xfs_ioctl.c 53.8 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0
L
Linus Torvalds 已提交
2
/*
3 4
 * Copyright (c) 2000-2005 Silicon Graphics, Inc.
 * All Rights Reserved.
L
Linus Torvalds 已提交
5 6 7
 */
#include "xfs.h"
#include "xfs_fs.h"
8
#include "xfs_shared.h"
9 10 11
#include "xfs_format.h"
#include "xfs_log_format.h"
#include "xfs_trans_resv.h"
L
Linus Torvalds 已提交
12 13 14
#include "xfs_mount.h"
#include "xfs_inode.h"
#include "xfs_rtalloc.h"
15
#include "xfs_iwalk.h"
L
Linus Torvalds 已提交
16
#include "xfs_itable.h"
17
#include "xfs_error.h"
L
Linus Torvalds 已提交
18
#include "xfs_attr.h"
19
#include "xfs_bmap.h"
D
Dave Chinner 已提交
20
#include "xfs_bmap_util.h"
L
Linus Torvalds 已提交
21
#include "xfs_fsops.h"
C
Christoph Hellwig 已提交
22
#include "xfs_discard.h"
23
#include "xfs_quota.h"
24
#include "xfs_export.h"
C
Christoph Hellwig 已提交
25
#include "xfs_trace.h"
26
#include "xfs_icache.h"
27
#include "xfs_trans.h"
28
#include "xfs_acl.h"
29 30 31
#include "xfs_btree.h"
#include <linux/fsmap.h>
#include "xfs_fsmap.h"
32
#include "scrub/xfs_scrub.h"
33
#include "xfs_sb.h"
34
#include "xfs_ag.h"
35
#include "xfs_health.h"
36
#include "xfs_reflink.h"
D
Darrick J. Wong 已提交
37
#include "xfs_ioctl.h"
38 39
#include "xfs_da_format.h"
#include "xfs_da_btree.h"
L
Linus Torvalds 已提交
40 41 42 43 44 45 46 47 48 49 50 51 52 53 54

#include <linux/mount.h>
#include <linux/namei.h>

/*
 * xfs_find_handle maps from userspace xfs_fsop_handlereq structure to
 * a file or fs handle.
 *
 * XFS_IOC_PATH_TO_FSHANDLE
 *    returns fs handle for a mount point or path within that mount point
 * XFS_IOC_FD_TO_HANDLE
 *    returns full handle for a FD opened in user space
 * XFS_IOC_PATH_TO_HANDLE
 *    returns full handle for a path
 */
55
int
L
Linus Torvalds 已提交
56 57
xfs_find_handle(
	unsigned int		cmd,
58
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
59 60 61 62
{
	int			hsize;
	xfs_handle_t		handle;
	struct inode		*inode;
63
	struct fd		f = {NULL};
C
Christoph Hellwig 已提交
64
	struct path		path;
65
	int			error;
C
Christoph Hellwig 已提交
66
	struct xfs_inode	*ip;
L
Linus Torvalds 已提交
67

C
Christoph Hellwig 已提交
68
	if (cmd == XFS_IOC_FD_TO_HANDLE) {
69 70
		f = fdget(hreq->fd);
		if (!f.file)
C
Christoph Hellwig 已提交
71
			return -EBADF;
A
Al Viro 已提交
72
		inode = file_inode(f.file);
C
Christoph Hellwig 已提交
73
	} else {
74
		error = user_path_at(AT_FDCWD, hreq->path, 0, &path);
C
Christoph Hellwig 已提交
75 76
		if (error)
			return error;
77
		inode = d_inode(path.dentry);
L
Linus Torvalds 已提交
78
	}
C
Christoph Hellwig 已提交
79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104
	ip = XFS_I(inode);

	/*
	 * We can only generate handles for inodes residing on a XFS filesystem,
	 * and only for regular files, directories or symbolic links.
	 */
	error = -EINVAL;
	if (inode->i_sb->s_magic != XFS_SB_MAGIC)
		goto out_put;

	error = -EBADF;
	if (!S_ISREG(inode->i_mode) &&
	    !S_ISDIR(inode->i_mode) &&
	    !S_ISLNK(inode->i_mode))
		goto out_put;


	memcpy(&handle.ha_fsid, ip->i_mount->m_fixedfsid, sizeof(xfs_fsid_t));

	if (cmd == XFS_IOC_PATH_TO_FSHANDLE) {
		/*
		 * This handle only contains an fsid, zero the rest.
		 */
		memset(&handle.ha_fid, 0, sizeof(handle.ha_fid));
		hsize = sizeof(xfs_fsid_t);
	} else {
C
Christoph Hellwig 已提交
105 106 107
		handle.ha_fid.fid_len = sizeof(xfs_fid_t) -
					sizeof(handle.ha_fid.fid_len);
		handle.ha_fid.fid_pad = 0;
108
		handle.ha_fid.fid_gen = inode->i_generation;
C
Christoph Hellwig 已提交
109
		handle.ha_fid.fid_ino = ip->i_ino;
C
Christoph Hellwig 已提交
110
		hsize = sizeof(xfs_handle_t);
L
Linus Torvalds 已提交
111 112
	}

C
Christoph Hellwig 已提交
113
	error = -EFAULT;
114
	if (copy_to_user(hreq->ohandle, &handle, hsize) ||
C
Christoph Hellwig 已提交
115 116
	    copy_to_user(hreq->ohandlen, &hsize, sizeof(__s32)))
		goto out_put;
L
Linus Torvalds 已提交
117

C
Christoph Hellwig 已提交
118 119 120 121
	error = 0;

 out_put:
	if (cmd == XFS_IOC_FD_TO_HANDLE)
122
		fdput(f);
C
Christoph Hellwig 已提交
123 124 125
	else
		path_put(&path);
	return error;
L
Linus Torvalds 已提交
126 127 128
}

/*
129 130
 * No need to do permission checks on the various pathname components
 * as the handle operations are privileged.
L
Linus Torvalds 已提交
131 132
 */
STATIC int
133 134 135 136 137 138 139 140 141 142 143 144 145 146 147
xfs_handle_acceptable(
	void			*context,
	struct dentry		*dentry)
{
	return 1;
}

/*
 * Convert userspace handle data into a dentry.
 */
struct dentry *
xfs_handle_to_dentry(
	struct file		*parfilp,
	void __user		*uhandle,
	u32			hlen)
L
Linus Torvalds 已提交
148 149
{
	xfs_handle_t		handle;
150
	struct xfs_fid64	fid;
L
Linus Torvalds 已提交
151 152 153 154

	/*
	 * Only allow handle opens under a directory.
	 */
A
Al Viro 已提交
155
	if (!S_ISDIR(file_inode(parfilp)->i_mode))
156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173
		return ERR_PTR(-ENOTDIR);

	if (hlen != sizeof(xfs_handle_t))
		return ERR_PTR(-EINVAL);
	if (copy_from_user(&handle, uhandle, hlen))
		return ERR_PTR(-EFAULT);
	if (handle.ha_fid.fid_len !=
	    sizeof(handle.ha_fid) - sizeof(handle.ha_fid.fid_len))
		return ERR_PTR(-EINVAL);

	memset(&fid, 0, sizeof(struct fid));
	fid.ino = handle.ha_fid.fid_ino;
	fid.gen = handle.ha_fid.fid_gen;

	return exportfs_decode_fh(parfilp->f_path.mnt, (struct fid *)&fid, 3,
			FILEID_INO32_GEN | XFS_FILEID_TYPE_64FLAG,
			xfs_handle_acceptable, NULL);
}
L
Linus Torvalds 已提交
174

175 176 177 178 179 180
STATIC struct dentry *
xfs_handlereq_to_dentry(
	struct file		*parfilp,
	xfs_fsop_handlereq_t	*hreq)
{
	return xfs_handle_to_dentry(parfilp, hreq->ihandle, hreq->ihandlen);
L
Linus Torvalds 已提交
181 182
}

183
int
L
Linus Torvalds 已提交
184 185
xfs_open_by_handle(
	struct file		*parfilp,
186
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
187
{
188
	const struct cred	*cred = current_cred();
L
Linus Torvalds 已提交
189
	int			error;
190
	int			fd;
L
Linus Torvalds 已提交
191 192 193 194
	int			permflag;
	struct file		*filp;
	struct inode		*inode;
	struct dentry		*dentry;
195
	fmode_t			fmode;
196
	struct path		path;
L
Linus Torvalds 已提交
197 198

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
199
		return -EPERM;
L
Linus Torvalds 已提交
200

201 202 203
	dentry = xfs_handlereq_to_dentry(parfilp, hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
204
	inode = d_inode(dentry);
L
Linus Torvalds 已提交
205 206 207

	/* Restrict xfs_open_by_handle to directories & regular files. */
	if (!(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode))) {
E
Eric Sandeen 已提交
208
		error = -EPERM;
209
		goto out_dput;
L
Linus Torvalds 已提交
210 211 212
	}

#if BITS_PER_LONG != 32
213
	hreq->oflags |= O_LARGEFILE;
L
Linus Torvalds 已提交
214
#endif
215

216
	permflag = hreq->oflags;
217
	fmode = OPEN_FMODE(permflag);
L
Linus Torvalds 已提交
218
	if ((!(permflag & O_APPEND) || (permflag & O_TRUNC)) &&
219
	    (fmode & FMODE_WRITE) && IS_APPEND(inode)) {
E
Eric Sandeen 已提交
220
		error = -EPERM;
221
		goto out_dput;
L
Linus Torvalds 已提交
222 223
	}

224
	if ((fmode & FMODE_WRITE) && IS_IMMUTABLE(inode)) {
E
Eryu Guan 已提交
225
		error = -EPERM;
226
		goto out_dput;
L
Linus Torvalds 已提交
227 228 229
	}

	/* Can't write directories. */
230
	if (S_ISDIR(inode->i_mode) && (fmode & FMODE_WRITE)) {
E
Eric Sandeen 已提交
231
		error = -EISDIR;
232
		goto out_dput;
L
Linus Torvalds 已提交
233 234
	}

235
	fd = get_unused_fd_flags(0);
236 237 238
	if (fd < 0) {
		error = fd;
		goto out_dput;
L
Linus Torvalds 已提交
239 240
	}

241 242 243 244
	path.mnt = parfilp->f_path.mnt;
	path.dentry = dentry;
	filp = dentry_open(&path, hreq->oflags, cred);
	dput(dentry);
L
Linus Torvalds 已提交
245
	if (IS_ERR(filp)) {
246 247
		put_unused_fd(fd);
		return PTR_ERR(filp);
L
Linus Torvalds 已提交
248
	}
249

A
Al Viro 已提交
250
	if (S_ISREG(inode->i_mode)) {
251
		filp->f_flags |= O_NOATIME;
252
		filp->f_mode |= FMODE_NOCMTIME;
253
	}
L
Linus Torvalds 已提交
254

255 256 257 258 259 260
	fd_install(fd, filp);
	return fd;

 out_dput:
	dput(dentry);
	return error;
L
Linus Torvalds 已提交
261 262
}

263
int
L
Linus Torvalds 已提交
264
xfs_readlink_by_handle(
265 266
	struct file		*parfilp,
	xfs_fsop_handlereq_t	*hreq)
L
Linus Torvalds 已提交
267
{
268
	struct dentry		*dentry;
L
Linus Torvalds 已提交
269
	__u32			olen;
270
	int			error;
L
Linus Torvalds 已提交
271 272

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
273
		return -EPERM;
L
Linus Torvalds 已提交
274

275 276 277
	dentry = xfs_handlereq_to_dentry(parfilp, hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
278 279

	/* Restrict this handle operation to symlinks only. */
280
	if (!d_is_symlink(dentry)) {
E
Eric Sandeen 已提交
281
		error = -EINVAL;
282
		goto out_dput;
L
Linus Torvalds 已提交
283 284
	}

285
	if (copy_from_user(&olen, hreq->ohandlen, sizeof(__u32))) {
E
Eric Sandeen 已提交
286
		error = -EFAULT;
287
		goto out_dput;
L
Linus Torvalds 已提交
288 289
	}

290
	error = vfs_readlink(dentry, hreq->ohandle, olen);
291

292 293
 out_dput:
	dput(dentry);
294
	return error;
L
Linus Torvalds 已提交
295 296
}

297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322
/*
 * Format an attribute and copy it out to the user's buffer.
 * Take care to check values and protect against them changing later,
 * we may be reading them directly out of a user buffer.
 */
static void
xfs_ioc_attr_put_listent(
	struct xfs_attr_list_context *context,
	int			flags,
	unsigned char		*name,
	int			namelen,
	int			valuelen)
{
	struct xfs_attrlist	*alist = context->buffer;
	struct xfs_attrlist_ent	*aep;
	int			arraytop;

