ioctl.c 28.0 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0
2
/*
3
 * linux/fs/ext4/ioctl.c
4 5 6 7 8 9 10 11 12 13 14
 *
 * Copyright (C) 1993, 1994, 1995
 * Remy Card (card@masi.ibp.fr)
 * Laboratoire MASI - Institut Blaise Pascal
 * Universite Pierre et Marie Curie (Paris VI)
 */

#include <linux/fs.h>
#include <linux/capability.h>
#include <linux/time.h>
#include <linux/compat.h>
15
#include <linux/mount.h>
16
#include <linux/file.h>
17
#include <linux/quotaops.h>
18
#include <linux/random.h>
19
#include <linux/uuid.h>
20
#include <linux/uaccess.h>
21
#include <linux/delay.h>
J
Jeff Layton 已提交
22
#include <linux/iversion.h>
23 24
#include "ext4_jbd2.h"
#include "ext4.h"
D
Darrick J. Wong 已提交
25 26 27
#include <linux/fsmap.h>
#include "fsmap.h"
#include <trace/events/ext4.h>
28

29 30 31 32 33 34 35 36 37 38 39 40 41 42 43
/**
 * Swap memory between @a and @b for @len bytes.
 *
 * @a:          pointer to first memory area
 * @b:          pointer to second memory area
 * @len:        number of bytes to swap
 *
 */
static void memswap(void *a, void *b, size_t len)
{
	unsigned char *ap, *bp;

	ap = (unsigned char *)a;
	bp = (unsigned char *)b;
	while (len-- > 0) {
F
Fabian Frederick 已提交
44
		swap(*ap, *bp);
45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69
		ap++;
		bp++;
	}
}

/**
 * Swap i_data and associated attributes between @inode1 and @inode2.
 * This function is used for the primary swap between inode1 and inode2
 * and also to revert this primary swap in case of errors.
 *
 * Therefore you have to make sure, that calling this method twice
 * will revert all changes.
 *
 * @inode1:     pointer to first inode
 * @inode2:     pointer to second inode
 */
static void swap_inode_data(struct inode *inode1, struct inode *inode2)
{
	loff_t isize;
	struct ext4_inode_info *ei1;
	struct ext4_inode_info *ei2;

	ei1 = EXT4_I(inode1);
	ei2 = EXT4_I(inode2);

70 71 72 73 74
	swap(inode1->i_version, inode2->i_version);
	swap(inode1->i_blocks, inode2->i_blocks);
	swap(inode1->i_bytes, inode2->i_bytes);
	swap(inode1->i_atime, inode2->i_atime);
	swap(inode1->i_mtime, inode2->i_mtime);
75 76

	memswap(ei1->i_data, ei2->i_data, sizeof(ei1->i_data));
77 78
	swap(ei1->i_flags, ei2->i_flags);
	swap(ei1->i_disksize, ei2->i_disksize);
79 80
	ext4_es_remove_extent(inode1, 0, EXT_MAX_BLOCKS);
	ext4_es_remove_extent(inode2, 0, EXT_MAX_BLOCKS);
81 82 83 84 85 86

	isize = i_size_read(inode1);
	i_size_write(inode1, i_size_read(inode2));
	i_size_write(inode2, isize);
}

T
Theodore Ts'o 已提交
87 88 89 90 91 92 93 94 95 96 97 98 99 100 101
static void reset_inode_seed(struct inode *inode)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	struct ext4_sb_info *sbi = EXT4_SB(inode->i_sb);
	__le32 inum = cpu_to_le32(inode->i_ino);
	__le32 gen = cpu_to_le32(inode->i_generation);
	__u32 csum;

	if (!ext4_has_metadata_csum(inode->i_sb))
		return;

	csum = ext4_chksum(sbi, sbi->s_csum_seed, (__u8 *)&inum, sizeof(inum));
	ei->i_csum_seed = ext4_chksum(sbi, csum, (__u8 *)&gen, sizeof(gen));
}

102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118
/**
 * Swap the information from the given @inode and the inode
 * EXT4_BOOT_LOADER_INO. It will basically swap i_data and all other
 * important fields of the inodes.
 *
 * @sb:         the super block of the filesystem
 * @inode:      the inode to swap with EXT4_BOOT_LOADER_INO
 *
 */
static long swap_inode_boot_loader(struct super_block *sb,
				struct inode *inode)
{
	handle_t *handle;
	int err;
	struct inode *inode_bl;
	struct ext4_inode_info *ei_bl;

119
	inode_bl = ext4_iget(sb, EXT4_BOOT_LOADER_INO, EXT4_IGET_SPECIAL);
120 121
	if (IS_ERR(inode_bl))
		return PTR_ERR(inode_bl);
122 123 124 125 126 127 128
	ei_bl = EXT4_I(inode_bl);

	filemap_flush(inode->i_mapping);
	filemap_flush(inode_bl->i_mapping);

	/* Protect orig inodes against a truncate and make sure,
	 * that only 1 swap_inode_boot_loader is running. */
129
	lock_two_nondirectories(inode, inode_bl);
130

