xfs: don't leak EFSBADCRC to userspace
[deliverable/linux.git] / fs / xfs / xfs_symlink.c
CommitLineData
19de7351
DC
1/*
2 * Copyright (c) 2000-2006 Silicon Graphics, Inc.
3 * Copyright (c) 2012-2013 Red Hat, Inc.
4 * All rights reserved.
5 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License as
8 * published by the Free Software Foundation.
9 *
10 * This program is distributed in the hope that it would be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License
16 * along with this program; if not, write the Free Software Foundation,
17 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
18 */
19#include "xfs.h"
239880ef 20#include "xfs_shared.h"
19de7351 21#include "xfs_fs.h"
6ca1c906 22#include "xfs_format.h"
239880ef
DC
23#include "xfs_log_format.h"
24#include "xfs_trans_resv.h"
19de7351 25#include "xfs_bit.h"
19de7351
DC
26#include "xfs_sb.h"
27#include "xfs_ag.h"
19de7351 28#include "xfs_mount.h"
57062787 29#include "xfs_da_format.h"
2b9ab5ab 30#include "xfs_dir2.h"
19de7351 31#include "xfs_inode.h"
19de7351
DC
32#include "xfs_ialloc.h"
33#include "xfs_alloc.h"
34#include "xfs_bmap.h"
a4fbe6ab 35#include "xfs_bmap_btree.h"
68988114 36#include "xfs_bmap_util.h"
19de7351
DC
37#include "xfs_error.h"
38#include "xfs_quota.h"
19de7351 39#include "xfs_trans_space.h"
19de7351
DC
40#include "xfs_trace.h"
41#include "xfs_symlink.h"
239880ef 42#include "xfs_trans.h"
239880ef 43#include "xfs_log.h"
a4fbe6ab 44#include "xfs_dinode.h"
19de7351
DC
45
46/* ----- Kernel only functions below ----- */
19de7351
DC
47STATIC int
48xfs_readlink_bmap(
f948dd76
DC
49 struct xfs_inode *ip,
50 char *link)
19de7351 51{
f948dd76
DC
52 struct xfs_mount *mp = ip->i_mount;
53 struct xfs_bmbt_irec mval[XFS_SYMLINK_MAPS];
54 struct xfs_buf *bp;
55 xfs_daddr_t d;
56 char *cur_chunk;
57 int pathlen = ip->i_d.di_size;
58 int nmaps = XFS_SYMLINK_MAPS;
59 int byte_cnt;
60 int n;
61 int error = 0;
62 int fsblocks = 0;
63 int offset;
19de7351 64
f948dd76
DC
65 fsblocks = xfs_symlink_blocks(mp, pathlen);
66 error = xfs_bmapi_read(ip, 0, fsblocks, mval, &nmaps, 0);
19de7351
DC
67 if (error)
68 goto out;
69
f948dd76 70 offset = 0;
19de7351
DC
71 for (n = 0; n < nmaps; n++) {
72 d = XFS_FSB_TO_DADDR(mp, mval[n].br_startblock);
73 byte_cnt = XFS_FSB_TO_B(mp, mval[n].br_blockcount);
74
f948dd76
DC
75 bp = xfs_buf_read(mp->m_ddev_targp, d, BTOBB(byte_cnt), 0,
76 &xfs_symlink_buf_ops);
19de7351
DC
77 if (!bp)
78 return XFS_ERROR(ENOMEM);
79 error = bp->b_error;
80 if (error) {
81 xfs_buf_ioerror_alert(bp, __func__);
82 xfs_buf_relse(bp);
ac75a1f7
DC
83
84 /* bad CRC means corrupted metadata */
85 if (error == EFSBADCRC)
86 error = EFSCORRUPTED;
19de7351
DC
87 goto out;
88 }
f948dd76 89 byte_cnt = XFS_SYMLINK_BUF_SPACE(mp, byte_cnt);
19de7351
DC
90 if (pathlen < byte_cnt)
91 byte_cnt = pathlen;