	ASSERT(!context->seen_enough);
	ASSERT(context->count >= 0);
	ASSERT(context->count < (ATTR_MAX_VALUELEN/8));
	ASSERT(context->firstu >= sizeof(*alist));
	ASSERT(context->firstu <= context->bufsize);

	/*
	 * Only list entries in the right namespace.
	 */
323
	if (context->attr_filter != (flags & XFS_ATTR_NSP_ONDISK_MASK))
324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347
		return;

	arraytop = sizeof(*alist) +
			context->count * sizeof(alist->al_offset[0]);

	/* decrement by the actual bytes used by the attr */
	context->firstu -= round_up(offsetof(struct xfs_attrlist_ent, a_name) +
			namelen + 1, sizeof(uint32_t));
	if (context->firstu < arraytop) {
		trace_xfs_attr_list_full(context);
		alist->al_more = 1;
		context->seen_enough = 1;
		return;
	}

	aep = context->buffer + context->firstu;
	aep->a_valuelen = valuelen;
	memcpy(aep->a_name, name, namelen);
	aep->a_name[namelen] = 0;
	alist->al_offset[context->count++] = context->firstu;
	alist->al_count = context->count;
	trace_xfs_attr_list_add(context);
}

348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369
static unsigned int
xfs_attr_filter(
	u32			ioc_flags)
{
	if (ioc_flags & XFS_IOC_ATTR_ROOT)
		return XFS_ATTR_ROOT;
	if (ioc_flags & XFS_IOC_ATTR_SECURE)
		return XFS_ATTR_SECURE;
	return 0;
}

static unsigned int
xfs_attr_flags(
	u32			ioc_flags)
{
	if (ioc_flags & XFS_IOC_ATTR_CREATE)
		return XATTR_CREATE;
	if (ioc_flags & XFS_IOC_ATTR_REPLACE)
		return XATTR_REPLACE;
	return 0;
}

370 371 372
int
xfs_ioc_attr_list(
	struct xfs_inode		*dp,
373
	void __user			*ubuf,
374 375
	int				bufsize,
	int				flags,
376
	struct xfs_attrlist_cursor __user *ucursor)
377
{
378
	struct xfs_attr_list_context	context = { };
379
	struct xfs_attrlist		*alist;
380
	void				*buffer;
381 382
	int				error;

383 384 385 386 387 388 389
	if (bufsize < sizeof(struct xfs_attrlist) ||
	    bufsize > XFS_XATTR_LIST_MAX)
		return -EINVAL;

	/*
	 * Reject flags, only allow namespaces.
	 */
390
	if (flags & ~(XFS_IOC_ATTR_ROOT | XFS_IOC_ATTR_SECURE))
391
		return -EINVAL;
392
	if (flags == (XFS_IOC_ATTR_ROOT | XFS_IOC_ATTR_SECURE))
393 394
		return -EINVAL;

395 396 397
	/*
	 * Validate the cursor.
	 */
398
	if (copy_from_user(&context.cursor, ucursor, sizeof(context.cursor)))
399
		return -EFAULT;
400
	if (context.cursor.pad1 || context.cursor.pad2)
401
		return -EINVAL;
402 403 404
	if (!context.cursor.initted &&
	    (context.cursor.hashval || context.cursor.blkno ||
	     context.cursor.offset))
405 406
		return -EINVAL;

407
	buffer = kvzalloc(bufsize, GFP_KERNEL);
408 409
	if (!buffer)
		return -ENOMEM;
410 411 412 413 414 415

	/*
	 * Initialize the output buffer.
	 */
	context.dp = dp;
	context.resynch = 1;
416
	context.attr_filter = xfs_attr_filter(flags);
417
	context.buffer = buffer;
418
	context.bufsize = round_down(bufsize, sizeof(uint32_t));
419 420 421 422 423 424 425 426
	context.firstu = context.bufsize;
	context.put_listent = xfs_ioc_attr_put_listent;

	alist = context.buffer;
	alist->al_count = 0;
	alist->al_more = 0;
	alist->al_offset[0] = context.bufsize;

427
	error = xfs_attr_list(&context);
428 429 430
	if (error)
		goto out_free;

431
	if (copy_to_user(ubuf, buffer, bufsize) ||
432
	    copy_to_user(ucursor, &context.cursor, sizeof(context.cursor)))
433 434 435
		error = -EFAULT;
out_free:
	kmem_free(buffer);
436 437 438
	return error;
}

L
Linus Torvalds 已提交
439 440
STATIC int
xfs_attrlist_by_handle(
441
	struct file		*parfilp,
442
	struct xfs_fsop_attrlist_handlereq __user *p)
L
Linus Torvalds 已提交
443
{
444
	struct xfs_fsop_attrlist_handlereq al_hreq;
445
	struct dentry		*dentry;
446
	int			error = -ENOMEM;
L
Linus Torvalds 已提交
447 448

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
449
		return -EPERM;
450
	if (copy_from_user(&al_hreq, p, sizeof(al_hreq)))
E
Eric Sandeen 已提交
451
		return -EFAULT;
452

453 454 455
	dentry = xfs_handlereq_to_dentry(parfilp, &al_hreq.hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
456

457
	error = xfs_ioc_attr_list(XFS_I(d_inode(dentry)), al_hreq.buffer,
458
				  al_hreq.buflen, al_hreq.flags, &p->pos);
459 460
	dput(dentry);
	return error;
L
Linus Torvalds 已提交
461 462
}

463
static int
L
Linus Torvalds 已提交
464
xfs_attrmulti_attr_get(
465
	struct inode		*inode,
466 467
	unsigned char		*name,
	unsigned char		__user *ubuf,
468 469
	uint32_t		*len,
	uint32_t		flags)
L
Linus Torvalds 已提交
470
{
471 472
	struct xfs_da_args	args = {
		.dp		= XFS_I(inode),
473 474
		.attr_filter	= xfs_attr_filter(flags),
		.attr_flags	= xfs_attr_flags(flags),
475 476 477 478 479
		.name		= name,
		.namelen	= strlen(name),
		.valuelen	= *len,
	};
	int			error;
480

481
	if (*len > XFS_XATTR_SIZE_MAX)
D
Dave Chinner 已提交
482
		return -EINVAL;
483 484

	error = xfs_attr_get(&args);
L
Linus Torvalds 已提交
485 486 487
	if (error)
		goto out_kfree;

488 489
	*len = args.valuelen;
	if (copy_to_user(ubuf, args.value, args.valuelen))
D
Dave Chinner 已提交
490
		error = -EFAULT;
L
Linus Torvalds 已提交
491

492
out_kfree:
493
	kmem_free(args.value);
L
Linus Torvalds 已提交
494 495 496
	return error;
}

497
static int
L
Linus Torvalds 已提交
498
xfs_attrmulti_attr_set(
499
	struct inode		*inode,
500 501
	unsigned char		*name,
	const unsigned char	__user *ubuf,
502 503
	uint32_t		len,
	uint32_t		flags)
L
Linus Torvalds 已提交
504
{
505 506
	struct xfs_da_args	args = {
		.dp		= XFS_I(inode),
507 508
		.attr_filter	= xfs_attr_filter(flags),
		.attr_flags	= xfs_attr_flags(flags),
509 510 511
		.name		= name,
		.namelen	= strlen(name),
	};
512
	int			error;
L
Linus Torvalds 已提交
513

514
	if (IS_IMMUTABLE(inode) || IS_APPEND(inode))
D
Dave Chinner 已提交
515
		return -EPERM;
L
Linus Torvalds 已提交
516

517 518 519
	if (ubuf) {
		if (len > XFS_XATTR_SIZE_MAX)
			return -EINVAL;
520 521 522 523
		args.value = memdup_user(ubuf, len);
		if (IS_ERR(args.value))
			return PTR_ERR(args.value);
		args.valuelen = len;
524
	}
525

526
	error = xfs_attr_set(&args);
527
	if (!error && (flags & XFS_IOC_ATTR_ROOT))
C
Christoph Hellwig 已提交
528
		xfs_forget_acl(inode, name);
529
	kfree(args.value);
530
	return error;
L
Linus Torvalds 已提交
531 532
}

533 534 535 536 537 538 539 540 541 542 543 544 545
int
xfs_ioc_attrmulti_one(
	struct file		*parfilp,
	struct inode		*inode,
	uint32_t		opcode,
	void __user		*uname,
	void __user		*value,
	uint32_t		*len,
	uint32_t		flags)
{
	unsigned char		*name;
	int			error;

546
	if ((flags & XFS_IOC_ATTR_ROOT) && (flags & XFS_IOC_ATTR_SECURE))
547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576
		return -EINVAL;

	name = strndup_user(uname, MAXNAMELEN);
	if (IS_ERR(name))
		return PTR_ERR(name);

	switch (opcode) {
	case ATTR_OP_GET:
		error = xfs_attrmulti_attr_get(inode, name, value, len, flags);
		break;
	case ATTR_OP_REMOVE:
		value = NULL;
		*len = 0;
		/* fall through */
	case ATTR_OP_SET:
		error = mnt_want_write_file(parfilp);
		if (error)
			break;
		error = xfs_attrmulti_attr_set(inode, name, value, *len, flags);
		mnt_drop_write_file(parfilp);
		break;
	default:
		error = -EINVAL;
		break;
	}

	kfree(name);
	return error;
}

L
Linus Torvalds 已提交
577 578
STATIC int
xfs_attrmulti_by_handle(
579
	struct file		*parfilp,
580
	void			__user *arg)
L
Linus Torvalds 已提交
581 582 583 584
{
	int			error;
	xfs_attr_multiop_t	*ops;
	xfs_fsop_attrmulti_handlereq_t am_hreq;
585
	struct dentry		*dentry;
L
Linus Torvalds 已提交
586 587 588
	unsigned int		i, size;

	if (!capable(CAP_SYS_ADMIN))
E
Eric Sandeen 已提交
589
		return -EPERM;
L
Linus Torvalds 已提交
590
	if (copy_from_user(&am_hreq, arg, sizeof(xfs_fsop_attrmulti_handlereq_t)))
E
Eric Sandeen 已提交
591
		return -EFAULT;
L
Linus Torvalds 已提交
592

593 594 595 596
	/* overflow check */
	if (am_hreq.opcount >= INT_MAX / sizeof(xfs_attr_multiop_t))
		return -E2BIG;

597 598 599
	dentry = xfs_handlereq_to_dentry(parfilp, &am_hreq.hreq);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
L
Linus Torvalds 已提交
600

D
Dave Chinner 已提交
601
	error = -E2BIG;
C
Christoph Hellwig 已提交
602
	size = am_hreq.opcount * sizeof(xfs_attr_multiop_t);
L
Linus Torvalds 已提交
603
	if (!size || size > 16 * PAGE_SIZE)
604
		goto out_dput;
L
Linus Torvalds 已提交
605

L
Li Zefan 已提交
606 607
	ops = memdup_user(am_hreq.ops, size);
	if (IS_ERR(ops)) {
D
Dave Chinner 已提交
608
		error = PTR_ERR(ops);
609
		goto out_dput;
L
Li Zefan 已提交
610
	}
L
Linus Torvalds 已提交
611 612 613

	error = 0;
	for (i = 0; i < am_hreq.opcount; i++) {
614 615 616 617
		ops[i].am_error = xfs_ioc_attrmulti_one(parfilp,
				d_inode(dentry), ops[i].am_opcode,
				ops[i].am_attrname, ops[i].am_attrvalue,
				&ops[i].am_length, ops[i].am_flags);
L
Linus Torvalds 已提交
618 619 620
	}

	if (copy_to_user(am_hreq.ops, ops, size))
D
Dave Chinner 已提交
621
		error = -EFAULT;
L
Linus Torvalds 已提交
622 623

	kfree(ops);
624 625
 out_dput:
	dput(dentry);
D
Dave Chinner 已提交
626
	return error;
L
Linus Torvalds 已提交
627 628
}

629
int
L
Linus Torvalds 已提交
630 631
xfs_ioc_space(
	struct file		*filp,
632
	xfs_flock64_t		*bf)
L
Linus Torvalds 已提交
633
{
634 635
	struct inode		*inode = file_inode(filp);
	struct xfs_inode	*ip = XFS_I(inode);
636
	struct iattr		iattr;
637
	enum xfs_prealloc_flags	flags = XFS_PREALLOC_CLEAR;
638
	uint			iolock = XFS_IOLOCK_EXCL | XFS_MMAPLOCK_EXCL;
L
Linus Torvalds 已提交
639 640
	int			error;

