copy_up.c 20.5 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0-only
M
Miklos Szeredi 已提交
2 3 4 5 6
/*
 *
 * Copyright (C) 2011 Novell Inc.
 */

7
#include <linux/module.h>
M
Miklos Szeredi 已提交
8 9 10 11 12 13 14
#include <linux/fs.h>
#include <linux/slab.h>
#include <linux/file.h>
#include <linux/splice.h>
#include <linux/xattr.h>
#include <linux/security.h>
#include <linux/uaccess.h>
15
#include <linux/sched/signal.h>
16
#include <linux/cred.h>
M
Miklos Szeredi 已提交
17
#include <linux/namei.h>
18 19
#include <linux/fdtable.h>
#include <linux/ratelimit.h>
20
#include <linux/exportfs.h>
M
Miklos Szeredi 已提交
21 22 23 24
#include "overlayfs.h"

#define OVL_COPY_UP_CHUNK_SIZE (1 << 20)

25
static int ovl_ccup_set(const char *buf, const struct kernel_param *param)
26
{
27
	pr_warn("overlayfs: \"check_copy_up\" module option is obsolete\n");
28 29 30
	return 0;
}

31
static int ovl_ccup_get(char *buf, const struct kernel_param *param)
32
{
33
	return sprintf(buf, "N\n");
34 35
}

36
module_param_call(check_copy_up, ovl_ccup_set, ovl_ccup_get, NULL, 0644);
37
MODULE_PARM_DESC(check_copy_up, "Obsolete; does nothing");
38

M
Miklos Szeredi 已提交
39 40
int ovl_copy_xattr(struct dentry *old, struct dentry *new)
{
41 42 43
	ssize_t list_size, size, value_size = 0;
	char *buf, *name, *value = NULL;
	int uninitialized_var(error);
44
	size_t slen;
M
Miklos Szeredi 已提交
45

46 47
	if (!(old->d_inode->i_opflags & IOP_XATTR) ||
	    !(new->d_inode->i_opflags & IOP_XATTR))
M
Miklos Szeredi 已提交
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63
		return 0;

	list_size = vfs_listxattr(old, NULL, 0);
	if (list_size <= 0) {
		if (list_size == -EOPNOTSUPP)
			return 0;
		return list_size;
	}

	buf = kzalloc(list_size, GFP_KERNEL);
	if (!buf)
		return -ENOMEM;

	list_size = vfs_listxattr(old, buf, list_size);
	if (list_size <= 0) {
		error = list_size;
64
		goto out;
M
Miklos Szeredi 已提交
65 66
	}

67 68 69 70 71 72 73 74 75 76
	for (name = buf; list_size; name += slen) {
		slen = strnlen(name, list_size) + 1;

		/* underlying fs providing us with an broken xattr list? */
		if (WARN_ON(slen > list_size)) {
			error = -EIO;
			break;
		}
		list_size -= slen;

M
Miklos Szeredi 已提交
77 78
		if (ovl_is_private_xattr(name))
			continue;
79 80 81 82 83
retry:
		size = vfs_getxattr(old, name, value, value_size);
		if (size == -ERANGE)
			size = vfs_getxattr(old, name, NULL, 0);

M
Miklos Szeredi 已提交
84
		if (size < 0) {
M
Miklos Szeredi 已提交
85
			error = size;
86
			break;
M
Miklos Szeredi 已提交
87
		}
88 89 90 91 92 93 94 95 96 97 98 99 100 101

		if (size > value_size) {
			void *new;

			new = krealloc(value, size, GFP_KERNEL);
			if (!new) {
				error = -ENOMEM;
				break;
			}
			value = new;
			value_size = size;
			goto retry;
		}

102 103 104 105 106 107 108
		error = security_inode_copy_up_xattr(name);
		if (error < 0 && error != -EOPNOTSUPP)
			break;
		if (error == 1) {
			error = 0;
			continue; /* Discard */
		}
M
Miklos Szeredi 已提交
109 110
		error = vfs_setxattr(new, name, value, size, 0);
		if (error)
111
			break;
M
Miklos Szeredi 已提交
112 113 114 115 116 117 118 119 120 121 122 123 124
	}
	kfree(value);
out:
	kfree(buf);
	return error;
}

static int ovl_copy_up_data(struct path *old, struct path *new, loff_t len)
{
	struct file *old_file;
	struct file *new_file;
	loff_t old_pos = 0;
	loff_t new_pos = 0;
125
	loff_t cloned;
M
Miklos Szeredi 已提交
126 127 128 129 130
	int error = 0;

	if (len == 0)
		return 0;

