libceph: Get secret from the kernel keys api when mounting with key=NAME.
[deliverable/linux.git] / net / ceph / ceph_common.c
CommitLineData
3d14c5d2
YS
1
2#include <linux/ceph/ceph_debug.h>
3#include <linux/backing-dev.h>
4#include <linux/ctype.h>
5#include <linux/fs.h>
6#include <linux/inet.h>
7#include <linux/in6.h>
e2c3d29b
TV
8#include <linux/key.h>
9#include <keys/user-type.h>
3d14c5d2
YS
10#include <linux/module.h>
11#include <linux/mount.h>
12#include <linux/parser.h>
13#include <linux/sched.h>
14#include <linux/seq_file.h>
15#include <linux/slab.h>
16#include <linux/statfs.h>
17#include <linux/string.h>
18
19
20#include <linux/ceph/libceph.h>
21#include <linux/ceph/debugfs.h>
22#include <linux/ceph/decode.h>
23#include <linux/ceph/mon_client.h>
24#include <linux/ceph/auth.h>
8323c3aa 25#include "crypto.h"
3d14c5d2
YS
26
27
28
29/*
30 * find filename portion of a path (/foo/bar/baz -> baz)
31 */
32const char *ceph_file_part(const char *s, int len)
33{
34 const char *e = s + len;
35
36 while (e != s && *(e-1) != '/')
37 e--;
38 return e;
39}
40EXPORT_SYMBOL(ceph_file_part);
41
42const char *ceph_msg_type_name(int type)
43{
44 switch (type) {
45 case CEPH_MSG_SHUTDOWN: return "shutdown";
46 case CEPH_MSG_PING: return "ping";
47 case CEPH_MSG_AUTH: return "auth";
48 case CEPH_MSG_AUTH_REPLY: return "auth_reply";
49 case CEPH_MSG_MON_MAP: return "mon_map";
50 case CEPH_MSG_MON_GET_MAP: return "mon_get_map";
51 case CEPH_MSG_MON_SUBSCRIBE: return "mon_subscribe";
52 case CEPH_MSG_MON_SUBSCRIBE_ACK: return "mon_subscribe_ack";
53 case CEPH_MSG_STATFS: return "statfs";
54 case CEPH_MSG_STATFS_REPLY: return "statfs_reply";
55 case CEPH_MSG_MDS_MAP: return "mds_map";
56 case CEPH_MSG_CLIENT_SESSION: return "client_session";
57 case CEPH_MSG_CLIENT_RECONNECT: return "client_reconnect";
58 case CEPH_MSG_CLIENT_REQUEST: return "client_request";
59 case CEPH_MSG_CLIENT_REQUEST_FORWARD: return "client_request_forward";
60 case CEPH_MSG_CLIENT_REPLY: return "client_reply";
61 case CEPH_MSG_CLIENT_CAPS: return "client_caps";
62 case CEPH_MSG_CLIENT_CAPRELEASE: return "client_cap_release";
63 case CEPH_MSG_CLIENT_SNAP: return "client_snap";
64 case CEPH_MSG_CLIENT_LEASE: return "client_lease";
65 case CEPH_MSG_OSD_MAP: return "osd_map";
66 case CEPH_MSG_OSD_OP: return "osd_op";
67 case CEPH_MSG_OSD_OPREPLY: return "osd_opreply";
a40c4f10 68 case CEPH_MSG_WATCH_NOTIFY: return "watch_notify";
3d14c5d2
YS
69 default: return "unknown";
70 }
71}
72EXPORT_SYMBOL(ceph_msg_type_name);
73
74/*
75 * Initially learn our fsid, or verify an fsid matches.