f948dd76
DC
92
93 cur_chunk = bp->b_addr;
94 if (xfs_sb_version_hascrc(&mp->m_sb)) {
95 if (!xfs_symlink_hdr_ok(mp, ip->i_ino, offset,
96 byte_cnt, bp)) {
97 error = EFSCORRUPTED;
98 xfs_alert(mp,
99"symlink header does not match required off/len/owner (0x%x/Ox%x,0x%llx)",
100 offset, byte_cnt, ip->i_ino);
101 xfs_buf_relse(bp);
102 goto out;
103
104 }
105
106 cur_chunk += sizeof(struct xfs_dsymlink_hdr);
107 }
108
109 memcpy(link + offset, bp->b_addr, byte_cnt);
110
19de7351 111 pathlen -= byte_cnt;
f948dd76 112 offset += byte_cnt;
19de7351 113
19de7351
DC
114 xfs_buf_relse(bp);
115 }
f948dd76 116 ASSERT(pathlen == 0);
19de7351
DC
117
118 link[ip->i_d.di_size] = '\0';
119 error = 0;
120
121 out:
122 return error;
123}
124
125int
126xfs_readlink(
f948dd76 127 struct xfs_inode *ip,
19de7351
DC
128 char *link)
129{
f948dd76 130 struct xfs_mount *mp = ip->i_mount;
19de7351
DC
131 xfs_fsize_t pathlen;
132 int error = 0;
133
134 trace_xfs_readlink(ip);
135
136 if (XFS_FORCED_SHUTDOWN(mp))
137 return XFS_ERROR(EIO);
138
139 xfs_ilock(ip, XFS_ILOCK_SHARED);
140
141 pathlen = ip->i_d.di_size;
142 if (!pathlen)
143 goto out;
144
145 if (pathlen < 0 || pathlen > MAXPATHLEN) {
146 xfs_alert(mp, "%s: inode (%llu) bad symlink length (%lld)",
147 __func__, (unsigned long long) ip->i_ino,
148 (long long) pathlen);
149 ASSERT(0);
150 error = XFS_ERROR(EFSCORRUPTED);
151 goto out;
152 }
153
154
155 if (ip->i_df.if_flags & XFS_IFINLINE) {
156 memcpy(link, ip->i_df.if_u1.if_data, pathlen);
157 link[pathlen] = '\0';
158 } else {
159 error = xfs_readlink_bmap(ip, link);
160 }
161
162 out:
163 xfs_iunlock(ip, XFS_ILOCK_SHARED);
164 return error;
165}
166
167int
168xfs_symlink(
f948dd76 169 struct xfs_inode *dp,
19de7351
DC
170 struct xfs_name *link_name,
171 const char *target_path,
172 umode_t mode,
f948dd76 173 struct xfs_inode **ipp)
19de7351 174{
f948dd76
DC
175 struct xfs_mount *mp = dp->i_mount;
176 struct xfs_trans *tp = NULL;
177 struct xfs_inode *ip = NULL;
178 int error = 0;
19de7351 179 int pathlen;
f948dd76 180 struct xfs_bmap_free free_list;
19de7351 181 xfs_fsblock_t first_block;
f948dd76 182 bool unlock_dp_on_error = false;
19de7351
DC
183 uint cancel_flags;
184 int committed;
185 xfs_fileoff_t first_fsb;
186 xfs_filblks_t fs_blocks;
187 int nmaps;
f948dd76 188 struct xfs_bmbt_irec mval[XFS_SYMLINK_MAPS];
19de7351
DC
189 xfs_daddr_t d;
190 const char *cur_chunk;
191 int byte_cnt;
192 int n;
193 xfs_buf_t *bp;
194 prid_t prid;
113a5683
CS
195 struct xfs_dquot *udqp = NULL;
196 struct xfs_dquot *gdqp = NULL;
92f8ff73 197 struct xfs_dquot *pdqp = NULL;
19de7351
DC
198 uint resblks;
199
200 *ipp = NULL;
19de7351
DC
201
202 trace_xfs_symlink(dp, link_name);
203
204 if (XFS_FORCED_SHUTDOWN(mp))
205 return XFS_ERROR(EIO);
206
207 /*
208 * Check component lengths of the target path name.
