldn't mark inode #%lu dirty (err %d)",
			inode->i_ino, err);
		/* Revert all changes: */
		swap_inode_data(inode, inode_bl);
T
Theodore Ts'o 已提交
191
		ext4_mark_inode_dirty(handle, inode);
192 193 194 195 196 197 198 199 200
	} else {
		err = ext4_mark_inode_dirty(handle, inode_bl);
		if (err < 0) {
			ext4_warning(inode_bl->i_sb,
				"couldn't mark inode #%lu dirty (err %d)",
				inode_bl->i_ino, err);
			/* Revert all changes: */
			swap_inode_data(inode, inode_bl);
			ext4_mark_inode_dirty(handle, inode);
T
Theodore Ts'o 已提交
201
			ext4_mark_inode_dirty(handle, inode_bl);
202 203 204 205 206
		}
	}
	ext4_journal_stop(handle);
	ext4_double_up_write_data_sem(inode, inode_bl);

207
journal_err_out:
208
	unlock_two_nondirectories(inode, inode_bl);
209 210 211 212
	iput(inode_bl);
	return err;
}

213
#ifdef CONFIG_EXT4_FS_ENCRYPTION
214 215 216 217 218 219 220 221 222
static int uuid_is_zero(__u8 u[16])
{
	int	i;

	for (i = 0; i < 16; i++)
		if (u[i])
			return 0;
	return 1;
}
223
#endif
224

225 226 227 228 229
static int ext4_ioctl_setflags(struct inode *inode,
			       unsigned int flags)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	handle_t *handle = NULL;
230
	int err = -EPERM, migrate = 0;
231 232 233 234 235
	struct ext4_iloc iloc;
	unsigned int oldflags, mask, i;
	unsigned int jflag;

	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
236
	if (ext4_is_quota_file(inode))
237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271
		goto flags_out;

	oldflags = ei->i_flags;

	/* The JOURNAL_DATA flag is modifiable only by root */
	jflag = flags & EXT4_JOURNAL_DATA_FL;

	/*
	 * The IMMUTABLE and APPEND_ONLY flags can only be changed by
	 * the relevant capability.
	 *
	 * This test looks nicer. Thanks to Pauline Middelink
	 */
	if ((flags ^ oldflags) & (EXT4_APPEND_FL | EXT4_IMMUTABLE_FL)) {
		if (!capable(CAP_LINUX_IMMUTABLE))
			goto flags_out;
	}

	/*
	 * The JOURNAL_DATA flag can only be changed by
	 * the relevant capability.
	 */
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		if (!capable(CAP_SYS_RESOURCE))
			goto flags_out;
	}
	if ((flags ^ oldflags) & EXT4_EXTENTS_FL)
		migrate = 1;

	if (flags & EXT4_EOFBLOCKS_FL) {
		/* we don't support adding EOFBLOCKS flag */
		if (!(oldflags & EXT4_EOFBLOCKS_FL)) {
			err = -EOPNOTSUPP;
			goto flags_out;
		}
272 273 274 275 276
	} else if (oldflags & EXT4_EOFBLOCKS_FL) {
		err = ext4_truncate(inode);
		if (err)
			goto flags_out;
	}
277 278 279 280 281 282 283 284 285 286 287 288 289 290 291

	handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
	if (IS_ERR(handle)) {
		err = PTR_ERR(handle);
		goto flags_out;
	}
	if (IS_SYNC(inode))
		ext4_handle_sync(handle);
	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto flags_err;

	for (i = 0, mask = 1; i < 32; i++, mask <<= 1) {
		if (!(mask & EXT4_FL_USER_MODIFIABLE))
			continue;
292 293 294
		/* These flags get special treatment later */
		if (mask == EXT4_JOURNAL_DATA_FL || mask == EXT4_EXTENTS_FL)
			continue;
295 296 297 298 299 300 301
		if (mask & flags)
			ext4_set_inode_flag(inode, i);
		else
			ext4_clear_inode_flag(inode, i);
	}

	ext4_set_inode_flags(inode);
302
	inode->i_ctime = current_time(inode);
303 304 305 306 307 308 309

	err = ext4_mark_iloc_dirty(handle, inode, &iloc);
flags_err:
	ext4_journal_stop(handle);
	if (err)
		goto flags_out;