641
	if (inode->i_flags & (S_IMMUTABLE|S_APPEND))
E
Eric Sandeen 已提交
642
		return -EPERM;
L
Linus Torvalds 已提交
643

644
	if (!(filp->f_mode & FMODE_WRITE))
E
Eric Sandeen 已提交
645
		return -EBADF;
L
Linus Torvalds 已提交
646

647
	if (!S_ISREG(inode->i_mode))
E
Eric Sandeen 已提交
648
		return -EINVAL;
L
Linus Torvalds 已提交
649

650 651 652
	if (xfs_is_always_cow_inode(ip))
		return -EOPNOTSUPP;

653 654
	if (filp->f_flags & O_DSYNC)
		flags |= XFS_PREALLOC_SYNC;
655
	if (filp->f_mode & FMODE_NOCMTIME)
656 657
		flags |= XFS_PREALLOC_INVISIBLE;

J
Jan Kara 已提交
658 659 660
	error = mnt_want_write_file(filp);
	if (error)
		return error;
661

662
	xfs_ilock(ip, iolock);
663
	error = xfs_break_layouts(inode, &iolock, BREAK_UNMAP);
664 665
	if (error)
		goto out_unlock;
666
	inode_dio_wait(inode);
667 668 669 670 671 672 673 674 675 676 677

	switch (bf->l_whence) {
	case 0: /*SEEK_SET*/
		break;
	case 1: /*SEEK_CUR*/
		bf->l_start += filp->f_pos;
		break;
	case 2: /*SEEK_END*/
		bf->l_start += XFS_ISIZE(ip);
		break;
	default:
D
Dave Chinner 已提交
678
		error = -EINVAL;
679 680 681
		goto out_unlock;
	}

682
	if (bf->l_start < 0 || bf->l_start > inode->i_sb->s_maxbytes) {
D
Dave Chinner 已提交
683
		error = -EINVAL;
684 685 686
		goto out_unlock;
	}

687 688 689 690 691
	if (bf->l_start > XFS_ISIZE(ip)) {
		error = xfs_alloc_file_space(ip, XFS_ISIZE(ip),
				bf->l_start - XFS_ISIZE(ip), 0);
		if (error)
			goto out_unlock;
692 693
	}

694 695
	iattr.ia_valid = ATTR_SIZE;
	iattr.ia_size = bf->l_start;
C
Christoph Hellwig 已提交
696 697
	error = xfs_vn_setattr_size(file_mnt_user_ns(filp), file_dentry(filp),
				    &iattr);
698 699 700
	if (error)
		goto out_unlock;

701
	error = xfs_update_prealloc_flags(ip, flags);
702 703

out_unlock:
704
	xfs_iunlock(ip, iolock);
J
Jan Kara 已提交
705
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
706
	return error;
L
Linus Torvalds 已提交
707 708
}

709 710
/* Return 0 on success or positive error */
int
D
Darrick J. Wong 已提交
711
xfs_fsbulkstat_one_fmt(
712 713
	struct xfs_ibulk		*breq,
	const struct xfs_bulkstat	*bstat)
714
{
715 716 717 718
	struct xfs_bstat		bs1;

	xfs_bulkstat_to_bstat(breq->mp, &bs1, bstat);
	if (copy_to_user(breq->ubuffer, &bs1, sizeof(bs1)))
719 720 721 722
		return -EFAULT;
	return xfs_ibulk_advance(breq, sizeof(struct xfs_bstat));
}

723
int
D
Darrick J. Wong 已提交
724
xfs_fsinumbers_fmt(
725 726
	struct xfs_ibulk		*breq,
	const struct xfs_inumbers	*igrp)
727
{
728 729 730 731
	struct xfs_inogrp		ig1;

	xfs_inumbers_to_inogrp(&ig1, igrp);
	if (copy_to_user(breq->ubuffer, &ig1, sizeof(struct xfs_inogrp)))
732 733 734 735
		return -EFAULT;
	return xfs_ibulk_advance(breq, sizeof(struct xfs_inogrp));
}

L
Linus Torvalds 已提交
736
STATIC int
D
Darrick J. Wong 已提交
737
xfs_ioc_fsbulkstat(
C
Christoph Hellwig 已提交
738
	struct file		*file,
L
Linus Torvalds 已提交
739 740 741
	unsigned int		cmd,
	void			__user *arg)
{
C
Christoph Hellwig 已提交
742
	struct xfs_mount	*mp = XFS_I(file_inode(file))->i_mount;
743 744 745
	struct xfs_fsop_bulkreq	bulkreq;
	struct xfs_ibulk	breq = {
		.mp		= mp,
C
Christoph Hellwig 已提交
746
		.mnt_userns	= file_mnt_user_ns(file),
747 748 749
		.ocount		= 0,
	};
	xfs_ino_t		lastino;
L
Linus Torvalds 已提交
750 751 752 753 754 755 756 757 758
	int			error;

	/* done = 1 if there are more stats to get and if bulkstat */
	/* should be called again (unused here, but used in dmapi) */

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (XFS_FORCED_SHUTDOWN(mp))
E
Eric Sandeen 已提交
759
		return -EIO;
L
Linus Torvalds 已提交
760

761
	if (copy_from_user(&bulkreq, arg, sizeof(struct xfs_fsop_bulkreq)))
E
Eric Sandeen 已提交
762
		return -EFAULT;
L
Linus Torvalds 已提交
763

764
	if (copy_from_user(&lastino, bulkreq.lastip, sizeof(__s64)))
E
Eric Sandeen 已提交
765
		return -EFAULT;
L
Linus Torvalds 已提交
766

767
	if (bulkreq.icount <= 0)
E
Eric Sandeen 已提交
768
		return -EINVAL;
L
Linus Torvalds 已提交
769

770
	if (bulkreq.ubuffer == NULL)
E
Eric Sandeen 已提交
771
		return -EINVAL;
772

773 774 775 776 777 778 779 780 781 782 783 784 785 786 787
	breq.ubuffer = bulkreq.ubuffer;
	breq.icount = bulkreq.icount;

	/*
	 * FSBULKSTAT_SINGLE expects that *lastip contains the inode number
	 * that we want to stat.  However, FSINUMBERS and FSBULKSTAT expect
	 * that *lastip contains either zero or the number of the last inode to
	 * be examined by the previous call and return results starting with
	 * the next inode after that.  The new bulk request back end functions
	 * take the inode to start with, so we have to compute the startino
	 * parameter from lastino to maintain correct function.  lastino == 0
	 * is a special case because it has traditionally meant "first inode
	 * in filesystem".
	 */
	if (cmd == XFS_IOC_FSINUMBERS) {
788
		breq.startino = lastino ? lastino + 1 : 0;
D
Darrick J. Wong 已提交
789
		error = xfs_inumbers(&breq, xfs_fsinumbers_fmt);
790
		lastino = breq.startino - 1;
791 792 793
	} else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE) {
		breq.startino = lastino;
		breq.icount = 1;
D
Darrick J. Wong 已提交
794
		error = xfs_bulkstat_one(&breq, xfs_fsbulkstat_one_fmt);
795 796
	} else {	/* XFS_IOC_FSBULKSTAT */
		breq.startino = lastino ? lastino + 1 : 0;
D
Darrick J. Wong 已提交
797
		error = xfs_bulkstat(&breq, xfs_fsbulkstat_one_fmt);
798 799
		lastino = breq.startino - 1;
	}
L
Linus Torvalds 已提交
800 801

	if (error)
D
Dave Chinner 已提交
802
		return error;
L
Linus Torvalds 已提交
803

804
	if (bulkreq.lastip != NULL &&
805
	    copy_to_user(bulkreq.lastip, &lastino, sizeof(xfs_ino_t)))
806
		return -EFAULT;
L
Linus Torvalds 已提交
807

808
	if (bulkreq.ocount != NULL &&
809
	    copy_to_user(bulkreq.ocount, &breq.ocount, sizeof(__s32)))
810
		return -EFAULT;
L
Linus Torvalds 已提交
811 812 813 814

	return 0;
}

815 816 817 818 819 820 821 822 823 824 825 826 827 828
/* Return 0 on success or positive error */
static int
xfs_bulkstat_fmt(
	struct xfs_ibulk		*breq,
	const struct xfs_bulkstat	*bstat)
{
	if (copy_to_user(breq->ubuffer, bstat, sizeof(struct xfs_bulkstat)))
		return -EFAULT;
	return xfs_ibulk_advance(breq, sizeof(struct xfs_bulkstat));
}

/*
 * Check the incoming bulk request @hdr from userspace and initialize the
 * internal @breq bulk request appropriately.  Returns 0 if the bulk request
829
 * should proceed; -ECANCELED if there's nothing to do; or the usual
830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847
 * negative error code.
 */
static int
xfs_bulk_ireq_setup(
	struct xfs_mount	*mp,
	struct xfs_bulk_ireq	*hdr,
	struct xfs_ibulk	*breq,
	void __user		*ubuffer)
{
	if (hdr->icount == 0 ||
	    (hdr->flags & ~XFS_BULK_IREQ_FLAGS_ALL) ||
	    memchr_inv(hdr->reserved, 0, sizeof(hdr->reserved)))
		return -EINVAL;

	breq->startino = hdr->ino;
	breq->ubuffer = ubuffer;
	breq->icount = hdr->icount;
	breq->ocount = 0;
D
Darrick J. Wong 已提交
848 849
	breq->flags = 0;

850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866
	/*
	 * The @ino parameter is a special value, so we must look it up here.
	 * We're not allowed to have IREQ_AGNO, and we only return one inode
	 * worth of data.
	 */
	if (hdr->flags & XFS_BULK_IREQ_SPECIAL) {
		if (hdr->flags & XFS_BULK_IREQ_AGNO)
			return -EINVAL;

		switch (hdr->ino) {
		case XFS_BULK_IREQ_SPECIAL_ROOT:
			hdr->ino = mp->m_sb.sb_rootino;
			break;
		default:
			return -EINVAL;
		}
		breq->icount = 1;
L
Linus Torvalds 已提交
867 868
	}

D
Darrick J. Wong 已提交
869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886
	/*
	 * The IREQ_AGNO flag means that we only want results from a given AG.
	 * If @hdr->ino is zero, we start iterating in that AG.  If @hdr->ino is
	 * beyond the specified AG then we return no results.
	 */
	if (hdr->flags & XFS_BULK_IREQ_AGNO) {
		if (hdr->agno >= mp->m_sb.sb_agcount)
			return -EINVAL;

		if (breq->startino == 0)
			breq->startino = XFS_AGINO_TO_INO(mp, hdr->agno, 0);
		else if (XFS_INO_TO_AGNO(mp, breq->startino) < hdr->agno)
			return -EINVAL;

		breq->flags |= XFS_IBULK_SAME_AG;

		/* Asking for an inode past the end of the AG?  We're done! */
		if (XFS_INO_TO_AGNO(mp, breq->startino) > hdr->agno)
887
			return -ECANCELED;
D
Darrick J. Wong 已提交
888 889
	} else if (hdr->agno)
		return -EINVAL;
890 891 892

	/* Asking for an inode past the end of the FS?  We're done! */
	if (XFS_INO_TO_AGNO(mp, breq->startino) >= mp->m_sb.sb_agcount)
893
		return -ECANCELED;
894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913

	return 0;
}

/*
 * Update the userspace bulk request @hdr to reflect the end state of the
 * internal bulk request @breq.
 */
static void
xfs_bulk_ireq_teardown(
	struct xfs_bulk_ireq	*hdr,
	struct xfs_ibulk	*breq)
{
	hdr->ino = breq->startino;
	hdr->ocount = breq->ocount;
}

