quota.c 10.1 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11
/*
 * Quota code necessary even when VFS quota support is not compiled
 * into the kernel.  The interesting stuff is over in dquot.c, here
 * we have symbols for initial quotactl(2) handling, the sysctl(2)
 * variables, etc - things needed even when quota support disabled.
 */

#include <linux/fs.h>
#include <linux/namei.h>
#include <linux/slab.h>
#include <asm/current.h>
12
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
13 14 15
#include <linux/kernel.h>
#include <linux/security.h>
#include <linux/syscalls.h>
16
#include <linux/capability.h>
A
Adrian Bunk 已提交
17
#include <linux/quotaops.h>
18
#include <linux/types.h>
C
Christoph Hellwig 已提交
19
#include <linux/writeback.h>
L
Linus Torvalds 已提交
20

21 22
static int check_quotactl_permission(struct super_block *sb, int type, int cmd,
				     qid_t id)
L
Linus Torvalds 已提交
23
{
24 25 26 27 28 29 30 31 32 33 34
	switch (cmd) {
	/* these commands do not require any special privilegues */
	case Q_GETFMT:
	case Q_SYNC:
	case Q_GETINFO:
	case Q_XGETQSTAT:
	case Q_XQUOTASYNC:
		break;
	/* allow to query information for dquots we "own" */
	case Q_GETQUOTA:
	case Q_XGETQUOTA:
E
Eric W. Biederman 已提交
35 36
		if ((type == USRQUOTA && uid_eq(current_euid(), make_kuid(current_user_ns(), id))) ||
		    (type == GRPQUOTA && in_egroup_p(make_kgid(current_user_ns(), id))))
37 38 39
			break;
		/*FALLTHROUGH*/
	default:
L
Linus Torvalds 已提交
40 41 42 43
		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;
	}

44
	return security_quotactl(cmd, type, id, sb);
L
Linus Torvalds 已提交
45 46
}

A
Al Viro 已提交
47 48 49
static void quota_sync_one(struct super_block *sb, void *arg)
{
	if (sb->s_qcop && sb->s_qcop->quota_sync)
50
		sb->s_qcop->quota_sync(sb, *(int *)arg);
A
Al Viro 已提交
51 52
}

53
static int quota_sync_all(int type)
L
Linus Torvalds 已提交
54
{
55 56 57 58 59
	int ret;

	if (type >= MAXQUOTAS)
		return -EINVAL;
	ret = security_quotactl(Q_SYNC, type, 0, NULL);
A
Al Viro 已提交
60 61 62
	if (!ret)
		iterate_supers(quota_sync_one, &type);
	return ret;
L
Linus Torvalds 已提交
63 64
}

C
Christoph Hellwig 已提交
65
static int quota_quotaon(struct super_block *sb, int type, int cmd, qid_t id,
66
		         struct path *path)
L
Linus Torvalds 已提交
67
{
68 69 70 71 72 73 74
	if (!sb->s_qcop->quota_on && !sb->s_qcop->quota_on_meta)
		return -ENOSYS;
	if (sb->s_qcop->quota_on_meta)
		return sb->s_qcop->quota_on_meta(sb, type, id);
	if (IS_ERR(path))
		return PTR_ERR(path);
	return sb->s_qcop->quota_on(sb, type, id, path);
C
Christoph Hellwig 已提交
75
}
L
Linus Torvalds 已提交
76

C
Christoph Hellwig 已提交
77 78 79
static int quota_getfmt(struct super_block *sb, int type, void __user *addr)
{
	__u32 fmt;
L
Linus Torvalds 已提交
80

C
Christoph Hellwig 已提交
81 82 83 84 85 86 87 88 89 90 91
	down_read(&sb_dqopt(sb)->dqptr_sem);
	if (!sb_has_quota_active(sb, type)) {
		up_read(&sb_dqopt(sb)->dqptr_sem);
		return -ESRCH;
	}
	fmt = sb_dqopt(sb)->info[type].dqi_format->qf_fmt_id;
	up_read(&sb_dqopt(sb)->dqptr_sem);
	if (copy_to_user(addr, &fmt, sizeof(fmt)))
		return -EFAULT;
	return 0;
}
L
Linus Torvalds 已提交
92

C
Christoph Hellwig 已提交
93 94 95 96
static int quota_getinfo(struct super_block *sb, int type, void __user *addr)
{
	struct if_dqinfo info;
	int ret;
L
Linus Torvalds 已提交
97

98 99
	if (!sb->s_qcop->get_info)
		return -ENOSYS;
C
Christoph Hellwig 已提交
100 101 102 103 104
	ret = sb->s_qcop->get_info(sb, type, &info);
	if (!ret && copy_to_user(addr, &info, sizeof(info)))
		return -EFAULT;
	return ret;
}
L
Linus Torvalds 已提交
105