310 311 312 313 314 315 316 317 318 319
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		/*
		 * Changes to the journaling mode can cause unsafe changes to
		 * S_DAX if we are using the DAX mount option.
		 */
		if (test_opt(inode->i_sb, DAX)) {
			err = -EBUSY;
			goto flags_out;
		}

320
		err = ext4_change_inode_journal_flag(inode, jflag);
321 322 323
		if (err)
			goto flags_out;
	}
324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345
	if (migrate) {
		if (flags & EXT4_EXTENTS_FL)
			err = ext4_ext_migrate(inode);
		else
			err = ext4_ind_migrate(inode);
	}

flags_out:
	return err;
}

#ifdef CONFIG_QUOTA
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	struct inode *inode = file_inode(filp);
	struct super_block *sb = inode->i_sb;
	struct ext4_inode_info *ei = EXT4_I(inode);
	int err, rc;
	handle_t *handle;
	kprojid_t kprojid;
	struct ext4_iloc iloc;
	struct ext4_inode *raw_inode;
346
	struct dquot *transfer_to[MAXQUOTAS] = { };
347

K
Kaho Ng 已提交
348
	if (!ext4_has_feature_project(sb)) {
349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364
		if (projid != EXT4_DEF_PROJID)
			return -EOPNOTSUPP;
		else
			return 0;
	}

	if (EXT4_INODE_SIZE(sb) <= EXT4_GOOD_OLD_INODE_SIZE)
		return -EOPNOTSUPP;

	kprojid = make_kprojid(&init_user_ns, (projid_t)projid);

	if (projid_eq(kprojid, EXT4_I(inode)->i_projid))
		return 0;

	err = -EPERM;
	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
365
	if (ext4_is_quota_file(inode))
366
		return err;
367 368 369

	err = ext4_get_inode_loc(inode, &iloc);
	if (err)
370
		return err;
371 372 373

	raw_inode = ext4_raw_inode(&iloc);
	if (!EXT4_FITS_IN_INODE(raw_inode, ei, i_projid)) {
374 375 376 377
		err = ext4_expand_extra_isize(inode,
					      EXT4_SB(sb)->s_want_extra_isize,
					      &iloc);
		if (err)
378
			return err;
379
	} else {
380 381 382
		brelse(iloc.bh);
	}

383 384 385
	err = dquot_initialize(inode);
	if (err)
		return err;
386 387 388 389

	handle = ext4_journal_start(inode, EXT4_HT_QUOTA,
		EXT4_QUOTA_INIT_BLOCKS(sb) +
		EXT4_QUOTA_DEL_BLOCKS(sb) + 3);
390 391
	if (IS_ERR(handle))
		return PTR_ERR(handle);
392 393 394 395 396

	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto out_stop;

397 398
	transfer_to[PRJQUOTA] = dqget(sb, make_kqid_projid(kprojid));
	if (!IS_ERR(transfer_to[PRJQUOTA])) {
399 400 401 402 403

		/* __dquot_transfer() calls back ext4_get_inode_usage() which
		 * counts xattr inode references.
		 */
		down_read(&EXT4_I(inode)->xattr_sem);
404
		err = __dquot_transfer(inode, transfer_to);
405
		up_read(&EXT4_I(inode)->xattr_sem);
406 407 408
		dqput(transfer_to[PRJQUOTA]);
		if (err)
			goto out_dirty;
409
	}
410

411
	EXT4_I(inode)->i_projid = kprojid;
412
	inode->i_ctime = current_time(inode);
413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449
out_dirty:
	rc = ext4_mark_iloc_dirty(handle, inode, &iloc);
	if (!err)
		err = rc;
out_stop:
	ext4_journal_stop(handle);
	return err;
}
#else
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	if (projid != EXT4_DEF_PROJID)
		return -EOPNOTSUPP;
	return 0;
}
#endif

/* Transfer internal flags to xflags */
static inline __u32 ext4_iflags_to_xflags(unsigned long iflags)
{
	__u32 xflags = 0;

	if (iflags & EXT4_SYNC_FL)
		xflags |= FS_XFLAG_SYNC;
	if (iflags & EXT4_IMMUTABLE_FL)
		xflags |= FS_XFLAG_IMMUTABLE;
	if (iflags & EXT4_APPEND_FL)
		xflags |= FS_XFLAG_APPEND;
	if (iflags & EXT4_NODUMP_FL)
		xflags |= FS_XFLAG_NODUMP;
	if (iflags & EXT4_NOATIME_FL)
		xflags |= FS_XFLAG_NOATIME;
	if (iflags & EXT4_PROJINHERIT_FL)
		xflags |= FS_XFLAG_PROJINHERIT;
	return xflags;
}