131 132 133 134 135 136 137 138 139 140 141 142 143
	if (inode->i_nlink != 1 || !S_ISREG(inode->i_mode) ||
	    IS_SWAPFILE(inode) || IS_ENCRYPTED(inode) ||
	    ext4_has_inline_data(inode)) {
		err = -EINVAL;
		goto journal_err_out;
	}

	if (IS_RDONLY(inode) || IS_APPEND(inode) || IS_IMMUTABLE(inode) ||
	    !inode_owner_or_capable(inode) || !capable(CAP_SYS_ADMIN)) {
		err = -EPERM;
		goto journal_err_out;
	}

144 145 146 147
	/* Wait for all existing dio workers */
	inode_dio_wait(inode);
	inode_dio_wait(inode_bl);

T
Theodore Ts'o 已提交
148 149 150
	truncate_inode_pages(&inode->i_data, 0);
	truncate_inode_pages(&inode_bl->i_data, 0);

151 152 153
	handle = ext4_journal_start(inode_bl, EXT4_HT_MOVE_EXTENTS, 2);
	if (IS_ERR(handle)) {
		err = -EINVAL;
154
		goto journal_err_out;
155 156 157 158 159 160 161 162 163 164 165 166
	}

	/* Protect extent tree against block allocations via delalloc */
	ext4_double_down_write_data_sem(inode, inode_bl);

	if (inode_bl->i_nlink == 0) {
		/* this inode has never been used as a BOOT_LOADER */
		set_nlink(inode_bl, 1);
		i_uid_write(inode_bl, 0);
		i_gid_write(inode_bl, 0);
		inode_bl->i_flags = 0;
		ei_bl->i_flags = 0;
J
Jeff Layton 已提交
167
		inode_set_iversion(inode_bl, 1);
168 169
		i_size_write(inode_bl, 0);
		inode_bl->i_mode = S_IFREG;
170
		if (ext4_has_feature_extents(sb)) {
171 172 173 174 175 176 177 178
			ext4_set_inode_flag(inode_bl, EXT4_INODE_EXTENTS);
			ext4_ext_tree_init(handle, inode_bl);
		} else
			memset(ei_bl->i_data, 0, sizeof(ei_bl->i_data));
	}

	swap_inode_data(inode, inode_bl);

179
	inode->i_ctime = inode_bl->i_ctime = current_time(inode);
180

181 182
	inode->i_generation = prandom_u32();
	inode_bl->i_generation = prandom_u32();
T
Theodore Ts'o 已提交
183 184
	reset_inode_seed(inode);
	reset_inode_seed(inode_bl);
185 186 187 188 189 190 191 192 193 194

	ext4_discard_preallocations(inode);

	err = ext4_mark_inode_dirty(handle, inode);
	if (err < 0) {
		ext4_warning(inode->i_sb,
			"couldn't mark inode #%lu dirty (err %d)",
			inode->i_ino, err);
		/* Revert all changes: */
		swap_inode_data(inode, inode_bl);
T
Theodore Ts'o 已提交
195
		ext4_mark_inode_dirty(handle, inode);
196 197 198 199 200 201 202 203 204
	} else {
		err = ext4_mark_inode_dirty(handle, inode_bl);
		if (err < 0) {
			ext4_warning(inode_bl->i_sb,
				"couldn't mark inode #%lu dirty (err %d)",
				inode_bl->i_ino, err);
			/* Revert all changes: */
			swap_inode_data(inode, inode_bl);
			ext4_mark_inode_dirty(handle, inode);
T
Theodore Ts'o 已提交
205
			ext4_mark_inode_dirty(handle, inode_bl);
206 207 208 209 210
		}
	}
	ext4_journal_stop(handle);
	ext4_double_up_write_data_sem(inode, inode_bl);

211
journal_err_out:
212
	unlock_two_nondirectories(inode, inode_bl);
213 214 215 216
	iput(inode_bl);
	return err;
}

217
#ifdef CONFIG_EXT4_FS_ENCRYPTION
218 219 220 221 222 223 224 225 226
static int uuid_is_zero(__u8 u[16])
{
	int	i;

	for (i = 0; i < 16; i++)
		if (u[i])
			return 0;
	return 1;
}
227
#endif
228

229 230 231 232 233
static int ext4_ioctl_setflags(struct inode *inode,
			       unsigned int flags)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	handle_t *handle = NULL;
234
	int err = -EPERM, migrate = 0;
235 236 237 238 239
	struct ext4_iloc iloc;
	unsigned int oldflags, mask, i;
	unsigned int jflag;

	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
240
	if (ext4_is_quota_file(inode))
241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275
		goto flags_out;

	oldflags = ei->i_flags;

	/* The JOURNAL_DATA flag is modifiable only by root */
	jflag = flags & EXT4_JOURNAL_DATA_FL;

	/*
	 * The IMMUTABLE and APPEND_ONLY flags can only be changed by
	 * the relevant capability.
	 *
	 * This test looks nicer. Thanks to Pauline Middelink
	 */
	if ((flags ^ oldflags) & (EXT4_APPEND_FL | EXT4_IMMUTABLE_FL)) {
		if (!capable(CAP_LINUX_IMMUTABLE))
			goto flags_out;
	}