209 */
210 pathlen = strlen(target_path);
211 if (pathlen >= MAXPATHLEN) /* total string too long */
212 return XFS_ERROR(ENAMETOOLONG);
213
214 udqp = gdqp = NULL;
215 if (dp->i_d.di_flags & XFS_DIFLAG_PROJINHERIT)
216 prid = xfs_get_projid(dp);
217 else
218 prid = XFS_PROJID_DEFAULT;
219
220 /*
221 * Make sure that we have allocated dquot(s) on disk.
222 */
7aab1b28
DE
223 error = xfs_qm_vop_dqalloc(dp,
224 xfs_kuid_to_uid(current_fsuid()),
225 xfs_kgid_to_gid(current_fsgid()), prid,
226 XFS_QMOPT_QUOTALL | XFS_QMOPT_INHERIT,
227 &udqp, &gdqp, &pdqp);
19de7351
DC
228 if (error)
229 goto std_return;
230
231 tp = xfs_trans_alloc(mp, XFS_TRANS_SYMLINK);
232 cancel_flags = XFS_TRANS_RELEASE_LOG_RES;
233 /*
234 * The symlink will fit into the inode data fork?
235 * There can't be any attributes so we get the whole variable part.
236 */
237 if (pathlen <= XFS_LITINO(mp, dp->i_d.di_version))
238 fs_blocks = 0;
239 else
321a9583 240 fs_blocks = xfs_symlink_blocks(mp, pathlen);
19de7351 241 resblks = XFS_SYMLINK_SPACE_RES(mp, link_name->len, fs_blocks);
3d3c8b52 242 error = xfs_trans_reserve(tp, &M_RES(mp)->tr_symlink, resblks, 0);
19de7351
DC
243 if (error == ENOSPC && fs_blocks == 0) {
244 resblks = 0;
3d3c8b52 245 error = xfs_trans_reserve(tp, &M_RES(mp)->tr_symlink, 0, 0);
19de7351
DC
246 }
247 if (error) {
248 cancel_flags = 0;
249 goto error_return;
250 }
251
252 xfs_ilock(dp, XFS_ILOCK_EXCL | XFS_ILOCK_PARENT);
253 unlock_dp_on_error = true;
254
255 /*
256 * Check whether the directory allows new symlinks or not.
257 */
258 if (dp->i_d.di_flags & XFS_DIFLAG_NOSYMLINKS) {
259 error = XFS_ERROR(EPERM);
260 goto error_return;
261 }
262
263 /*
264 * Reserve disk quota : blocks and inode.
265 */
92f8ff73
CS
266 error = xfs_trans_reserve_quota(tp, mp, udqp, gdqp,
267 pdqp, resblks, 1, 0);
19de7351
DC
268 if (error)
269 goto error_return;
270
271 /*
272 * Check for ability to enter directory entry, if no space reserved.
273 */
274 error = xfs_dir_canenter(tp, dp, link_name, resblks);
275 if (error)
276 goto error_return;
277 /*
278 * Initialize the bmap freelist prior to calling either
279 * bmapi or the directory create code.
280 */
281 xfs_bmap_init(&free_list, &first_block);
282
283 /*
284 * Allocate an inode for the symlink.
285 */
286 error = xfs_dir_ialloc(&tp, dp, S_IFLNK | (mode & ~S_IFMT), 1, 0,
287 prid, resblks > 0, &ip, NULL);
288 if (error) {
289 if (error == ENOSPC)
290 goto error_return;
291 goto error1;
292 }
293
294 /*
295 * An error after we've joined dp to the transaction will result in the
296 * transaction cancel unlocking dp so don't do it explicitly in the
297 * error path.
298 */
299 xfs_trans_ijoin(tp, dp, XFS_ILOCK_EXCL);
300 unlock_dp_on_error = false;
301
302 /*
303 * Also attach the dquot(s) to it, if applicable.
304 */
92f8ff73 305 xfs_qm_vop_create_dqattach(tp, ip, udqp, gdqp, pdqp);
19de7351
DC
306
307 if (resblks)
308 resblks -= XFS_IALLOC_SPACE_RES(mp);
309 /*
310 * If the symlink will fit into the inode, write it inline.