450 451 452 453
#define EXT4_SUPPORTED_FS_XFLAGS (FS_XFLAG_SYNC | FS_XFLAG_IMMUTABLE | \
				  FS_XFLAG_APPEND | FS_XFLAG_NODUMP | \
				  FS_XFLAG_NOATIME | FS_XFLAG_PROJINHERIT)

454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474
/* Transfer xflags flags to internal */
static inline unsigned long ext4_xflags_to_iflags(__u32 xflags)
{
	unsigned long iflags = 0;

	if (xflags & FS_XFLAG_SYNC)
		iflags |= EXT4_SYNC_FL;
	if (xflags & FS_XFLAG_IMMUTABLE)
		iflags |= EXT4_IMMUTABLE_FL;
	if (xflags & FS_XFLAG_APPEND)
		iflags |= EXT4_APPEND_FL;
	if (xflags & FS_XFLAG_NODUMP)
		iflags |= EXT4_NODUMP_FL;
	if (xflags & FS_XFLAG_NOATIME)
		iflags |= EXT4_NOATIME_FL;
	if (xflags & FS_XFLAG_PROJINHERIT)
		iflags |= EXT4_PROJINHERIT_FL;

	return iflags;
}

E
Eric Biggers 已提交
475
static int ext4_shutdown(struct super_block *sb, unsigned long arg)
476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492
{
	struct ext4_sb_info *sbi = EXT4_SB(sb);
	__u32 flags;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (get_user(flags, (__u32 __user *)arg))
		return -EFAULT;

	if (flags > EXT4_GOING_FLAGS_NOLOGFLUSH)
		return -EINVAL;

	if (ext4_forced_shutdown(sbi))
		return 0;

	ext4_msg(sb, KERN_ALERT, "shut down requested (%d)", flags);
493
	trace_ext4_shutdown(sb, flags);
494 495 496 497 498 499 500 501 502 503 504

	switch (flags) {
	case EXT4_GOING_FLAGS_DEFAULT:
		freeze_bdev(sb->s_bdev);
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		thaw_bdev(sb->s_bdev, sb);
		break;
	case EXT4_GOING_FLAGS_LOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal)) {
			(void) ext4_force_commit(sb);
505
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
506 507 508 509
		}
		break;
	case EXT4_GOING_FLAGS_NOLOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
510
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal))
511
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
512 513 514 515 516 517 518 519
		break;
	default:
		return -EINVAL;
	}
	clear_opt(sb, DISCARD);
	return 0;
}

D
Darrick J. Wong 已提交
520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603
struct getfsmap_info {
	struct super_block	*gi_sb;
	struct fsmap_head __user *gi_data;
	unsigned int		gi_idx;
	__u32			gi_last_flags;
};

static int ext4_getfsmap_format(struct ext4_fsmap *xfm, void *priv)
{
	struct getfsmap_info *info = priv;
	struct fsmap fm;

	trace_ext4_getfsmap_mapping(info->gi_sb, xfm);

	info->gi_last_flags = xfm->fmr_flags;
	ext4_fsmap_from_internal(info->gi_sb, &fm, xfm);
	if (copy_to_user(&info->gi_data->fmh_recs[info->gi_idx++], &fm,
			sizeof(struct fsmap)))
		return -EFAULT;

	return 0;
}

static int ext4_ioc_getfsmap(struct super_block *sb,
			     struct fsmap_head __user *arg)
{
	struct getfsmap_info info = {0};
	struct ext4_fsmap_head xhead = {0};
	struct fsmap_head head;
	bool aborted = false;
	int error;