76 */
77int ceph_check_fsid(struct ceph_client *client, struct ceph_fsid *fsid)
78{
79 if (client->have_fsid) {
80 if (ceph_fsid_compare(&client->fsid, fsid)) {
81 pr_err("bad fsid, had %pU got %pU",
82 &client->fsid, fsid);
83 return -1;
84 }
85 } else {
86 pr_info("client%lld fsid %pU\n", ceph_client_id(client), fsid);
87 memcpy(&client->fsid, fsid, sizeof(*fsid));
88 ceph_debugfs_client_init(client);
89 client->have_fsid = true;
90 }
91 return 0;
92}
93EXPORT_SYMBOL(ceph_check_fsid);
94
95static int strcmp_null(const char *s1, const char *s2)
96{
97 if (!s1 && !s2)
98 return 0;
99 if (s1 && !s2)
100 return -1;
101 if (!s1 && s2)
102 return 1;
103 return strcmp(s1, s2);
104}
105
106int ceph_compare_options(struct ceph_options *new_opt,
107 struct ceph_client *client)
108{
109 struct ceph_options *opt1 = new_opt;
110 struct ceph_options *opt2 = client->options;
111 int ofs = offsetof(struct ceph_options, mon_addr);
112 int i;
113 int ret;
114
115 ret = memcmp(opt1, opt2, ofs);
116 if (ret)
117 return ret;
118
119 ret = strcmp_null(opt1->name, opt2->name);
120 if (ret)
121 return ret;
122
8323c3aa
TV
123 if (opt1->key && !opt2->key)
124 return -1;
125 if (!opt1->key && opt2->key)
126 return 1;
127 if (opt1->key && opt2->key) {
128 if (opt1->key->type != opt2->key->type)
129 return -1;
130 if (opt1->key->created.tv_sec != opt2->key->created.tv_sec)
131 return -1;
132 if (opt1->key->created.tv_nsec != opt2->key->created.tv_nsec)
133 return -1;
134 if (opt1->key->len != opt2->key->len)
135 return -1;
136 if (opt1->key->key && !opt2->key->key)
137 return -1;
138 if (!opt1->key->key && opt2->key->key)
139 return 1;
140 if (opt1->key->key && opt2->key->key) {
141 ret = memcmp(opt1->key->key, opt2->key->key, opt1->key->len);
142 if (ret)
143 return ret;
144 }
145 }
3d14c5d2
YS
146
147 /* any matching mon ip implies a match */
148 for (i = 0; i < opt1->num_mon; i++) {
149 if (ceph_monmap_contains(client->monc.monmap,
150 &opt1->mon_addr[i]))
151 return 0;
152 }
153 return -1;
154}
155EXPORT_SYMBOL(ceph_compare_options);
156
157
158static int parse_fsid(const char *str, struct ceph_fsid *fsid)
159{
160 int i = 0;
161 char tmp[3];
162 int err = -EINVAL;
163 int d;
164
165 dout("parse_fsid '%s'\n", str);
166 tmp[2] = 0;
167 while (*str && i < 16) {
168 if (ispunct(*str)) {
169 str++;
170 continue;
171 }
172 if (!isxdigit(str[0]) || !isxdigit(str[1]))
173 break;
174 tmp[0] = str[0];
175 tmp[1] = str[1];
176 if (sscanf(tmp, "%x", &d) < 1)
177 break;
178 fsid->fsid[i] = d & 0xff;
179 i++;
180 str += 2;
181 }
182
183 if (i == 16)
184 err = 0;
185 dout("parse_fsid ret %d got fsid %pU", err, fsid);
186 return err;
187}
188
189/*
190 * ceph options
191 */
192enum {
193 Opt_osdtimeout,
194 Opt_osdkeepalivetimeout,
195 Opt_mount_timeout,
196 Opt_osd_idle_ttl,
197 Opt_last_int,
198 /* int args above */
199 Opt_fsid,
200 Opt_name,
201 Opt_secret,
e2c3d29b 202 Opt_key,
3d14c5d2
YS
203 Opt_ip,
204 Opt_last_string,
205 /* string args above */
206 Opt_noshare,
207 Opt_nocrc,
208};
209
210static match_table_t opt_tokens = {
211 {Opt_osdtimeout, "osdtimeout=%d"},
212 {Opt_osdkeepalivetimeout, "osdkeepalive=%d"},
213 {Opt_mount_timeout, "mount_timeout=%d"},
214 {Opt_osd_idle_ttl, "osd_idle_ttl=%d"},
215 /* int args above */
216 {Opt_fsid, "fsid=%s"},
217 {Opt_name, "name=%s"},
218 {Opt_secret, "secret=%s"},
e2c3d29b 219 {Opt_key, "key=%s"},
3d14c5d2
