ioctl.c 29.2 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0
2
/*
3
 * linux/fs/ext4/ioctl.c
4 5 6 7 8 9 10 11 12 13 14
 *
 * Copyright (C) 1993, 1994, 1995
 * Remy Card (card@masi.ibp.fr)
 * Laboratoire MASI - Institut Blaise Pascal
 * Universite Pierre et Marie Curie (Paris VI)
 */

#include <linux/fs.h>
#include <linux/capability.h>
#include <linux/time.h>
#include <linux/compat.h>
15
#include <linux/mount.h>
16
#include <linux/file.h>
17
#include <linux/quotaops.h>
18
#include <linux/random.h>
19
#include <linux/uuid.h>
20
#include <linux/uaccess.h>
21
#include <linux/delay.h>
J
Jeff Layton 已提交
22
#include <linux/iversion.h>
23 24
#include "ext4_jbd2.h"
#include "ext4.h"
D
Darrick J. Wong 已提交
25 26 27
#include <linux/fsmap.h>
#include "fsmap.h"
#include <trace/events/ext4.h>
28

29 30 31 32 33 34 35 36 37 38 39 40 41 42 43
/**
 * Swap memory between @a and @b for @len bytes.
 *
 * @a:          pointer to first memory area
 * @b:          pointer to second memory area
 * @len:        number of bytes to swap
 *
 */
static void memswap(void *a, void *b, size_t len)
{
	unsigned char *ap, *bp;

	ap = (unsigned char *)a;
	bp = (unsigned char *)b;
	while (len-- > 0) {
F
Fabian Frederick 已提交
44
		swap(*ap, *bp);
45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65
		ap++;
		bp++;
	}
}

/**
 * Swap i_data and associated attributes between @inode1 and @inode2.
 * This function is used for the primary swap between inode1 and inode2
 * and also to revert this primary swap in case of errors.
 *
 * Therefore you have to make sure, that calling this method twice
 * will revert all changes.
 *
 * @inode1:     pointer to first inode
 * @inode2:     pointer to second inode
 */
static void swap_inode_data(struct inode *inode1, struct inode *inode2)
{
	loff_t isize;
	struct ext4_inode_info *ei1;
	struct ext4_inode_info *ei2;
Y
yangerkun 已提交
66
	unsigned long tmp;
67 68 69 70

	ei1 = EXT4_I(inode1);
	ei2 = EXT4_I(inode2);

71 72 73
	swap(inode1->i_version, inode2->i_version);
	swap(inode1->i_atime, inode2->i_atime);
	swap(inode1->i_mtime, inode2->i_mtime);
74 75

	memswap(ei1->i_data, ei2->i_data, sizeof(ei1->i_data));
Y
yangerkun 已提交
76 77 78 79
	tmp = ei1->i_flags & EXT4_FL_SHOULD_SWAP;
	ei1->i_flags = (ei2->i_flags & EXT4_FL_SHOULD_SWAP) |
		(ei1->i_flags & ~EXT4_FL_SHOULD_SWAP);
	ei2->i_flags = tmp | (ei2->i_flags & ~EXT4_FL_SHOULD_SWAP);
80
	swap(ei1->i_disksize, ei2->i_disksize);
81 82
	ext4_es_remove_extent(inode1, 0, EXT_MAX_BLOCKS);
	ext4_es_remove_extent(inode2, 0, EXT_MAX_BLOCKS);
83 84 85 86 87 88

	isize = i_size_read(inode1);
	i_size_write(inode1, i_size_read(inode2));
	i_size_write(inode2, isize);
}

T
Theodore Ts'o 已提交
89 90 91 92 93 94 95 96 97 98 99 100 101 102 103
static void reset_inode_seed(struct inode *inode)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	struct ext4_sb_info *sbi = EXT4_SB(inode->i_sb);
	__le32 inum = cpu_to_le32(inode->i_ino);
	__le32 gen = cpu_to_le32(inode->i_generation);
	__u32 csum;

	if (!ext4_has_metadata_csum(inode->i_sb))
		return;

	csum = ext4_chksum(sbi, sbi->s_csum_seed, (__u8 *)&inum, sizeof(inum));
	ei->i_csum_seed = ext4_chksum(sbi, csum, (__u8 *)&gen, sizeof(gen));
}

104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119
/**
 * Swap the information from the given @inode and the inode
 * EXT4_BOOT_LOADER_INO. It will basically swap i_data and all other
 * important fields of the inodes.
 *
 * @sb:         the super block of the filesystem
 * @inode:      the inode to swap with EXT4_BOOT_LOADER_INO
 *
 */
static long swap_inode_boot_loader(struct super_block *sb,
				struct inode *inode)
{
	handle_t *handle;
	int err;
	struct inode *inode_bl;
	struct ext4_inode_info *ei_bl;
120 121 122
	qsize_t size, size_bl, diff;
	blkcnt_t blocks;
	unsigned short bytes;
123

124
	inode_bl = ext4_iget(sb, EXT4_BOOT_LOADER_INO, EXT4_IGET_SPECIAL);
125 126
	if (IS_ERR(inode_bl))
		return PTR_ERR(inode_bl);
127 128 129 130
	ei_bl = EXT4_I(inode_bl);

	/* Protect orig inodes against a truncate and make sure,
	 * that only 1 swap_inode_boot_loader is running. */
131
	lock_two_nondirectories(inode, inode_bl);
132