	/*
	 * The JOURNAL_DATA flag can only be changed by
	 * the relevant capability.
	 */
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		if (!capable(CAP_SYS_RESOURCE))
			goto flags_out;
	}
	if ((flags ^ oldflags) & EXT4_EXTENTS_FL)
		migrate = 1;

	if (flags & EXT4_EOFBLOCKS_FL) {
		/* we don't support adding EOFBLOCKS flag */
		if (!(oldflags & EXT4_EOFBLOCKS_FL)) {
			err = -EOPNOTSUPP;
			goto flags_out;
		}
276 277 278 279 280
	} else if (oldflags & EXT4_EOFBLOCKS_FL) {
		err = ext4_truncate(inode);
		if (err)
			goto flags_out;
	}
281 282 283 284 285 286 287 288 289 290 291 292 293 294 295

	handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
	if (IS_ERR(handle)) {
		err = PTR_ERR(handle);
		goto flags_out;
	}
	if (IS_SYNC(inode))
		ext4_handle_sync(handle);
	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto flags_err;

	for (i = 0, mask = 1; i < 32; i++, mask <<= 1) {
		if (!(mask & EXT4_FL_USER_MODIFIABLE))
			continue;
296 297 298
		/* These flags get special treatment later */
		if (mask == EXT4_JOURNAL_DATA_FL || mask == EXT4_EXTENTS_FL)
			continue;
299 300 301 302 303 304 305
		if (mask & flags)
			ext4_set_inode_flag(inode, i);
		else
			ext4_clear_inode_flag(inode, i);
	}

	ext4_set_inode_flags(inode);
306
	inode->i_ctime = current_time(inode);
307 308 309 310 311 312 313

	err = ext4_mark_iloc_dirty(handle, inode, &iloc);
flags_err:
	ext4_journal_stop(handle);
	if (err)
		goto flags_out;

314 315 316 317 318 319 320 321 322 323
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		/*
		 * Changes to the journaling mode can cause unsafe changes to
		 * S_DAX if we are using the DAX mount option.
		 */
		if (test_opt(inode->i_sb, DAX)) {
			err = -EBUSY;
			goto flags_out;
		}

324
		err = ext4_change_inode_journal_flag(inode, jflag);
325 326 327
		if (err)
			goto flags_out;
	}
328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349
	if (migrate) {
		if (flags & EXT4_EXTENTS_FL)
			err = ext4_ext_migrate(inode);
		else
			err = ext4_ind_migrate(inode);
	}

flags_out:
	return err;
}

#ifdef CONFIG_QUOTA
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	struct inode *inode = file_inode(filp);
	struct super_block *sb = inode->i_sb;
	struct ext4_inode_info *ei = EXT4_I(inode);
	int err, rc;
	handle_t *handle;
	kprojid_t kprojid;
	struct ext4_iloc iloc;
	struct ext4_inode *raw_inode;
350
	struct dquot *transfer_to[MAXQUOTAS] = { };
351

K
Kaho Ng 已提交
352
	if (!ext4_has_feature_project(sb)) {
353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368
		if (projid != EXT4_DEF_PROJID)
			return -EOPNOTSUPP;
		else
			return 0;
	}

	if (EXT4_INODE_SIZE(sb) <= EXT4_GOOD_OLD_INODE_SIZE)
		return -EOPNOTSUPP;

	kprojid = make_kprojid(&init_user_ns, (projid_t)projid);

	if (projid_eq(kprojid, EXT4_I(inode)->i_projid))
		return 0;

	err = -EPERM;
	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
369
	if (ext4_is_quota_file(inode))
370
		return err;
371 372 373

	err = ext4_get_inode_loc(inode, &iloc);
	if (err)
374
		return err;
375 376 377

	raw_inode = ext4_raw_inode(&iloc);
	if (!EXT4_FITS_IN_INODE(raw_inode, ei, i_projid)) {
378 379 380 381
		err = ext4_expand_extra_isize(inode,
					      EXT4_SB(sb)->s_want_extra_isize,
					      &iloc);
		if (err)
382
			return err;
383
	} else {
384 385 386
		brelse(iloc.bh);
	}

387 388 389
	err = dquot_initialize(inode);
	if (err)
		return err;
390 391 392 393

	handle = ext4_journal_start(inode, EXT4_HT_QUOTA,
		EXT4_QUOTA_INIT_BLOCKS(sb) +
		EXT4_QUOTA_DEL_BLOCKS(sb) + 3);
394 395
	if (IS_ERR(handle))
		return PTR_ERR(handle);
396 397 398 399 400

	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto out_stop;

401 402
	transfer_to[PRJQUOTA] = dqget(sb, make_kqid_projid(kprojid));
	if (!IS_ERR(transfer_to[PRJQUOTA])) {
403 404 405 406 407

		/* __dquot_transfer() calls back ext4_get_inode_usage() which
		 * counts xattr inode references.
		 */
		down_read(&EXT4_I(inode)->xattr_sem);
408
		err = __dquot_transfer(inode, transfer_to);
409
		up_read(&EXT4_I(inode)->xattr_sem);
410 411 412
		dqput(transfer_to[PRJQUOTA]);
		if (err)
			goto out_dirty;
413
	}
414

415
	EXT4_I(inode)->i_projid = kprojid;
416
	inode->i_ctime = current_time(inode);
417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453
out_dirty:
	rc = ext4_mark_iloc_dirty(handle, inode, &iloc);
	if (!err)
		err = rc;
out_stop:
	ext4_journal_stop(handle);
	return err;
}
#else
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	if (projid != EXT4_DEF_PROJID)
		return -EOPNOTSUPP;
	return 0;
}
#endif

