]> bbs.cooldavid.org Git - net-next-2.6.git/blame - fs/nfsd/nfs4recover.c
CRED: Inaugurate COW credentials
[net-next-2.6.git] / fs / nfsd / nfs4recover.c
CommitLineData
a55370a3
N
1/*
2* linux/fs/nfsd/nfs4recover.c
3*
4* Copyright (c) 2004 The Regents of the University of Michigan.
5* All rights reserved.
6*
7* Andy Adamson <andros@citi.umich.edu>
8*
9* Redistribution and use in source and binary forms, with or without
10* modification, are permitted provided that the following conditions
11* are met:
12*
13* 1. Redistributions of source code must retain the above copyright
14* notice, this list of conditions and the following disclaimer.
15* 2. Redistributions in binary form must reproduce the above copyright
16* notice, this list of conditions and the following disclaimer in the
17* documentation and/or other materials provided with the distribution.
18* 3. Neither the name of the University nor the names of its
19* contributors may be used to endorse or promote products derived
20* from this software without specific prior written permission.
21*
22* THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
23* WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
24* MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
25* DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
29* BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
30* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
31* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
32* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
33*
34*/
35
35058687 36#include <linux/err.h>
a55370a3
N
37#include <linux/sunrpc/svc.h>
38#include <linux/nfsd/nfsd.h>
39#include <linux/nfs4.h>
40#include <linux/nfsd/state.h>
41#include <linux/nfsd/xdr4.h>
190e4fbf
N
42#include <linux/param.h>
43#include <linux/file.h>
44#include <linux/namei.h>
a55370a3 45#include <asm/uaccess.h>
87ae9afd 46#include <linux/scatterlist.h>
a55370a3 47#include <linux/crypto.h>
e8edc6e0 48#include <linux/sched.h>
0622753b 49#include <linux/mount.h>
a55370a3
N
50
51#define NFSDDBG_FACILITY NFSDDBG_PROC
52
190e4fbf 53/* Globals */
a63bb996 54static struct path rec_dir;
190e4fbf
N
55static int rec_dir_init = 0;
56
d84f4f99
DH
57static int
58nfs4_save_creds(const struct cred **original_creds)
190e4fbf 59{
d84f4f99
DH
60 struct cred *new;
61
62 new = prepare_creds();
63 if (!new)
64 return -ENOMEM;
65
66 new->fsuid = 0;
67 new->fsgid = 0;
68 *original_creds = override_creds(new);
69 put_cred(new);
70 return 0;
190e4fbf
N
71}
72
73static void
d84f4f99 74nfs4_reset_creds(const struct cred *original)
190e4fbf 75{
d84f4f99 76 revert_creds(original);
190e4fbf
N
77}
78
a55370a3
N
79static void
80md5_to_hex(char *out, char *md5)
81{
82 int i;
83
84 for (i=0; i<16; i++) {
85 unsigned char c = md5[i];
86
87 *out++ = '0' + ((c&0xf0)>>4) + (c>=0xa0)*('a'-'9'-1);
88 *out++ = '0' + (c&0x0f) + ((c&0x0f)>=0x0a)*('a'-'9'-1);
89 }
90 *out = '\0';
91}
92
b37ad28b 93__be32
a55370a3
N
94nfs4_make_rec_clidname(char *dname, struct xdr_netobj *clname)
95{
96 struct xdr_netobj cksum;
35058687 97 struct hash_desc desc;
60c74f81 98 struct scatterlist sg;
b37ad28b 99 __be32 status = nfserr_resource;
a55370a3
N
100
101 dprintk("NFSD: nfs4_make_rec_clidname for %.*s\n",
102 clname->len, clname->data);
35058687
HX