133 134 135 136 137 138 139 140 141 142 143 144 145
	if (inode->i_nlink != 1 || !S_ISREG(inode->i_mode) ||
	    IS_SWAPFILE(inode) || IS_ENCRYPTED(inode) ||
	    ext4_has_inline_data(inode)) {
		err = -EINVAL;
		goto journal_err_out;
	}

	if (IS_RDONLY(inode) || IS_APPEND(inode) || IS_IMMUTABLE(inode) ||
	    !inode_owner_or_capable(inode) || !capable(CAP_SYS_ADMIN)) {
		err = -EPERM;
		goto journal_err_out;
	}

146 147 148 149 150 151 152 153 154
	down_write(&EXT4_I(inode)->i_mmap_sem);
	err = filemap_write_and_wait(inode->i_mapping);
	if (err)
		goto err_out;

	err = filemap_write_and_wait(inode_bl->i_mapping);
	if (err)
		goto err_out;

155 156 157 158
	/* Wait for all existing dio workers */
	inode_dio_wait(inode);
	inode_dio_wait(inode_bl);

T
Theodore Ts'o 已提交
159 160 161
	truncate_inode_pages(&inode->i_data, 0);
	truncate_inode_pages(&inode_bl->i_data, 0);

162 163 164
	handle = ext4_journal_start(inode_bl, EXT4_HT_MOVE_EXTENTS, 2);
	if (IS_ERR(handle)) {
		err = -EINVAL;
165
		goto err_out;
166 167 168 169 170 171 172 173 174 175 176 177
	}

	/* Protect extent tree against block allocations via delalloc */
	ext4_double_down_write_data_sem(inode, inode_bl);

	if (inode_bl->i_nlink == 0) {
		/* this inode has never been used as a BOOT_LOADER */
		set_nlink(inode_bl, 1);
		i_uid_write(inode_bl, 0);
		i_gid_write(inode_bl, 0);
		inode_bl->i_flags = 0;
		ei_bl->i_flags = 0;
J
Jeff Layton 已提交
178
		inode_set_iversion(inode_bl, 1);
179 180
		i_size_write(inode_bl, 0);
		inode_bl->i_mode = S_IFREG;
181
		if (ext4_has_feature_extents(sb)) {
182 183 184 185 186 187
			ext4_set_inode_flag(inode_bl, EXT4_INODE_EXTENTS);
			ext4_ext_tree_init(handle, inode_bl);
		} else
			memset(ei_bl->i_data, 0, sizeof(ei_bl->i_data));
	}

188 189 190 191 192 193 194
	err = dquot_initialize(inode);
	if (err)
		goto err_out1;

	size = (qsize_t)(inode->i_blocks) * (1 << 9) + inode->i_bytes;
	size_bl = (qsize_t)(inode_bl->i_blocks) * (1 << 9) + inode_bl->i_bytes;
	diff = size - size_bl;
195 196
	swap_inode_data(inode, inode_bl);

197
	inode->i_ctime = inode_bl->i_ctime = current_time(inode);
198

199 200
	inode->i_generation = prandom_u32();
	inode_bl->i_generation = prandom_u32();
T
Theodore Ts'o 已提交
201 202
	reset_inode_seed(inode);
	reset_inode_seed(inode_bl);
203 204 205 206 207

	ext4_discard_preallocations(inode);

	err = ext4_mark_inode_dirty(handle, inode);
	if (err < 0) {
208
		/* No need to update quota information. */
209 210 211 212 213
		ext4_warning(inode->i_sb,
			"couldn't mark inode #%lu dirty (err %d)",
			inode->i_ino, err);
		/* Revert all changes: */
		swap_inode_data(inode, inode_bl);
T
Theodore Ts'o 已提交
214
		ext4_mark_inode_dirty(handle, inode);
215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244
		goto err_out1;
	}

	blocks = inode_bl->i_blocks;
	bytes = inode_bl->i_bytes;
	inode_bl->i_blocks = inode->i_blocks;
	inode_bl->i_bytes = inode->i_bytes;
	err = ext4_mark_inode_dirty(handle, inode_bl);
	if (err < 0) {
		/* No need to update quota information. */
		ext4_warning(inode_bl->i_sb,
			"couldn't mark inode #%lu dirty (err %d)",
			inode_bl->i_ino, err);
		goto revert;
	}

	/* Bootloader inode should not be counted into quota information. */
	if (diff > 0)
		dquot_free_space(inode, diff);
	else
		err = dquot_alloc_space(inode, -1 * diff);

	if (err < 0) {
revert:
		/* Revert all changes: */
		inode_bl->i_blocks = blocks;
		inode_bl->i_bytes = bytes;
		swap_inode_data(inode, inode_bl);
		ext4_mark_inode_dirty(handle, inode);
		ext4_mark_inode_dirty(handle, inode_bl);
245
	}
246 247

err_out1:
248 249 250
	ext4_journal_stop(handle);
	ext4_double_up_write_data_sem(inode, inode_bl);

251 252
err_out:
	up_write(&EXT4_I(inode)->i_mmap_sem);
253
journal_err_out:
254
	unlock_two_nondirectories(inode, inode_bl);
255 256 257 258
	iput(inode_bl);
	return err;
}

259
#ifdef CONFIG_EXT4_FS_ENCRYPTION
260 261 262 263 264 265 266 267 268
static int uuid_is_zero(__u8 u[16])
{
	int	i;

	for (i = 0; i < 16; i++)
		if (u[i])
			return 0;
	return 1;
}
269
#endif
270

271 272 273 274 275
static int ext4_ioctl_setflags(struct inode *inode,
			       unsigned int flags)
{
	struct ext4_inode_info *ei = EXT4_I(inode);
	handle_t *handle = NULL;
276
	int err = -EPERM, migrate = 0;
277 278 279 280 281
	struct ext4_iloc iloc;
	unsigned int oldflags, mask, i;
	unsigned int jflag;