/* Handle the v5 bulkstat ioctl. */
STATIC int
xfs_ioc_bulkstat(
C
Christoph Hellwig 已提交
914
	struct file			*file,
915 916 917
	unsigned int			cmd,
	struct xfs_bulkstat_req __user	*arg)
{
C
Christoph Hellwig 已提交
918
	struct xfs_mount		*mp = XFS_I(file_inode(file))->i_mount;
919 920 921
	struct xfs_bulk_ireq		hdr;
	struct xfs_ibulk		breq = {
		.mp			= mp,
C
Christoph Hellwig 已提交
922
		.mnt_userns		= file_mnt_user_ns(file),
923 924 925 926 927 928 929 930 931 932 933 934 935
	};
	int				error;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (XFS_FORCED_SHUTDOWN(mp))
		return -EIO;

	if (copy_from_user(&hdr, &arg->hdr, sizeof(hdr)))
		return -EFAULT;

	error = xfs_bulk_ireq_setup(mp, &hdr, &breq, arg->bulkstat);
936
	if (error == -ECANCELED)
937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952
		goto out_teardown;
	if (error < 0)
		return error;

	error = xfs_bulkstat(&breq, xfs_bulkstat_fmt);
	if (error)
		return error;

out_teardown:
	xfs_bulk_ireq_teardown(&hdr, &breq);
	if (copy_to_user(&arg->hdr, &hdr, sizeof(hdr)))
		return -EFAULT;

	return 0;
}

953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985
STATIC int
xfs_inumbers_fmt(
	struct xfs_ibulk		*breq,
	const struct xfs_inumbers	*igrp)
{
	if (copy_to_user(breq->ubuffer, igrp, sizeof(struct xfs_inumbers)))
		return -EFAULT;
	return xfs_ibulk_advance(breq, sizeof(struct xfs_inumbers));
}

/* Handle the v5 inumbers ioctl. */
STATIC int
xfs_ioc_inumbers(
	struct xfs_mount		*mp,
	unsigned int			cmd,
	struct xfs_inumbers_req __user	*arg)
{
	struct xfs_bulk_ireq		hdr;
	struct xfs_ibulk		breq = {
		.mp			= mp,
	};
	int				error;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (XFS_FORCED_SHUTDOWN(mp))
		return -EIO;

	if (copy_from_user(&hdr, &arg->hdr, sizeof(hdr)))
		return -EFAULT;

	error = xfs_bulk_ireq_setup(mp, &hdr, &breq, arg->inumbers);
986
	if (error == -ECANCELED)
987 988 989 990 991 992 993 994 995 996 997 998 999
		goto out_teardown;
	if (error < 0)
		return error;

	error = xfs_inumbers(&breq, xfs_inumbers_fmt);
	if (error)
		return error;

out_teardown:
	xfs_bulk_ireq_teardown(&hdr, &breq);
	if (copy_to_user(&arg->hdr, &hdr, sizeof(hdr)))
		return -EFAULT;

L
Linus Torvalds 已提交
1000 1001 1002 1003 1004
	return 0;
}

STATIC int
xfs_ioc_fsgeometry(
1005 1006 1007
	struct xfs_mount	*mp,
	void			__user *arg,
	int			struct_version)
L
Linus Torvalds 已提交
1008
{
1009 1010
	struct xfs_fsop_geom	fsgeo;
	size_t			len;
L
Linus Torvalds 已提交
1011

1012
	xfs_fs_geometry(&mp->m_sb, &fsgeo, struct_version);
L
Linus Torvalds 已提交
1013

1014 1015 1016 1017
	if (struct_version <= 3)
		len = sizeof(struct xfs_fsop_geom_v1);
	else if (struct_version == 4)
		len = sizeof(struct xfs_fsop_geom_v4);
1018 1019
	else {
		xfs_fsop_geom_health(mp, &fsgeo);
1020
		len = sizeof(fsgeo);
1021
	}
1022 1023

	if (copy_to_user(arg, &fsgeo, len))
E
Eric Sandeen 已提交
1024
		return -EFAULT;
L
Linus Torvalds 已提交
1025 1026 1027
	return 0;
}

1028 1029 1030 1031 1032 1033 1034 1035 1036 1037
STATIC int
xfs_ioc_ag_geometry(
	struct xfs_mount	*mp,
	void			__user *arg)
{
	struct xfs_ag_geometry	ageo;
	int			error;

	if (copy_from_user(&ageo, arg, sizeof(ageo)))
		return -EFAULT;
1038 1039 1040 1041
	if (ageo.ag_flags)
		return -EINVAL;
	if (memchr_inv(&ageo.ag_reserved, 0, sizeof(ageo.ag_reserved)))
		return -EINVAL;
1042 1043 1044 1045 1046 1047 1048 1049 1050 1051

	error = xfs_ag_get_geometry(mp, ageo.ag_number, &ageo);
	if (error)
		return error;

	if (copy_to_user(arg, &ageo, sizeof(ageo)))
		return -EFAULT;
	return 0;
}

L
Linus Torvalds 已提交
1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062
/*
 * Linux extended inode flags interface.
 */

STATIC unsigned int
xfs_merge_ioc_xflags(
	unsigned int	flags,
	unsigned int	start)
{
	unsigned int	xflags = start;

1063
	if (flags & FS_IMMUTABLE_FL)
1064
		xflags |= FS_XFLAG_IMMUTABLE;
L
Linus Torvalds 已提交
1065
	else
1066
		xflags &= ~FS_XFLAG_IMMUTABLE;
1067
	if (flags & FS_APPEND_FL)
1068
		xflags |= FS_XFLAG_APPEND;
L
Linus Torvalds 已提交
1069
	else
1070
		xflags &= ~FS_XFLAG_APPEND;
1071
	if (flags & FS_SYNC_FL)
1072
		xflags |= FS_XFLAG_SYNC;
L
Linus Torvalds 已提交
1073
	else
1074
		xflags &= ~FS_XFLAG_SYNC;
1075
	if (flags & FS_NOATIME_FL)
1076
		xflags |= FS_XFLAG_NOATIME;
L
Linus Torvalds 已提交
1077
	else
1078
		xflags &= ~FS_XFLAG_NOATIME;
1079
	if (flags & FS_NODUMP_FL)
1080
		xflags |= FS_XFLAG_NODUMP;
L
Linus Torvalds 已提交
1081
	else
1082
		xflags &= ~FS_XFLAG_NODUMP;
1083 1084 1085 1086
	if (flags & FS_DAX_FL)
		xflags |= FS_XFLAG_DAX;
	else
		xflags &= ~FS_XFLAG_DAX;
L
Linus Torvalds 已提交
1087 1088 1089 1090 1091 1092

	return xflags;
}

STATIC unsigned int
xfs_di2lxflags(
1093 1094
	uint16_t	di_flags,
	uint64_t	di_flags2)
L
Linus Torvalds 已提交
1095 1096 1097 1098
{
	unsigned int	flags = 0;

	if (di_flags & XFS_DIFLAG_IMMUTABLE)
1099
		flags |= FS_IMMUTABLE_FL;
L
Linus Torvalds 已提交
1100
	if (di_flags & XFS_DIFLAG_APPEND)
1101
		flags |= FS_APPEND_FL;
L
Linus Torvalds 已提交
1102
	if (di_flags & XFS_DIFLAG_SYNC)
1103
		flags |= FS_SYNC_FL;
L
Linus Torvalds 已提交
1104
	if (di_flags & XFS_DIFLAG_NOATIME)
1105
		flags |= FS_NOATIME_FL;
L
Linus Torvalds 已提交
1106
	if (di_flags & XFS_DIFLAG_NODUMP)
1107
		flags |= FS_NODUMP_FL;
1108 1109 1110
	if (di_flags2 & XFS_DIFLAG2_DAX) {
		flags |= FS_DAX_FL;
	}
L
Linus Torvalds 已提交
1111 1112 1113
	return flags;
}

1114 1115 1116 1117 1118
static void
xfs_fill_fsxattr(
	struct xfs_inode	*ip,
	bool			attr,
	struct fsxattr		*fa)
1119
{
1120
	struct xfs_mount	*mp = ip->i_mount;
1121 1122
	struct xfs_ifork	*ifp = attr ? ip->i_afp : &ip->i_df;

1123
	simple_fill_fsxattr(fa, xfs_ip2xflags(ip));
1124 1125

	fa->fsx_extsize = XFS_FSB_TO_B(mp, ip->i_extsize);
1126 1127
	if (ip->i_d.di_flags2 & XFS_DIFLAG2_COWEXTSIZE)
		fa->fsx_cowextsize = XFS_FSB_TO_B(mp, ip->i_cowextsize);
1128
	fa->fsx_projid = ip->i_projid;
1129 1130 1131 1132
	if (ifp && (ifp->if_flags & XFS_IFEXTENTS))
		fa->fsx_nextents = xfs_iext_count(ifp);
	else
		fa->fsx_nextents = xfs_ifork_nextents(ifp);
1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144
}

STATIC int
xfs_ioc_fsgetxattr(
	xfs_inode_t		*ip,
	int			attr,
	void			__user *arg)
{
	struct fsxattr		fa;

	xfs_ilock(ip, XFS_ILOCK_SHARED);
	xfs_fill_fsxattr(ip, attr, &fa);
1145 1146 1147 1148 1149 1150 1151
	xfs_iunlock(ip, XFS_ILOCK_SHARED);

	if (copy_to_user(arg, &fa, sizeof(fa)))
		return -EFAULT;
	return 0;
}

1152 1153
STATIC uint16_t
xfs_flags2diflags(
1154 1155 1156 1157
	struct xfs_inode	*ip,
	unsigned int		xflags)
{
	/* can't set PREALLOC this way, just preserve it */
1158 1159 1160
	uint16_t		di_flags =
		(ip->i_d.di_flags & XFS_DIFLAG_PREALLOC);

1161
	if (xflags & FS_XFLAG_IMMUTABLE)
1162
		di_flags |= XFS_DIFLAG_IMMUTABLE;
1163
	if (xflags & FS_XFLAG_APPEND)
1164
		di_flags |= XFS_DIFLAG_APPEND;
1165
	if (xflags & FS_XFLAG_SYNC)
1166
		di_flags |= XFS_DIFLAG_SYNC;
1167
	if (xflags & FS_XFLAG_NOATIME)
1168
		di_flags |= XFS_DIFLAG_NOATIME;
1169
	if (xflags & FS_XFLAG_NODUMP)
1170
		di_flags |= XFS_DIFLAG_NODUMP;
1171
	if (xflags & FS_XFLAG_NODEFRAG)
1172
		di_flags |= XFS_DIFLAG_NODEFRAG;
1173
	if (xflags & FS_XFLAG_FILESTREAM)
1174
		di_flags |= XFS_DIFLAG_FILESTREAM;
D
Dave Chinner 已提交
1175
	if (S_ISDIR(VFS_I(ip)->i_mode)) {
1176
		if (xflags & FS_XFLAG_RTINHERIT)
1177
			di_flags |= XFS_DIFLAG_RTINHERIT;
1178
		if (xflags & FS_XFLAG_NOSYMLINKS)
1179
			di_flags |= XFS_DIFLAG_NOSYMLINKS;
1180
		if (xflags & FS_XFLAG_EXTSZINHERIT)
1181
			di_flags |= XFS_DIFLAG_EXTSZINHERIT;
1182
		if (xflags & FS_XFLAG_PROJINHERIT)
1183
			di_flags |= XFS_DIFLAG_PROJINHERIT;
D
Dave Chinner 已提交
1184
	} else if (S_ISREG(VFS_I(ip)->i_mode)) {
1185
		if (xflags & FS_XFLAG_REALTIME)
1186
			di_flags |= XFS_DIFLAG_REALTIME;
1187
		if (xflags & FS_XFLAG_EXTSIZE)
1188 1189
			di_flags |= XFS_DIFLAG_EXTSIZE;
	}
1190

1191 1192 1193 1194 1195 1196 1197 1198 1199
	return di_flags;
}

STATIC uint64_t
xfs_flags2diflags2(
	struct xfs_inode	*ip,
	unsigned int		xflags)
{
	uint64_t		di_flags2 =
1200 1201
		(ip->i_d.di_flags2 & (XFS_DIFLAG2_REFLINK |
				      XFS_DIFLAG2_BIGTIME));
1202 1203 1204

	if (xflags & FS_XFLAG_DAX)
		di_flags2 |= XFS_DIFLAG2_DAX;
1205 1206
	if (xflags & FS_XFLAG_COWEXTSIZE)
		di_flags2 |= XFS_DIFLAG2_COWEXTSIZE;
1207

1208
	return di_flags2;
1209 1210
}

1211 1212 1213 1214 1215 1216 1217
static int
xfs_ioctl_setattr_xflags(
	struct xfs_trans	*tp,
	struct xfs_inode	*ip,
	struct fsxattr		*fa)
{
	struct xfs_mount	*mp = ip->i_mount;
1218
	uint64_t		di_flags2;
1219 1220

	/* Can't change realtime flag if any extents are allocated. */
1221
	if ((ip->i_df.if_nextents || ip->i_delayed_blks) &&
1222
	    XFS_IS_REALTIME_INODE(ip) != (fa->fsx_xflags & FS_XFLAG_REALTIME))
1223 1224 1225
		return -EINVAL;