103 desc.flags = CRYPTO_TFM_REQ_MAY_SLEEP;
104 desc.tfm = crypto_alloc_hash("md5", 0, CRYPTO_ALG_ASYNC);
105 if (IS_ERR(desc.tfm))
106 goto out_no_tfm;
107 cksum.len = crypto_hash_digestsize(desc.tfm);
a55370a3
N
108 cksum.data = kmalloc(cksum.len, GFP_KERNEL);
109 if (cksum.data == NULL)
110 goto out;
a55370a3 111
60c74f81 112 sg_init_one(&sg, clname->data, clname->len);
a55370a3 113
60c74f81 114 if (crypto_hash_digest(&desc, &sg, sg.length, cksum.data))
35058687 115 goto out;
a55370a3
N
116
117 md5_to_hex(dname, cksum.data);
118
119 kfree(cksum.data);
120 status = nfs_ok;
121out:
35058687
HX
122 crypto_free_hash(desc.tfm);
123out_no_tfm:
a55370a3
N
124 return status;
125}
190e4fbf 126
a6ccbbb8
N
127static void
128nfsd4_sync_rec_dir(void)
c7b9a459 129{
a63bb996
AV
130 mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
131 nfsd_sync_dir(rec_dir.dentry);
132 mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
c7b9a459
N
133}
134
135int
136nfsd4_create_clid_dir(struct nfs4_client *clp)
137{
d84f4f99 138 const struct cred *original_cred;
c7b9a459
N
139 char *dname = clp->cl_recdir;
140 struct dentry *dentry;
c7b9a459
N
141 int status;
142
143 dprintk("NFSD: nfsd4_create_clid_dir for \"%s\"\n", dname);
144
145 if (!rec_dir_init || clp->cl_firststate)
146 return 0;
147
d84f4f99
DH
148 status = nfs4_save_creds(&original_cred);
149 if (status < 0)
150 return status;
c7b9a459
N
151
152 /* lock the parent */
a63bb996 153 mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
c7b9a459 154
a63bb996 155 dentry = lookup_one_len(dname, rec_dir.dentry, HEXDIR_LEN-1);
c7b9a459
N
156 if (IS_ERR(dentry)) {
157 status = PTR_ERR(dentry);
158 goto out_unlock;
159 }
160 status = -EEXIST;
161 if (dentry->d_inode) {
162 dprintk("NFSD: nfsd4_create_clid_dir: DIRECTORY EXISTS\n");
163 goto out_put;
164 }
a63bb996 165 status = mnt_want_write(rec_dir.mnt);
463c3197
DH
166 if (status)
167 goto out_put;
a63bb996
AV
168 status = vfs_mkdir(rec_dir.dentry->d_inode, dentry, S_IRWXU);
169 mnt_drop_write(rec_dir.mnt);
c7b9a459
N
170out_put:
171 dput(dentry);
172out_unlock:
a63bb996 173 mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
c7b9a459
N
174 if (status == 0) {
175 clp->cl_firststate = 1;
a6ccbbb8 176 nfsd4_sync_rec_dir();
c7b9a459 177 }
d84f4f99 178 nfs4_reset_creds(original_cred);
c7b9a459
N
179 dprintk("NFSD: nfsd4_create_clid_dir returns %d\n", status);
180 return status;
181}
182
190e4fbf
N
183typedef int (recdir_func)(struct dentry *, struct dentry *);
184
185struct dentry_list {
186 struct dentry *dentry;
187 struct list_head list;
188};
189
190struct dentry_list_arg {
191 struct list_head dentries;
192 struct dentry *parent;
193};
194
195static int
196nfsd4_build_dentrylist(void *arg, const char *name, int namlen,
afefdbb2 197 loff_t offset, u64 ino, unsigned int d_type)
190e4fbf
N
198{
199 struct dentry_list_arg *dla = arg;
200 struct list_head *dentries = &dla->dentries;
201 struct dentry *parent = dla->parent;
202 struct dentry *dentry;
203 struct dentry_list *child;
204
205 if (name && isdotent(name, namlen))
b37ad28b 206 return 0;
190e4fbf
N
207 dentry = lookup_one_len(name, parent, namlen);
208 if (IS_ERR(dentry))
209 return PTR_ERR(dentry);
210 child = kmalloc(sizeof(*child), GFP_KERNEL);
211 if (child == NULL)
212 return -ENOMEM;
213 child->dentry = dentry;