	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
282
	if (ext4_is_quota_file(inode))
283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317
		goto flags_out;

	oldflags = ei->i_flags;

	/* The JOURNAL_DATA flag is modifiable only by root */
	jflag = flags & EXT4_JOURNAL_DATA_FL;

	/*
	 * The IMMUTABLE and APPEND_ONLY flags can only be changed by
	 * the relevant capability.
	 *
	 * This test looks nicer. Thanks to Pauline Middelink
	 */
	if ((flags ^ oldflags) & (EXT4_APPEND_FL | EXT4_IMMUTABLE_FL)) {
		if (!capable(CAP_LINUX_IMMUTABLE))
			goto flags_out;
	}

	/*
	 * The JOURNAL_DATA flag can only be changed by
	 * the relevant capability.
	 */
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		if (!capable(CAP_SYS_RESOURCE))
			goto flags_out;
	}
	if ((flags ^ oldflags) & EXT4_EXTENTS_FL)
		migrate = 1;

	if (flags & EXT4_EOFBLOCKS_FL) {
		/* we don't support adding EOFBLOCKS flag */
		if (!(oldflags & EXT4_EOFBLOCKS_FL)) {
			err = -EOPNOTSUPP;
			goto flags_out;
		}
318 319 320 321 322
	} else if (oldflags & EXT4_EOFBLOCKS_FL) {
		err = ext4_truncate(inode);
		if (err)
			goto flags_out;
	}
323 324 325 326 327 328 329 330 331 332 333 334 335 336 337

	handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
	if (IS_ERR(handle)) {
		err = PTR_ERR(handle);
		goto flags_out;
	}
	if (IS_SYNC(inode))
		ext4_handle_sync(handle);
	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto flags_err;

	for (i = 0, mask = 1; i < 32; i++, mask <<= 1) {
		if (!(mask & EXT4_FL_USER_MODIFIABLE))
			continue;
338 339 340
		/* These flags get special treatment later */
		if (mask == EXT4_JOURNAL_DATA_FL || mask == EXT4_EXTENTS_FL)
			continue;
341 342 343 344 345 346 347
		if (mask & flags)
			ext4_set_inode_flag(inode, i);
		else
			ext4_clear_inode_flag(inode, i);
	}

	ext4_set_inode_flags(inode);
348
	inode->i_ctime = current_time(inode);
349 350 351 352 353 354 355

	err = ext4_mark_iloc_dirty(handle, inode, &iloc);
flags_err:
	ext4_journal_stop(handle);
	if (err)
		goto flags_out;

356 357 358 359 360 361 362 363 364 365
	if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
		/*
		 * Changes to the journaling mode can cause unsafe changes to
		 * S_DAX if we are using the DAX mount option.
		 */
		if (test_opt(inode->i_sb, DAX)) {
			err = -EBUSY;
			goto flags_out;
		}

366
		err = ext4_change_inode_journal_flag(inode, jflag);
367 368 369
		if (err)
			goto flags_out;
	}
370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391
	if (migrate) {
		if (flags & EXT4_EXTENTS_FL)
			err = ext4_ext_migrate(inode);
		else
			err = ext4_ind_migrate(inode);
	}

flags_out:
	return err;
}

#ifdef CONFIG_QUOTA
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	struct inode *inode = file_inode(filp);
	struct super_block *sb = inode->i_sb;
	struct ext4_inode_info *ei = EXT4_I(inode);
	int err, rc;
	handle_t *handle;
	kprojid_t kprojid;
	struct ext4_iloc iloc;
	struct ext4_inode *raw_inode;
392
	struct dquot *transfer_to[MAXQUOTAS] = { };
393

K
Kaho Ng 已提交
394
	if (!ext4_has_feature_project(sb)) {
395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410
		if (projid != EXT4_DEF_PROJID)
			return -EOPNOTSUPP;
		else
			return 0;
	}

	if (EXT4_INODE_SIZE(sb) <= EXT4_GOOD_OLD_INODE_SIZE)
		return -EOPNOTSUPP;

	kprojid = make_kprojid(&init_user_ns, (projid_t)projid);

	if (projid_eq(kprojid, EXT4_I(inode)->i_projid))
		return 0;

	err = -EPERM;
	/* Is it quota file? Do not allow user to mess with it */
T
Tahsin Erdogan 已提交
411
	if (ext4_is_quota_file(inode))
412
		return err;
413 414 415

	err = ext4_get_inode_loc(inode, &iloc);
	if (err)
416
		return err;
417 418 419

	raw_inode = ext4_raw_inode(&iloc);
	if (!EXT4_FITS_IN_INODE(raw_inode, ei, i_projid)) {
420 421 422 423
		err = ext4_expand_extra_isize(inode,
					      EXT4_SB(sb)->s_want_extra_isize,
					      &iloc);
		if (err)
424
			return err;
425
	} else {
426 427 428
		brelse(iloc.bh);
	}

429 430 431
	err = dquot_initialize(inode);
	if (err)
		return err;
432 433 434 435

	handle = ext4_journal_start(inode, EXT4_HT_QUOTA,
		EXT4_QUOTA_INIT_BLOCKS(sb) +
		EXT4_QUOTA_DEL_BLOCKS(sb) + 3);
436 437
	if (IS_ERR(handle))
		return PTR_ERR(handle);
438 439 440 441 442

	err = ext4_reserve_inode_write(handle, inode, &iloc);
	if (err)
		goto out_stop;

443 444
	transfer_to[PRJQUOTA] = dqget(sb, make_kqid_projid(kprojid));
	if (!IS_ERR(transfer_to[PRJQUOTA])) {
445 446 447 448 449