131
	old_file = ovl_path_open(old, O_LARGEFILE | O_RDONLY);
M
Miklos Szeredi 已提交
132 133 134
	if (IS_ERR(old_file))
		return PTR_ERR(old_file);

135
	new_file = ovl_path_open(new, O_LARGEFILE | O_WRONLY);
M
Miklos Szeredi 已提交
136 137 138 139 140
	if (IS_ERR(new_file)) {
		error = PTR_ERR(new_file);
		goto out_fput;
	}

141
	/* Try to use clone_file_range to clone up within the same fs */
142
	cloned = do_clone_file_range(old_file, 0, new_file, 0, len, 0);
143
	if (cloned == len)
144 145 146
		goto out;
	/* Couldn't clone, so now we try to copy the data */

M
Miklos Szeredi 已提交
147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170
	/* FIXME: copy up sparse files efficiently */
	while (len) {
		size_t this_len = OVL_COPY_UP_CHUNK_SIZE;
		long bytes;

		if (len < this_len)
			this_len = len;

		if (signal_pending_state(TASK_KILLABLE, current)) {
			error = -EINTR;
			break;
		}

		bytes = do_splice_direct(old_file, &old_pos,
					 new_file, &new_pos,
					 this_len, SPLICE_F_MOVE);
		if (bytes <= 0) {
			error = bytes;
			break;
		}
		WARN_ON(old_pos != new_pos);

		len -= bytes;
	}
171
out:
M
Miklos Szeredi 已提交
172 173
	if (!error)
		error = vfs_fsync(new_file, 0);
M
Miklos Szeredi 已提交
174 175 176 177 178 179
	fput(new_file);
out_fput:
	fput(old_file);
	return error;
}

180 181 182 183 184 185 186 187 188 189
static int ovl_set_size(struct dentry *upperdentry, struct kstat *stat)
{
	struct iattr attr = {
		.ia_valid = ATTR_SIZE,
		.ia_size = stat->size,
	};

	return notify_change(upperdentry, &attr, NULL);
}

M
Miklos Szeredi 已提交
190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226
static int ovl_set_timestamps(struct dentry *upperdentry, struct kstat *stat)
{
	struct iattr attr = {
		.ia_valid =
		     ATTR_ATIME | ATTR_MTIME | ATTR_ATIME_SET | ATTR_MTIME_SET,
		.ia_atime = stat->atime,
		.ia_mtime = stat->mtime,
	};

	return notify_change(upperdentry, &attr, NULL);
}

int ovl_set_attr(struct dentry *upperdentry, struct kstat *stat)
{
	int err = 0;

	if (!S_ISLNK(stat->mode)) {
		struct iattr attr = {
			.ia_valid = ATTR_MODE,
			.ia_mode = stat->mode,
		};
		err = notify_change(upperdentry, &attr, NULL);
	}
	if (!err) {
		struct iattr attr = {
			.ia_valid = ATTR_UID | ATTR_GID,
			.ia_uid = stat->uid,
			.ia_gid = stat->gid,
		};
		err = notify_change(upperdentry, &attr, NULL);
	}
	if (!err)
		ovl_set_timestamps(upperdentry, stat);

	return err;
}

227
struct ovl_fh *ovl_encode_real_fh(struct dentry *real, bool is_upper)
228 229 230 231 232
{
	struct ovl_fh *fh;
	int fh_type, fh_len, dwords;
	void *buf;
	int buflen = MAX_HANDLE_SZ;
233
	uuid_t *uuid = &real->d_sb->s_uuid;
234

235
	buf = kmalloc(buflen, GFP_KERNEL);
236 237 238 239 240 241 242 243 244
	if (!buf)
		return ERR_PTR(-ENOMEM);