/* Transfer internal flags to xflags */
static inline __u32 ext4_iflags_to_xflags(unsigned long iflags)
{
	__u32 xflags = 0;

	if (iflags & EXT4_SYNC_FL)
		xflags |= FS_XFLAG_SYNC;
	if (iflags & EXT4_IMMUTABLE_FL)
		xflags |= FS_XFLAG_IMMUTABLE;
	if (iflags & EXT4_APPEND_FL)
		xflags |= FS_XFLAG_APPEND;
	if (iflags & EXT4_NODUMP_FL)
		xflags |= FS_XFLAG_NODUMP;
	if (iflags & EXT4_NOATIME_FL)
		xflags |= FS_XFLAG_NOATIME;
	if (iflags & EXT4_PROJINHERIT_FL)
		xflags |= FS_XFLAG_PROJINHERIT;
	return xflags;
}

454 455 456 457
#define EXT4_SUPPORTED_FS_XFLAGS (FS_XFLAG_SYNC | FS_XFLAG_IMMUTABLE | \
				  FS_XFLAG_APPEND | FS_XFLAG_NODUMP | \
				  FS_XFLAG_NOATIME | FS_XFLAG_PROJINHERIT)

458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478
/* Transfer xflags flags to internal */
static inline unsigned long ext4_xflags_to_iflags(__u32 xflags)
{
	unsigned long iflags = 0;

	if (xflags & FS_XFLAG_SYNC)
		iflags |= EXT4_SYNC_FL;
	if (xflags & FS_XFLAG_IMMUTABLE)
		iflags |= EXT4_IMMUTABLE_FL;
	if (xflags & FS_XFLAG_APPEND)
		iflags |= EXT4_APPEND_FL;
	if (xflags & FS_XFLAG_NODUMP)
		iflags |= EXT4_NODUMP_FL;
	if (xflags & FS_XFLAG_NOATIME)
		iflags |= EXT4_NOATIME_FL;
	if (xflags & FS_XFLAG_PROJINHERIT)
		iflags |= EXT4_PROJINHERIT_FL;

	return iflags;
}

E
Eric Biggers 已提交
479
static int ext4_shutdown(struct super_block *sb, unsigned long arg)
480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496
{
	struct ext4_sb_info *sbi = EXT4_SB(sb);
	__u32 flags;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (get_user(flags, (__u32 __user *)arg))
		return -EFAULT;

	if (flags > EXT4_GOING_FLAGS_NOLOGFLUSH)
		return -EINVAL;

	if (ext4_forced_shutdown(sbi))
		return 0;

	ext4_msg(sb, KERN_ALERT, "shut down requested (%d)", flags);
497
	trace_ext4_shutdown(sb, flags);
498 499 500 501 502 503 504 505 506 507 508

	switch (flags) {
	case EXT4_GOING_FLAGS_DEFAULT:
		freeze_bdev(sb->s_bdev);
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		thaw_bdev(sb->s_bdev, sb);
		break;
	case EXT4_GOING_FLAGS_LOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal)) {
			(void) ext4_force_commit(sb);
509
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
510 511 512 513
		}
		break;
	case EXT4_GOING_FLAGS_NOLOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
514
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal))
515
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
516 517 518 519 520 521 522 523
		break;
	default:
		return -EINVAL;
	}
	clear_opt(sb, DISCARD);
	return 0;
}

D
Darrick J. Wong 已提交
524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607
struct getfsmap_info {
	struct super_block	*gi_sb;
	struct fsmap_head __user *gi_data;
	unsigned int		gi_idx;
	__u32			gi_last_flags;
};

static int ext4_getfsmap_format(struct ext4_fsmap *xfm, void *priv)
{
	struct getfsmap_info *info = priv;
	struct fsmap fm;

	trace_ext4_getfsmap_mapping(info->gi_sb, xfm);

	info->gi_last_flags = xfm->fmr_flags;
	ext4_fsmap_from_internal(info->gi_sb, &fm, xfm);
	if (copy_to_user(&info->gi_data->fmh_recs[info->gi_idx++], &fm,
			sizeof(struct fsmap)))
		return -EFAULT;

	return 0;
}

static int ext4_ioc_getfsmap(struct super_block *sb,
			     struct fsmap_head __user *arg)
{
	struct getfsmap_info info = {0};
	struct ext4_fsmap_head xhead = {0};
	struct fsmap_head head;
	bool aborted = false;
	int error;

	if (copy_from_user(&head, arg, sizeof(struct fsmap_head)))
		return -EFAULT;
	if (memchr_inv(head.fmh_reserved, 0, sizeof(head.fmh_reserved)) ||
	    memchr_inv(head.fmh_keys[0].fmr_reserved, 0,
		       sizeof(head.fmh_keys[0].fmr_reserved)) ||
	    memchr_inv(head.fmh_keys[1].fmr_reserved, 0,
		       sizeof(head.fmh_keys[1].fmr_reserved)))
		return -EINVAL;
	/*
	 * ext4 doesn't report file extents at all, so the only valid
	 * file offsets are the magic ones (all zeroes or all ones).
	 */
	if (head.fmh_keys[0].fmr_offset ||
	    (head.fmh_keys[1].fmr_offset != 0 &&
	     head.fmh_keys[1].fmr_offset != -1ULL))
		return -EINVAL;