	if (copy_from_user(&head, arg, sizeof(struct fsmap_head)))
		return -EFAULT;
	if (memchr_inv(head.fmh_reserved, 0, sizeof(head.fmh_reserved)) ||
	    memchr_inv(head.fmh_keys[0].fmr_reserved, 0,
		       sizeof(head.fmh_keys[0].fmr_reserved)) ||
	    memchr_inv(head.fmh_keys[1].fmr_reserved, 0,
		       sizeof(head.fmh_keys[1].fmr_reserved)))
		return -EINVAL;
	/*
	 * ext4 doesn't report file extents at all, so the only valid
	 * file offsets are the magic ones (all zeroes or all ones).
	 */
	if (head.fmh_keys[0].fmr_offset ||
	    (head.fmh_keys[1].fmr_offset != 0 &&
	     head.fmh_keys[1].fmr_offset != -1ULL))
		return -EINVAL;

	xhead.fmh_iflags = head.fmh_iflags;
	xhead.fmh_count = head.fmh_count;
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[0], &head.fmh_keys[0]);
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[1], &head.fmh_keys[1]);

	trace_ext4_getfsmap_low_key(sb, &xhead.fmh_keys[0]);
	trace_ext4_getfsmap_high_key(sb, &xhead.fmh_keys[1]);

	info.gi_sb = sb;
	info.gi_data = arg;
	error = ext4_getfsmap(sb, &xhead, ext4_getfsmap_format, &info);
	if (error == EXT4_QUERY_RANGE_ABORT) {
		error = 0;
		aborted = true;
	} else if (error)
		return error;

	/* If we didn't abort, set the "last" flag in the last fmx */
	if (!aborted && info.gi_idx) {
		info.gi_last_flags |= FMR_OF_LAST;
		if (copy_to_user(&info.gi_data->fmh_recs[info.gi_idx - 1].fmr_flags,
				 &info.gi_last_flags,
				 sizeof(info.gi_last_flags)))
			return -EFAULT;
	}

	/* copy back header */
	head.fmh_entries = xhead.fmh_entries;
	head.fmh_oflags = xhead.fmh_oflags;
	if (copy_to_user(arg, &head, sizeof(struct fsmap_head)))
		return -EFAULT;

	return 0;
}

604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641
static long ext4_ioctl_group_add(struct file *file,
				 struct ext4_new_group_data *input)
{
	struct super_block *sb = file_inode(file)->i_sb;
	int err, err2=0;

	err = ext4_resize_begin(sb);
	if (err)
		return err;

	if (ext4_has_feature_bigalloc(sb)) {
		ext4_msg(sb, KERN_ERR,
			 "Online resizing not supported with bigalloc");
		err = -EOPNOTSUPP;
		goto group_add_out;
	}

	err = mnt_want_write_file(file);
	if (err)
		goto group_add_out;

	err = ext4_group_add(sb, input);
	if (EXT4_SB(sb)->s_journal) {
		jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
		err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
		jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
	}
	if (err == 0)
		err = err2;
	mnt_drop_write_file(file);
	if (!err && ext4_has_group_desc_csum(sb) &&
	    test_opt(sb, INIT_INODE_TABLE))
		err = ext4_register_li_request(sb, input->group);
group_add_out:
	ext4_resize_end(sb);
	return err;
}

642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665
static int ext4_ioctl_check_project(struct inode *inode, struct fsxattr *fa)
{
	/*
	 * Project Quota ID state is only allowed to change from within the init
	 * namespace. Enforce that restriction only if we are trying to change
	 * the quota ID state. Everything else is allowed in user namespaces.
	 */
	if (current_user_ns() == &init_user_ns)
		return 0;

	if (__kprojid_val(EXT4_I(inode)->i_projid) != fa->fsx_projid)
		return -EINVAL;

	if (ext4_test_inode_flag(inode, EXT4_INODE_PROJINHERIT)) {
		if (!(fa->fsx_xflags & FS_XFLAG_PROJINHERIT))
			return -EINVAL;
	} else {
		if (fa->fsx_xflags & FS_XFLAG_PROJINHERIT)
			return -EINVAL;
	}

	return 0;
}

A
Andi Kleen 已提交
666
long ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
667
{
A
Al Viro 已提交
668
	struct inode *inode = file_inode(filp);
669
	struct super_block *sb = inode->i_sb;
670
	struct ext4_inode_info *ei = EXT4_I(inode);
671 672
	unsigned int flags;