	/*
	 * We encode a non-connectable file handle for non-dir, because we
	 * only need to find the lower inode number and we don't want to pay
	 * the price or reconnecting the dentry.
	 */
	dwords = buflen >> 2;
245
	fh_type = exportfs_encode_fh(real, buf, &dwords, 0);
246 247 248 249 250 251 252 253
	buflen = (dwords << 2);

	fh = ERR_PTR(-EIO);
	if (WARN_ON(fh_type < 0) ||
	    WARN_ON(buflen > MAX_HANDLE_SZ) ||
	    WARN_ON(fh_type == FILEID_INVALID))
		goto out;

254 255 256 257 258
	/* Make sure the real fid stays 32bit aligned */
	BUILD_BUG_ON(OVL_FH_FID_OFFSET % 4);
	BUILD_BUG_ON(MAX_HANDLE_SZ + OVL_FH_FID_OFFSET > 255);
	fh_len = OVL_FH_FID_OFFSET + buflen;
	fh = kzalloc(fh_len, GFP_KERNEL);
259 260 261 262 263
	if (!fh) {
		fh = ERR_PTR(-ENOMEM);
		goto out;
	}

264 265 266 267
	fh->fb.version = OVL_FH_VERSION;
	fh->fb.magic = OVL_FH_MAGIC;
	fh->fb.type = fh_type;
	fh->fb.flags = OVL_FH_FLAG_CPU_ENDIAN;
268 269 270 271 272 273 274
	/*
	 * When we will want to decode an overlay dentry from this handle
	 * and all layers are on the same fs, if we get a disconncted real
	 * dentry when we decode fid, the only way to tell if we should assign
	 * it to upperdentry or to lowerstack is by checking this flag.
	 */
	if (is_upper)
275 276 277 278
		fh->fb.flags |= OVL_FH_FLAG_PATH_UPPER;
	fh->fb.len = fh_len - OVL_FH_WIRE_OFFSET;
	fh->fb.uuid = *uuid;
	memcpy(fh->fb.fid, buf, buflen);
279 280 281 282 283 284

out:
	kfree(buf);
	return fh;
}

285 286
int ovl_set_origin(struct dentry *dentry, struct dentry *lower,
		   struct dentry *upper)
287 288 289 290 291 292 293 294 295
{
	const struct ovl_fh *fh = NULL;
	int err;

	/*
	 * When lower layer doesn't support export operations store a 'null' fh,
	 * so we can use the overlay.origin xattr to distignuish between a copy
	 * up and a pure upper inode.
	 */
296
	if (ovl_can_decode_fh(lower->d_sb)) {
297
		fh = ovl_encode_real_fh(lower, false);
298 299 300 301
		if (IS_ERR(fh))
			return PTR_ERR(fh);
	}

302 303 304
	/*
	 * Do not fail when upper doesn't support xattrs.
	 */
305 306
	err = ovl_check_setxattr(dentry, upper, OVL_XATTR_ORIGIN, fh->buf,
				 fh ? fh->fb.len : 0, 0);
307 308 309 310 311
	kfree(fh);

	return err;
}

312 313 314 315 316 317
/* Store file handle of @upper dir in @index dir entry */
static int ovl_set_upper_fh(struct dentry *upper, struct dentry *index)
{
	const struct ovl_fh *fh;
	int err;

318
	fh = ovl_encode_real_fh(upper, true);
319 320 321
	if (IS_ERR(fh))
		return PTR_ERR(fh);

322
	err = ovl_do_setxattr(index, OVL_XATTR_UPPER, fh->buf, fh->fb.len, 0);
323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361

	kfree(fh);
	return err;
}

/*
 * Create and install index entry.
 *
 * Caller must hold i_mutex on indexdir.
 */
static int ovl_create_index(struct dentry *dentry, struct dentry *origin,
			    struct dentry *upper)
{
	struct dentry *indexdir = ovl_indexdir(dentry->d_sb);
	struct inode *dir = d_inode(indexdir);
	struct dentry *index = NULL;
	struct dentry *temp = NULL;
	struct qstr name = { };
	int err;

	/*
	 * For now this is only used for creating index entry for directories,
	 * because non-dir are copied up directly to index and then hardlinked
	 * to upper dir.
	 *
	 * TODO: implement create index for non-dir, so we can call it when
	 * encoding file handle for non-dir in case index does not exist.
	 */
	if (WARN_ON(!d_is_dir(dentry)))
		return -EIO;

	/* Directory not expected to be indexed before copy up */
	if (WARN_ON(ovl_test_flag(OVL_INDEX, d_inode(dentry))))
		return -EIO;

	err = ovl_get_index_name(origin, &name);
	if (err)
		return err;