		/* __dquot_transfer() calls back ext4_get_inode_usage() which
		 * counts xattr inode references.
		 */
		down_read(&EXT4_I(inode)->xattr_sem);
450
		err = __dquot_transfer(inode, transfer_to);
451
		up_read(&EXT4_I(inode)->xattr_sem);
452 453 454
		dqput(transfer_to[PRJQUOTA]);
		if (err)
			goto out_dirty;
455
	}
456

457
	EXT4_I(inode)->i_projid = kprojid;
458
	inode->i_ctime = current_time(inode);
459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495
out_dirty:
	rc = ext4_mark_iloc_dirty(handle, inode, &iloc);
	if (!err)
		err = rc;
out_stop:
	ext4_journal_stop(handle);
	return err;
}
#else
static int ext4_ioctl_setproject(struct file *filp, __u32 projid)
{
	if (projid != EXT4_DEF_PROJID)
		return -EOPNOTSUPP;
	return 0;
}
#endif

/* Transfer internal flags to xflags */
static inline __u32 ext4_iflags_to_xflags(unsigned long iflags)
{
	__u32 xflags = 0;

	if (iflags & EXT4_SYNC_FL)
		xflags |= FS_XFLAG_SYNC;
	if (iflags & EXT4_IMMUTABLE_FL)
		xflags |= FS_XFLAG_IMMUTABLE;
	if (iflags & EXT4_APPEND_FL)
		xflags |= FS_XFLAG_APPEND;
	if (iflags & EXT4_NODUMP_FL)
		xflags |= FS_XFLAG_NODUMP;
	if (iflags & EXT4_NOATIME_FL)
		xflags |= FS_XFLAG_NOATIME;
	if (iflags & EXT4_PROJINHERIT_FL)
		xflags |= FS_XFLAG_PROJINHERIT;
	return xflags;
}

496 497 498 499
#define EXT4_SUPPORTED_FS_XFLAGS (FS_XFLAG_SYNC | FS_XFLAG_IMMUTABLE | \
				  FS_XFLAG_APPEND | FS_XFLAG_NODUMP | \
				  FS_XFLAG_NOATIME | FS_XFLAG_PROJINHERIT)

500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520
/* Transfer xflags flags to internal */
static inline unsigned long ext4_xflags_to_iflags(__u32 xflags)
{
	unsigned long iflags = 0;

	if (xflags & FS_XFLAG_SYNC)
		iflags |= EXT4_SYNC_FL;
	if (xflags & FS_XFLAG_IMMUTABLE)
		iflags |= EXT4_IMMUTABLE_FL;
	if (xflags & FS_XFLAG_APPEND)
		iflags |= EXT4_APPEND_FL;
	if (xflags & FS_XFLAG_NODUMP)
		iflags |= EXT4_NODUMP_FL;
	if (xflags & FS_XFLAG_NOATIME)
		iflags |= EXT4_NOATIME_FL;
	if (xflags & FS_XFLAG_PROJINHERIT)
		iflags |= EXT4_PROJINHERIT_FL;

	return iflags;
}

E
Eric Biggers 已提交
521
static int ext4_shutdown(struct super_block *sb, unsigned long arg)
522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538
{
	struct ext4_sb_info *sbi = EXT4_SB(sb);
	__u32 flags;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (get_user(flags, (__u32 __user *)arg))
		return -EFAULT;

	if (flags > EXT4_GOING_FLAGS_NOLOGFLUSH)
		return -EINVAL;

	if (ext4_forced_shutdown(sbi))
		return 0;

	ext4_msg(sb, KERN_ALERT, "shut down requested (%d)", flags);
539
	trace_ext4_shutdown(sb, flags);
540 541 542 543 544 545 546 547 548 549 550

	switch (flags) {
	case EXT4_GOING_FLAGS_DEFAULT:
		freeze_bdev(sb->s_bdev);
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		thaw_bdev(sb->s_bdev, sb);
		break;
	case EXT4_GOING_FLAGS_LOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal)) {
			(void) ext4_force_commit(sb);
551
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
552 553 554 555
		}
		break;
	case EXT4_GOING_FLAGS_NOLOGFLUSH:
		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
556
		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal))
557
			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
558 559 560 561 562 563 564 565
		break;
	default:
		return -EINVAL;
	}
	clear_opt(sb, DISCARD);
	return 0;
}

D
Darrick J. Wong 已提交
566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649
struct getfsmap_info {
	struct super_block	*gi_sb;
	struct fsmap_head __user *gi_data;
	unsigned int		gi_idx;
	__u32			gi_last_flags;
};

static int ext4_getfsmap_format(struct ext4_fsmap *xfm, void *priv)
{
	struct getfsmap_info *info = priv;
	struct fsmap fm;

	trace_ext4_getfsmap_mapping(info->gi_sb, xfm);

	info->gi_last_flags = xfm->fmr_flags;
	ext4_fsmap_from_internal(info->gi_sb, &fm, xfm);
	if (copy_to_user(&info->gi_data->fmh_recs[info->gi_idx++], &fm,
			sizeof(struct fsmap)))
		return -EFAULT;

	return 0;
}

static int ext4_ioc_getfsmap(struct super_block *sb,
			     struct fsmap_head __user *arg)
{
	struct getfsmap_info info = {0};
	struct ext4_fsmap_head xhead = {0};
	struct fsmap_head head;
	bool aborted = false;
	int error;