	/* If realtime flag is set then must have realtime device */
1226
	if (fa->fsx_xflags & FS_XFLAG_REALTIME) {
1227
		if (mp->m_sb.sb_rblocks == 0 || mp->m_sb.sb_rextsize == 0 ||
1228
		    (ip->i_extsize % mp->m_sb.sb_rextsize))
1229 1230 1231
			return -EINVAL;
	}

1232
	/* Clear reflink if we are actually able to set the rt flag. */
1233
	if ((fa->fsx_xflags & FS_XFLAG_REALTIME) && xfs_is_reflink_inode(ip))
1234
		ip->i_d.di_flags2 &= ~XFS_DIFLAG2_REFLINK;
1235

1236 1237 1238 1239
	/* Don't allow us to set DAX mode for a reflinked file for now. */
	if ((fa->fsx_xflags & FS_XFLAG_DAX) && xfs_is_reflink_inode(ip))
		return -EINVAL;

1240 1241
	/* diflags2 only valid for v3 inodes. */
	di_flags2 = xfs_flags2diflags2(ip, fa->fsx_xflags);
1242
	if (di_flags2 && !xfs_sb_version_has_v3inode(&mp->m_sb))
1243 1244 1245 1246 1247
		return -EINVAL;

	ip->i_d.di_flags = xfs_flags2diflags(ip, fa->fsx_xflags);
	ip->i_d.di_flags2 = di_flags2;

1248
	xfs_diflags_to_iflags(ip, false);
1249 1250
	xfs_trans_ichgtime(tp, ip, XFS_ICHGTIME_CHG);
	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
1251
	XFS_STATS_INC(mp, xs_ig_attrchg);
1252 1253 1254
	return 0;
}

1255 1256
static void
xfs_ioctl_setattr_prepare_dax(
1257
	struct xfs_inode	*ip,
1258
	struct fsxattr		*fa)
1259
{
1260 1261
	struct xfs_mount	*mp = ip->i_mount;
	struct inode            *inode = VFS_I(ip);
1262

1263
	if (S_ISDIR(inode->i_mode))
1264
		return;
1265

1266 1267 1268
	if ((mp->m_flags & XFS_MOUNT_DAX_ALWAYS) ||
	    (mp->m_flags & XFS_MOUNT_DAX_NEVER))
		return;
1269

1270 1271 1272 1273 1274
	if (((fa->fsx_xflags & FS_XFLAG_DAX) &&
	    !(ip->i_d.di_flags2 & XFS_DIFLAG2_DAX)) ||
	    (!(fa->fsx_xflags & FS_XFLAG_DAX) &&
	     (ip->i_d.di_flags2 & XFS_DIFLAG2_DAX)))
		d_mark_dontcache(inode);
1275 1276
}

1277 1278 1279 1280 1281 1282 1283 1284
/*
 * Set up the transaction structure for the setattr operation, checking that we
 * have permission to do so. On success, return a clean transaction and the
 * inode locked exclusively ready for further operation specific checks. On
 * failure, return an error without modifying or locking the inode.
 */
static struct xfs_trans *
xfs_ioctl_setattr_get_trans(
1285
	struct file		*file,
1286
	struct xfs_dquot	*pdqp)
1287
{
C
Christoph Hellwig 已提交
1288
	struct xfs_inode	*ip = XFS_I(file_inode(file));
1289 1290
	struct xfs_mount	*mp = ip->i_mount;
	struct xfs_trans	*tp;
1291
	int			error = -EROFS;
1292 1293

	if (mp->m_flags & XFS_MOUNT_RDONLY)
1294
		goto out_error;
1295
	error = -EIO;
1296
	if (XFS_FORCED_SHUTDOWN(mp))
1297
		goto out_error;
1298

1299 1300
	error = xfs_trans_alloc_ichange(ip, NULL, NULL, pdqp,
			capable(CAP_FOWNER), &tp);
1301
	if (error)
1302
		goto out_error;
1303 1304 1305 1306 1307 1308 1309

	/*
	 * CAP_FOWNER overrides the following restrictions:
	 *
	 * The user ID of the calling process must be equal to the file owner
	 * ID, except in cases where the CAP_FSETID capability is applicable.
	 */
C
Christoph Hellwig 已提交
1310
	if (!inode_owner_or_capable(file_mnt_user_ns(file), VFS_I(ip))) {
1311 1312 1313 1314 1315 1316 1317 1318 1319 1320
		error = -EPERM;
		goto out_cancel;
	}

	if (mp->m_flags & XFS_MOUNT_WSYNC)
		xfs_trans_set_sync(tp);

	return tp;

out_cancel:
1321
	xfs_trans_cancel(tp);
1322
out_error:
1323 1324 1325
	return ERR_PTR(error);
}

1326 1327 1328 1329
/*
 * extent size hint validation is somewhat cumbersome. Rules are:
 *
 * 1. extent size hint is only valid for directories and regular files
1330 1331
 * 2. FS_XFLAG_EXTSIZE is only valid for regular files
 * 3. FS_XFLAG_EXTSZINHERIT is only valid for directories.
1332 1333 1334 1335 1336 1337 1338
 * 4. can only be changed on regular files if no extents are allocated
 * 5. can be changed on directories at any time
 * 6. extsize hint of 0 turns off hints, clears inode flags.
 * 7. Extent size must be a multiple of the appropriate block size.
 * 8. for non-realtime files, the extent size hint must be limited
 *    to half the AG size to avoid alignment extending the extent beyond the
 *    limits of the AG.
D
Darrick J. Wong 已提交
1339 1340
 *
 * Please keep this function in sync with xfs_scrub_inode_extsize.
1341
 */
1342
static int
1343 1344 1345 1346 1347
xfs_ioctl_setattr_check_extsize(
	struct xfs_inode	*ip,
	struct fsxattr		*fa)
{
	struct xfs_mount	*mp = ip->i_mount;
1348 1349
	xfs_extlen_t		size;
	xfs_fsblock_t		extsize_fsb;
1350

1351
	if (S_ISREG(VFS_I(ip)->i_mode) && ip->i_df.if_nextents &&
1352
	    ((ip->i_extsize << mp->m_sb.sb_blocklog) != fa->fsx_extsize))
1353 1354
		return -EINVAL;

1355 1356
	if (fa->fsx_extsize == 0)
		return 0;
1357

1358 1359 1360
	extsize_fsb = XFS_B_TO_FSB(mp, fa->fsx_extsize);
	if (extsize_fsb > MAXEXTLEN)
		return -EINVAL;
1361

1362 1363 1364 1365 1366 1367
	if (XFS_IS_REALTIME_INODE(ip) ||
	    (fa->fsx_xflags & FS_XFLAG_REALTIME)) {
		size = mp->m_sb.sb_rextsize << mp->m_sb.sb_blocklog;
	} else {
		size = mp->m_sb.sb_blocksize;
		if (extsize_fsb > mp->m_sb.sb_agblocks / 2)
1368
			return -EINVAL;
1369 1370 1371 1372
	}

	if (fa->fsx_extsize % size)
		return -EINVAL;
1373

1374 1375 1376
	return 0;
}

1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388
/*
 * CoW extent size hint validation rules are:
 *
 * 1. CoW extent size hint can only be set if reflink is enabled on the fs.
 *    The inode does not have to have any shared blocks, but it must be a v3.
 * 2. FS_XFLAG_COWEXTSIZE is only valid for directories and regular files;
 *    for a directory, the hint is propagated to new files.
 * 3. Can be changed on files & directories at any time.
 * 4. CoW extsize hint of 0 turns off hints, clears inode flags.
 * 5. Extent size must be a multiple of the appropriate block size.
 * 6. The extent size hint must be limited to half the AG size to avoid
 *    alignment extending the extent beyond the limits of the AG.
D
Darrick J. Wong 已提交
1389 1390
 *
 * Please keep this function in sync with xfs_scrub_inode_cowextsize.
1391 1392 1393 1394 1395 1396 1397
 */
static int
xfs_ioctl_setattr_check_cowextsize(
	struct xfs_inode	*ip,
	struct fsxattr		*fa)
{
	struct xfs_mount	*mp = ip->i_mount;
1398 1399
	xfs_extlen_t		size;
	xfs_fsblock_t		cowextsize_fsb;
1400 1401 1402 1403

	if (!(fa->fsx_xflags & FS_XFLAG_COWEXTSIZE))
		return 0;

1404
	if (!xfs_sb_version_hasreflink(&ip->i_mount->m_sb))
1405 1406
		return -EINVAL;

1407 1408
	if (fa->fsx_cowextsize == 0)
		return 0;
1409

1410 1411 1412
	cowextsize_fsb = XFS_B_TO_FSB(mp, fa->fsx_cowextsize);
	if (cowextsize_fsb > MAXEXTLEN)
		return -EINVAL;
1413

1414 1415 1416
	size = mp->m_sb.sb_blocksize;
	if (cowextsize_fsb > mp->m_sb.sb_agblocks / 2)
		return -EINVAL;
1417

1418 1419
	if (fa->fsx_cowextsize % size)
		return -EINVAL;
1420 1421 1422 1423

	return 0;
}

1424
static int
1425 1426 1427 1428 1429
xfs_ioctl_setattr_check_projid(
	struct xfs_inode	*ip,
	struct fsxattr		*fa)
{
	/* Disallow 32bit project ids if projid32bit feature is not enabled. */
1430
	if (fa->fsx_projid > (uint16_t)-1 &&
1431 1432 1433 1434
	    !xfs_sb_version_hasprojid32bit(&ip->i_mount->m_sb))
		return -EINVAL;
	return 0;
}
1435 1436 1437

STATIC int
xfs_ioctl_setattr(
C
Christoph Hellwig 已提交
1438
	struct file		*file,
1439
	struct fsxattr		*fa)
1440
{
C
Christoph Hellwig 已提交
1441 1442
	struct user_namespace	*mnt_userns = file_mnt_user_ns(file);
	struct xfs_inode	*ip = XFS_I(file_inode(file));
1443
	struct fsxattr		old_fa;
1444 1445
	struct xfs_mount	*mp = ip->i_mount;
	struct xfs_trans	*tp;
1446
	struct xfs_dquot	*pdqp = NULL;
1447
	struct xfs_dquot	*olddquot = NULL;
1448
	int			error;
1449

C
Christoph Hellwig 已提交
1450
	trace_xfs_ioctl_setattr(ip);
1451

1452 1453 1454
	error = xfs_ioctl_setattr_check_projid(ip, fa);
	if (error)
		return error;
1455

1456 1457 1458 1459 1460 1461 1462 1463
	/*
	 * If disk quotas is on, we make sure that the dquots do exist on disk,
	 * before we start any other transactions. Trying to do this later
	 * is messy. We don't care to take a readlock to look at the ids
	 * in inode here, because we can't hold it across the trans_reserve.
	 * If the IDs do change before we take the ilock, we're covered
	 * because the i_*dquot fields will get updated anyway.
	 */
1464
	if (XFS_IS_QUOTA_ON(mp)) {
1465
		error = xfs_qm_vop_dqalloc(ip, VFS_I(ip)->i_uid,
1466
				VFS_I(ip)->i_gid, fa->fsx_projid,
1467
				XFS_QMOPT_PQUOTA, NULL, NULL, &pdqp);
1468 1469
		if (error)
			return error;
1470 1471
	}

1472
	xfs_ioctl_setattr_prepare_dax(ip, fa);
1473

1474
	tp = xfs_ioctl_setattr_get_trans(file, pdqp);
1475
	if (IS_ERR(tp)) {
1476
		error = PTR_ERR(tp);
1477
		goto error_free_dquots;
1478 1479
	}

1480
	xfs_fill_fsxattr(ip, false, &old_fa);
1481 1482
	error = vfs_ioc_fssetxattr_check(VFS_I(ip), &old_fa, fa);
	if (error)
1483 1484
		goto error_trans_cancel;

1485 1486
	error = xfs_ioctl_setattr_check_extsize(ip, fa);
	if (error)
1487
		goto error_trans_cancel;
1488

1489 1490
	error = xfs_ioctl_setattr_check_cowextsize(ip, fa);
	if (error)
1491 1492
		goto error_trans_cancel;

1493 1494
	error = xfs_ioctl_setattr_xflags(tp, ip, fa);
	if (error)
1495
		goto error_trans_cancel;
1496 1497

	/*
1498 1499 1500 1501 1502
	 * Change file ownership.  Must be the owner or privileged.  CAP_FSETID
	 * overrides the following restrictions:
	 *
	 * The set-user-ID and set-group-ID bits of a file will be cleared upon
	 * successful return from chown()
1503 1504
	 */