311 */
312 if (pathlen <= XFS_IFORK_DSIZE(ip)) {
313 xfs_idata_realloc(ip, pathlen, XFS_DATA_FORK);
314 memcpy(ip->i_df.if_u1.if_data, target_path, pathlen);
315 ip->i_d.di_size = pathlen;
316
317 /*
318 * The inode was initially created in extent format.
319 */
320 ip->i_df.if_flags &= ~(XFS_IFEXTENTS | XFS_IFBROOT);
321 ip->i_df.if_flags |= XFS_IFINLINE;
322
323 ip->i_d.di_format = XFS_DINODE_FMT_LOCAL;
324 xfs_trans_log_inode(tp, ip, XFS_ILOG_DDATA | XFS_ILOG_CORE);
325
326 } else {
f948dd76
DC
327 int offset;
328
19de7351
DC
329 first_fsb = 0;
330 nmaps = XFS_SYMLINK_MAPS;
331
332 error = xfs_bmapi_write(tp, ip, first_fsb, fs_blocks,
333 XFS_BMAPI_METADATA, &first_block, resblks,
334 mval, &nmaps, &free_list);
335 if (error)
336 goto error2;
337
338 if (resblks)
339 resblks -= fs_blocks;
340 ip->i_d.di_size = pathlen;
341 xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
342
343 cur_chunk = target_path;
f948dd76 344 offset = 0;
19de7351 345 for (n = 0; n < nmaps; n++) {
321a9583 346 char *buf;
f948dd76 347
19de7351
DC
348 d = XFS_FSB_TO_DADDR(mp, mval[n].br_startblock);
349 byte_cnt = XFS_FSB_TO_B(mp, mval[n].br_blockcount);
350 bp = xfs_trans_get_buf(tp, mp->m_ddev_targp, d,
351 BTOBB(byte_cnt), 0);
352 if (!bp) {
353 error = ENOMEM;
354 goto error2;
355 }
f948dd76
DC
356 bp->b_ops = &xfs_symlink_buf_ops;
357
358 byte_cnt = XFS_SYMLINK_BUF_SPACE(mp, byte_cnt);
321a9583 359 byte_cnt = min(byte_cnt, pathlen);
19de7351 360
f948dd76
DC
361 buf = bp->b_addr;
362 buf += xfs_symlink_hdr_set(mp, ip->i_ino, offset,
363 byte_cnt, bp);
364
365 memcpy(buf, cur_chunk, byte_cnt);
366
19de7351 367 cur_chunk += byte_cnt;
f948dd76
DC
368 pathlen -= byte_cnt;
369 offset += byte_cnt;
19de7351 370
daf7b799 371 xfs_trans_buf_set_type(tp, bp, XFS_BLFT_SYMLINK_BUF);
f948dd76
DC
372 xfs_trans_log_buf(tp, bp, 0, (buf + byte_cnt - 1) -
373 (char *)bp->b_addr);
19de7351 374 }
321a9583 375 ASSERT(pathlen == 0);
19de7351
DC
376 }
377
378 /*
379 * Create the directory entry for the symlink.
380 */
381 error = xfs_dir_createname(tp, dp, link_name, ip->i_ino,
382 &first_block, &free_list, resblks);
383 if (error)
384 goto error2;
385 xfs_trans_ichgtime(tp, dp, XFS_ICHGTIME_MOD | XFS_ICHGTIME_CHG);
386 xfs_trans_log_inode(tp, dp, XFS_ILOG_CORE);
387
388 /*
389 * If this is a synchronous mount, make sure that the
390 * symlink transaction goes to disk before returning to
391 * the user.