C
Christoph Hellwig 已提交
106 107 108
static int quota_setinfo(struct super_block *sb, int type, void __user *addr)
{
	struct if_dqinfo info;
L
Linus Torvalds 已提交
109

C
Christoph Hellwig 已提交
110 111
	if (copy_from_user(&info, addr, sizeof(info)))
		return -EFAULT;
112 113
	if (!sb->s_qcop->set_info)
		return -ENOSYS;
C
Christoph Hellwig 已提交
114 115 116
	return sb->s_qcop->set_info(sb, type, &info);
}

C
Christoph Hellwig 已提交
117 118 119 120 121 122 123 124 125 126 127 128 129
static void copy_to_if_dqblk(struct if_dqblk *dst, struct fs_disk_quota *src)
{
	dst->dqb_bhardlimit = src->d_blk_hardlimit;
	dst->dqb_bsoftlimit = src->d_blk_softlimit;
	dst->dqb_curspace = src->d_bcount;
	dst->dqb_ihardlimit = src->d_ino_hardlimit;
	dst->dqb_isoftlimit = src->d_ino_softlimit;
	dst->dqb_curinodes = src->d_icount;
	dst->dqb_btime = src->d_btimer;
	dst->dqb_itime = src->d_itimer;
	dst->dqb_valid = QIF_ALL;
}

C
Christoph Hellwig 已提交
130 131 132
static int quota_getquota(struct super_block *sb, int type, qid_t id,
			  void __user *addr)
{
E
Eric W. Biederman 已提交
133
	struct kqid qid;
C
Christoph Hellwig 已提交
134
	struct fs_disk_quota fdq;
C
Christoph Hellwig 已提交
135 136 137
	struct if_dqblk idq;
	int ret;

138 139
	if (!sb->s_qcop->get_dqblk)
		return -ENOSYS;
E
Eric W. Biederman 已提交
140 141 142 143
	qid = make_kqid(current_user_ns(), type, id);
	if (!qid_valid(qid))
		return -EINVAL;
	ret = sb->s_qcop->get_dqblk(sb, qid, &fdq);
C
Christoph Hellwig 已提交
144 145
	if (ret)
		return ret;
C
Christoph Hellwig 已提交
146
	copy_to_if_dqblk(&idq, &fdq);
C
Christoph Hellwig 已提交
147 148 149 150 151
	if (copy_to_user(addr, &idq, sizeof(idq)))
		return -EFAULT;
	return 0;
}

C
Christoph Hellwig 已提交
152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177
static void copy_from_if_dqblk(struct fs_disk_quota *dst, struct if_dqblk *src)
{
	dst->d_blk_hardlimit = src->dqb_bhardlimit;
	dst->d_blk_softlimit  = src->dqb_bsoftlimit;
	dst->d_bcount = src->dqb_curspace;
	dst->d_ino_hardlimit = src->dqb_ihardlimit;
	dst->d_ino_softlimit = src->dqb_isoftlimit;
	dst->d_icount = src->dqb_curinodes;
	dst->d_btimer = src->dqb_btime;
	dst->d_itimer = src->dqb_itime;

	dst->d_fieldmask = 0;
	if (src->dqb_valid & QIF_BLIMITS)
		dst->d_fieldmask |= FS_DQ_BSOFT | FS_DQ_BHARD;
	if (src->dqb_valid & QIF_SPACE)
		dst->d_fieldmask |= FS_DQ_BCOUNT;
	if (src->dqb_valid & QIF_ILIMITS)
		dst->d_fieldmask |= FS_DQ_ISOFT | FS_DQ_IHARD;
	if (src->dqb_valid & QIF_INODES)
		dst->d_fieldmask |= FS_DQ_ICOUNT;
	if (src->dqb_valid & QIF_BTIME)
		dst->d_fieldmask |= FS_DQ_BTIMER;
	if (src->dqb_valid & QIF_ITIME)
		dst->d_fieldmask |= FS_DQ_ITIMER;
}

C
Christoph Hellwig 已提交
178 179 180
static int quota_setquota(struct super_block *sb, int type, qid_t id,
			  void __user *addr)
{
C
Christoph Hellwig 已提交
181
	struct fs_disk_quota fdq;
C
Christoph Hellwig 已提交
182
	struct if_dqblk idq;
E
Eric W. Biederman 已提交
183
	struct kqid qid;
C
Christoph Hellwig 已提交
184 185 186