362
	temp = ovl_create_temp(indexdir, OVL_CATTR(S_IFDIR | 0));
363
	err = PTR_ERR(temp);
364
	if (IS_ERR(temp))
365
		goto free_name;
366 367 368

	err = ovl_set_upper_fh(upper, temp);
	if (err)
369
		goto out;
370 371 372 373 374 375 376 377 378

	index = lookup_one_len(name.name, indexdir, name.len);
	if (IS_ERR(index)) {
		err = PTR_ERR(index);
	} else {
		err = ovl_do_rename(dir, temp, dir, index, 0);
		dput(index);
	}
out:
379 380
	if (err)
		ovl_cleanup(dir, temp);
381
	dput(temp);
382
free_name:
383 384 385 386
	kfree(name.name);
	return err;
}

387 388 389 390 391 392 393 394 395 396 397
struct ovl_copy_up_ctx {
	struct dentry *parent;
	struct dentry *dentry;
	struct path lowerpath;
	struct kstat stat;
	struct kstat pstat;
	const char *link;
	struct dentry *destdir;
	struct qstr destname;
	struct dentry *workdir;
	bool origin;
398
	bool indexed;
399
	bool metacopy;
400 401 402
};

static int ovl_link_up(struct ovl_copy_up_ctx *c)
403 404 405
{
	int err;
	struct dentry *upper;
406
	struct dentry *upperdir = ovl_dentry_upper(c->parent);
407 408
	struct inode *udir = d_inode(upperdir);

409 410 411 412 413 414
	/* Mark parent "impure" because it may now contain non-pure upper */
	err = ovl_set_impure(c->parent, upperdir);
	if (err)
		return err;

	err = ovl_set_nlink_lower(c->dentry);
415 416 417
	if (err)
		return err;

418
	inode_lock_nested(udir, I_MUTEX_PARENT);
419 420
	upper = lookup_one_len(c->dentry->d_name.name, upperdir,
			       c->dentry->d_name.len);
421 422
	err = PTR_ERR(upper);
	if (!IS_ERR(upper)) {
423
		err = ovl_do_link(ovl_dentry_upper(c->dentry), udir, upper);
424 425
		dput(upper);

426 427 428 429 430
		if (!err) {
			/* Restore timestamps on parent (best effort) */
			ovl_set_timestamps(upperdir, &c->pstat);
			ovl_dentry_set_upper_alias(c->dentry);
		}
431 432
	}
	inode_unlock(udir);
433 434 435 436
	if (err)
		return err;

	err = ovl_set_nlink_upper(c->dentry);
437 438 439 440

	return err;
}

441
static int ovl_copy_up_inode(struct ovl_copy_up_ctx *c, struct dentry *temp)
442 443 444
{
	int err;

445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462
	/*
	 * Copy up data first and then xattrs. Writing data after
	 * xattrs will remove security.capability xattr automatically.
	 */
	if (S_ISREG(c->stat.mode) && !c->metacopy) {
		struct path upperpath, datapath;

		ovl_path_upper(c->dentry, &upperpath);
		if (WARN_ON(upperpath.dentry != NULL))
			return -EIO;
		upperpath.dentry = temp;

		ovl_path_lowerdata(c->dentry, &datapath);
		err = ovl_copy_up_data(&datapath, &upperpath, c->stat.size);
		if (err)
			return err;
	}

463
	err = ovl_copy_xattr(c->lowerpath.dentry, temp);
M
Miklos Szeredi 已提交
464
	if (err)
465
		return err;
M
Miklos Szeredi 已提交
466

467 468 469
	/*
	 * Store identifier of lower inode in upper inode xattr to
	 * allow lookup of the copy up origin inode.
470 471 472
	 *
	 * Don't set origin when we are breaking the association with a lower
	 * hard link.
473
	 */
474
	if (c->origin) {
475
		err = ovl_set_origin(c->dentry, c->lowerpath.dentry, temp);
476
		if (err)
477
			return err;
478
	}
479

480 481 482 483 484 485 486
	if (c->metacopy) {
		err = ovl_check_setxattr(c->dentry, temp, OVL_XATTR_METACOPY,
					 NULL, 0, -EOPNOTSUPP);
		if (err)
			return err;
	}