	if (copy_from_user(&head, arg, sizeof(struct fsmap_head)))
		return -EFAULT;
	if (memchr_inv(head.fmh_reserved, 0, sizeof(head.fmh_reserved)) ||
	    memchr_inv(head.fmh_keys[0].fmr_reserved, 0,
		       sizeof(head.fmh_keys[0].fmr_reserved)) ||
	    memchr_inv(head.fmh_keys[1].fmr_reserved, 0,
		       sizeof(head.fmh_keys[1].fmr_reserved)))
		return -EINVAL;
	/*
	 * ext4 doesn't report file extents at all, so the only valid
	 * file offsets are the magic ones (all zeroes or all ones).
	 */
	if (head.fmh_keys[0].fmr_offset ||
	    (head.fmh_keys[1].fmr_offset != 0 &&
	     head.fmh_keys[1].fmr_offset != -1ULL))
		return -EINVAL;

	xhead.fmh_iflags = head.fmh_iflags;
	xhead.fmh_count = head.fmh_count;
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[0], &head.fmh_keys[0]);
	ext4_fsmap_to_internal(sb, &xhead.fmh_keys[1], &head.fmh_keys[1]);

	trace_ext4_getfsmap_low_key(sb, &xhead.fmh_keys[0]);
	trace_ext4_getfsmap_high_key(sb, &xhead.fmh_keys[1]);

	info.gi_sb = sb;
	info.gi_data = arg;
	error = ext4_getfsmap(sb, &xhead, ext4_getfsmap_format, &info);
	if (error == EXT4_QUERY_RANGE_ABORT) {
		error = 0;
		aborted = true;
	} else if (error)
		return error;

	/* If we didn't abort, set the "last" flag in the last fmx */
	if (!aborted && info.gi_idx) {
		info.gi_last_flags |= FMR_OF_LAST;
		if (copy_to_user(&info.gi_data->fmh_recs[info.gi_idx - 1].fmr_flags,
				 &info.gi_last_flags,
				 sizeof(info.gi_last_flags)))
			return -EFAULT;
	}

	/* copy back header */
	head.fmh_entries = xhead.fmh_entries;
	head.fmh_oflags = xhead.fmh_oflags;
	if (copy_to_user(arg, &head, sizeof(struct fsmap_head)))
		return -EFAULT;

	return 0;
}

650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687
static long ext4_ioctl_group_add(struct file *file,
				 struct ext4_new_group_data *input)
{
	struct super_block *sb = file_inode(file)->i_sb;
	int err, err2=0;

	err = ext4_resize_begin(sb);
	if (err)
		return err;

	if (ext4_has_feature_bigalloc(sb)) {
		ext4_msg(sb, KERN_ERR,
			 "Online resizing not supported with bigalloc");
		err = -EOPNOTSUPP;
		goto group_add_out;
	}

	err = mnt_want_write_file(file);
	if (err)
		goto group_add_out;

	err = ext4_group_add(sb, input);
	if (EXT4_SB(sb)->s_journal) {
		jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
		err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
		jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
	}
	if (err == 0)
		err = err2;
	mnt_drop_write_file(file);
	if (!err && ext4_has_group_desc_csum(sb) &&
	    test_opt(sb, INIT_INODE_TABLE))
		err = ext4_register_li_request(sb, input->group);
group_add_out:
	ext4_resize_end(sb);
	return err;
}

688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711
static int ext4_ioctl_check_project(struct inode *inode, struct fsxattr *fa)
{
	/*
	 * Project Quota ID state is only allowed to change from within the init
	 * namespace. Enforce that restriction only if we are trying to change
	 * the quota ID state. Everything else is allowed in user namespaces.
	 */
	if (current_user_ns() == &init_user_ns)
		return 0;

	if (__kprojid_val(EXT4_I(inode)->i_projid) != fa->fsx_projid)
		return -EINVAL;

	if (ext4_test_inode_flag(inode, EXT4_INODE_PROJINHERIT)) {
		if (!(fa->fsx_xflags & FS_XFLAG_PROJINHERIT))
			return -EINVAL;
	} else {
		if (fa->fsx_xflags & FS_XFLAG_PROJINHERIT)
			return -EINVAL;
	}

	return 0;
}

A
Andi Kleen 已提交
712
long ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
713
{
A
Al Viro 已提交
714
	struct inode *inode = file_inode(filp);
715
	struct super_block *sb = inode->i_sb;
716
	struct ext4_inode_info *ei = EXT4_I(inode);
717 718
	unsigned int flags;

719
	ext4_debug("cmd = %u, arg = %lu\n", cmd, arg);
720 721

	switch (cmd) {
D
Darrick J. Wong 已提交
722 723
	case FS_IOC_GETFSMAP:
		return ext4_ioc_getfsmap(sb, (void __user *)arg);
724 725
	case EXT4_IOC_GETFLAGS:
		flags = ei->i_flags & EXT4_FL_USER_VISIBLE;
726
		return put_user(flags, (int __user *) arg);
727
	case EXT4_IOC_SETFLAGS: {
728
		int err;
729

730
		if (!inode_owner_or_capable(inode))
731 732 733 734 735
			return -EACCES;

		if (get_user(flags, (int __user *) arg))
			return -EFAULT;

736 737 738 739 740 741 742 743 744 745 746 747
		if (flags & ~EXT4_FL_USER_VISIBLE)
			return -EOPNOTSUPP;
		/*
		 * chattr(1) grabs flags via GETFLAGS, modifies the result and
		 * passes that to SETFLAGS. So we cannot easily make SETFLAGS
		 * more restrictive than just silently masking off visible but
		 * not settable flags as we always did.
		 */
		flags &= EXT4_FL_USER_MODIFIABLE;
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