	if (copy_from_user(&idq, addr, sizeof(idq)))
		return -EFAULT;
187 188
	if (!sb->s_qcop->set_dqblk)
		return -ENOSYS;
E
Eric W. Biederman 已提交
189 190 191
	qid = make_kqid(current_user_ns(), type, id);
	if (!qid_valid(qid))
		return -EINVAL;
C
Christoph Hellwig 已提交
192
	copy_from_if_dqblk(&fdq, &idq);
E
Eric W. Biederman 已提交
193
	return sb->s_qcop->set_dqblk(sb, qid, &fdq);
C
Christoph Hellwig 已提交
194 195 196 197 198 199 200 201
}

static int quota_setxstate(struct super_block *sb, int cmd, void __user *addr)
{
	__u32 flags;

	if (copy_from_user(&flags, addr, sizeof(flags)))
		return -EFAULT;
202 203
	if (!sb->s_qcop->set_xstate)
		return -ENOSYS;
C
Christoph Hellwig 已提交
204 205 206 207 208 209 210
	return sb->s_qcop->set_xstate(sb, flags, cmd);
}

static int quota_getxstate(struct super_block *sb, void __user *addr)
{
	struct fs_quota_stat fqs;
	int ret;
211 212 213

	if (!sb->s_qcop->get_xstate)
		return -ENOSYS;
C
Christoph Hellwig 已提交
214 215 216 217 218
	ret = sb->s_qcop->get_xstate(sb, &fqs);
	if (!ret && copy_to_user(addr, &fqs, sizeof(fqs)))
		return -EFAULT;
	return ret;
}
L
Linus Torvalds 已提交
219

C
Christoph Hellwig 已提交
220 221 222 223
static int quota_setxquota(struct super_block *sb, int type, qid_t id,
			   void __user *addr)
{
	struct fs_disk_quota fdq;
E
Eric W. Biederman 已提交
224
	struct kqid qid;
C
Christoph Hellwig 已提交
225 226 227

	if (copy_from_user(&fdq, addr, sizeof(fdq)))
		return -EFAULT;
C
Christoph Hellwig 已提交
228
	if (!sb->s_qcop->set_dqblk)
229
		return -ENOSYS;
E
Eric W. Biederman 已提交
230 231 232 233
	qid = make_kqid(current_user_ns(), type, id);
	if (!qid_valid(qid))
		return -EINVAL;
	return sb->s_qcop->set_dqblk(sb, qid, &fdq);
C
Christoph Hellwig 已提交
234 235 236 237 238 239
}

static int quota_getxquota(struct super_block *sb, int type, qid_t id,
			   void __user *addr)
{
	struct fs_disk_quota fdq;
E
Eric W. Biederman 已提交
240
	struct kqid qid;
C
Christoph Hellwig 已提交
241 242
	int ret;

C
Christoph Hellwig 已提交
243
	if (!sb->s_qcop->get_dqblk)
244
		return -ENOSYS;
E
Eric W. Biederman 已提交
245 246 247 248
	qid = make_kqid(current_user_ns(), type, id);
	if (!qid_valid(qid))
		return -EINVAL;
	ret = sb->s_qcop->get_dqblk(sb, qid, &fdq);
C
Christoph Hellwig 已提交
249 250 251 252 253 254 255
	if (!ret && copy_to_user(addr, &fdq, sizeof(fdq)))
		return -EFAULT;
	return ret;
}

/* Copy parameters and call proper function */
static int do_quotactl(struct super_block *sb, int type, int cmd, qid_t id,
256
		       void __user *addr, struct path *path)
C
Christoph Hellwig 已提交
257
{
258 259 260 261 262 263 264 265 266 267 268
	int ret;

	if (type >= (XQM_COMMAND(cmd) ? XQM_MAXQUOTAS : MAXQUOTAS))
		return -EINVAL;
	if (!sb->s_qcop)
		return -ENOSYS;

	ret = check_quotactl_permission(sb, type, cmd, id);
	if (ret < 0)
		return ret;

C
Christoph Hellwig 已提交
269 270
	switch (cmd) {
	case Q_QUOTAON:
271
		return quota_quotaon(sb, type, cmd, id, path);
C
Christoph Hellwig 已提交
272
	case Q_QUOTAOFF:
273 274
		if (!sb->s_qcop->quota_off)
			return -ENOSYS;
275
		return sb->s_qcop->quota_off(sb, type);
C
Christoph Hellwig 已提交
276 277 278 279 280 281 282 283 284 285 286
	case Q_GETFMT:
		return quota_getfmt(sb, type, addr);
	case Q_GETINFO:
		return quota_getinfo(sb, type, addr);
	case Q_SETINFO:
		return quota_setinfo(sb, type, addr);
	case Q_GETQUOTA:
		return quota_getquota(sb, type, id, addr);
	case Q_SETQUOTA:
		return quota_setquota(sb, type, id, addr);
	case Q_SYNC:
287 288
		if (!sb->s_qcop->quota_sync)
			return -ENOSYS;
289
		return sb->s_qcop->quota_sync(sb, type);
C
Christoph Hellwig 已提交
290 291 292 293 294 295 296 297 298 299 300
	case Q_XQUOTAON:
	case Q_XQUOTAOFF:
	case Q_XQUOTARM:
		return quota_setxstate(sb, cmd, addr);
	case Q_XGETQSTAT:
		return quota_getxstate(sb, addr);
	case Q_XSETQLIM:
		return quota_setxquota(sb, type, id, addr);
	case Q_XGETQUOTA:
		return quota_getxquota(sb, type, id, addr);
	case Q_XQUOTASYNC:
C
Christoph Hellwig 已提交
301 302
		if (sb->s_flags & MS_RDONLY)
			return -EROFS;
303
		/* XFS quotas are fully coherent now, making this call a noop */
C
Christoph Hellwig 已提交
304
		return 0;
C
Christoph Hellwig 已提交
305
	default:
306
		return -EINVAL;
L
Linus Torvalds 已提交
307 308 309
	}
}