	xhead.fmh_iflags = head.fmh_iflags;
	xhead.fmh_count = head.fmh_count;
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[0], &head.fmh_keys[0]);
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[1], &head.fmh_keys[1]);

	trace_ext4_getfsmap_low_key(sb, &xhead.fmh_keys[0]);
	trace_ext4_getfsmap_high_key(sb, &xhead.fmh_keys[1]);

	info.gi_sb = sb;
	info.gi_data = arg;
	error = ext4_getfsmap(sb, &xhead, ext4_getfsmap_format, &info);
	if (error == EXT4_QUERY_RANGE_ABORT) {
		error = 0;
		aborted = true;
	} else if (error)
		return error;

	/* If we didn't abort, set the "last" flag in the last fmx */
	if (!aborted && info.gi_idx) {
		info.gi_last_flags |= FMR_OF_LAST;
		if (copy_to_user(&info.gi_data->fmh_recs[info.gi_idx - 1].fmr_flags,
				 &info.gi_last_flags,
				 sizeof(info.gi_last_flags)))
			return -EFAULT;
	}

	/* copy back header */
	head.fmh_entries = xhead.fmh_entries;
	head.fmh_oflags = xhead.fmh_oflags;
	if (copy_to_user(arg, &head, sizeof(struct fsmap_head)))
		return -EFAULT;

	return 0;
}

608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645
static long ext4_ioctl_group_add(struct file *file,
				 struct ext4_new_group_data *input)
{
	struct super_block *sb = file_inode(file)->i_sb;
	int err, err2=0;

	err = ext4_resize_begin(sb);
	if (err)
		return err;

	if (ext4_has_feature_bigalloc(sb)) {
		ext4_msg(sb, KERN_ERR,
			 "Online resizing not supported with bigalloc");
		err = -EOPNOTSUPP;
		goto group_add_out;
	}

	err = mnt_want_write_file(file);
	if (err)
		goto group_add_out;

	err = ext4_group_add(sb, input);
	if (EXT4_SB(sb)->s_journal) {
		jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
		err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
		jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
	}
	if (err == 0)
		err = err2;
	mnt_drop_write_file(file);
	if (!err && ext4_has_group_desc_csum(sb) &&
	    test_opt(sb, INIT_INODE_TABLE))
		err = ext4_register_li_request(sb, input->group);
group_add_out:
	ext4_resize_end(sb);
	return err;
}

646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669
static int ext4_ioctl_check_project(struct inode *inode, struct fsxattr *fa)
{
	/*
	 * Project Quota ID state is only allowed to change from within the init
	 * namespace. Enforce that restriction only if we are trying to change
	 * the quota ID state. Everything else is allowed in user namespaces.
	 */
	if (current_user_ns() == &init_user_ns)
		return 0;

	if (__kprojid_val(EXT4_I(inode)->i_projid) != fa->fsx_projid)
		return -EINVAL;

	if (ext4_test_inode_flag(inode, EXT4_INODE_PROJINHERIT)) {
		if (!(fa->fsx_xflags & FS_XFLAG_PROJINHERIT))
			return -EINVAL;
	} else {
		if (fa->fsx_xflags & FS_XFLAG_PROJINHERIT)
			return -EINVAL;
	}

	return 0;
}

A
Andi Kleen 已提交
670
long ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
671
{
A
Al Viro 已提交
672
	struct inode *inode = file_inode(filp);
673
	struct super_block *sb = inode->i_sb;
674
	struct ext4_inode_info *ei = EXT4_I(inode);
675 676
	unsigned int flags;

677
	ext4_debug("cmd = %u, arg = %lu\n", cmd, arg);
678 679

	switch (cmd) {
D
Darrick J. Wong 已提交
680 681
	case FS_IOC_GETFSMAP:
		return ext4_ioc_getfsmap(sb, (void __user *)arg);
682 683
	case EXT4_IOC_GETFLAGS:
		flags = ei->i_flags & EXT4_FL_USER_VISIBLE;
684
		return put_user(flags, (int __user *) arg);
685
	case EXT4_IOC_SETFLAGS: {
686
		int err;
687

688
		if (!inode_owner_or_capable(inode))
689 690 691 692 693
			return -EACCES;

		if (get_user(flags, (int __user *) arg))
			return -EFAULT;

694 695 696 697 698 699 700 701 702 703 704 705
		if (flags & ~EXT4_FL_USER_VISIBLE)
			return -EOPNOTSUPP;
		/*
		 * chattr(1) grabs flags via GETFLAGS, modifies the result and
		 * passes that to SETFLAGS. So we cannot easily make SETFLAGS
		 * more restrictive than just silently masking off visible but
		 * not settable flags as we always did.
		 */
		flags &= EXT4_FL_USER_MODIFIABLE;
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

706
		err = mnt_want_write_file(filp);
707 708 709
		if (err)
			return err;