487
	inode_lock(temp->d_inode);
488 489 490 491
	if (c->metacopy)
		err = ovl_set_size(temp, &c->stat);
	if (!err)
		err = ovl_set_attr(temp, &c->stat);
492 493 494
	inode_unlock(temp->d_inode);

	return err;
495 496
}

497 498 499 500 501 502
struct ovl_cu_creds {
	const struct cred *old;
	struct cred *new;
};

static int ovl_prep_cu_creds(struct dentry *dentry, struct ovl_cu_creds *cc)
A
Amir Goldstein 已提交
503 504 505
{
	int err;

506 507
	cc->old = cc->new = NULL;
	err = security_inode_copy_up(dentry, &cc->new);
A
Amir Goldstein 已提交
508
	if (err < 0)
509
		return err;
A
Amir Goldstein 已提交
510

511 512
	if (cc->new)
		cc->old = override_creds(cc->new);
A
Amir Goldstein 已提交
513

514
	return 0;
A
Amir Goldstein 已提交
515 516
}

517
static void ovl_revert_cu_creds(struct ovl_cu_creds *cc)
A
Amir Goldstein 已提交
518
{
519 520 521 522
	if (cc->new) {
		revert_creds(cc->old);
		put_cred(cc->new);
	}
A
Amir Goldstein 已提交
523 524 525 526 527 528 529
}

/*
 * Copyup using workdir to prepare temp file.  Used when copying up directories,
 * special files or when upper fs doesn't support O_TMPFILE.
 */
static int ovl_copy_up_workdir(struct ovl_copy_up_ctx *c)
530
{
531
	struct inode *inode;
532 533 534
	struct inode *udir = d_inode(c->destdir), *wdir = d_inode(c->workdir);
	struct dentry *temp, *upper;
	struct ovl_cu_creds cc;
535
	int err;
536 537 538 539 540 541
	struct ovl_cattr cattr = {
		/* Can't properly set mode on creation because of the umask */
		.mode = c->stat.mode & S_IFMT,
		.rdev = c->stat.rdev,
		.link = c->link
	};
542

A
Amir Goldstein 已提交
543 544 545 546
	err = ovl_lock_rename_workdir(c->workdir, c->destdir);
	if (err)
		return err;

547 548 549 550 551 552 553
	err = ovl_prep_cu_creds(c->dentry, &cc);
	if (err)
		goto unlock;

	temp = ovl_create_temp(c->workdir, &cattr);
	ovl_revert_cu_creds(&cc);

A
Amir Goldstein 已提交
554
	err = PTR_ERR(temp);
555
	if (IS_ERR(temp))
A
Amir Goldstein 已提交
556
		goto unlock;
557

558
	err = ovl_copy_up_inode(c, temp);
559
	if (err)
A
Amir Goldstein 已提交
560
		goto cleanup;
561

562 563 564
	if (S_ISDIR(c->stat.mode) && c->indexed) {
		err = ovl_create_index(c->dentry, c->lowerpath.dentry, temp);
		if (err)
A
Amir Goldstein 已提交
565
			goto cleanup;
566 567
	}

568 569 570 571 572 573 574
	upper = lookup_one_len(c->destname.name, c->destdir, c->destname.len);
	err = PTR_ERR(upper);
	if (IS_ERR(upper))
		goto cleanup;

	err = ovl_do_rename(wdir, temp, udir, upper, 0);
	dput(upper);
M
Miklos Szeredi 已提交
575
	if (err)
A
Amir Goldstein 已提交
576
		goto cleanup;
M
Miklos Szeredi 已提交
577

578 579
	if (!c->metacopy)
		ovl_set_upperdata(d_inode(c->dentry));
580
	inode = d_inode(c->dentry);
581
	ovl_inode_update(inode, temp);
582 583
	if (S_ISDIR(inode->i_mode))
		ovl_set_flag(OVL_WHITEOUTS, inode);
A
Amir Goldstein 已提交
584 585 586 587 588 589
unlock:
	unlock_rename(c->workdir, c->destdir);

	return err;

cleanup:
590 591 592
	ovl_cleanup(wdir, temp);
	dput(temp);
	goto unlock;
A
Amir Goldstein 已提交
593 594
}