748
		err = mnt_want_write_file(filp);
749 750 751
		if (err)
			return err;

A
Al Viro 已提交
752
		inode_lock(inode);
753
		err = ext4_ioctl_setflags(inode, flags);
A
Al Viro 已提交
754
		inode_unlock(inode);
A
Al Viro 已提交
755
		mnt_drop_write_file(filp);
756 757
		return err;
	}
758 759
	case EXT4_IOC_GETVERSION:
	case EXT4_IOC_GETVERSION_OLD:
760
		return put_user(inode->i_generation, (int __user *) arg);
761 762
	case EXT4_IOC_SETVERSION:
	case EXT4_IOC_SETVERSION_OLD: {
763
		handle_t *handle;
764
		struct ext4_iloc iloc;
765 766 767
		__u32 generation;
		int err;

768
		if (!inode_owner_or_capable(inode))
769
			return -EPERM;
770

771
		if (ext4_has_metadata_csum(inode->i_sb)) {
772 773 774 775 776
			ext4_warning(sb, "Setting inode version is not "
				     "supported with metadata_csum enabled.");
			return -ENOTTY;
		}

777
		err = mnt_want_write_file(filp);
778 779 780 781 782 783
		if (err)
			return err;
		if (get_user(generation, (int __user *) arg)) {
			err = -EFAULT;
			goto setversion_out;
		}
784

A
Al Viro 已提交
785
		inode_lock(inode);
786
		handle = ext4_journal_start(inode, EXT4_HT_INODE, 1);
787 788
		if (IS_ERR(handle)) {
			err = PTR_ERR(handle);
789
			goto unlock_out;
790
		}
791
		err = ext4_reserve_inode_write(handle, inode, &iloc);
792
		if (err == 0) {
793
			inode->i_ctime = current_time(inode);
794
			inode->i_generation = generation;
795
			err = ext4_mark_iloc_dirty(handle, inode, &iloc);
796
		}
797
		ext4_journal_stop(handle);
798 799

unlock_out:
A
Al Viro 已提交
800
		inode_unlock(inode);
801
setversion_out:
A
Al Viro 已提交
802
		mnt_drop_write_file(filp);
803 804
		return err;
	}
805 806
	case EXT4_IOC_GROUP_EXTEND: {
		ext4_fsblk_t n_blocks_count;
807
		int err, err2=0;
808

809 810 811
		err = ext4_resize_begin(sb);
		if (err)
			return err;
812

813 814 815 816
		if (get_user(n_blocks_count, (__u32 __user *)arg)) {
			err = -EFAULT;
			goto group_extend_out;
		}
817

818
		if (ext4_has_feature_bigalloc(sb)) {
819 820
			ext4_msg(sb, KERN_ERR,
				 "Online resizing not supported with bigalloc");
821 822
			err = -EOPNOTSUPP;
			goto group_extend_out;
823 824
		}

825
		err = mnt_want_write_file(filp);
826
		if (err)
827
			goto group_extend_out;
828

829
		err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
830 831 832 833 834
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
835 836
		if (err == 0)
			err = err2;
A
Al Viro 已提交
837
		mnt_drop_write_file(filp);
838
group_extend_out:
839
		ext4_resize_end(sb);
840 841
		return err;
	}
842 843 844

	case EXT4_IOC_MOVE_EXT: {
		struct move_extent me;
845 846
		struct fd donor;
		int err;
847

848 849 850 851
		if (!(filp->f_mode & FMODE_READ) ||
		    !(filp->f_mode & FMODE_WRITE))
			return -EBADF;

852 853 854
		if (copy_from_user(&me,
			(struct move_extent __user *)arg, sizeof(me)))
			return -EFAULT;
855
		me.moved_len = 0;
856

857 858
		donor = fdget(me.donor_fd);
		if (!donor.file)
859 860
			return -EBADF;

861
		if (!(donor.file->f_mode & FMODE_WRITE)) {
862 863
			err = -EBADF;
			goto mext_out;
864 865
		}

866
		if (ext4_has_feature_bigalloc(sb)) {
867 868
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with bigalloc");
869 870
			err = -EOPNOTSUPP;
			goto mext_out;
871 872 873 874 875
		} else if (IS_DAX(inode)) {
			ext4_msg(sb, KERN_ERR,
				 "Online defrag not supported with DAX");
			err = -EOPNOTSUPP;
			goto mext_out;
876 877
		}

878
		err = mnt_want_write_file(filp);
879 880 881
		if (err)
			goto mext_out;

882
		err = ext4_move_extents(filp, donor.file, me.orig_start,
883
					me.donor_start, me.len, &me.moved_len);
A
Al Viro 已提交
884
		mnt_drop_write_file(filp);
885

886
		if (copy_to_user((struct move_extent __user *)arg,
887
				 &me, sizeof(me)))
888 889
			err = -EFAULT;
mext_out:
890
		fdput(donor);
891 892 893
		return err;
	}

894 895
	case EXT4_IOC_GROUP_ADD: {
		struct ext4_new_group_data input;
896

897
		if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
898 899
				sizeof(input)))
			return -EFAULT;
900

901
		return ext4_ioctl_group_add(filp, &input);
902 903
	}

904
	case EXT4_IOC_MIGRATE:
905 906
	{
		int err;
907
		if (!inode_owner_or_capable(inode))
908 909
			return -EACCES;