673
	ext4_debug("cmd = %u, arg = %lu\n", cmd, arg);
674 675

	switch (cmd) {
D
Darrick J. Wong 已提交
676 677
	case FS_IOC_GETFSMAP:
		return ext4_ioc_getfsmap(sb, (void __user *)arg);
678 679
	case EXT4_IOC_GETFLAGS:
		flags = ei->i_flags & EXT4_FL_USER_VISIBLE;
680
		return put_user(flags, (int __user *) arg);
681
	case EXT4_IOC_SETFLAGS: {
682
		int err;
683

684
		if (!inode_owner_or_capable(inode))
685 686 687 688 689
			return -EACCES;

		if (get_user(flags, (int __user *) arg))
			return -EFAULT;

690 691 692 693 694 695 696 697 698 699 700 701
		if (flags & ~EXT4_FL_USER_VISIBLE)
			return -EOPNOTSUPP;
		/*
		 * chattr(1) grabs flags via GETFLAGS, modifies the result and
		 * passes that to SETFLAGS. So we cannot easily make SETFLAGS
		 * more restrictive than just silently masking off visible but
		 * not settable flags as we always did.
		 */
		flags &= EXT4_FL_USER_MODIFIABLE;
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

702
		err = mnt_want_write_file(filp);
703 704 705
		if (err)
			return err;

A
Al Viro 已提交
706
		inode_lock(inode);
707
		err = ext4_ioctl_setflags(inode, flags);
A
Al Viro 已提交
708
		inode_unlock(inode);
A
Al Viro 已提交
709
		mnt_drop_write_file(filp);
710 711
		return err;
	}
712 713
	case EXT4_IOC_GETVERSION:
	case EXT4_IOC_GETVERSION_OLD:
714
		return put_user(inode->i_generation, (int __user *) arg);
715 716
	case EXT4_IOC_SETVERSION:
	case EXT4_IOC_SETVERSION_OLD: {
717
		handle_t *handle;
718
		struct ext4_iloc iloc;
719 720 721
		__u32 generation;
		int err;

722
		if (!inode_owner_or_capable(inode))
723
			return -EPERM;
724

725
		if (ext4_has_metadata_csum(inode->i_sb)) {
726 727 728 729 730
			ext4_warning(sb, "Setting inode version is not "
				     "supported with metadata_csum enabled.");
			return -ENOTTY;
		}

731
		err = mnt_want_write_file(filp);
732 733 734 735 736 737
		if (err)
			return err;
		if (get_user(generation, (int __user *) arg)) {
			err = -EFAULT;
			goto setversion_out;
		}
738

A
Al Viro 已提交
739
		inode_lock(inode);
740
		handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
741 742
		if (IS_ERR(handle)) {
			err = PTR_ERR(handle);
743
			goto unlock_out;
744
		}
745
		err = ext4_reserve_inode_write(handle, inode, &iloc);
746
		if (err == 0) {
747
			inode->i_ctime = current_time(inode);
748
			inode->i_generation = generation;
749
			err = ext4_mark_iloc_dirty(handle, inode, &iloc);
750
		}
751
		ext4_journal_stop(handle);
752 753

unlock_out:
A
Al Viro 已提交
754
		inode_unlock(inode);
755
setversion_out:
A
Al Viro 已提交
756
		mnt_drop_write_file(filp);
757 758
		return err;
	}
759 760
	case EXT4_IOC_GROUP_EXTEND: {
		ext4_fsblk_t n_blocks_count;
761
		int err, err2=0;
762

763 764 765
		err = ext4_resize_begin(sb);
		if (err)
			return err;
766

767 768 769 770
		if (get_user(n_blocks_count, (__u32 __user *)arg)) {
			err = -EFAULT;
			goto group_extend_out;
		}
771

772
		if (ext4_has_feature_bigalloc(sb)) {
773 774
			ext4_msg(sb, KERN_ERR,
				 "Online resizing not supported with bigalloc");
775 776
			err = -EOPNOTSUPP;
			goto group_extend_out;
777 778
		}

779
		err = mnt_want_write_file(filp);
780
		if (err)
781
			goto group_extend_out;
782

783
		err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
784 785 786 787 788
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
789 790
		if (err == 0)
			err = err2;
A
Al Viro 已提交
791
		mnt_drop_write_file(filp);
792
group_extend_out:
793
		ext4_resize_end(sb);
794 795
		return err;
	}
796 797 798

	case EXT4_IOC_MOVE_EXT: {
		struct move_extent me;
799 800
		struct fd donor;
		int err;
801

