nfs4namespace.c 9.4 KB
Newer Older
D
David Howells 已提交
1 2 3 4
/*
 * linux/fs/nfs/nfs4namespace.c
 *
 * Copyright (C) 2005 Trond Myklebust <Trond.Myklebust@netapp.com>
5
 * - Modified by David Howells <dhowells@redhat.com>
D
David Howells 已提交
6 7 8 9 10 11 12 13
 *
 * NFSv4 namespace
 */

#include <linux/dcache.h>
#include <linux/mount.h>
#include <linux/namei.h>
#include <linux/nfs_fs.h>
14
#include <linux/slab.h>
D
David Howells 已提交
15 16 17 18 19
#include <linux/string.h>
#include <linux/sunrpc/clnt.h>
#include <linux/vfs.h>
#include <linux/inet.h>
#include "internal.h"
20
#include "nfs4_fs.h"
21
#include "dns_resolve.h"
D
David Howells 已提交
22 23 24 25

#define NFSDBG_FACILITY		NFSDBG_VFS

/*
26 27 28
 * Convert the NFSv4 pathname components into a standard posix path.
 *
 * Note that the resulting string will be placed at the end of the buffer
D
David Howells 已提交
29
 */
D
David Howells 已提交
30
static inline char *nfs4_pathname_string(const struct nfs4_pathname *pathname,
D
David Howells 已提交
31 32 33 34 35 36 37 38 39 40
					 char *buffer, ssize_t buflen)
{
	char *end = buffer + buflen;
	int n;

	*--end = '\0';
	buflen--;

	n = pathname->ncomponents;
	while (--n >= 0) {
D
David Howells 已提交
41
		const struct nfs4_string *component = &pathname->components[n];
D
David Howells 已提交
42 43 44 45 46 47 48 49 50 51 52 53
		buflen -= component->len + 1;
		if (buflen < 0)
			goto Elong;
		end -= component->len;
		memcpy(end, component->data, component->len);
		*--end = '/';
	}
	return end;
Elong:
	return ERR_PTR(-ENAMETOOLONG);
}

54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77
/*
 * return the path component of "<server>:<path>"
 *  nfspath - the "<server>:<path>" string
 *  end - one past the last char that could contain "<server>:"
 * returns NULL on failure
 */
static char *nfs_path_component(const char *nfspath, const char *end)
{
	char *p;

	if (*nfspath == '[') {
		/* parse [] escaped IPv6 addrs */
		p = strchr(nfspath, ']');
		if (p != NULL && ++p < end && *p == ':')
			return p + 1;
	} else {
		/* otherwise split on first colon */
		p = strchr(nfspath, ':');
		if (p != NULL && p < end)
			return p + 1;
	}
	return NULL;
}

78 79 80
/*
 * Determine the mount path as a string
 */
81
static char *nfs4_path(struct dentry *dentry, char *buffer, ssize_t buflen)
82
{
83 84 85
	char *limit;
	char *path = nfs_path(&limit, dentry, buffer, buflen);
	if (!IS_ERR(path)) {
86 87 88
		char *path_component = nfs_path_component(path, limit);
		if (path_component)
			return path_component;
89 90
	}
	return path;
91 92 93 94 95 96
}

/*
 * Check that fs_locations::fs_root [RFC3530 6.3] is a prefix for what we
 * believe to be the server path to this dentry
 */
97
static int nfs4_validate_fspath(struct dentry *dentry,
98 99 100 101 102
				const struct nfs4_fs_locations *locations,
				char *page, char *page2)
{
	const char *path, *fs_path;

103
	path = nfs4_path(dentry, page, PAGE_SIZE);
104 105 106 107 108 109 110 111 112
	if (IS_ERR(path))
		return PTR_ERR(path);

	fs_path = nfs4_pathname_string(&locations->fs_path, page2, PAGE_SIZE);
	if (IS_ERR(fs_path))
		return PTR_ERR(fs_path);

	if (strncmp(path, fs_path, strlen(fs_path)) != 0) {
		dprintk("%s: path %s does not begin with fsroot %s\n",
113
			__func__, path, fs_path);
114 115 116 117 118 119
		return -ENOENT;
	}

	return 0;
}

120
static size_t nfs_parse_server_name(char *string, size_t len,
121
		struct sockaddr *sa, size_t salen, struct nfs_server *server)
122
{
123
	struct net *net = rpc_net_ns(server->client);
124 125
	ssize_t ret;

126
	ret = rpc_pton(net, string, len, sa, salen);
127
	if (ret == 0) {
128
		ret = nfs_dns_resolve_name(net, string, len, sa, salen);
129 130 131 132 133 134
		if (ret < 0)
			ret = 0;
	}
	return ret;
}