910
		err = mnt_want_write_file(filp);
911 912 913 914 915 916 917 918
		if (err)
			return err;
		/*
		 * inode_mutex prevent write and truncate on the file.
		 * Read still goes through. We take i_data_sem in
		 * ext4_ext_swap_inode_data before we switch the
		 * inode format to prevent read.
		 */
A
Al Viro 已提交
919
		inode_lock((inode));
920
		err = ext4_ext_migrate(inode);
A
Al Viro 已提交
921
		inode_unlock((inode));
A
Al Viro 已提交
922
		mnt_drop_write_file(filp);
923 924
		return err;
	}
925

926 927 928
	case EXT4_IOC_ALLOC_DA_BLKS:
	{
		int err;
929
		if (!inode_owner_or_capable(inode))
930 931
			return -EACCES;

932
		err = mnt_want_write_file(filp);
933 934 935
		if (err)
			return err;
		err = ext4_alloc_da_blocks(inode);
A
Al Viro 已提交
936
		mnt_drop_write_file(filp);
937 938 939
		return err;
	}

940
	case EXT4_IOC_SWAP_BOOT:
941 942
	{
		int err;
943 944
		if (!(filp->f_mode & FMODE_WRITE))
			return -EBADF;
945 946 947 948 949 950 951
		err = mnt_want_write_file(filp);
		if (err)
			return err;
		err = swap_inode_boot_loader(sb, inode);
		mnt_drop_write_file(filp);
		return err;
	}
952

953 954 955
	case EXT4_IOC_RESIZE_FS: {
		ext4_fsblk_t n_blocks_count;
		int err = 0, err2 = 0;
956
		ext4_group_t o_group = EXT4_SB(sb)->s_groups_count;
957 958 959 960 961 962 963 964 965 966

		if (copy_from_user(&n_blocks_count, (__u64 __user *)arg,
				   sizeof(__u64))) {
			return -EFAULT;
		}

		err = ext4_resize_begin(sb);
		if (err)
			return err;

967
		err = mnt_want_write_file(filp);
968 969 970 971 972 973 974 975 976 977 978
		if (err)
			goto resizefs_out;

		err = ext4_resize_fs(sb, n_blocks_count);
		if (EXT4_SB(sb)->s_journal) {
			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
		}
		if (err == 0)
			err = err2;
979
		mnt_drop_write_file(filp);
980
		if (!err && (o_group < EXT4_SB(sb)->s_groups_count) &&
981 982 983 984
		    ext4_has_group_desc_csum(sb) &&
		    test_opt(sb, INIT_INODE_TABLE))
			err = ext4_register_li_request(sb, o_group);

985 986 987 988 989
resizefs_out:
		ext4_resize_end(sb);
		return err;
	}

990 991
	case FITRIM:
	{
992
		struct request_queue *q = bdev_get_queue(sb->s_bdev);
993 994 995 996 997 998
		struct fstrim_range range;
		int ret = 0;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

999 1000 1001
		if (!blk_queue_discard(q))
			return -EOPNOTSUPP;

1002 1003 1004 1005 1006 1007 1008
		/*
		 * We haven't replayed the journal, so we cannot use our
		 * block-bitmap-guided storage zapping commands.
		 */
		if (test_opt(sb, NOLOAD) && ext4_has_feature_journal(sb))
			return -EROFS;

1009
		if (copy_from_user(&range, (struct fstrim_range __user *)arg,
1010 1011 1012
		    sizeof(range)))
			return -EFAULT;

1013 1014
		range.minlen = max((unsigned int)range.minlen,
				   q->limits.discard_granularity);
1015 1016 1017 1018
		ret = ext4_trim_fs(sb, &range);
		if (ret < 0)
			return ret;

1019
		if (copy_to_user((struct fstrim_range __user *)arg, &range,
1020 1021 1022 1023 1024
		    sizeof(range)))
			return -EFAULT;

		return 0;
	}
1025 1026
	case EXT4_IOC_PRECACHE_EXTENTS:
		return ext4_ext_precache(inode);
1027

1028
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
1029 1030
		if (!ext4_has_feature_encrypt(sb))
			return -EOPNOTSUPP;
1031
		return fscrypt_ioctl_set_policy(filp, (const void __user *)arg);
1032

1033
	case EXT4_IOC_GET_ENCRYPTION_PWSALT: {
1034
#ifdef CONFIG_EXT4_FS_ENCRYPTION
1035 1036 1037 1038
		int err, err2;
		struct ext4_sb_info *sbi = EXT4_SB(sb);
		handle_t *handle;

1039
		if (!ext4_has_feature_encrypt(sb))
1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064
			return -EOPNOTSUPP;
		if (uuid_is_zero(sbi->s_es->s_encrypt_pw_salt)) {
			err = mnt_want_write_file(filp);
			if (err)
				return err;
			handle = ext4_journal_start_sb(sb, EXT4_HT_MISC, 1);
			if (IS_ERR(handle)) {
				err = PTR_ERR(handle);
				goto pwsalt_err_exit;
			}
			err = ext4_journal_get_write_access(handle, sbi->s_sbh);
			if (err)
				goto pwsalt_err_journal;
			generate_random_uuid(sbi->s_es->s_encrypt_pw_salt);
			err = ext4_handle_dirty_metadata(handle, NULL,
							 sbi->s_sbh);
		pwsalt_err_journal:
			err2 = ext4_journal_stop(handle);
			if (err2 && !err)
				err = err2;
		pwsalt_err_exit:
			mnt_drop_write_file(filp);
			if (err)
				return err;
		}
1065 1066
		if (copy_to_user((void __user *) arg,
				 sbi->s_es->s_encrypt_pw_salt, 16))
1067 1068
			return -EFAULT;
		return 0;
1069 1070 1071
#else
		return -EOPNOTSUPP;
#endif
1072
	}
1073 1074
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
		return fscrypt_ioctl_get_policy(filp, (void __user *)arg);
1075