D
Dave Chinner 已提交
1505
	if ((VFS_I(ip)->i_mode & (S_ISUID|S_ISGID)) &&
C
Christoph Hellwig 已提交
1506
	    !capable_wrt_inode_uidgid(mnt_userns, VFS_I(ip), CAP_FSETID))
D
Dave Chinner 已提交
1507
		VFS_I(ip)->i_mode &= ~(S_ISUID|S_ISGID);
1508

1509
	/* Change the ownerships and register project quota modifications */
1510
	if (ip->i_projid != fa->fsx_projid) {
1511 1512 1513 1514
		if (XFS_IS_QUOTA_RUNNING(mp) && XFS_IS_PQUOTA_ON(mp)) {
			olddquot = xfs_qm_vop_chown(tp, ip,
						&ip->i_pdquot, pdqp);
		}
1515
		ip->i_projid = fa->fsx_projid;
1516
	}
1517

1518 1519 1520 1521 1522
	/*
	 * Only set the extent size hint if we've already determined that the
	 * extent size hint should be set on the inode. If no extent size flags
	 * are set on the inode then unconditionally clear the extent size hint.
	 */
1523
	if (ip->i_d.di_flags & (XFS_DIFLAG_EXTSIZE | XFS_DIFLAG_EXTSZINHERIT))
1524
		ip->i_extsize = XFS_B_TO_FSB(mp, fa->fsx_extsize);
1525
	else
1526
		ip->i_extsize = 0;
1527 1528 1529 1530 1531 1532 1533

	if (xfs_sb_version_has_v3inode(&mp->m_sb)) {
		if (ip->i_d.di_flags2 & XFS_DIFLAG2_COWEXTSIZE)
			ip->i_cowextsize = XFS_B_TO_FSB(mp, fa->fsx_cowextsize);
		else
			ip->i_cowextsize = 0;
	}
1534

1535
	error = xfs_trans_commit(tp);
1536 1537 1538 1539

	/*
	 * Release any dquot(s) the inode had kept before chown.
	 */
C
Christoph Hellwig 已提交
1540
	xfs_qm_dqrele(olddquot);
1541
	xfs_qm_dqrele(pdqp);
1542

1543
	return error;
1544

1545
error_trans_cancel:
1546
	xfs_trans_cancel(tp);
1547
error_free_dquots:
1548
	xfs_qm_dqrele(pdqp);
1549
	return error;
1550 1551
}

L
Linus Torvalds 已提交
1552
STATIC int
L
Lachlan McIlroy 已提交
1553
xfs_ioc_fssetxattr(
L
Linus Torvalds 已提交
1554 1555 1556 1557
	struct file		*filp,
	void			__user *arg)
{
	struct fsxattr		fa;
J
Jan Kara 已提交
1558
	int error;
L
Lachlan McIlroy 已提交
1559 1560 1561

	if (copy_from_user(&fa, arg, sizeof(fa)))
		return -EFAULT;
L
Linus Torvalds 已提交
1562

J
Jan Kara 已提交
1563 1564 1565
	error = mnt_want_write_file(filp);
	if (error)
		return error;
C
Christoph Hellwig 已提交
1566
	error = xfs_ioctl_setattr(filp, &fa);
J
Jan Kara 已提交
1567
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1568
	return error;
L
Lachlan McIlroy 已提交
1569
}
L
Linus Torvalds 已提交
1570

L
Lachlan McIlroy 已提交
1571 1572 1573 1574 1575 1576
STATIC int
xfs_ioc_getxflags(
	xfs_inode_t		*ip,
	void			__user *arg)
{
	unsigned int		flags;
L
Linus Torvalds 已提交
1577

1578
	flags = xfs_di2lxflags(ip->i_d.di_flags, ip->i_d.di_flags2);
L
Lachlan McIlroy 已提交
1579 1580 1581 1582
	if (copy_to_user(arg, &flags, sizeof(flags)))
		return -EFAULT;
	return 0;
}
L
Linus Torvalds 已提交
1583

L
Lachlan McIlroy 已提交
1584 1585
STATIC int
xfs_ioc_setxflags(
1586
	struct xfs_inode	*ip,
L
Lachlan McIlroy 已提交
1587 1588 1589
	struct file		*filp,
	void			__user *arg)
{
1590
	struct xfs_trans	*tp;
1591
	struct fsxattr		fa;
1592
	struct fsxattr		old_fa;
L
Lachlan McIlroy 已提交
1593
	unsigned int		flags;
1594
	int			error;
L
Linus Torvalds 已提交
1595

L
Lachlan McIlroy 已提交
1596 1597
	if (copy_from_user(&flags, arg, sizeof(flags)))
		return -EFAULT;
L
Linus Torvalds 已提交
1598

L
Lachlan McIlroy 已提交
1599 1600
	if (flags & ~(FS_IMMUTABLE_FL | FS_APPEND_FL | \
		      FS_NOATIME_FL | FS_NODUMP_FL | \
1601
		      FS_SYNC_FL | FS_DAX_FL))
L
Lachlan McIlroy 已提交
1602
		return -EOPNOTSUPP;
L
Linus Torvalds 已提交
1603

1604
	fa.fsx_xflags = xfs_merge_ioc_xflags(flags, xfs_ip2xflags(ip));
L
Linus Torvalds 已提交
1605

J
Jan Kara 已提交
1606 1607 1608
	error = mnt_want_write_file(filp);
	if (error)
		return error;
1609

1610
	xfs_ioctl_setattr_prepare_dax(ip, &fa);
1611

1612
	tp = xfs_ioctl_setattr_get_trans(filp, NULL);
1613 1614 1615 1616 1617
	if (IS_ERR(tp)) {
		error = PTR_ERR(tp);
		goto out_drop_write;
	}

1618 1619 1620 1621 1622 1623 1624
	xfs_fill_fsxattr(ip, false, &old_fa);
	error = vfs_ioc_fssetxattr_check(VFS_I(ip), &old_fa, &fa);
	if (error) {
		xfs_trans_cancel(tp);
		goto out_drop_write;
	}

1625 1626
	error = xfs_ioctl_setattr_xflags(tp, ip, &fa);
	if (error) {
1627
		xfs_trans_cancel(tp);
1628 1629 1630
		goto out_drop_write;
	}

1631
	error = xfs_trans_commit(tp);
1632
out_drop_write:
J
Jan Kara 已提交
1633
	mnt_drop_write_file(filp);
D
Dave Chinner 已提交
1634
	return error;
L
Linus Torvalds 已提交
1635 1636
}

1637 1638 1639 1640 1641
static bool
xfs_getbmap_format(
	struct kgetbmap		*p,
	struct getbmapx __user	*u,
	size_t			recsize)
1642
{
1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656
	if (put_user(p->bmv_offset, &u->bmv_offset) ||
	    put_user(p->bmv_block, &u->bmv_block) ||
	    put_user(p->bmv_length, &u->bmv_length) ||
	    put_user(0, &u->bmv_count) ||
	    put_user(0, &u->bmv_entries))
		return false;
	if (recsize < sizeof(struct getbmapx))
		return true;
	if (put_user(0, &u->bmv_iflags) ||
	    put_user(p->bmv_oflags, &u->bmv_oflags) ||
	    put_user(0, &u->bmv_unused1) ||
	    put_user(0, &u->bmv_unused2))
		return false;
	return true;
1657 1658
}

L
Linus Torvalds 已提交
1659 1660
STATIC int
xfs_ioc_getbmap(
1661
	struct file		*file,
L
Linus Torvalds 已提交
1662 1663 1664
	unsigned int		cmd,
	void			__user *arg)
{
1665
	struct getbmapx		bmx = { 0 };
1666 1667 1668
	struct kgetbmap		*buf;
	size_t			recsize;
	int			error, i;
L
Linus Torvalds 已提交
1669

1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683
	switch (cmd) {
	case XFS_IOC_GETBMAPA:
		bmx.bmv_iflags = BMV_IF_ATTRFORK;
		/*FALLTHRU*/
	case XFS_IOC_GETBMAP:
		if (file->f_mode & FMODE_NOCMTIME)
			bmx.bmv_iflags |= BMV_IF_NO_DMAPI_READ;
		/* struct getbmap is a strict subset of struct getbmapx. */
		recsize = sizeof(struct getbmap);
		break;
	case XFS_IOC_GETBMAPX:
		recsize = sizeof(struct getbmapx);
		break;
	default:
E
Eric Sandeen 已提交
1684
		return -EINVAL;
1685
	}
L
Linus Torvalds 已提交
1686

1687
	if (copy_from_user(&bmx, arg, recsize))
E
Eric Sandeen 已提交
1688
		return -EFAULT;
L
Linus Torvalds 已提交
1689 1690

	if (bmx.bmv_count < 2)
E
Eric Sandeen 已提交
1691
		return -EINVAL;
1692 1693
	if (bmx.bmv_count > ULONG_MAX / recsize)
		return -ENOMEM;
L
Linus Torvalds 已提交
1694

1695
	buf = kvzalloc(bmx.bmv_count * sizeof(*buf), GFP_KERNEL);
1696 1697
	if (!buf)
		return -ENOMEM;
L
Linus Torvalds 已提交
1698

1699
	error = xfs_getbmap(XFS_I(file_inode(file)), &bmx, buf);
L
Linus Torvalds 已提交
1700
	if (error)
1701
		goto out_free_buf;
L
Linus Torvalds 已提交
1702

1703 1704 1705 1706 1707 1708 1709 1710 1711 1712
	error = -EFAULT;
	if (copy_to_user(arg, &bmx, recsize))
		goto out_free_buf;
	arg += recsize;

	for (i = 0; i < bmx.bmv_entries; i++) {
		if (!xfs_getbmap_format(buf + i, arg, recsize))
			goto out_free_buf;
		arg += recsize;
	}
L
Linus Torvalds 已提交
1713

1714 1715 1716
	error = 0;
out_free_buf:
	kmem_free(buf);
1717
	return error;
L
Linus Torvalds 已提交
1718
}
L
Lachlan McIlroy 已提交
1719

1720 1721 1722
STATIC int
xfs_ioc_getfsmap(
	struct xfs_inode	*ip,
1723
	struct fsmap_head	__user *arg)
1724 1725 1726
{
	struct xfs_fsmap_head	xhead = {0};
	struct fsmap_head	head;
1727 1728 1729 1730
	struct fsmap		*recs;
	unsigned int		count;
	__u32			last_flags = 0;
	bool			done = false;
1731 1732 1733 1734 1735 1736 1737 1738 1739 1740 1741
	int			error;

	if (copy_from_user(&head, arg, sizeof(struct fsmap_head)))
		return -EFAULT;
	if (memchr_inv(head.fmh_reserved, 0, sizeof(head.fmh_reserved)) ||
	    memchr_inv(head.fmh_keys[0].fmr_reserved, 0,
		       sizeof(head.fmh_keys[0].fmr_reserved)) ||
	    memchr_inv(head.fmh_keys[1].fmr_reserved, 0,
		       sizeof(head.fmh_keys[1].fmr_reserved)))
		return -EINVAL;

1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757
	/*
	 * Use an internal memory buffer so that we don't have to copy fsmap
	 * data to userspace while holding locks.  Start by trying to allocate
	 * up to 128k for the buffer, but fall back to a single page if needed.
	 */
	count = min_t(unsigned int, head.fmh_count,
			131072 / sizeof(struct fsmap));
	recs = kvzalloc(count * sizeof(struct fsmap), GFP_KERNEL);
	if (!recs) {
		count = min_t(unsigned int, head.fmh_count,
				PAGE_SIZE / sizeof(struct fsmap));
		recs = kvzalloc(count * sizeof(struct fsmap), GFP_KERNEL);
		if (!recs)
			return -ENOMEM;
	}

1758 1759 1760 1761 1762 1763 1764
	xhead.fmh_iflags = head.fmh_iflags;
	xfs_fsmap_to_internal(&xhead.fmh_keys[0], &head.fmh_keys[0]);
	xfs_fsmap_to_internal(&xhead.fmh_keys[1], &head.fmh_keys[1]);

	trace_xfs_getfsmap_low_key(ip->i_mount, &xhead.fmh_keys[0]);
	trace_xfs_getfsmap_high_key(ip->i_mount, &xhead.fmh_keys[1]);

1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795 1796 1797
	head.fmh_entries = 0;
	do {
		struct fsmap __user	*user_recs;
		struct fsmap		*last_rec;

		user_recs = &arg->fmh_recs[head.fmh_entries];
		xhead.fmh_entries = 0;
		xhead.fmh_count = min_t(unsigned int, count,
					head.fmh_count - head.fmh_entries);