A
Al Viro 已提交
710
		inode_lock(inode);
711
		err = ext4_ioctl_setflags(inode, flags);
A
Al Viro 已提交
712
		inode_unlock(inode);
A
Al Viro 已提交
713
		mnt_drop_write_file(filp);
714 715
		return err;
	}
716 717
	case EXT4_IOC_GETVERSION:
	case EXT4_IOC_GETVERSION_OLD:
718
		return put_user(inode->i_generation, (int __user *) arg);
719 720
	case EXT4_IOC_SETVERSION:
	case EXT4_IOC_SETVERSION_OLD: {
721
		handle_t *handle;
722
		struct ext4_iloc iloc;
723 724 725
		__u32 generation;
		int err;

726
		if (!inode_owner_or_capable(inode))
727
			return -EPERM;
728

729
		if (ext4_has_metadata_csum(inode->i_sb)) {
730 731 732 733 734
			ext4_warning(sb, "Setting inode version is not "
				     "supported with metadata_csum enabled.");
			return -ENOTTY;
		}

735
		err = mnt_want_write_file(filp);
736 737 738 739 740 741
		if (err)
			return err;
		if (get_user(generation, (int __user *) arg)) {
			err = -EFAULT;
			goto setversion_out;
		}
742

A
Al Viro 已提交
743
		inode_lock(inode);
744
		handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
745 746
		if (IS_ERR(handle)) {
			err = PTR_ERR(handle);
747
			goto unlock_out;
748
		}
749
		err = ext4_reserve_inode_write(handle, inode, &iloc);
750
		if (err == 0) {
751
			inode->i_ctime = current_time(inode);
752
			inode->i_generation = generation;
753
			err = ext4_mark_iloc_dirty(handle, inode, &iloc);
754
		}
755
		ext4_journal_stop(handle);
756 757

unlock_out:
A
Al Viro 已提交
758
		inode_unlock(inode);
759
setversion_out:
A
Al Viro 已提交
760
		mnt_drop_write_file(filp);
761 762
		return err;
	}
763 764
	case EXT4_IOC_GROUP_EXTEND: {
		ext4_fsblk_t n_blocks_count;
765
		int err, err2=0;
766

767 768 769
		err = ext4_resize_begin(sb);
		if (err)
			return err;
770

771 772 773 774
		if (get_user(n_blocks_count, (__u32 __user *)arg)) {
			err = -EFAULT;
			goto group_extend_out;
		}
775

776
		if (ext4_has_feature_bigalloc(sb)) {
777 778
			ext4_msg(sb, KERN_ERR,
				 "Online resizing not supported with bigalloc");
779 780
			err = -EOPNOTSUPP;
			goto group_extend_out;
781 782
		}

783
		err = mnt_want_write_file(filp);
784
		if (err)
785
			goto group_extend_out;
786

787
		err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
788 789 790 791 792
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
793 794
		if (err == 0)
			err = err2;
A
Al Viro 已提交
795
		mnt_drop_write_file(filp);
796
group_extend_out:
797
		ext4_resize_end(sb);
798 799
		return err;
	}
800 801 802

	case EXT4_IOC_MOVE_EXT: {
		struct move_extent me;
803 804
		struct fd donor;
		int err;
805

806 807 808 809
		if (!(filp->f_mode & FMODE_READ) ||
		    !(filp->f_mode & FMODE_WRITE))
			return -EBADF;

810 811 812
		if (copy_from_user(&me,
			(struct move_extent __user *)arg, sizeof(me)))
			return -EFAULT;
813
		me.moved_len = 0;
814

815 816
		donor = fdget(me.donor_fd);
		if (!donor.file)
817 818
			return -EBADF;

819
		if (!(donor.file->f_mode & FMODE_WRITE)) {
820 821
			err = -EBADF;
			goto mext_out;
822 823
		}

824
		if (ext4_has_feature_bigalloc(sb)) {
825 826
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with bigalloc");
827 828
			err = -EOPNOTSUPP;
			goto mext_out;
829 830 831 832 833
		} else if (IS_DAX(inode)) {
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with DAX");
			err = -EOPNOTSUPP;
			goto mext_out;
834 835
		}

836
		err = mnt_want_write_file(filp);
837 838 839
		if (err)
			goto mext_out;

840
		err = ext4_move_extents(filp, donor.file, me.orig_start,
841
					me.donor_start, me.len, &me.moved_len);
A
Al Viro 已提交
842
		mnt_drop_write_file(filp);
843

844
		if (copy_to_user((struct move_extent __user *)arg,
845
				 &me, sizeof(me)))
846 847
			err = -EFAULT;
mext_out:
848
		fdput(donor);
849 850 851
		return err;
	}

852 853
	case EXT4_IOC_GROUP_ADD: {
		struct ext4_new_group_data input;
854

855
		if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
856 857
				sizeof(input)))
			return -EFAULT;
858

859
		return ext4_ioctl_group_add(filp, &input);
860 861
	}

862
	case EXT4_IOC_MIGRATE:
863 864
	{
		int err;
865
		if (!inode_owner_or_capable(inode))
866 867
			return -EACCES;

868
		err = mnt_want_write_file(filp);
869 870 871 872 873 874 875 876
		if (err)
			return err;
		/*
		 * inode_mutex prevent write and truncate on the file.
		 * Read still goes through. We take i_data_sem in
		 * ext4_ext_swap_inode_data before we switch the
		 * inode format to prevent read.
		 */
A
Al Viro 已提交
877
		inode_lock((inode));
878
		err = ext4_ext_migrate(inode);
A
Al Viro 已提交
879
		inode_unlock((inode));
A
Al Viro 已提交
880
		mnt_drop_write_file(filp);
881 882
		return err;
	}
883