YS
220 {Opt_ip, "ip=%s"},
221 /* string args above */
222 {Opt_noshare, "noshare"},
223 {Opt_nocrc, "nocrc"},
224 {-1, NULL}
225};
226
227void ceph_destroy_options(struct ceph_options *opt)
228{
229 dout("destroy_options %p\n", opt);
230 kfree(opt->name);
8323c3aa
TV
231 if (opt->key) {
232 ceph_crypto_key_destroy(opt->key);
233 kfree(opt->key);
234 }
3d14c5d2
YS
235 kfree(opt);
236}
237EXPORT_SYMBOL(ceph_destroy_options);
238
e2c3d29b
TV
239/* get secret from key store */
240static int get_secret(struct ceph_crypto_key *dst, const char *name) {
241 struct key *ukey;
242 int key_err;
243 int err = 0;
244 struct user_key_payload *payload;
245 void *p;
246
247 ukey = request_key(&key_type_user, name, NULL);
248 if (!ukey || IS_ERR(ukey)) {
249 /* request_key errors don't map nicely to mount(2)
250 errors; don't even try, but still printk */
251 key_err = PTR_ERR(ukey);
252 switch (key_err) {
253 case -ENOKEY:
254 pr_warning("ceph: Mount failed due to key not found: %s\n", name);
255 break;
256 case -EKEYEXPIRED:
257 pr_warning("ceph: Mount failed due to expired key: %s\n", name);
258 break;
259 case -EKEYREVOKED:
260 pr_warning("ceph: Mount failed due to revoked key: %s\n", name);
261 break;
262 default:
263 pr_warning("ceph: Mount failed due to unknown key error"
264 " %d: %s\n", key_err, name);
265 }
266 err = -EPERM;
267 goto out;
268 }
269
270 payload = ukey->payload.data;
271 p = payload->data;
272 err = ceph_crypto_key_decode(dst, &p, p + payload->datalen);
273 if (err)
274 goto out_key;
275 /* pass through, err is 0 */
276
277out_key:
278 key_put(ukey);
279out:
280 return err;
281}
282
3d14c5d2
YS
283int ceph_parse_options(struct ceph_options **popt, char *options,
284 const char *dev_name, const char *dev_name_end,
285 int (*parse_extra_token)(char *c, void *private),
286 void *private)
287{
288 struct ceph_options *opt;
289 const char *c;
290 int err = -ENOMEM;
291 substring_t argstr[MAX_OPT_ARGS];
292
293 opt = kzalloc(sizeof(*opt), GFP_KERNEL);
294 if (!opt)
295 return err;
296 opt->mon_addr = kcalloc(CEPH_MAX_MON, sizeof(*opt->mon_addr),
297 GFP_KERNEL);
298 if (!opt->mon_addr)
299 goto out;
300
301 dout("parse_options %p options '%s' dev_name '%s'\n", opt, options,
302 dev_name);
303
304 /* start with defaults */
305 opt->flags = CEPH_OPT_DEFAULT;
306 opt->osd_timeout = CEPH_OSD_TIMEOUT_DEFAULT;
307 opt->osd_keepalive_timeout = CEPH_OSD_KEEPALIVE_DEFAULT;
308 opt->mount_timeout = CEPH_MOUNT_TIMEOUT_DEFAULT; /* seconds */
309 opt->osd_idle_ttl = CEPH_OSD_IDLE_TTL_DEFAULT; /* seconds */
310
311 /* get mon ip(s) */
312 /* ip1[:port1][,ip2[:port2]...] */
313 err = ceph_parse_ips(dev_name, dev_name_end, opt->mon_addr,
314 CEPH_MAX_MON, &opt->num_mon);
315 if (err < 0)
316 goto out;
317
318 /* parse mount options */
319 while ((c = strsep(&options, ",")) != NULL) {
320 int token, intval, ret;
321 if (!*c)
322 continue;
323 err = -EINVAL;
324 token = match_token((char *)c, opt_tokens, argstr);
010e3b48 325 if (token < 0 && parse_extra_token) {
3d14c5d2
YS
326 /* extra? */
327 err = parse_extra_token((char *)c, private);
328 if (err < 0) {
329 pr_err("bad option at '%s'\n", c);
330 goto out;
331 }
332 continue;
333 }
334 if (token < Opt_last_int) {
335 ret = match_int(&argstr[0], &intval);
336 if (ret < 0) {
337 pr_err("bad mount option arg (not int) "
338 "at '%s'\n", c);
339 continue;
340 }