		/* Run query, record how many entries we got. */
		error = xfs_getfsmap(ip->i_mount, &xhead, recs);
		switch (error) {
		case 0:
			/*
			 * There are no more records in the result set.  Copy
			 * whatever we got to userspace and break out.
			 */
			done = true;
			break;
		case -ECANCELED:
			/*
			 * The internal memory buffer is full.  Copy whatever
			 * records we got to userspace and go again if we have
			 * not yet filled the userspace buffer.
			 */
			error = 0;
			break;
		default:
			goto out_free;
		}
		head.fmh_entries += xhead.fmh_entries;
		head.fmh_oflags = xhead.fmh_oflags;
1798

1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836
		/*
		 * If the caller wanted a record count or there aren't any
		 * new records to return, we're done.
		 */
		if (head.fmh_count == 0 || xhead.fmh_entries == 0)
			break;

		/* Copy all the records we got out to userspace. */
		if (copy_to_user(user_recs, recs,
				 xhead.fmh_entries * sizeof(struct fsmap))) {
			error = -EFAULT;
			goto out_free;
		}

		/* Remember the last record flags we copied to userspace. */
		last_rec = &recs[xhead.fmh_entries - 1];
		last_flags = last_rec->fmr_flags;

		/* Set up the low key for the next iteration. */
		xfs_fsmap_to_internal(&xhead.fmh_keys[0], last_rec);
		trace_xfs_getfsmap_low_key(ip->i_mount, &xhead.fmh_keys[0]);
	} while (!done && head.fmh_entries < head.fmh_count);

	/*
	 * If there are no more records in the query result set and we're not
	 * in counting mode, mark the last record returned with the LAST flag.
	 */
	if (done && head.fmh_count > 0 && head.fmh_entries > 0) {
		struct fsmap __user	*user_rec;

		last_flags |= FMR_OF_LAST;
		user_rec = &arg->fmh_recs[head.fmh_entries - 1];

		if (copy_to_user(&user_rec->fmr_flags, &last_flags,
					sizeof(last_flags))) {
			error = -EFAULT;
			goto out_free;
		}
1837 1838 1839
	}

	/* copy back header */
1840 1841 1842 1843
	if (copy_to_user(arg, &head, sizeof(struct fsmap_head))) {
		error = -EFAULT;
		goto out_free;
	}
1844

1845 1846 1847
out_free:
	kmem_free(recs);
	return error;
1848 1849
}

1850 1851 1852 1853 1854 1855 1856 1857 1858 1859 1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873
STATIC int
xfs_ioc_scrub_metadata(
	struct xfs_inode		*ip,
	void				__user *arg)
{
	struct xfs_scrub_metadata	scrub;
	int				error;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

	if (copy_from_user(&scrub, arg, sizeof(scrub)))
		return -EFAULT;

	error = xfs_scrub_metadata(ip, &scrub);
	if (error)
		return error;

	if (copy_to_user(arg, &scrub, sizeof(scrub)))
		return -EFAULT;

	return 0;
}

D
Dave Chinner 已提交
1874 1875 1876 1877 1878 1879 1880 1881 1882 1883 1884
int
xfs_ioc_swapext(
	xfs_swapext_t	*sxp)
{
	xfs_inode_t     *ip, *tip;
	struct fd	f, tmp;
	int		error = 0;

	/* Pull information for the target fd */
	f = fdget((int)sxp->sx_fdtarget);
	if (!f.file) {
D
Dave Chinner 已提交
1885
		error = -EINVAL;
D
Dave Chinner 已提交
1886 1887 1888 1889 1890 1891
		goto out;
	}

	if (!(f.file->f_mode & FMODE_WRITE) ||
	    !(f.file->f_mode & FMODE_READ) ||
	    (f.file->f_flags & O_APPEND)) {
D
Dave Chinner 已提交
1892
		error = -EBADF;
D
Dave Chinner 已提交
1893 1894 1895 1896 1897
		goto out_put_file;
	}

	tmp = fdget((int)sxp->sx_fdtmp);
	if (!tmp.file) {
D
Dave Chinner 已提交
1898
		error = -EINVAL;
D
Dave Chinner 已提交
1899 1900 1901 1902 1903 1904
		goto out_put_file;
	}

	if (!(tmp.file->f_mode & FMODE_WRITE) ||
	    !(tmp.file->f_mode & FMODE_READ) ||
	    (tmp.file->f_flags & O_APPEND)) {
D
Dave Chinner 已提交
1905
		error = -EBADF;
D
Dave Chinner 已提交
1906 1907 1908 1909 1910
		goto out_put_tmp_file;
	}

	if (IS_SWAPFILE(file_inode(f.file)) ||
	    IS_SWAPFILE(file_inode(tmp.file))) {
D
Dave Chinner 已提交
1911
		error = -EINVAL;
D
Dave Chinner 已提交
1912 1913 1914
		goto out_put_tmp_file;
	}

1915 1916 1917 1918 1919 1920 1921 1922 1923 1924 1925
	/*
	 * We need to ensure that the fds passed in point to XFS inodes
	 * before we cast and access them as XFS structures as we have no
	 * control over what the user passes us here.
	 */
	if (f.file->f_op != &xfs_file_operations ||
	    tmp.file->f_op != &xfs_file_operations) {
		error = -EINVAL;
		goto out_put_tmp_file;
	}

D
Dave Chinner 已提交
1926 1927 1928 1929
	ip = XFS_I(file_inode(f.file));
	tip = XFS_I(file_inode(tmp.file));

	if (ip->i_mount != tip->i_mount) {
D
Dave Chinner 已提交
1930
		error = -EINVAL;
D
Dave Chinner 已提交
1931 1932 1933 1934
		goto out_put_tmp_file;
	}

	if (ip->i_ino == tip->i_ino) {
D
Dave Chinner 已提交
1935
		error = -EINVAL;
D
Dave Chinner 已提交
1936 1937 1938 1939
		goto out_put_tmp_file;
	}

	if (XFS_FORCED_SHUTDOWN(ip->i_mount)) {
D
Dave Chinner 已提交
1940
		error = -EIO;
D
Dave Chinner 已提交
1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953
		goto out_put_tmp_file;
	}

	error = xfs_swap_extents(ip, tip, sxp);

 out_put_tmp_file:
	fdput(tmp);
 out_put_file:
	fdput(f);
 out:
	return error;
}

1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964
static int
xfs_ioc_getlabel(
	struct xfs_mount	*mp,
	char			__user *user_label)
{
	struct xfs_sb		*sbp = &mp->m_sb;
	char			label[XFSLABEL_MAX + 1];

	/* Paranoia */
	BUILD_BUG_ON(sizeof(sbp->sb_fname) > FSLABEL_MAX);

1965 1966
	/* 1 larger than sb_fname, so this ensures a trailing NUL char */
	memset(label, 0, sizeof(label));
1967
	spin_lock(&mp->m_sb_lock);
1968
	strncpy(label, sbp->sb_fname, XFSLABEL_MAX);
1969 1970
	spin_unlock(&mp->m_sb_lock);

1971
	if (copy_to_user(user_label, label, sizeof(label)))
1972 1973 1974 1975 1976 1977 1978 1979 1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006
		return -EFAULT;
	return 0;
}

static int
xfs_ioc_setlabel(
	struct file		*filp,
	struct xfs_mount	*mp,
	char			__user *newlabel)
{
	struct xfs_sb		*sbp = &mp->m_sb;
	char			label[XFSLABEL_MAX + 1];
	size_t			len;
	int			error;

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;
	/*
	 * The generic ioctl allows up to FSLABEL_MAX chars, but XFS is much
	 * smaller, at 12 bytes.  We copy one more to be sure we find the
	 * (required) NULL character to test the incoming label length.
	 * NB: The on disk label doesn't need to be null terminated.
	 */
	if (copy_from_user(label, newlabel, XFSLABEL_MAX + 1))
		return -EFAULT;
	len = strnlen(label, XFSLABEL_MAX + 1);
	if (len > sizeof(sbp->sb_fname))
		return -EINVAL;

	error = mnt_want_write_file(filp);
	if (error)
		return error;

	spin_lock(&mp->m_sb_lock);
	memset(sbp->sb_fname, 0, sizeof(sbp->sb_fname));
2007
	memcpy(sbp->sb_fname, label, len);
2008 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031 2032 2033 2034 2035
	spin_unlock(&mp->m_sb_lock);

	/*
	 * Now we do several things to satisfy userspace.
	 * In addition to normal logging of the primary superblock, we also
	 * immediately write these changes to sector zero for the primary, then
	 * update all backup supers (as xfs_db does for a label change), then
	 * invalidate the block device page cache.  This is so that any prior
	 * buffered reads from userspace (i.e. from blkid) are invalidated,
	 * and userspace will see the newly-written label.
	 */
	error = xfs_sync_sb_buf(mp);
	if (error)
		goto out;
	/*
	 * growfs also updates backup supers so lock against that.
	 */
	mutex_lock(&mp->m_growlock);
	error = xfs_update_secondary_sbs(mp);
	mutex_unlock(&mp->m_growlock);

	invalidate_bdev(mp->m_ddev_targp->bt_bdev);

out:
	mnt_drop_write_file(filp);
	return error;
}

2036 2037 2038 2039 2040 2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051 2052 2053 2054 2055 2056 2057 2058 2059 2060 2061 2062 2063 2064 2065 2066 2067 2068 2069 2070
static inline int
xfs_fs_eofblocks_from_user(
	struct xfs_fs_eofblocks		*src,
	struct xfs_eofblocks		*dst)
{
	if (src->eof_version != XFS_EOFBLOCKS_VERSION)
		return -EINVAL;

	if (src->eof_flags & ~XFS_EOF_FLAGS_VALID)
		return -EINVAL;

	if (memchr_inv(&src->pad32, 0, sizeof(src->pad32)) ||
	    memchr_inv(src->pad64, 0, sizeof(src->pad64)))
		return -EINVAL;

	dst->eof_flags = src->eof_flags;
	dst->eof_prid = src->eof_prid;
	dst->eof_min_file_size = src->eof_min_file_size;

	dst->eof_uid = INVALID_UID;
	if (src->eof_flags & XFS_EOF_FLAGS_UID) {
		dst->eof_uid = make_kuid(current_user_ns(), src->eof_uid);
		if (!uid_valid(dst->eof_uid))
			return -EINVAL;
	}

	dst->eof_gid = INVALID_GID;
	if (src->eof_flags & XFS_EOF_FLAGS_GID) {
		dst->eof_gid = make_kgid(current_user_ns(), src->eof_gid);
		if (!gid_valid(dst->eof_gid))
			return -EINVAL;
	}
	return 0;
}

2071 2072 2073 2074 2075 2076 2077 2078
/*
 * Note: some of the ioctl's return positive numbers as a
 * byte count indicating success, such as readlink_by_handle.
 * So we don't "sign flip" like most other routines.  This means
 * true errors need to be returned as a negative value.
 */
long
xfs_file_ioctl(
L
Lachlan McIlroy 已提交
2079 2080
	struct file		*filp,
	unsigned int		cmd,
2081
	unsigned long		p)
L
Lachlan McIlroy 已提交
2082
{
A
Al Viro 已提交
2083
	struct inode		*inode = file_inode(filp);
2084 2085 2086
	struct xfs_inode	*ip = XFS_I(inode);
	struct xfs_mount	*mp = ip->i_mount;
	void			__user *arg = (void __user *)p;
L
Lachlan McIlroy 已提交
2087 2088
	int			error;

C
Christoph Hellwig 已提交
2089
	trace_xfs_file_ioctl(ip);
2090 2091

	switch (cmd) {
C
Christoph Hellwig 已提交
2092 2093
	case FITRIM:
		return xfs_ioc_trim(mp, arg);
2094 2095 2096 2097
	case FS_IOC_GETFSLABEL:
		return xfs_ioc_getlabel(mp, arg);
	case FS_IOC_SETFSLABEL:
		return xfs_ioc_setlabel(filp, mp, arg);
L
Lachlan McIlroy 已提交
2098 2099 2100
	case XFS_IOC_ALLOCSP:
	case XFS_IOC_FREESP:
	case XFS_IOC_ALLOCSP64:
2101
	case XFS_IOC_FREESP64: {
2102
		xfs_flock64_t		bf;
L
Lachlan McIlroy 已提交
2103