884 885 886
	case EXT4_IOC_ALLOC_DA_BLKS:
	{
		int err;
887
		if (!inode_owner_or_capable(inode))
888 889
			return -EACCES;

890
		err = mnt_want_write_file(filp);
891 892 893
		if (err)
			return err;
		err = ext4_alloc_da_blocks(inode);
A
Al Viro 已提交
894
		mnt_drop_write_file(filp);
895 896 897
		return err;
	}

898
	case EXT4_IOC_SWAP_BOOT:
899 900
	{
		int err;
901 902
		if (!(filp->f_mode & FMODE_WRITE))
			return -EBADF;
903 904 905 906 907 908 909
		err = mnt_want_write_file(filp);
		if (err)
			return err;
		err = swap_inode_boot_loader(sb, inode);
		mnt_drop_write_file(filp);
		return err;
	}
910

911 912 913
	case EXT4_IOC_RESIZE_FS: {
		ext4_fsblk_t n_blocks_count;
		int err = 0, err2 = 0;
914
		ext4_group_t o_group = EXT4_SB(sb)->s_groups_count;
915 916 917 918 919 920 921 922 923 924

		if (copy_from_user(&n_blocks_count, (__u64 __user *)arg,
				   sizeof(__u64))) {
			return -EFAULT;
		}

		err = ext4_resize_begin(sb);
		if (err)
			return err;

925
		err = mnt_want_write_file(filp);
926 927 928 929 930 931 932 933 934 935 936
		if (err)
			goto resizefs_out;

		err = ext4_resize_fs(sb, n_blocks_count);
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
		if (err == 0)
			err = err2;
937
		mnt_drop_write_file(filp);
938 939 940 941 942
		if (!err && (o_group > EXT4_SB(sb)->s_groups_count) &&
		    ext4_has_group_desc_csum(sb) &&
		    test_opt(sb, INIT_INODE_TABLE))
			err = ext4_register_li_request(sb, o_group);

943 944 945 946 947
resizefs_out:
		ext4_resize_end(sb);
		return err;
	}

948 949
	case FITRIM:
	{
950
		struct request_queue *q = bdev_get_queue(sb->s_bdev);
951 952 953 954 955 956
		struct fstrim_range range;
		int ret = 0;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

957 958 959
		if (!blk_queue_discard(q))
			return -EOPNOTSUPP;

960
		if (copy_from_user(&range, (struct fstrim_range __user *)arg,
961 962 963
		    sizeof(range)))
			return -EFAULT;

964 965
		range.minlen = max((unsigned int)range.minlen,
				   q->limits.discard_granularity);
966 967 968 969
		ret = ext4_trim_fs(sb, &range);
		if (ret < 0)
			return ret;

970
		if (copy_to_user((struct fstrim_range __user *)arg, &range,
971 972 973 974 975
		    sizeof(range)))
			return -EFAULT;

		return 0;
	}
976 977
	case EXT4_IOC_PRECACHE_EXTENTS:
		return ext4_ext_precache(inode);
978

979
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
980 981
		if (!ext4_has_feature_encrypt(sb))
			return -EOPNOTSUPP;
982
		return fscrypt_ioctl_set_policy(filp, (const void __user *)arg);
983

984
	case EXT4_IOC_GET_ENCRYPTION_PWSALT: {
985
#ifdef CONFIG_EXT4_FS_ENCRYPTION
986 987 988 989
		int err, err2;
		struct ext4_sb_info *sbi = EXT4_SB(sb);
		handle_t *handle;

990
		if (!ext4_has_feature_encrypt(sb))
991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015
			return -EOPNOTSUPP;
		if (uuid_is_zero(sbi->s_es->s_encrypt_pw_salt)) {
			err = mnt_want_write_file(filp);
			if (err)
				return err;
			handle = ext4_journal_start_sb(sb, EXT4_HT_MISC, 1);
			if (IS_ERR(handle)) {
				err = PTR_ERR(handle);
				goto pwsalt_err_exit;
			}
			err = ext4_journal_get_write_access(handle, sbi->s_sbh);
			if (err)
				goto pwsalt_err_journal;
			generate_random_uuid(sbi->s_es->s_encrypt_pw_salt);
			err = ext4_handle_dirty_metadata(handle, NULL,
							 sbi->s_sbh);
		pwsalt_err_journal:
			err2 = ext4_journal_stop(handle);
			if (err2 && !err)
				err = err2;
		pwsalt_err_exit:
			mnt_drop_write_file(filp);
			if (err)
				return err;
		}
1016 1017
		if (copy_to_user((void __user *) arg,
				 sbi->s_es->s_encrypt_pw_salt, 16))
1018 1019
			return -EFAULT;
		return 0;
1020 1021 1022
#else
		return -EOPNOTSUPP;
#endif
1023
	}
1024 1025
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
		return fscrypt_ioctl_get_policy(filp, (void __user *)arg);
1026