341 dout("got int token %d val %d\n", token, intval);
342 } else if (token > Opt_last_int && token < Opt_last_string) {
343 dout("got string token %d val %s\n", token,
344 argstr[0].from);
345 } else {
346 dout("got token %d\n", token);
347 }
348 switch (token) {
349 case Opt_ip:
350 err = ceph_parse_ips(argstr[0].from,
351 argstr[0].to,
352 &opt->my_addr,
353 1, NULL);
354 if (err < 0)
355 goto out;
356 opt->flags |= CEPH_OPT_MYIP;
357 break;
358
359 case Opt_fsid:
360 err = parse_fsid(argstr[0].from, &opt->fsid);
361 if (err == 0)
362 opt->flags |= CEPH_OPT_FSID;
363 break;
364 case Opt_name:
365 opt->name = kstrndup(argstr[0].from,
366 argstr[0].to-argstr[0].from,
367 GFP_KERNEL);
368 break;
369 case Opt_secret:
8323c3aa
TV
370 opt->key = kzalloc(sizeof(*opt->key), GFP_KERNEL);
371 if (!opt->key) {
372 err = -ENOMEM;
373 goto out;
374 }
375 err = ceph_crypto_key_unarmor(opt->key, argstr[0].from);
376 if (err < 0)
377 goto out;
3d14c5d2 378 break;
e2c3d29b
TV
379 case Opt_key:
380 opt->key = kzalloc(sizeof(*opt->key), GFP_KERNEL);
381 if (!opt->key) {
382 err = -ENOMEM;
383 goto out;
384 }
385 err = get_secret(opt->key, argstr[0].from);
386 if (err < 0)
387 goto out;
388 break;
3d14c5d2
YS
389
390 /* misc */
391 case Opt_osdtimeout:
392 opt->osd_timeout = intval;
393 break;
394 case Opt_osdkeepalivetimeout:
395 opt->osd_keepalive_timeout = intval;
396 break;
397 case Opt_osd_idle_ttl:
398 opt->osd_idle_ttl = intval;
399 break;
400 case Opt_mount_timeout:
401 opt->mount_timeout = intval;
402 break;
403
404 case Opt_noshare:
405 opt->flags |= CEPH_OPT_NOSHARE;
406 break;
407
408 case Opt_nocrc:
409 opt->flags |= CEPH_OPT_NOCRC;
410 break;
411
412 default:
413 BUG_ON(token);
414 }
415 }
416
417 /* success */
418 *popt = opt;
419 return 0;
420
421out:
422 ceph_destroy_options(opt);
423 return err;
424}
425EXPORT_SYMBOL(ceph_parse_options);
426
427u64 ceph_client_id(struct ceph_client *client)
428{
429 return client->monc.auth->global_id;
430}
431EXPORT_SYMBOL(ceph_client_id);
432
433/*
434 * create a fresh client instance
435 */
436struct ceph_client *ceph_create_client(struct ceph_options *opt, void *private)
437{
438 struct ceph_client *client;
439 int err = -ENOMEM;
440
441 client = kzalloc(sizeof(*client), GFP_KERNEL);
442 if (client == NULL)
443 return ERR_PTR(-ENOMEM);
444
445 client->private = private;
446 client->options = opt;
447
448 mutex_init(&client->mount_mutex);
449 init_waitqueue_head(&client->auth_wq);
450 client->auth_err = 0;
451
452 client->extra_mon_dispatch = NULL;
453 client->supported_features = CEPH_FEATURE_SUPPORTED_DEFAULT;
454 client->required_features = CEPH_FEATURE_REQUIRED_DEFAULT;
455
456 client->msgr = NULL;
457
458 /* subsystems */
459 err = ceph_monc_init(&client->monc, client);
460 if (err < 0)
461 goto fail;
462 err = ceph_osdc_init(&client->osdc, client);
463 if (err < 0)
464 goto fail_monc;
465
466 return client;
467
468fail_monc:
469 ceph_monc_stop(&client->monc);
470fail:
471 kfree(client);
472 return ERR_PTR(err);
473}
474EXPORT_SYMBOL(ceph_create_client);
475
476void ceph_destroy_client(struct ceph_client *client)
477{
478 dout("destroy_client %p\n", client);
479
480 /* unmount */
481 ceph_osdc_stop(&client->osdc);
482
483 /*
ef550f6f
SW
484 * make sure osd connections close out before destroying the
485 * auth module, which is needed to free those connections'
3d14c5d2
YS
486 * ceph_authorizers.