595 596
/* Copyup using O_TMPFILE which does not require cross dir locking */
static int ovl_copy_up_tmpfile(struct ovl_copy_up_ctx *c)
A
Amir Goldstein 已提交
597
{
598 599 600
	struct inode *udir = d_inode(c->destdir);
	struct dentry *temp, *upper;
	struct ovl_cu_creds cc;
A
Amir Goldstein 已提交
601 602
	int err;

603 604 605
	err = ovl_prep_cu_creds(c->dentry, &cc);
	if (err)
		return err;
A
Amir Goldstein 已提交
606 607

	temp = ovl_do_tmpfile(c->workdir, c->stat.mode);
608
	ovl_revert_cu_creds(&cc);
A
Amir Goldstein 已提交
609

610 611
	if (IS_ERR(temp))
		return PTR_ERR(temp);
A
Amir Goldstein 已提交
612

613 614 615
	err = ovl_copy_up_inode(c, temp);
	if (err)
		goto out_dput;
A
Amir Goldstein 已提交
616 617 618 619 620

	inode_lock_nested(udir, I_MUTEX_PARENT);

	upper = lookup_one_len(c->destname.name, c->destdir, c->destname.len);
	err = PTR_ERR(upper);
621 622 623 624
	if (!IS_ERR(upper)) {
		err = ovl_do_link(temp, udir, upper);
		dput(upper);
	}
A
Amir Goldstein 已提交
625 626 627
	inode_unlock(udir);

	if (err)
628
		goto out_dput;
A
Amir Goldstein 已提交
629 630 631

	if (!c->metacopy)
		ovl_set_upperdata(d_inode(c->dentry));
632
	ovl_inode_update(d_inode(c->dentry), temp);
633

634 635 636
	return 0;

out_dput:
637
	dput(temp);
M
Miklos Szeredi 已提交
638 639 640 641 642 643
	return err;
}

/*
 * Copy up a single dentry
 *
M
Miklos Szeredi 已提交
644 645 646 647 648
 * All renames start with copy up of source if necessary.  The actual
 * rename will only proceed once the copy up was successful.  Copy up uses
 * upper parent i_mutex for exclusion.  Since rename can change d_parent it
 * is possible that the copy up will lock the old parent.  At that point
 * the file will have already been copied up anyway.
M
Miklos Szeredi 已提交
649
 */
M
Miklos Szeredi 已提交
650
static int ovl_do_copy_up(struct ovl_copy_up_ctx *c)
M
Miklos Szeredi 已提交
651 652
{
	int err;
653
	struct ovl_fs *ofs = c->dentry->d_sb->s_fs_info;
654
	bool to_index = false;
655

656 657 658 659 660 661 662 663 664 665 666 667 668 669 670
	/*
	 * Indexed non-dir is copied up directly to the index entry and then
	 * hardlinked to upper dir. Indexed dir is copied up to indexdir,
	 * then index entry is created and then copied up dir installed.
	 * Copying dir up to indexdir instead of workdir simplifies locking.
	 */
	if (ovl_need_index(c->dentry)) {
		c->indexed = true;
		if (S_ISDIR(c->stat.mode))
			c->workdir = ovl_indexdir(c->dentry->d_sb);
		else
			to_index = true;
	}

	if (S_ISDIR(c->stat.mode) || c->stat.nlink == 1 || to_index)
671 672
		c->origin = true;

673
	if (to_index) {
674 675 676 677
		c->destdir = ovl_indexdir(c->dentry->d_sb);
		err = ovl_get_index_name(c->lowerpath.dentry, &c->destname);
		if (err)
			return err;
678 679 680
	} else if (WARN_ON(!c->parent)) {
		/* Disconnected dentry must be copied up to index dir */
		return -EIO;
681 682 683 684 685 686 687 688 689
	} else {
		/*
		 * Mark parent "impure" because it may now contain non-pure
		 * upper
		 */
		err = ovl_set_impure(c->parent, c->destdir);
		if (err)
			return err;
	}
M
Miklos Szeredi 已提交
690