392 */
393 if (mp->m_flags & (XFS_MOUNT_WSYNC|XFS_MOUNT_DIRSYNC)) {
394 xfs_trans_set_sync(tp);
395 }
396
397 error = xfs_bmap_finish(&tp, &free_list, &committed);
398 if (error) {
399 goto error2;
400 }
401 error = xfs_trans_commit(tp, XFS_TRANS_RELEASE_LOG_RES);
402 xfs_qm_dqrele(udqp);
403 xfs_qm_dqrele(gdqp);
92f8ff73 404 xfs_qm_dqrele(pdqp);
19de7351
DC
405
406 *ipp = ip;
407 return 0;
408
409 error2:
410 IRELE(ip);
411 error1:
412 xfs_bmap_cancel(&free_list);
413 cancel_flags |= XFS_TRANS_ABORT;
414 error_return:
415 xfs_trans_cancel(tp, cancel_flags);
416 xfs_qm_dqrele(udqp);
417 xfs_qm_dqrele(gdqp);
92f8ff73 418 xfs_qm_dqrele(pdqp);
19de7351
DC
419
420 if (unlock_dp_on_error)
421 xfs_iunlock(dp, XFS_ILOCK_EXCL);
422 std_return:
423 return error;
424}
425
426/*
427 * Free a symlink that has blocks associated with it.
428 */
725eb1eb 429STATIC int
19de7351 430xfs_inactive_symlink_rmt(
36b21dde 431 struct xfs_inode *ip)
19de7351
DC
432{
433 xfs_buf_t *bp;
434 int committed;
435 int done;
436 int error;
437 xfs_fsblock_t first_block;
438 xfs_bmap_free_t free_list;
439 int i;
440 xfs_mount_t *mp;
441 xfs_bmbt_irec_t mval[XFS_SYMLINK_MAPS];
442 int nmaps;
19de7351
DC
443 int size;
444 xfs_trans_t *tp;
445
19de7351 446 mp = ip->i_mount;
725eb1eb 447 ASSERT(ip->i_df.if_flags & XFS_IFEXTENTS);
19de7351
DC
448 /*
449 * We're freeing a symlink that has some
450 * blocks allocated to it. Free the
451 * blocks here. We know that we've got
452 * either 1 or 2 extents and that we can
453 * free them all in one bunmapi call.
454 */
455 ASSERT(ip->i_d.di_nextents > 0 && ip->i_d.di_nextents <= 2);
456
36b21dde
BF
457 tp = xfs_trans_alloc(mp, XFS_TRANS_INACTIVE);
458 error = xfs_trans_reserve(tp, &M_RES(mp)->tr_itruncate, 0, 0);
459 if (error) {
460 xfs_trans_cancel(tp, 0);
461 return error;
462 }
463
464 xfs_ilock(ip, XFS_ILOCK_EXCL);
465 xfs_trans_ijoin(tp, ip, 0);
466
19de7351
DC
467 /*
468 * Lock the inode, fix the size, and join it to the transaction.
469 * Hold it so in the normal path, we still have it locked for
470 * the second transaction. In the error paths we need it
471 * held so the cancel won't rele it, see below.
472 */
473 size = (int)ip->i_d.di_size;
474 ip->i_d.di_size = 0;
475 xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
476 /*
477 * Find the block(s) so we can inval and unmap them.
478 */
479 done = 0;
480 xfs_bmap_init(&free_list, &first_block);
481 nmaps = ARRAY_SIZE(mval);
f948dd76 482 error = xfs_bmapi_read(ip, 0, xfs_symlink_blocks(mp, size),
19de7351
DC
483 mval, &nmaps, 0);
484 if (error)
36b21dde 485 goto error_trans_cancel;
19de7351 486 /*
f948dd76 487 * Invalidate the block(s). No validation is done.
19de7351
DC
488 */
489 for (i = 0; i < nmaps; i++) {
490 bp = xfs_trans_get_buf(tp, mp->m_ddev_targp,
491 XFS_FSB_TO_DADDR(mp, mval[i].br_startblock),
492 XFS_FSB_TO_BB(mp, mval[i].br_blockcount), 0);
493 if (!bp) {
494 error = ENOMEM;
36b21dde 495 goto error_bmap_cancel;
19de7351
DC
496 }
497 xfs_trans_binval(tp, bp);
498 }
499 /*
500 * Unmap the dead block(s) to the free_list.
501 */
36b21dde
BF
502 error = xfs_bunmapi(tp, ip, 0, size, XFS_BMAPI_METADATA, nmaps,
503 &first_block, &free_list, &done);
504 if (error)
505 goto error_bmap_cancel;
19de7351
DC
506 ASSERT(done);
507 /*
508 * Commit the first transaction. This logs the EFI and the inode.
