]> bbs.cooldavid.org Git - net-next-2.6.git/blame - fs/readdir.c
[CVE-2009-0029] System call wrappers part 20
[net-next-2.6.git] / fs / readdir.c
CommitLineData
1da177e4
LT
1/*
2 * linux/fs/readdir.c
3 *
4 * Copyright (C) 1995 Linus Torvalds
5 */
6
022a1692 7#include <linux/kernel.h>
1da177e4
LT
8#include <linux/module.h>
9#include <linux/time.h>
10#include <linux/mm.h>
11#include <linux/errno.h>
12#include <linux/stat.h>
13#include <linux/file.h>
1da177e4
LT
14#include <linux/fs.h>
15#include <linux/dirent.h>
16#include <linux/security.h>
17#include <linux/syscalls.h>
18#include <linux/unistd.h>
19
20#include <asm/uaccess.h>
21
22int vfs_readdir(struct file *file, filldir_t filler, void *buf)
23{
0f7fc9e4 24 struct inode *inode = file->f_path.dentry->d_inode;
1da177e4
LT
25 int res = -ENOTDIR;
26 if (!file->f_op || !file->f_op->readdir)
27 goto out;
28
29 res = security_file_permission(file, MAY_READ);
30 if (res)
31 goto out;
32
da784511
LH
33 res = mutex_lock_killable(&inode->i_mutex);
34 if (res)
35 goto out;
36
1da177e4
LT
37 res = -ENOENT;
38 if (!IS_DEADDIR(inode)) {
39 res = file->f_op->readdir(file, buf, filler);
40 file_accessed(file);
41 }
1b1dcc1b 42 mutex_unlock(&inode->i_mutex);
1da177e4
LT
43out:
44 return res;
45}
46
47EXPORT_SYMBOL(vfs_readdir);
48
49/*
50 * Traditional linux readdir() handling..
51 *
52 * "count=1" is a special case, meaning that the buffer is one
53 * dirent-structure in size and that the code can't handle more
54 * anyway. Thus the special "fillonedir()" function for that
55 * case (the low-level handlers don't need to care about this).
56 */
57#define NAME_OFFSET(de) ((int) ((de)->d_name - (char __user *) (de)))
1da177e4
LT
58
59#ifdef __ARCH_WANT_OLD_READDIR
60
61struct old_linux_dirent {
62 unsigned long d_ino;
63 unsigned long d_offset;
64 unsigned short d_namlen;
65 char d_name[1];
66};
67
68struct readdir_callback {
69 struct old_linux_dirent __user * dirent;
70 int result;
71};
72
73static int fillonedir(void * __buf, const char * name, int namlen, loff_t offset,
afefdbb2 74 u64 ino, unsigned int d_type)
1da177e4
LT
75{
76 struct readdir_callback * buf = (struct readdir_callback *) __buf;
77 struct old_linux_dirent __user * dirent;
afefdbb2 78 unsigned long d_ino;
1da177e4
LT
79
80 if (buf->result)
81 return -EINVAL;
afefdbb2 82 d_ino = ino;
8f3f655d
AV
83 if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
84 buf->result = -EOVERFLOW;
afefdbb2 85 return -EOVERFLOW;
8f3f655d 86 }
1da177e4
LT
87 buf->result++;
88 dirent = buf->dirent;
89 if (!access_ok(VERIFY_WRITE, dirent,
90 (unsigned long)(dirent->d_name + namlen + 1) -
91 (unsigned long)dirent))
92 goto efault;
afefdbb2 93 if ( __put_user(d_ino, &dirent->d_ino) ||
1da177e4
LT
94 __put_user(offset, &dirent->d_offset) ||
95 __put_user(namlen, &dirent->d_namlen) ||
96 __copy_to_user(dirent->d_name, name, namlen) ||
97 __put_user(0, dirent->d_name + namlen))
98 goto efault;
99 return 0;
100efault:
101 buf->result = -EFAULT;
102 return -EFAULT;
103}
104
e55380ed 105asmlinkage long sys_old_readdir(unsigned int fd, struct old_linux_dirent __user * dirent, unsigned int count)
1da177e4
LT
106{
107 int error;
108 struct file * file;
109 struct readdir_callback buf;
110
111 error = -EBADF;
112 file = fget(fd);
113 if (!file)
114 goto out;
115
116 buf.result = 0;
117 buf.dirent = dirent;
118
119 error = vfs_readdir(file, fillonedir, &buf);
53c9c5c0 120 if (buf.result)
1da177e4
LT
121 error = buf.result;
122
123 fput(file);
124out:
125 return error;
126}
127
128#endif /* __ARCH_WANT_OLD_READDIR */
129
130/*
131 * New, all-improved, singing, dancing, iBCS2-compliant getdents()
132 * interface.