135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163
rpc_authflavor_t nfs_find_best_sec(struct nfs4_secinfo_flavors *flavors)
{
	struct gss_api_mech *mech;
	struct xdr_netobj oid;
	int i;
	rpc_authflavor_t pseudoflavor = RPC_AUTH_UNIX;

	for (i = 0; i < flavors->num_flavors; i++) {
		struct nfs4_secinfo_flavor *flavor;
		flavor = &flavors->flavors[i];

		if (flavor->flavor == RPC_AUTH_NULL || flavor->flavor == RPC_AUTH_UNIX) {
			pseudoflavor = flavor->flavor;
			break;
		} else if (flavor->flavor == RPC_AUTH_GSS) {
			oid.len  = flavor->gss.sec_oid4.len;
			oid.data = flavor->gss.sec_oid4.data;
			mech = gss_mech_get_by_OID(&oid);
			if (!mech)
				continue;
			pseudoflavor = gss_svc_to_pseudoflavor(mech, flavor->gss.service);
			gss_mech_put(mech);
			break;
		}
	}

	return pseudoflavor;
}

164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199
static rpc_authflavor_t nfs4_negotiate_security(struct inode *inode, struct qstr *name)
{
	struct page *page;
	struct nfs4_secinfo_flavors *flavors;
	rpc_authflavor_t flavor;
	int err;

	page = alloc_page(GFP_KERNEL);
	if (!page)
		return -ENOMEM;
	flavors = page_address(page);

	err = nfs4_proc_secinfo(inode, name, flavors);
	if (err < 0) {
		flavor = err;
		goto out;
	}

	flavor = nfs_find_best_sec(flavors);

out:
	put_page(page);
	return flavor;
}

/*
 * Please call rpc_shutdown_client() when you are done with this client.
 */
struct rpc_clnt *nfs4_create_sec_client(struct rpc_clnt *clnt, struct inode *inode,
					struct qstr *name)
{
	struct rpc_clnt *clone;
	struct rpc_auth *auth;
	rpc_authflavor_t flavor;

	flavor = nfs4_negotiate_security(inode, name);
200
	if ((int)flavor < 0)
201
		return ERR_PTR((int)flavor);
202 203 204 205 206 207

	clone = rpc_clone_client(clnt);
	if (IS_ERR(clone))
		return clone;

	auth = rpcauth_create(flavor, clone);
208
	if (IS_ERR(auth)) {
209 210 211 212 213 214 215
		rpc_shutdown_client(clone);
		clone = ERR_PTR(-EIO);
	}

	return clone;
}

216 217 218 219
static struct vfsmount *try_location(struct nfs_clone_mount *mountdata,
				     char *page, char *page2,
				     const struct nfs4_fs_location *location)
{
220
	const size_t addr_bufsize = sizeof(struct sockaddr_storage);
221 222
	struct vfsmount *mnt = ERR_PTR(-ENOENT);
	char *mnt_path;
223
	unsigned int maxbuflen;
224
	unsigned int s;
225 226 227

	mnt_path = nfs4_pathname_string(&location->rootpath, page2, PAGE_SIZE);
	if (IS_ERR(mnt_path))
228
		return ERR_CAST(mnt_path);
229
	mountdata->mnt_path = mnt_path;
230
	maxbuflen = mnt_path - 1 - page2;
231

232 233 234 235
	mountdata->addr = kmalloc(addr_bufsize, GFP_KERNEL);
	if (mountdata->addr == NULL)
		return ERR_PTR(-ENOMEM);

236
	for (s = 0; s < location->nservers; s++) {
237
		const struct nfs4_string *buf = &location->servers[s];
238

239
		if (buf->len <= 0 || buf->len >= maxbuflen)
240 241
			continue;

242 243
		if (memchr(buf->data, IPV6_SCOPE_DELIMITER, buf->len))
			continue;
244 245

		mountdata->addrlen = nfs_parse_server_name(buf->data, buf->len,
246 247
				mountdata->addr, addr_bufsize,
				NFS_SB(mountdata->sb));
248
		if (mountdata->addrlen == 0)
249
			continue;
250

251
		rpc_set_port(mountdata->addr, NFS_PORT);
252

253 254
		memcpy(page2, buf->data, buf->len);
		page2[buf->len] = '\0';
255
		mountdata->hostname = page2;
256 257 258 259 260 261 262 263 264

		snprintf(page, PAGE_SIZE, "%s:%s",
				mountdata->hostname,
				mountdata->mnt_path);

		mnt = vfs_kern_mount(&nfs4_referral_fs_type, 0, page, mountdata);
		if (!IS_ERR(mnt))
			break;
	}
265
	kfree(mountdata->addr);
266 267 268
	return mnt;
}