1076 1077 1078 1079 1080 1081 1082
	case EXT4_IOC_FSGETXATTR:
	{
		struct fsxattr fa;

		memset(&fa, 0, sizeof(struct fsxattr));
		fa.fsx_xflags = ext4_iflags_to_xflags(ei->i_flags & EXT4_FL_USER_VISIBLE);

K
Kaho Ng 已提交
1083
		if (ext4_has_feature_project(inode->i_sb)) {
1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105
			fa.fsx_projid = (__u32)from_kprojid(&init_user_ns,
				EXT4_I(inode)->i_projid);
		}

		if (copy_to_user((struct fsxattr __user *)arg,
				 &fa, sizeof(fa)))
			return -EFAULT;
		return 0;
	}
	case EXT4_IOC_FSSETXATTR:
	{
		struct fsxattr fa;
		int err;

		if (copy_from_user(&fa, (struct fsxattr __user *)arg,
				   sizeof(fa)))
			return -EFAULT;

		/* Make sure caller has proper permission */
		if (!inode_owner_or_capable(inode))
			return -EACCES;

1106 1107 1108 1109 1110 1111 1112
		if (fa.fsx_xflags & ~EXT4_SUPPORTED_FS_XFLAGS)
			return -EOPNOTSUPP;

		flags = ext4_xflags_to_iflags(fa.fsx_xflags);
		if (ext4_mask_flags(inode->i_mode, flags) != flags)
			return -EOPNOTSUPP;

1113 1114 1115 1116
		err = mnt_want_write_file(filp);
		if (err)
			return err;

A
Al Viro 已提交
1117
		inode_lock(inode);
1118 1119 1120
		err = ext4_ioctl_check_project(inode, &fa);
		if (err)
			goto out;
1121 1122 1123 1124
		flags = (ei->i_flags & ~EXT4_FL_XFLAG_VISIBLE) |
			 (flags & EXT4_FL_XFLAG_VISIBLE);
		err = ext4_ioctl_setflags(inode, flags);
		if (err)
1125
			goto out;
1126
		err = ext4_ioctl_setproject(filp, fa.fsx_projid);
1127 1128 1129 1130
out:
		inode_unlock(inode);
		mnt_drop_write_file(filp);
		return err;
1131
	}
1132 1133
	case EXT4_IOC_SHUTDOWN:
		return ext4_shutdown(sb, arg);
1134 1135 1136 1137 1138 1139
	default:
		return -ENOTTY;
	}
}

#ifdef CONFIG_COMPAT
1140
long ext4_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
1141 1142 1143
{
	/* These are just misnamed, they actually get/put from/to user an int */
	switch (cmd) {
1144 1145
	case EXT4_IOC32_GETFLAGS:
		cmd = EXT4_IOC_GETFLAGS;
1146
		break;
1147 1148
	case EXT4_IOC32_SETFLAGS:
		cmd = EXT4_IOC_SETFLAGS;
1149
		break;
1150 1151
	case EXT4_IOC32_GETVERSION:
		cmd = EXT4_IOC_GETVERSION;
1152
		break;
1153 1154
	case EXT4_IOC32_SETVERSION:
		cmd = EXT4_IOC_SETVERSION;
1155
		break;
1156 1157
	case EXT4_IOC32_GROUP_EXTEND:
		cmd = EXT4_IOC_GROUP_EXTEND;
1158
		break;
1159 1160
	case EXT4_IOC32_GETVERSION_OLD:
		cmd = EXT4_IOC_GETVERSION_OLD;
1161
		break;
1162 1163
	case EXT4_IOC32_SETVERSION_OLD:
		cmd = EXT4_IOC_SETVERSION_OLD;
1164
		break;
1165 1166
	case EXT4_IOC32_GETRSVSZ:
		cmd = EXT4_IOC_GETRSVSZ;
1167
		break;
1168 1169
	case EXT4_IOC32_SETRSVSZ:
		cmd = EXT4_IOC_SETRSVSZ;
1170
		break;
1171 1172
	case EXT4_IOC32_GROUP_ADD: {
		struct compat_ext4_new_group_input __user *uinput;
1173
		struct ext4_new_group_data input;
1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185
		int err;

		uinput = compat_ptr(arg);
		err = get_user(input.group, &uinput->group);
		err |= get_user(input.block_bitmap, &uinput->block_bitmap);
		err |= get_user(input.inode_bitmap, &uinput->inode_bitmap);
		err |= get_user(input.inode_table, &uinput->inode_table);
		err |= get_user(input.blocks_count, &uinput->blocks_count);
		err |= get_user(input.reserved_blocks,
				&uinput->reserved_blocks);
		if (err)
			return -EFAULT;
1186
		return ext4_ioctl_group_add(file, &input);
1187
	}
1188
	case EXT4_IOC_MOVE_EXT:
1189
	case EXT4_IOC_RESIZE_FS:
1190
	case EXT4_IOC_PRECACHE_EXTENTS:
1191 1192 1193
	case EXT4_IOC_SET_ENCRYPTION_POLICY:
	case EXT4_IOC_GET_ENCRYPTION_PWSALT:
	case EXT4_IOC_GET_ENCRYPTION_POLICY:
1194
	case EXT4_IOC_SHUTDOWN:
D
Darrick J. Wong 已提交
1195
	case FS_IOC_GETFSMAP:
1196
		break;
1197 1198 1199
	default:
		return -ENOIOCTLCMD;
	}
A
Andi Kleen 已提交
1200
	return ext4_ioctl(file, cmd, (unsigned long) compat_ptr(arg));
1201 1202
}
#endif