2104
		if (copy_from_user(&bf, arg, sizeof(bf)))
E
Eric Sandeen 已提交
2105
			return -EFAULT;
2106
		return xfs_ioc_space(filp, &bf);
2107
	}
L
Lachlan McIlroy 已提交
2108
	case XFS_IOC_DIOINFO: {
2109 2110
		struct xfs_buftarg	*target = xfs_inode_buftarg(ip);
		struct dioattr		da;
L
Lachlan McIlroy 已提交
2111

2112
		da.d_mem =  da.d_miniosz = target->bt_logical_sectorsize;
L
Lachlan McIlroy 已提交
2113 2114 2115
		da.d_maxiosz = INT_MAX & ~(da.d_miniosz - 1);

		if (copy_to_user(arg, &da, sizeof(da)))
E
Eric Sandeen 已提交
2116
			return -EFAULT;
L
Lachlan McIlroy 已提交
2117 2118 2119 2120 2121 2122
		return 0;
	}

	case XFS_IOC_FSBULKSTAT_SINGLE:
	case XFS_IOC_FSBULKSTAT:
	case XFS_IOC_FSINUMBERS:
C
Christoph Hellwig 已提交
2123
		return xfs_ioc_fsbulkstat(filp, cmd, arg);
L
Lachlan McIlroy 已提交
2124

2125
	case XFS_IOC_BULKSTAT:
C
Christoph Hellwig 已提交
2126
		return xfs_ioc_bulkstat(filp, cmd, arg);
2127 2128
	case XFS_IOC_INUMBERS:
		return xfs_ioc_inumbers(mp, cmd, arg);
L
Lachlan McIlroy 已提交
2129 2130

	case XFS_IOC_FSGEOMETRY_V1:
2131 2132 2133
		return xfs_ioc_fsgeometry(mp, arg, 3);
	case XFS_IOC_FSGEOMETRY_V4:
		return xfs_ioc_fsgeometry(mp, arg, 4);
L
Lachlan McIlroy 已提交
2134
	case XFS_IOC_FSGEOMETRY:
2135
		return xfs_ioc_fsgeometry(mp, arg, 5);
L
Lachlan McIlroy 已提交
2136

2137 2138 2139
	case XFS_IOC_AG_GEOMETRY:
		return xfs_ioc_ag_geometry(mp, arg);

L
Lachlan McIlroy 已提交
2140 2141 2142 2143 2144 2145 2146
	case XFS_IOC_GETVERSION:
		return put_user(inode->i_generation, (int __user *)arg);

	case XFS_IOC_FSGETXATTR:
		return xfs_ioc_fsgetxattr(ip, 0, arg);
	case XFS_IOC_FSGETXATTRA:
		return xfs_ioc_fsgetxattr(ip, 1, arg);
L
Lachlan McIlroy 已提交
2147
	case XFS_IOC_FSSETXATTR:
C
Christoph Hellwig 已提交
2148
		return xfs_ioc_fssetxattr(filp, arg);
L
Lachlan McIlroy 已提交
2149
	case XFS_IOC_GETXFLAGS:
L
Lachlan McIlroy 已提交
2150
		return xfs_ioc_getxflags(ip, arg);
L
Lachlan McIlroy 已提交
2151
	case XFS_IOC_SETXFLAGS:
L
Lachlan McIlroy 已提交
2152
		return xfs_ioc_setxflags(ip, filp, arg);
L
Lachlan McIlroy 已提交
2153 2154 2155 2156

	case XFS_IOC_GETBMAP:
	case XFS_IOC_GETBMAPA:
	case XFS_IOC_GETBMAPX:
2157
		return xfs_ioc_getbmap(filp, cmd, arg);
L
Lachlan McIlroy 已提交
2158

2159 2160 2161
	case FS_IOC_GETFSMAP:
		return xfs_ioc_getfsmap(ip, arg);

2162 2163 2164
	case XFS_IOC_SCRUB_METADATA:
		return xfs_ioc_scrub_metadata(ip, arg);

L
Lachlan McIlroy 已提交
2165 2166
	case XFS_IOC_FD_TO_HANDLE:
	case XFS_IOC_PATH_TO_HANDLE:
2167 2168
	case XFS_IOC_PATH_TO_FSHANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
2169

2170
		if (copy_from_user(&hreq, arg, sizeof(hreq)))
E
Eric Sandeen 已提交
2171
			return -EFAULT;
2172 2173 2174 2175
		return xfs_find_handle(cmd, &hreq);
	}
	case XFS_IOC_OPEN_BY_HANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
2176

2177
		if (copy_from_user(&hreq, arg, sizeof(xfs_fsop_handlereq_t)))
E
Eric Sandeen 已提交
2178
			return -EFAULT;
2179
		return xfs_open_by_handle(filp, &hreq);
2180
	}
L
Lachlan McIlroy 已提交
2181

2182 2183
	case XFS_IOC_READLINK_BY_HANDLE: {
		xfs_fsop_handlereq_t	hreq;
L
Lachlan McIlroy 已提交
2184

2185
		if (copy_from_user(&hreq, arg, sizeof(xfs_fsop_handlereq_t)))
E
Eric Sandeen 已提交
2186
			return -EFAULT;
2187
		return xfs_readlink_by_handle(filp, &hreq);
2188
	}
L
Lachlan McIlroy 已提交
2189
	case XFS_IOC_ATTRLIST_BY_HANDLE:
2190
		return xfs_attrlist_by_handle(filp, arg);
L
Lachlan McIlroy 已提交
2191 2192

	case XFS_IOC_ATTRMULTI_BY_HANDLE:
2193
		return xfs_attrmulti_by_handle(filp, arg);
L
Lachlan McIlroy 已提交
2194 2195

	case XFS_IOC_SWAPEXT: {
2196 2197 2198
		struct xfs_swapext	sxp;

		if (copy_from_user(&sxp, arg, sizeof(xfs_swapext_t)))
E
Eric Sandeen 已提交
2199
			return -EFAULT;
J
Jan Kara 已提交
2200 2201 2202
		error = mnt_want_write_file(filp);
		if (error)
			return error;
D
Dave Chinner 已提交
2203
		error = xfs_ioc_swapext(&sxp);
J
Jan Kara 已提交
2204
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
2205
		return error;
L
Lachlan McIlroy 已提交
2206 2207 2208 2209 2210
	}

	case XFS_IOC_FSCOUNTS: {
		xfs_fsop_counts_t out;

2211
		xfs_fs_counts(mp, &out);
L
Lachlan McIlroy 已提交
2212 2213

		if (copy_to_user(arg, &out, sizeof(out)))
E
Eric Sandeen 已提交
2214
			return -EFAULT;
L
Lachlan McIlroy 已提交
2215 2216 2217 2218 2219
		return 0;
	}

	case XFS_IOC_SET_RESBLKS: {
		xfs_fsop_resblks_t inout;
2220
		uint64_t	   in;
L
Lachlan McIlroy 已提交
2221 2222 2223 2224

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

E
Eric Sandeen 已提交
2225
		if (mp->m_flags & XFS_MOUNT_RDONLY)
E
Eric Sandeen 已提交
2226
			return -EROFS;
E
Eric Sandeen 已提交
2227

L
Lachlan McIlroy 已提交
2228
		if (copy_from_user(&inout, arg, sizeof(inout)))
E
Eric Sandeen 已提交
2229
			return -EFAULT;
L
Lachlan McIlroy 已提交
2230

J
Jan Kara 已提交
2231 2232 2233 2234
		error = mnt_want_write_file(filp);
		if (error)
			return error;

L
Lachlan McIlroy 已提交
2235 2236 2237
		/* input parameter is passed in resblks field of structure */
		in = inout.resblks;
		error = xfs_reserve_blocks(mp, &in, &inout);
J
Jan Kara 已提交
2238
		mnt_drop_write_file(filp);
L
Lachlan McIlroy 已提交
2239
		if (error)
D
Dave Chinner 已提交
2240
			return error;
L
Lachlan McIlroy 已提交
2241 2242

		if (copy_to_user(arg, &inout, sizeof(inout)))
E
Eric Sandeen 已提交
2243
			return -EFAULT;
L
Lachlan McIlroy 已提交
2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254
		return 0;
	}

	case XFS_IOC_GET_RESBLKS: {
		xfs_fsop_resblks_t out;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		error = xfs_reserve_blocks(mp, NULL, &out);
		if (error)
D
Dave Chinner 已提交
2255
			return error;
L
Lachlan McIlroy 已提交
2256 2257

		if (copy_to_user(arg, &out, sizeof(out)))
E
Eric Sandeen 已提交
2258
			return -EFAULT;
L
Lachlan McIlroy 已提交
2259 2260 2261 2262 2263

		return 0;
	}

	case XFS_IOC_FSGROWFSDATA: {
2264
		struct xfs_growfs_data in;
L
Lachlan McIlroy 已提交
2265 2266

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
2267
			return -EFAULT;
L
Lachlan McIlroy 已提交
2268

J
Jan Kara 已提交
2269 2270 2271
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
2272
		error = xfs_growfs_data(mp, &in);
J
Jan Kara 已提交
2273
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
2274
		return error;
L
Lachlan McIlroy 已提交
2275 2276 2277
	}

	case XFS_IOC_FSGROWFSLOG: {
2278
		struct xfs_growfs_log in;
L
Lachlan McIlroy 已提交
2279 2280

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
2281
			return -EFAULT;
L
Lachlan McIlroy 已提交
2282

J
Jan Kara 已提交
2283 2284 2285
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
2286
		error = xfs_growfs_log(mp, &in);
J
Jan Kara 已提交
2287
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
2288
		return error;
L
Lachlan McIlroy 已提交
2289 2290 2291 2292 2293 2294
	}

	case XFS_IOC_FSGROWFSRT: {
		xfs_growfs_rt_t in;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
2295
			return -EFAULT;
L
Lachlan McIlroy 已提交
2296

J
Jan Kara 已提交
2297 2298 2299
		error = mnt_want_write_file(filp);
		if (error)
			return error;
L
Lachlan McIlroy 已提交
2300
		error = xfs_growfs_rt(mp, &in);
J
Jan Kara 已提交
2301
		mnt_drop_write_file(filp);
D
Dave Chinner 已提交
2302
		return error;
L
Lachlan McIlroy 已提交
2303 2304 2305
	}

	case XFS_IOC_GOINGDOWN: {
2306
		uint32_t in;
L
Lachlan McIlroy 已提交
2307 2308 2309 2310

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

2311
		if (get_user(in, (uint32_t __user *)arg))
E
Eric Sandeen 已提交
2312
			return -EFAULT;
L
Lachlan McIlroy 已提交
2313

D
Dave Chinner 已提交
2314
		return xfs_fs_goingdown(mp, in);
L
Lachlan McIlroy 已提交
2315 2316 2317 2318 2319 2320 2321 2322 2323
	}

	case XFS_IOC_ERROR_INJECTION: {
		xfs_error_injection_t in;

		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		if (copy_from_user(&in, arg, sizeof(in)))
E
Eric Sandeen 已提交
2324
			return -EFAULT;
L
Lachlan McIlroy 已提交
2325

2326
		return xfs_errortag_add(mp, in.errtag);
L
Lachlan McIlroy 已提交
2327 2328 2329 2330 2331 2332
	}

	case XFS_IOC_ERROR_CLEARALL:
		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

2333
		return xfs_errortag_clearall(mp);
L
Lachlan McIlroy 已提交
2334

2335
	case XFS_IOC_FREE_EOFBLOCKS: {
2336 2337
		struct xfs_fs_eofblocks eofb;
		struct xfs_eofblocks keofb;
2338

2339 2340 2341 2342
		if (!capable(CAP_SYS_ADMIN))
			return -EPERM;

		if (mp->m_flags & XFS_MOUNT_RDONLY)
E
Eric Sandeen 已提交
2343
			return -EROFS;
2344

2345
		if (copy_from_user(&eofb, arg, sizeof(eofb)))
E
Eric Sandeen 已提交
2346
			return -EFAULT;
2347

2348 2349
		error = xfs_fs_eofblocks_from_user(&eofb, &keofb);
		if (error)
D
Dave Chinner 已提交
2350
			return error;
2351

2352 2353
		trace_xfs_ioc_free_eofblocks(mp, &keofb, _RET_IP_);

2354
		sb_start_write(mp->m_super);
2355
		error = xfs_blockgc_free_space(mp, &keofb);
2356 2357
		sb_end_write(mp->m_super);
		return error;
2358 2359
	}

L
Lachlan McIlroy 已提交
2360 2361 2362 2363
	default:
		return -ENOTTY;
	}
}