D
David Howells 已提交
269 270 271
/**
 * nfs_follow_referral - set up mountpoint when hitting a referral on moved error
 * @dentry - parent directory
272
 * @locations - array of NFSv4 server location information
D
David Howells 已提交
273 274
 *
 */
275
static struct vfsmount *nfs_follow_referral(struct dentry *dentry,
D
David Howells 已提交
276
					    const struct nfs4_fs_locations *locations)
D
David Howells 已提交
277 278 279
{
	struct vfsmount *mnt = ERR_PTR(-ENOENT);
	struct nfs_clone_mount mountdata = {
280
		.sb = dentry->d_sb,
D
David Howells 已提交
281
		.dentry = dentry,
282
		.authflavor = NFS_SB(dentry->d_sb)->client->cl_auth->au_flavor,
D
David Howells 已提交
283
	};
284
	char *page = NULL, *page2 = NULL;
285
	int loc, error;
D
David Howells 已提交
286 287 288 289

	if (locations == NULL || locations->nlocations <= 0)
		goto out;

290
	dprintk("%s: referral at %s/%s\n", __func__,
D
David Howells 已提交
291 292 293
		dentry->d_parent->d_name.name, dentry->d_name.name);

	page = (char *) __get_free_page(GFP_USER);
294
	if (!page)
D
David Howells 已提交
295
		goto out;
296

D
David Howells 已提交
297
	page2 = (char *) __get_free_page(GFP_USER);
298
	if (!page2)
D
David Howells 已提交
299 300
		goto out;

301
	/* Ensure fs path is a prefix of current dentry path */
302
	error = nfs4_validate_fspath(dentry, locations, page, page2);
303 304 305
	if (error < 0) {
		mnt = ERR_PTR(error);
		goto out;
D
David Howells 已提交
306 307
	}

308
	for (loc = 0; loc < locations->nlocations; loc++) {
D
David Howells 已提交
309
		const struct nfs4_fs_location *location = &locations->locations[loc];
D
David Howells 已提交
310 311

		if (location == NULL || location->nservers <= 0 ||
312
		    location->rootpath.ncomponents == 0)
D
David Howells 已提交
313 314
			continue;

315 316 317
		mnt = try_location(&mountdata, page, page2, location);
		if (!IS_ERR(mnt))
			break;
D
David Howells 已提交
318 319 320
	}

out:
321 322
	free_page((unsigned long) page);
	free_page((unsigned long) page2);
323
	dprintk("%s: done\n", __func__);
D
David Howells 已提交
324 325 326 327 328 329 330 331
	return mnt;
}

/*
 * nfs_do_refmount - handle crossing a referral on server
 * @dentry - dentry of referral
 *
 */
B
Bryan Schumaker 已提交
332
static struct vfsmount *nfs_do_refmount(struct rpc_clnt *client, struct dentry *dentry)
D
David Howells 已提交
333
{
334
	struct vfsmount *mnt = ERR_PTR(-ENOMEM);
D
David Howells 已提交
335 336 337 338 339 340
	struct dentry *parent;
	struct nfs4_fs_locations *fs_locations = NULL;
	struct page *page;
	int err;

	/* BUG_ON(IS_ROOT(dentry)); */
341
	dprintk("%s: enter\n", __func__);
D
David Howells 已提交
342 343 344 345 346 347 348 349 350 351

	page = alloc_page(GFP_KERNEL);
	if (page == NULL)
		goto out;

	fs_locations = kmalloc(sizeof(struct nfs4_fs_locations), GFP_KERNEL);
	if (fs_locations == NULL)
		goto out_free;

	/* Get locations */
352 353
	mnt = ERR_PTR(-ENOENT);

D
David Howells 已提交
354
	parent = dget_parent(dentry);
355
	dprintk("%s: getting locations for %s/%s\n",
356
		__func__, parent->d_name.name, dentry->d_name.name);
357

358
	err = nfs4_proc_fs_locations(client, parent->d_inode, &dentry->d_name, fs_locations, page);
D
David Howells 已提交
359
	dput(parent);
360 361
	if (err != 0 ||
	    fs_locations->nlocations <= 0 ||
D
David Howells 已提交
362 363 364
	    fs_locations->fs_path.ncomponents <= 0)
		goto out_free;

365
	mnt = nfs_follow_referral(dentry, fs_locations);
D
David Howells 已提交
366 367 368 369
out_free:
	__free_page(page);
	kfree(fs_locations);
out:
370
	dprintk("%s: done\n", __func__);
D
David Howells 已提交
371 372
	return mnt;
}
B
Bryan Schumaker 已提交
373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394

struct vfsmount *nfs4_submount(struct nfs_server *server, struct dentry *dentry,
			       struct nfs_fh *fh, struct nfs_fattr *fattr)
{
	struct dentry *parent = dget_parent(dentry);
	struct rpc_clnt *client;
	struct vfsmount *mnt;

	/* Look it up again to get its attributes and sec flavor */
	client = nfs4_proc_lookup_mountpoint(parent->d_inode, &dentry->d_name, fh, fattr);
	dput(parent);
	if (IS_ERR(client))
		return ERR_CAST(client);

	if (fattr->valid & NFS_ATTR_FATTR_V4_REFERRAL)
		mnt = nfs_do_refmount(client, dentry);
	else
		mnt = nfs_do_submount(dentry, fh, fattr, client->cl_auth->au_flavor);

	rpc_shutdown_client(client);
	return mnt;
}