802 803 804 805
		if (!(filp->f_mode & FMODE_READ) ||
		    !(filp->f_mode & FMODE_WRITE))
			return -EBADF;

806 807 808
		if (copy_from_user(&me,
			(struct move_extent __user *)arg, sizeof(me)))
			return -EFAULT;
809
		me.moved_len = 0;
810

811 812
		donor = fdget(me.donor_fd);
		if (!donor.file)
813 814
			return -EBADF;

815
		if (!(donor.file->f_mode & FMODE_WRITE)) {
816 817
			err = -EBADF;
			goto mext_out;
818 819
		}

820
		if (ext4_has_feature_bigalloc(sb)) {
821 822
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with bigalloc");
823 824
			err = -EOPNOTSUPP;
			goto mext_out;
825 826 827 828 829
		} else if (IS_DAX(inode)) {
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with DAX");
			err = -EOPNOTSUPP;
			goto mext_out;
830 831
		}

832
		err = mnt_want_write_file(filp);
833 834 835
		if (err)
			goto mext_out;

836
		err = ext4_move_extents(filp, donor.file, me.orig_start,
837
					me.donor_start, me.len, &me.moved_len);
A
Al Viro 已提交
838
		mnt_drop_write_file(filp);
839

840
		if (copy_to_user((struct move_extent __user *)arg,
841
				 &me, sizeof(me)))
842 843
			err = -EFAULT;
mext_out:
844
		fdput(donor);
845 846 847
		return err;
	}

848 849
	case EXT4_IOC_GROUP_ADD: {
		struct ext4_new_group_data input;
850

851
		if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
852 853
				sizeof(input)))
			return -EFAULT;
854

855
		return ext4_ioctl_group_add(filp, &input);
856 857
	}

858
	case EXT4_IOC_MIGRATE:
859 860
	{
		int err;
861
		if (!inode_owner_or_capable(inode))
862 863
			return -EACCES;

864
		err = mnt_want_write_file(filp);
865 866 867 868 869 870 871 872
		if (err)
			return err;
		/*
		 * inode_mutex prevent write and truncate on the file.
		 * Read still goes through. We take i_data_sem in
		 * ext4_ext_swap_inode_data before we switch the
		 * inode format to prevent read.
		 */
A
Al Viro 已提交
873
		inode_lock((inode));
874
		err = ext4_ext_migrate(inode);
A
Al Viro 已提交
875
		inode_unlock((inode));
A
Al Viro 已提交
876
		mnt_drop_write_file(filp);
877 878
		return err;
	}
879

880 881 882
	case EXT4_IOC_ALLOC_DA_BLKS:
	{
		int err;
883
		if (!inode_owner_or_capable(inode))
884 885
			return -EACCES;

886
		err = mnt_want_write_file(filp);
887 888 889
		if (err)
			return err;
		err = ext4_alloc_da_blocks(inode);
A
Al Viro 已提交
890
		mnt_drop_write_file(filp);
891 892 893
		return err;
	}

894
	case EXT4_IOC_SWAP_BOOT:
895 896
	{
		int err;
897 898
		if (!(filp->f_mode & FMODE_WRITE))
			return -EBADF;
899 900 901 902 903 904 905
		err = mnt_want_write_file(filp);
		if (err)
			return err;
		err = swap_inode_boot_loader(sb, inode);
		mnt_drop_write_file(filp);
		return err;
	}
906

907 908 909
	case EXT4_IOC_RESIZE_FS: {
		ext4_fsblk_t n_blocks_count;
		int err = 0, err2 = 0;
910
		ext4_group_t o_group = EXT4_SB(sb)->s_groups_count;
911 912 913 914 915 916 917 918 919 920

		if (copy_from_user(&n_blocks_count, (__u64 __user *)arg,
				   sizeof(__u64))) {
			return -EFAULT;
		}

		err = ext4_resize_begin(sb);
		if (err)
			return err;

921
		err = mnt_want_write_file(filp);
922 923 924 925 926 927 928 929 930 931 932
		if (err)
			goto resizefs_out;

		err = ext4_resize_fs(sb, n_blocks_count);
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
		if (err == 0)
			err = err2;
933
		mnt_drop_write_file(filp);
934 935 936 937 938
		if (!err && (o_group > EXT4_SB(sb)->s_groups_count) &&
		    ext4_has_group_desc_csum(sb) &&
		    test_opt(sb, INIT_INODE_TABLE))
			err = ext4_register_li_request(sb, o_group);