133 */
134struct linux_dirent {
135 unsigned long d_ino;
136 unsigned long d_off;
137 unsigned short d_reclen;
138 char d_name[1];
139};
140
141struct getdents_callback {
142 struct linux_dirent __user * current_dir;
143 struct linux_dirent __user * previous;
144 int count;
145 int error;
146};
147
148static int filldir(void * __buf, const char * name, int namlen, loff_t offset,
afefdbb2 149 u64 ino, unsigned int d_type)
1da177e4
LT
150{
151 struct linux_dirent __user * dirent;
152 struct getdents_callback * buf = (struct getdents_callback *) __buf;
afefdbb2 153 unsigned long d_ino;
022a1692 154 int reclen = ALIGN(NAME_OFFSET(dirent) + namlen + 2, sizeof(long));
1da177e4
LT
155
156 buf->error = -EINVAL; /* only used if we fail.. */
157 if (reclen > buf->count)
158 return -EINVAL;
afefdbb2 159 d_ino = ino;
8f3f655d
AV
160 if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
161 buf->error = -EOVERFLOW;
afefdbb2 162 return -EOVERFLOW;
8f3f655d 163 }
1da177e4
LT
164 dirent = buf->previous;
165 if (dirent) {
166 if (__put_user(offset, &dirent->d_off))
167 goto efault;
168 }
169 dirent = buf->current_dir;
afefdbb2 170 if (__put_user(d_ino, &dirent->d_ino))
1da177e4
LT
171 goto efault;
172 if (__put_user(reclen, &dirent->d_reclen))
173 goto efault;
174 if (copy_to_user(dirent->d_name, name, namlen))
175 goto efault;
176 if (__put_user(0, dirent->d_name + namlen))
177 goto efault;
178 if (__put_user(d_type, (char __user *) dirent + reclen - 1))
179 goto efault;
180 buf->previous = dirent;
181 dirent = (void __user *)dirent + reclen;
182 buf->current_dir = dirent;
183 buf->count -= reclen;
184 return 0;
185efault:
186 buf->error = -EFAULT;
187 return -EFAULT;
188}
189
190asmlinkage long sys_getdents(unsigned int fd, struct linux_dirent __user * dirent, unsigned int count)
191{
192 struct file * file;
193 struct linux_dirent __user * lastdirent;
194 struct getdents_callback buf;
195 int error;
196
197 error = -EFAULT;
198 if (!access_ok(VERIFY_WRITE, dirent, count))
199 goto out;
200
201 error = -EBADF;
202 file = fget(fd);
203 if (!file)
204 goto out;
205
206 buf.current_dir = dirent;
207 buf.previous = NULL;
208 buf.count = count;
209 buf.error = 0;
210
211 error = vfs_readdir(file, filldir, &buf);
53c9c5c0
AV
212 if (error >= 0)
213 error = buf.error;
1da177e4
LT
214 lastdirent = buf.previous;
215 if (lastdirent) {
216 if (put_user(file->f_pos, &lastdirent->d_off))
217 error = -EFAULT;
218 else
219 error = count - buf.count;
220 }
1da177e4
LT
221 fput(file);
222out:
223 return error;
224}
225
1da177e4
LT
226struct getdents_callback64 {
227 struct linux_dirent64 __user * current_dir;
228 struct linux_dirent64 __user * previous;
229 int count;
230 int error;
231};
232
233static int filldir64(void * __buf, const char * name, int namlen, loff_t offset,
afefdbb2 234 u64 ino, unsigned int d_type)
1da177e4
LT
235{
236 struct linux_dirent64 __user *dirent;
237 struct getdents_callback64 * buf = (struct getdents_callback64 *) __buf;
022a1692 238 int reclen = ALIGN(NAME_OFFSET(dirent) + namlen + 1, sizeof(u64));
1da177e4
LT
239
240 buf->error = -EINVAL; /* only used if we fail.. */
241 if (reclen > buf->count)
242 return -EINVAL;
243 dirent = buf->previous;
244 if (dirent) {
245 if (__put_user(offset, &dirent->d_off))
246 goto efault;
247 }
248 dirent = buf->current_dir;
249 if (__put_user(ino, &dirent->d_ino))
250 goto efault;
251 if (__put_user(0, &dirent->d_off))
252 goto efault;
253 if (__put_user(reclen, &dirent->d_reclen))
254 goto efault;
255 if (__put_user(d_type, &dirent->d_type))
256 goto efault;
257 if (copy_to_user(dirent->d_name, name, namlen))
258 goto efault;
259 if (__put_user(0, dirent->d_name + namlen))
260 goto efault;
261 buf->previous = dirent;
262 dirent = (void __user *)dirent + reclen;
263 buf->current_dir = dirent;
264 buf->count -= reclen;
265 return 0;
266efault:
267 buf->error = -EFAULT;
268 return -EFAULT;
269}
270
271asmlinkage long sys_getdents64(unsigned int fd, struct linux_dirent64 __user * dirent, unsigned int count)
272{
273 struct file * file;
274 struct linux_dirent64 __user * lastdirent;
275 struct getdents_callback64 buf;
276 int error;
277
278 error = -EFAULT;
279 if (!access_ok(VERIFY_WRITE, dirent, count))
280 goto out;
281
282 error = -EBADF;
283 file = fget(fd);
284 if (!file)
285 goto out;
286
287 buf.current_dir = dirent;
288 buf.previous = NULL;
289 buf.count = count;
290 buf.error = 0;
291
292 error = vfs_readdir(file, filldir64, &buf);
53c9c5c0
AV
293 if (error >= 0)
294 error = buf.error;
1da177e4
LT
295 lastdirent = buf.previous;
296 if (lastdirent) {
297 typeof(lastdirent->d_off) d_off = file->f_pos;
1da177e4 298 if (__put_user(d_off, &lastdirent->d_off))
53c9c5c0
AV
299 error = -EFAULT;
300 else
301 error = count - buf.count;
1da177e4 302 }
1da177e4
LT
303 fput(file);
304out:
305 return error;
306}