214 list_add(&child->list, dentries);
215 return 0;
216}
217
218static int
219nfsd4_list_rec_dir(struct dentry *dir, recdir_func *f)
220{
d84f4f99 221 const struct cred *original_cred;
190e4fbf
N
222 struct file *filp;
223 struct dentry_list_arg dla = {
224 .parent = dir,
225 };
226 struct list_head *dentries = &dla.dentries;
227 struct dentry_list *child;
190e4fbf
N
228 int status;
229
230 if (!rec_dir_init)
231 return 0;
232
d84f4f99
DH
233 status = nfs4_save_creds(&original_cred);
234 if (status < 0)
235 return status;
190e4fbf 236
745ca247
DH
237 filp = dentry_open(dget(dir), mntget(rec_dir.mnt), O_RDONLY,
238 current_cred());
190e4fbf
N
239 status = PTR_ERR(filp);
240 if (IS_ERR(filp))
241 goto out;
242 INIT_LIST_HEAD(dentries);
243 status = vfs_readdir(filp, nfsd4_build_dentrylist, &dla);
244 fput(filp);
245 while (!list_empty(dentries)) {
246 child = list_entry(dentries->next, struct dentry_list, list);
247 status = f(dir, child->dentry);
248 if (status)
249 goto out;
250 list_del(&child->list);
251 dput(child->dentry);
252 kfree(child);
253 }
254out:
255 while (!list_empty(dentries)) {
256 child = list_entry(dentries->next, struct dentry_list, list);
257 list_del(&child->list);
258 dput(child->dentry);
259 kfree(child);
260 }
d84f4f99 261 nfs4_reset_creds(original_cred);
190e4fbf
N
262 return status;
263}
264
c7b9a459
N
265static int
266nfsd4_remove_clid_file(struct dentry *dir, struct dentry *dentry)
267{
268 int status;
269
270 if (!S_ISREG(dir->d_inode->i_mode)) {
271 printk("nfsd4: non-file found in client recovery directory\n");
272 return -EINVAL;
273 }
4b75f78e 274 mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
c7b9a459 275 status = vfs_unlink(dir->d_inode, dentry);
1b1dcc1b 276 mutex_unlock(&dir->d_inode->i_mutex);
c7b9a459
N
277 return status;
278}
279
280static int
281nfsd4_clear_clid_dir(struct dentry *dir, struct dentry *dentry)
282{
283 int status;
284
285 /* For now this directory should already be empty, but we empty it of
286 * any regular files anyway, just in case the directory was created by
287 * a kernel from the future.... */
288 nfsd4_list_rec_dir(dentry, nfsd4_remove_clid_file);
7ef55b8a 289 mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
c7b9a459 290 status = vfs_rmdir(dir->d_inode, dentry);
1b1dcc1b 291 mutex_unlock(&dir->d_inode->i_mutex);
c7b9a459
N
292 return status;
293}
294
295static int
296nfsd4_unlink_clid_dir(char *name, int namlen)
297{
298 struct dentry *dentry;
299 int status;
300
301 dprintk("NFSD: nfsd4_unlink_clid_dir. name %.*s\n", namlen, name);
302
a63bb996
AV
303 mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
304 dentry = lookup_one_len(name, rec_dir.dentry, namlen);
305 mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
c7b9a459
N
306 if (IS_ERR(dentry)) {
307 status = PTR_ERR(dentry);
308 return status;
309 }
310 status = -ENOENT;
311 if (!dentry->d_inode)
312 goto out;
313
a63bb996 314 status = nfsd4_clear_clid_dir(rec_dir.dentry, dentry);
c7b9a459
N
315out:
316 dput(dentry);
317 return status;
318}
319
320void
321nfsd4_remove_clid_dir(struct nfs4_client *clp)
322{
d84f4f99 323 const struct cred *original_cred;
c7b9a459
N
324 int status;
325
326 if (!rec_dir_init || !clp->cl_firststate)
327 return;
328
a63bb996 329 status = mnt_want_write(rec_dir.mnt);