939 940 941 942 943
resizefs_out:
		ext4_resize_end(sb);
		return err;
	}

944 945
	case FITRIM:
	{
946
		struct request_queue *q = bdev_get_queue(sb->s_bdev);
947 948 949 950 951 952
		struct fstrim_range range;
		int ret = 0;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

953 954 955
		if (!blk_queue_discard(q))
			return -EOPNOTSUPP;

956
		if (copy_from_user(&range, (struct fstrim_range __user *)arg,
957 958 959
		    sizeof(range)))
			return -EFAULT;

960 961
		range.minlen = max((unsigned int)range.minlen,
				   q->limits.discard_granularity);
962 963 964 965
		ret = ext4_trim_fs(sb, &range);
		if (ret < 0)
			return ret;

966
		if (copy_to_user((struct fstrim_range __user *)arg, &range,
967 968 969 970 971
		    sizeof(range)))
			return -EFAULT;

		return 0;
	}
972 973
	case EXT4_IOC_PRECACHE_EXTENTS:
		return ext4_ext_precache(inode);
974

975
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
976 977
		if (!ext4_has_feature_encrypt(sb))
			return -EOPNOTSUPP;
978
		return fscrypt_ioctl_set_policy(filp, (const void __user *)arg);
979

980
	case EXT4_IOC_GET_ENCRYPTION_PWSALT: {
981
#ifdef CONFIG_EXT4_FS_ENCRYPTION
982 983 984 985
		int err, err2;
		struct ext4_sb_info *sbi = EXT4_SB(sb);
		handle_t *handle;

986
		if (!ext4_has_feature_encrypt(sb))
987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011
			return -EOPNOTSUPP;
		if (uuid_is_zero(sbi->s_es->s_encrypt_pw_salt)) {
			err = mnt_want_write_file(filp);
			if (err)
				return err;
			handle = ext4_journal_start_sb(sb, EXT4_HT_MISC, 1);
			if (IS_ERR(handle)) {
				err = PTR_ERR(handle);
				goto pwsalt_err_exit;
			}
			err = ext4_journal_get_write_access(handle, sbi->s_sbh);
			if (err)
				goto pwsalt_err_journal;
			generate_random_uuid(sbi->s_es->s_encrypt_pw_salt);
			err = ext4_handle_dirty_metadata(handle, NULL,
							 sbi->s_sbh);
		pwsalt_err_journal:
			err2 = ext4_journal_stop(handle);
			if (err2 && !err)
				err = err2;
		pwsalt_err_exit:
			mnt_drop_write_file(filp);
			if (err)
				return err;
		}
1012 1013
		if (copy_to_user((void __user *) arg,
				 sbi->s_es->s_encrypt_pw_salt, 16))
1014 1015
			return -EFAULT;
		return 0;
1016 1017 1018
#else
		return -EOPNOTSUPP;
#endif
1019
	}
1020 1021
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
		return fscrypt_ioctl_get_policy(filp, (void __user *)arg);
1022

1023 1024 1025 1026 1027 1028 1029
	case EXT4_IOC_FSGETXATTR:
	{
		struct fsxattr fa;

		memset(&fa, 0, sizeof(struct fsxattr));
		fa.fsx_xflags = ext4_iflags_to_xflags(ei->i_flags & EXT4_FL_USER_VISIBLE);

K
Kaho Ng 已提交
1030
		if (ext4_has_feature_project(inode->i_sb)) {
1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052
			fa.fsx_projid = (__u32)from_kprojid(&init_user_ns,
				EXT4_I(inode)->i_projid);
		}

		if (copy_to_user((struct fsxattr __user *)arg,
				 &fa, sizeof(fa)))
			return -EFAULT;
		return 0;
	}
	case EXT4_IOC_FSSETXATTR:
	{
		struct fsxattr fa;
		int err;

		if (copy_from_user(&fa, (struct fsxattr __user *)arg,
				   sizeof(fa)))
			return -EFAULT;

		/* Make sure caller has proper permission */
		if (!inode_owner_or_capable(inode))
			return -EACCES;