487 */
488 ceph_msgr_flush();
489
490 ceph_monc_stop(&client->monc);
491
492 ceph_debugfs_client_cleanup(client);
493
494 if (client->msgr)
495 ceph_messenger_destroy(client->msgr);
496
497 ceph_destroy_options(client->options);
498
499 kfree(client);
500 dout("destroy_client %p done\n", client);
501}
502EXPORT_SYMBOL(ceph_destroy_client);
503
504/*
505 * true if we have the mon map (and have thus joined the cluster)
506 */
507static int have_mon_and_osd_map(struct ceph_client *client)
508{
509 return client->monc.monmap && client->monc.monmap->epoch &&
510 client->osdc.osdmap && client->osdc.osdmap->epoch;
511}
512
513/*
514 * mount: join the ceph cluster, and open root directory.
515 */
516int __ceph_open_session(struct ceph_client *client, unsigned long started)
517{
518 struct ceph_entity_addr *myaddr = NULL;
519 int err;
520 unsigned long timeout = client->options->mount_timeout * HZ;
521
522 /* initialize the messenger */
523 if (client->msgr == NULL) {
524 if (ceph_test_opt(client, MYIP))
525 myaddr = &client->options->my_addr;
526 client->msgr = ceph_messenger_create(myaddr,
527 client->supported_features,
528 client->required_features);
529 if (IS_ERR(client->msgr)) {
530 client->msgr = NULL;
531 return PTR_ERR(client->msgr);
532 }
533 client->msgr->nocrc = ceph_test_opt(client, NOCRC);
534 }
535
536 /* open session, and wait for mon and osd maps */
537 err = ceph_monc_open_session(&client->monc);
538 if (err < 0)
539 return err;
540
541 while (!have_mon_and_osd_map(client)) {
542 err = -EIO;
543 if (timeout && time_after_eq(jiffies, started + timeout))
544 return err;
545
546 /* wait */
547 dout("mount waiting for mon_map\n");
548 err = wait_event_interruptible_timeout(client->auth_wq,
549 have_mon_and_osd_map(client) || (client->auth_err < 0),
550 timeout);
551 if (err == -EINTR || err == -ERESTARTSYS)
552 return err;
553 if (client->auth_err < 0)
554 return client->auth_err;
555 }
556
557 return 0;
558}
559EXPORT_SYMBOL(__ceph_open_session);
560
561
562int ceph_open_session(struct ceph_client *client)
563{
564 int ret;
565 unsigned long started = jiffies; /* note the start time */
566
567 dout("open_session start\n");
568 mutex_lock(&client->mount_mutex);
569
570 ret = __ceph_open_session(client, started);
571
572 mutex_unlock(&client->mount_mutex);
573 return ret;
574}
575EXPORT_SYMBOL(ceph_open_session);
576
577
578static int __init init_ceph_lib(void)
579{
580 int ret = 0;
581
582 ret = ceph_debugfs_init();
583 if (ret < 0)
584 goto out;
585
586 ret = ceph_msgr_init();
587 if (ret < 0)
588 goto out_debugfs;
589
590 pr_info("loaded (mon/osd proto %d/%d, osdmap %d/%d %d/%d)\n",
591 CEPH_MONC_PROTOCOL, CEPH_OSDC_PROTOCOL,
592 CEPH_OSDMAP_VERSION, CEPH_OSDMAP_VERSION_EXT,
593 CEPH_OSDMAP_INC_VERSION, CEPH_OSDMAP_INC_VERSION_EXT);
594
595 return 0;
596
597out_debugfs:
598 ceph_debugfs_cleanup();
599out:
600 return ret;
601}
602
603static void __exit exit_ceph_lib(void)
604{
605 dout("exit_ceph_lib\n");
606 ceph_msgr_exit();
607 ceph_debugfs_cleanup();
608}
609
610module_init(init_ceph_lib);
611module_exit(exit_ceph_lib);
612
613MODULE_AUTHOR("Sage Weil <sage@newdream.net>");
614MODULE_AUTHOR("Yehuda Sadeh <yehuda@hq.newdream.net>");
615MODULE_AUTHOR("Patience Warnick <patience@newdream.net>");
616MODULE_DESCRIPTION("Ceph filesystem for Linux");
617MODULE_LICENSE("GPL");
This page took 0.103201 seconds and 5 git commands to generate.