310 311
#ifdef CONFIG_BLOCK

312 313 314 315 316 317 318 319 320 321 322 323 324 325 326
/* Return 1 if 'cmd' will block on frozen filesystem */
static int quotactl_cmd_write(int cmd)
{
	switch (cmd) {
	case Q_GETFMT:
	case Q_GETINFO:
	case Q_SYNC:
	case Q_XGETQSTAT:
	case Q_XGETQUOTA:
	case Q_XQUOTASYNC:
		return 0;
	}
	return 1;
}

327 328
#endif /* CONFIG_BLOCK */

329 330 331 332
/*
 * look up a superblock on which quota ops will be performed
 * - use the name of a block device to find the superblock thereon
 */
333
static struct super_block *quotactl_block(const char __user *special, int cmd)
334 335 336 337
{
#ifdef CONFIG_BLOCK
	struct block_device *bdev;
	struct super_block *sb;
338
	struct filename *tmp = getname(special);
339 340

	if (IS_ERR(tmp))
341
		return ERR_CAST(tmp);
342
	bdev = lookup_bdev(tmp->name);
343 344
	putname(tmp);
	if (IS_ERR(bdev))
345
		return ERR_CAST(bdev);
346 347 348 349
	if (quotactl_cmd_write(cmd))
		sb = get_super_thawed(bdev);
	else
		sb = get_super(bdev);
350 351 352 353 354 355 356 357 358 359
	bdput(bdev);
	if (!sb)
		return ERR_PTR(-ENODEV);

	return sb;
#else
	return ERR_PTR(-ENODEV);
#endif
}

L
Linus Torvalds 已提交
360 361 362 363 364 365
/*
 * This is the system call interface. This communicates with
 * the user-level programs. Currently this only supports diskquota
 * calls. Maybe we need to add the process quotas etc. in the future,
 * but we probably should use rlimits for that.
 */
366 367
SYSCALL_DEFINE4(quotactl, unsigned int, cmd, const char __user *, special,
		qid_t, id, void __user *, addr)
L
Linus Torvalds 已提交
368 369 370
{
	uint cmds, type;
	struct super_block *sb = NULL;
371
	struct path path, *pathp = NULL;
L
Linus Torvalds 已提交
372 373 374 375 376
	int ret;

	cmds = cmd >> SUBCMDSHIFT;
	type = cmd & SUBCMDMASK;

377 378 379 380 381 382 383 384 385
	/*
	 * As a special case Q_SYNC can be called without a specific device.
	 * It will iterate all superblocks that have quota enabled and call
	 * the sync action on each of them.
	 */
	if (!special) {
		if (cmds == Q_SYNC)
			return quota_sync_all(type);
		return -ENODEV;
L
Linus Torvalds 已提交
386 387
	}

388 389 390 391 392 393
	/*
	 * Path for quotaon has to be resolved before grabbing superblock
	 * because that gets s_umount sem which is also possibly needed by path
	 * resolution (think about autofs) and thus deadlocks could arise.
	 */
	if (cmds == Q_QUOTAON) {
394
		ret = user_path_at(AT_FDCWD, addr, LOOKUP_FOLLOW|LOOKUP_AUTOMOUNT, &path);
395 396 397 398 399 400
		if (ret)
			pathp = ERR_PTR(ret);
		else
			pathp = &path;
	}

401
	sb = quotactl_block(special, cmds);
402 403 404 405
	if (IS_ERR(sb)) {
		ret = PTR_ERR(sb);
		goto out;
	}
406

407
	ret = do_quotactl(sb, type, cmds, id, addr, pathp);
L
Linus Torvalds 已提交
408

409
	drop_super(sb);
410
out:
411 412
	if (pathp && !IS_ERR(pathp))
		path_put(pathp);
L
Linus Torvalds 已提交
413 414
	return ret;
}