691
	/* Should we copyup with O_TMPFILE or with workdir? */
A
Amir Goldstein 已提交
692 693 694 695
	if (S_ISREG(c->stat.mode) && ofs->tmpfile)
		err = ovl_copy_up_tmpfile(c);
	else
		err = ovl_copy_up_workdir(c);
696 697 698 699
	if (err)
		goto out;

	if (c->indexed)
700 701 702
		ovl_set_flag(OVL_INDEX, d_inode(c->dentry));

	if (to_index) {
703 704 705
		/* Initialize nlink for copy up of disconnected dentry */
		err = ovl_set_nlink_upper(c->dentry);
	} else {
706 707 708 709 710 711 712 713
		struct inode *udir = d_inode(c->destdir);

		/* Restore timestamps on parent (best effort) */
		inode_lock(udir);
		ovl_set_timestamps(c->destdir, &c->pstat);
		inode_unlock(udir);

		ovl_dentry_set_upper_alias(c->dentry);
M
Miklos Szeredi 已提交
714 715
	}

716 717 718
out:
	if (to_index)
		kfree(c->destname.name);
M
Miklos Szeredi 已提交
719 720 721
	return err;
}

722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738
static bool ovl_need_meta_copy_up(struct dentry *dentry, umode_t mode,
				  int flags)
{
	struct ovl_fs *ofs = dentry->d_sb->s_fs_info;

	if (!ofs->config.metacopy)
		return false;

	if (!S_ISREG(mode))
		return false;

	if (flags && ((OPEN_FMODE(flags) & FMODE_WRITE) || (flags & O_TRUNC)))
		return false;

	return true;
}

739 740 741
/* Copy up data of an inode which was copied up metadata only in the past. */
static int ovl_copy_up_meta_inode_data(struct ovl_copy_up_ctx *c)
{
742
	struct path upperpath, datapath;
743
	int err;
744 745
	char *capability = NULL;
	ssize_t uninitialized_var(cap_size);
746 747 748 749 750

	ovl_path_upper(c->dentry, &upperpath);
	if (WARN_ON(upperpath.dentry == NULL))
		return -EIO;

751 752 753 754
	ovl_path_lowerdata(c->dentry, &datapath);
	if (WARN_ON(datapath.dentry == NULL))
		return -EIO;

755 756 757 758 759 760 761
	if (c->stat.size) {
		err = cap_size = ovl_getxattr(upperpath.dentry, XATTR_NAME_CAPS,
					      &capability, 0);
		if (err < 0 && err != -ENODATA)
			goto out;
	}

762
	err = ovl_copy_up_data(&datapath, &upperpath, c->stat.size);
763
	if (err)
764 765 766 767 768 769 770 771 772 773 774 775 776
		goto out_free;

	/*
	 * Writing to upper file will clear security.capability xattr. We
	 * don't want that to happen for normal copy-up operation.
	 */
	if (capability) {
		err = ovl_do_setxattr(upperpath.dentry, XATTR_NAME_CAPS,
				      capability, cap_size, 0);
		if (err)
			goto out_free;
	}

777 778 779

	err = vfs_removexattr(upperpath.dentry, OVL_XATTR_METACOPY);
	if (err)
780
		goto out_free;
781 782

	ovl_set_upperdata(d_inode(c->dentry));
783 784 785
out_free:
	kfree(capability);
out:
786 787 788
	return err;
}

M
Miklos Szeredi 已提交
789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809
static int ovl_copy_up_one(struct dentry *parent, struct dentry *dentry,
			   int flags)
{
	int err;
	DEFINE_DELAYED_CALL(done);
	struct path parentpath;
	struct ovl_copy_up_ctx ctx = {
		.parent = parent,
		.dentry = dentry,
		.workdir = ovl_workdir(dentry),
	};

	if (WARN_ON(!ctx.workdir))
		return -EROFS;

	ovl_path_lower(dentry, &ctx.lowerpath);
	err = vfs_getattr(&ctx.lowerpath, &ctx.stat,
			  STATX_BASIC_STATS, AT_STATX_SYNC_AS_STAT);
	if (err)
		return err;

810 811
	ctx.metacopy = ovl_need_meta_copy_up(dentry, ctx.stat.mode, flags);

812 813 814 815
	if (parent) {
		ovl_path_upper(parent, &parentpath);
		ctx.destdir = parentpath.dentry;
		ctx.destname = dentry->d_name;
M
Miklos Szeredi 已提交
816

817 818 819 820 821 822
		err = vfs_getattr(&parentpath, &ctx.pstat,
				  STATX_ATIME | STATX_MTIME,
				  AT_STATX_SYNC_AS_STAT);
		if (err)
			return err;
	}
M
Miklos Szeredi 已提交
823 824 825 826 827 828 829 830 831 832 833