509 */
36b21dde
BF
510 error = xfs_bmap_finish(&tp, &free_list, &committed);
511 if (error)
512 goto error_bmap_cancel;
19de7351
DC
513 /*
514 * The transaction must have been committed, since there were
515 * actually extents freed by xfs_bunmapi. See xfs_bmap_finish.
516 * The new tp has the extent freeing and EFDs.
517 */
518 ASSERT(committed);
519 /*
520 * The first xact was committed, so add the inode to the new one.
521 * Mark it dirty so it will be logged and moved forward in the log as
522 * part of every commit.
523 */
524 xfs_trans_ijoin(tp, ip, 0);
525 xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
19de7351
DC
526 /*
527 * Commit the transaction containing extent freeing and EFDs.
19de7351 528 */
36b21dde 529 error = xfs_trans_commit(tp, XFS_TRANS_RELEASE_LOG_RES);
19de7351
DC
530 if (error) {
531 ASSERT(XFS_FORCED_SHUTDOWN(mp));
36b21dde 532 goto error_unlock;
19de7351 533 }
19de7351
DC
534
535 /*
536 * Remove the memory for extent descriptions (just bookkeeping).
537 */
538 if (ip->i_df.if_bytes)
539 xfs_idata_realloc(ip, -ip->i_df.if_bytes, XFS_DATA_FORK);
540 ASSERT(ip->i_df.if_bytes == 0);
19de7351 541
36b21dde 542 xfs_iunlock(ip, XFS_ILOCK_EXCL);
19de7351
DC
543 return 0;
544
36b21dde 545error_bmap_cancel:
19de7351 546 xfs_bmap_cancel(&free_list);
36b21dde
BF
547error_trans_cancel:
548 xfs_trans_cancel(tp, XFS_TRANS_RELEASE_LOG_RES | XFS_TRANS_ABORT);
549error_unlock:
550 xfs_iunlock(ip, XFS_ILOCK_EXCL);
19de7351
DC
551 return error;
552}
725eb1eb
MT
553
554/*
555 * xfs_inactive_symlink - free a symlink
556 */
557int
558xfs_inactive_symlink(
36b21dde 559 struct xfs_inode *ip)
725eb1eb
MT
560{
561 struct xfs_mount *mp = ip->i_mount;
562 int pathlen;
563
564 trace_xfs_inactive_symlink(ip);
565
725eb1eb
MT
566 if (XFS_FORCED_SHUTDOWN(mp))
567 return XFS_ERROR(EIO);
568
36b21dde
BF
569 xfs_ilock(ip, XFS_ILOCK_EXCL);
570
725eb1eb
MT
571 /*
572 * Zero length symlinks _can_ exist.
573 */
574 pathlen = (int)ip->i_d.di_size;
36b21dde
BF
575 if (!pathlen) {
576 xfs_iunlock(ip, XFS_ILOCK_EXCL);
725eb1eb 577 return 0;
36b21dde 578 }
725eb1eb
MT
579
580 if (pathlen < 0 || pathlen > MAXPATHLEN) {
581 xfs_alert(mp, "%s: inode (0x%llx) bad symlink length (%d)",
582 __func__, (unsigned long long)ip->i_ino, pathlen);
36b21dde 583 xfs_iunlock(ip, XFS_ILOCK_EXCL);
725eb1eb
MT
584 ASSERT(0);
585 return XFS_ERROR(EFSCORRUPTED);
586 }
587
588 if (ip->i_df.if_flags & XFS_IFINLINE) {
36b21dde 589 if (ip->i_df.if_bytes > 0)
725eb1eb
MT
590 xfs_idata_realloc(ip, -(ip->i_df.if_bytes),
591 XFS_DATA_FORK);
36b21dde 592 xfs_iunlock(ip, XFS_ILOCK_EXCL);
725eb1eb
MT
593 ASSERT(ip->i_df.if_bytes == 0);
594 return 0;
595 }
596
36b21dde
BF
597 xfs_iunlock(ip, XFS_ILOCK_EXCL);
598
725eb1eb 599 /* remove the remote symlink */
36b21dde 600 return xfs_inactive_symlink_rmt(ip);
725eb1eb 601}
This page took 0.080562 seconds and 5 git commands to generate.