1053 1054 1055 1056 1057 1058 1059
		if (fa.fsx_xflags & ~EXT4_SUPPORTED_FS_XFLAGS)
			return -EOPNOTSUPP;

		flags = ext4_xflags_to_iflags(fa.fsx_xflags);
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

1060 1061 1062 1063
		err = mnt_want_write_file(filp);
		if (err)
			return err;

A
Al Viro 已提交
1064
		inode_lock(inode);
1065 1066 1067
		err = ext4_ioctl_check_project(inode, &fa);
		if (err)
			goto out;
1068 1069 1070 1071
		flags = (ei->i_flags & ~EXT4_FL_XFLAG_VISIBLE) |
			 (flags & EXT4_FL_XFLAG_VISIBLE);
		err = ext4_ioctl_setflags(inode, flags);
		if (err)
1072
			goto out;
1073
		err = ext4_ioctl_setproject(filp, fa.fsx_projid);
1074 1075 1076 1077
out:
		inode_unlock(inode);
		mnt_drop_write_file(filp);
		return err;
1078
	}
1079 1080
	case EXT4_IOC_SHUTDOWN:
		return ext4_shutdown(sb, arg);
1081 1082 1083 1084 1085 1086
	default:
		return -ENOTTY;
	}
}

#ifdef CONFIG_COMPAT
1087
long ext4_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
1088 1089 1090
{
	/* These are just misnamed, they actually get/put from/to user an int */
	switch (cmd) {
1091 1092
	case EXT4_IOC32_GETFLAGS:
		cmd = EXT4_IOC_GETFLAGS;
1093
		break;
1094 1095
	case EXT4_IOC32_SETFLAGS:
		cmd = EXT4_IOC_SETFLAGS;
1096
		break;
1097 1098
	case EXT4_IOC32_GETVERSION:
		cmd = EXT4_IOC_GETVERSION;
1099
		break;
1100 1101
	case EXT4_IOC32_SETVERSION:
		cmd = EXT4_IOC_SETVERSION;
1102
		break;
1103 1104
	case EXT4_IOC32_GROUP_EXTEND:
		cmd = EXT4_IOC_GROUP_EXTEND;
1105
		break;
1106 1107
	case EXT4_IOC32_GETVERSION_OLD:
		cmd = EXT4_IOC_GETVERSION_OLD;
1108
		break;
1109 1110
	case EXT4_IOC32_SETVERSION_OLD:
		cmd = EXT4_IOC_SETVERSION_OLD;
1111
		break;
1112 1113
	case EXT4_IOC32_GETRSVSZ:
		cmd = EXT4_IOC_GETRSVSZ;
1114
		break;
1115 1116
	case EXT4_IOC32_SETRSVSZ:
		cmd = EXT4_IOC_SETRSVSZ;
1117
		break;
1118 1119
	case EXT4_IOC32_GROUP_ADD: {
		struct compat_ext4_new_group_input __user *uinput;
1120
		struct ext4_new_group_data input;
1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132
		int err;

		uinput = compat_ptr(arg);
		err = get_user(input.group, &uinput->group);
		err |= get_user(input.block_bitmap, &uinput->block_bitmap);
		err |= get_user(input.inode_bitmap, &uinput->inode_bitmap);
		err |= get_user(input.inode_table, &uinput->inode_table);
		err |= get_user(input.blocks_count, &uinput->blocks_count);
		err |= get_user(input.reserved_blocks,
				&uinput->reserved_blocks);
		if (err)
			return -EFAULT;
1133
		return ext4_ioctl_group_add(file, &input);
1134
	}
1135
	case EXT4_IOC_MOVE_EXT:
1136
	case EXT4_IOC_RESIZE_FS:
1137
	case EXT4_IOC_PRECACHE_EXTENTS:
1138 1139 1140
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
	case EXT4_IOC_GET_ENCRYPTION_PWSALT:
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
1141
	case EXT4_IOC_SHUTDOWN:
D
Darrick J. Wong 已提交
1142
	case FS_IOC_GETFSMAP:
1143
		break;
1144 1145 1146
	default:
		return -ENOIOCTLCMD;
	}
A
Andi Kleen 已提交
1147
	return ext4_ioctl(file, cmd, (unsigned long) compat_ptr(arg));
1148 1149
}
#endif