	/* maybe truncate regular file. this has no effect on dirs */
	if (flags & O_TRUNC)
		ctx.stat.size = 0;

	if (S_ISLNK(ctx.stat.mode)) {
		ctx.link = vfs_get_link(ctx.lowerpath.dentry, &done);
		if (IS_ERR(ctx.link))
			return PTR_ERR(ctx.link);
	}

834
	err = ovl_copy_up_start(dentry, flags);
M
Miklos Szeredi 已提交
835 836 837 838 839
	/* err < 0: interrupted, err > 0: raced with another copy-up */
	if (unlikely(err)) {
		if (err > 0)
			err = 0;
	} else {
840 841
		if (!ovl_dentry_upper(dentry))
			err = ovl_do_copy_up(&ctx);
842
		if (!err && parent && !ovl_dentry_has_upper_alias(dentry))
843
			err = ovl_link_up(&ctx);
844 845
		if (!err && ovl_dentry_needs_data_copy_up_locked(dentry, flags))
			err = ovl_copy_up_meta_inode_data(&ctx);
M
Miklos Szeredi 已提交
846 847
		ovl_copy_up_end(dentry);
	}
M
Miklos Szeredi 已提交
848
	do_delayed_call(&done);
M
Miklos Szeredi 已提交
849 850 851 852

	return err;
}

853
int ovl_copy_up_flags(struct dentry *dentry, int flags)
M
Miklos Szeredi 已提交
854
{
855 856
	int err = 0;
	const struct cred *old_cred = ovl_override_creds(dentry->d_sb);
857 858 859 860 861 862 863 864 865
	bool disconnected = (dentry->d_flags & DCACHE_DISCONNECTED);

	/*
	 * With NFS export, copy up can get called for a disconnected non-dir.
	 * In this case, we will copy up lower inode to index dir without
	 * linking it to upper dir.
	 */
	if (WARN_ON(disconnected && d_is_dir(dentry)))
		return -EIO;
M
Miklos Szeredi 已提交
866 867 868

	while (!err) {
		struct dentry *next;
869
		struct dentry *parent = NULL;
M
Miklos Szeredi 已提交
870

871
		if (ovl_already_copied_up(dentry, flags))
M
Miklos Szeredi 已提交
872 873 874 875
			break;

		next = dget(dentry);
		/* find the topmost dentry not yet copied up */
876
		for (; !disconnected;) {
M
Miklos Szeredi 已提交
877 878
			parent = dget_parent(next);

879
			if (ovl_dentry_upper(parent))
M
Miklos Szeredi 已提交
880 881 882 883 884 885
				break;

			dput(next);
			next = parent;
		}

M
Miklos Szeredi 已提交
886
		err = ovl_copy_up_one(parent, next, flags);
M
Miklos Szeredi 已提交
887 888 889 890

		dput(parent);
		dput(next);
	}
891
	revert_creds(old_cred);
M
Miklos Szeredi 已提交
892 893 894

	return err;
}
895

896 897 898
static bool ovl_open_need_copy_up(struct dentry *dentry, int flags)
{
	/* Copy up of disconnected dentry does not set upper alias */
899
	if (ovl_already_copied_up(dentry, flags))
900 901 902 903 904
		return false;

	if (special_file(d_inode(dentry)->i_mode))
		return false;

905
	if (!ovl_open_flags_need_copy_up(flags))
906 907 908 909 910
		return false;

	return true;
}

911
int ovl_maybe_copy_up(struct dentry *dentry, int flags)
912 913 914
{
	int err = 0;

915
	if (ovl_open_need_copy_up(dentry, flags)) {
916 917
		err = ovl_want_write(dentry);
		if (!err) {
918
			err = ovl_copy_up_flags(dentry, flags);
919 920 921 922 923 924 925
			ovl_drop_write(dentry);
		}
	}

	return err;
}

926 927 928 929 930
int ovl_copy_up_with_data(struct dentry *dentry)
{
	return ovl_copy_up_flags(dentry, O_WRONLY);
}

931 932 933 934
int ovl_copy_up(struct dentry *dentry)
{
	return ovl_copy_up_flags(dentry, 0);
}