1027 1028 1029 1030 1031 1032 1033
	case EXT4_IOC_FSGETXATTR:
	{
		struct fsxattr fa;

		memset(&fa, 0, sizeof(struct fsxattr));
		fa.fsx_xflags = ext4_iflags_to_xflags(ei->i_flags & EXT4_FL_USER_VISIBLE);

K
Kaho Ng 已提交
1034
		if (ext4_has_feature_project(inode->i_sb)) {
1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056
			fa.fsx_projid = (__u32)from_kprojid(&init_user_ns,
				EXT4_I(inode)->i_projid);
		}

		if (copy_to_user((struct fsxattr __user *)arg,
				 &fa, sizeof(fa)))
			return -EFAULT;
		return 0;
	}
	case EXT4_IOC_FSSETXATTR:
	{
		struct fsxattr fa;
		int err;

		if (copy_from_user(&fa, (struct fsxattr __user *)arg,
				   sizeof(fa)))
			return -EFAULT;

		/* Make sure caller has proper permission */
		if (!inode_owner_or_capable(inode))
			return -EACCES;

1057 1058 1059 1060 1061 1062 1063
		if (fa.fsx_xflags & ~EXT4_SUPPORTED_FS_XFLAGS)
			return -EOPNOTSUPP;

		flags = ext4_xflags_to_iflags(fa.fsx_xflags);
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

1064 1065 1066 1067
		err = mnt_want_write_file(filp);
		if (err)
			return err;

A
Al Viro 已提交
1068
		inode_lock(inode);
1069 1070 1071
		err = ext4_ioctl_check_project(inode, &fa);
		if (err)
			goto out;
1072 1073 1074 1075
		flags = (ei->i_flags & ~EXT4_FL_XFLAG_VISIBLE) |
			 (flags & EXT4_FL_XFLAG_VISIBLE);
		err = ext4_ioctl_setflags(inode, flags);
		if (err)
1076
			goto out;
1077
		err = ext4_ioctl_setproject(filp, fa.fsx_projid);
1078 1079 1080 1081
out:
		inode_unlock(inode);
		mnt_drop_write_file(filp);
		return err;
1082
	}
1083 1084
	case EXT4_IOC_SHUTDOWN:
		return ext4_shutdown(sb, arg);
1085 1086 1087 1088 1089 1090
	default:
		return -ENOTTY;
	}
}

#ifdef CONFIG_COMPAT
1091
long ext4_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
1092 1093 1094
{
	/* These are just misnamed, they actually get/put from/to user an int */
	switch (cmd) {
1095 1096
	case EXT4_IOC32_GETFLAGS:
		cmd = EXT4_IOC_GETFLAGS;
1097
		break;
1098 1099
	case EXT4_IOC32_SETFLAGS:
		cmd = EXT4_IOC_SETFLAGS;
1100
		break;
1101 1102
	case EXT4_IOC32_GETVERSION:
		cmd = EXT4_IOC_GETVERSION;
1103
		break;
1104 1105
	case EXT4_IOC32_SETVERSION:
		cmd = EXT4_IOC_SETVERSION;
1106
		break;
1107 1108
	case EXT4_IOC32_GROUP_EXTEND:
		cmd = EXT4_IOC_GROUP_EXTEND;
1109
		break;
1110 1111
	case EXT4_IOC32_GETVERSION_OLD:
		cmd = EXT4_IOC_GETVERSION_OLD;
1112
		break;
1113 1114
	case EXT4_IOC32_SETVERSION_OLD:
		cmd = EXT4_IOC_SETVERSION_OLD;
1115
		break;
1116 1117
	case EXT4_IOC32_GETRSVSZ:
		cmd = EXT4_IOC_GETRSVSZ;
1118
		break;
1119 1120
	case EXT4_IOC32_SETRSVSZ:
		cmd = EXT4_IOC_SETRSVSZ;
1121
		break;
1122 1123
	case EXT4_IOC32_GROUP_ADD: {
		struct compat_ext4_new_group_input __user *uinput;
1124
		struct ext4_new_group_data input;
1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136
		int err;

		uinput = compat_ptr(arg);
		err = get_user(input.group, &uinput->group);
		err |= get_user(input.block_bitmap, &uinput->block_bitmap);
		err |= get_user(input.inode_bitmap, &uinput->inode_bitmap);
		err |= get_user(input.inode_table, &uinput->inode_table);
		err |= get_user(input.blocks_count, &uinput->blocks_count);
		err |= get_user(input.reserved_blocks,
				&uinput->reserved_blocks);
		if (err)
			return -EFAULT;
1137
		return ext4_ioctl_group_add(file, &input);
1138
	}
1139
	case EXT4_IOC_MOVE_EXT:
1140
	case EXT4_IOC_RESIZE_FS:
1141
	case EXT4_IOC_PRECACHE_EXTENTS:
1142 1143 1144
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
	case EXT4_IOC_GET_ENCRYPTION_PWSALT:
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
1145
	case EXT4_IOC_SHUTDOWN:
D
Darrick J. Wong 已提交
1146
	case FS_IOC_GETFSMAP:
1147
		break;
1148 1149 1150
	default:
		return -ENOIOCTLCMD;
	}
A
Andi Kleen 已提交
1151
	return ext4_ioctl(file, cmd, (unsigned long) compat_ptr(arg));
1152 1153
}
#endif