0622753b
DH
330 if (status)
331 goto out;
67be4313 332 clp->cl_firststate = 0;
d84f4f99
DH
333
334 status = nfs4_save_creds(&original_cred);
335 if (status < 0)
336 goto out;
337
c7b9a459 338 status = nfsd4_unlink_clid_dir(clp->cl_recdir, HEXDIR_LEN-1);
d84f4f99 339 nfs4_reset_creds(original_cred);
c7b9a459 340 if (status == 0)
a6ccbbb8 341 nfsd4_sync_rec_dir();
a63bb996 342 mnt_drop_write(rec_dir.mnt);
0622753b 343out:
c7b9a459
N
344 if (status)
345 printk("NFSD: Failed to remove expired client state directory"
346 " %.*s\n", HEXDIR_LEN, clp->cl_recdir);
347 return;
348}
349
350static int
351purge_old(struct dentry *parent, struct dentry *child)
352{
353 int status;
354
355 if (nfs4_has_reclaimed_state(child->d_name.name))
b37ad28b 356 return 0;
c7b9a459
N
357
358 status = nfsd4_clear_clid_dir(parent, child);
359 if (status)
360 printk("failed to remove client recovery directory %s\n",
361 child->d_name.name);
362 /* Keep trying, success or failure: */
b37ad28b 363 return 0;
c7b9a459
N
364}
365
366void
367nfsd4_recdir_purge_old(void) {
368 int status;
369
370 if (!rec_dir_init)
371 return;
a63bb996 372 status = mnt_want_write(rec_dir.mnt);
0622753b
DH
373 if (status)
374 goto out;
a63bb996 375 status = nfsd4_list_rec_dir(rec_dir.dentry, purge_old);
c7b9a459 376 if (status == 0)
a6ccbbb8 377 nfsd4_sync_rec_dir();
a63bb996 378 mnt_drop_write(rec_dir.mnt);
0622753b 379out:
c7b9a459
N
380 if (status)
381 printk("nfsd4: failed to purge old clients from recovery"
a63bb996 382 " directory %s\n", rec_dir.dentry->d_name.name);
c7b9a459
N
383}
384
190e4fbf
N
385static int
386load_recdir(struct dentry *parent, struct dentry *child)
387{
388 if (child->d_name.len != HEXDIR_LEN - 1) {
389 printk("nfsd4: illegal name %s in recovery directory\n",
390 child->d_name.name);
391 /* Keep trying; maybe the others are OK: */
b37ad28b 392 return 0;
190e4fbf
N
393 }
394 nfs4_client_to_reclaim(child->d_name.name);
b37ad28b 395 return 0;
190e4fbf
N
396}
397
398int
399nfsd4_recdir_load(void) {
400 int status;
401
a63bb996 402 status = nfsd4_list_rec_dir(rec_dir.dentry, load_recdir);
190e4fbf
N
403 if (status)
404 printk("nfsd4: failed loading clients from recovery"
a63bb996 405 " directory %s\n", rec_dir.dentry->d_name.name);
190e4fbf
N
406 return status;
407}
408
409/*
410 * Hold reference to the recovery directory.
411 */
412
413void
414nfsd4_init_recdir(char *rec_dirname)
415{
d84f4f99
DH
416 const struct cred *original_cred;
417 int status;
190e4fbf
N
418
419 printk("NFSD: Using %s as the NFSv4 state recovery directory\n",
420 rec_dirname);
421
422 BUG_ON(rec_dir_init);
423
d84f4f99
DH
424 status = nfs4_save_creds(&original_cred);
425 if (status < 0) {
426 printk("NFSD: Unable to change credentials to find recovery"
427 " directory: error %d\n",
428 status);
429 return;
430 }
190e4fbf 431
a63bb996 432 status = kern_path(rec_dirname, LOOKUP_FOLLOW | LOOKUP_DIRECTORY,
c2642ab0
BF
433 &rec_dir);
434 if (status)
435 printk("NFSD: unable to find recovery directory %s\n",
190e4fbf
N
436 rec_dirname);
437
438 if (!status)
439 rec_dir_init = 1;
d84f4f99 440 nfs4_reset_creds(original_cred);
190e4fbf
N
441}
442
443void
444nfsd4_shutdown_recdir(void)
445{
446 if (!rec_dir_init)
447 return;
448 rec_dir_init = 0;
a63bb996 449 path_put(&rec_dir);
190e4fbf 450}