Linux Audio

Check our new training course

Loading...
v4.17
 
  1/*
  2 * Copyright (c) 2004-2005 Silicon Graphics, Inc.
  3 * All Rights Reserved.
  4 *
  5 * This program is free software; you can redistribute it and/or
  6 * modify it under the terms of the GNU General Public License as
  7 * published by the Free Software Foundation.
  8 *
  9 * This program is distributed in the hope that it would be useful,
 10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 12 * GNU General Public License for more details.
 13 *
 14 * You should have received a copy of the GNU General Public License
 15 * along with this program; if not, write the Free Software Foundation,
 16 * Inc.,  51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
 17 */
 18#include <linux/compat.h>
 19#include <linux/ioctl.h>
 20#include <linux/mount.h>
 21#include <linux/slab.h>
 22#include <linux/uaccess.h>
 23#include <linux/fsmap.h>
 24#include "xfs.h"
 25#include "xfs_fs.h"
 
 26#include "xfs_format.h"
 27#include "xfs_log_format.h"
 28#include "xfs_trans_resv.h"
 29#include "xfs_mount.h"
 30#include "xfs_inode.h"
 
 31#include "xfs_itable.h"
 32#include "xfs_error.h"
 33#include "xfs_fsops.h"
 34#include "xfs_alloc.h"
 35#include "xfs_rtalloc.h"
 36#include "xfs_attr.h"
 37#include "xfs_ioctl.h"
 38#include "xfs_ioctl32.h"
 39#include "xfs_trace.h"
 40#include "xfs_sb.h"
 41
 42#define  _NATIVE_IOC(cmd, type) \
 43	  _IOC(_IOC_DIR(cmd), _IOC_TYPE(cmd), _IOC_NR(cmd), sizeof(type))
 44
 45#ifdef BROKEN_X86_ALIGNMENT
 46STATIC int
 47xfs_compat_flock64_copyin(
 48	xfs_flock64_t		*bf,
 49	compat_xfs_flock64_t	__user *arg32)
 50{
 51	if (get_user(bf->l_type,	&arg32->l_type) ||
 52	    get_user(bf->l_whence,	&arg32->l_whence) ||
 53	    get_user(bf->l_start,	&arg32->l_start) ||
 54	    get_user(bf->l_len,		&arg32->l_len) ||
 55	    get_user(bf->l_sysid,	&arg32->l_sysid) ||
 56	    get_user(bf->l_pid,		&arg32->l_pid) ||
 57	    copy_from_user(bf->l_pad,	&arg32->l_pad,	4*sizeof(u32)))
 58		return -EFAULT;
 59	return 0;
 60}
 61
 62STATIC int
 63xfs_compat_ioc_fsgeometry_v1(
 64	struct xfs_mount	  *mp,
 65	compat_xfs_fsop_geom_v1_t __user *arg32)
 66{
 67	xfs_fsop_geom_t		  fsgeo;
 68	int			  error;
 69
 70	error = xfs_fs_geometry(&mp->m_sb, &fsgeo, 3);
 71	if (error)
 72		return error;
 73	/* The 32-bit variant simply has some padding at the end */
 74	if (copy_to_user(arg32, &fsgeo, sizeof(struct compat_xfs_fsop_geom_v1)))
 75		return -EFAULT;
 76	return 0;
 77}
 78
 79STATIC int
 80xfs_compat_growfs_data_copyin(
 81	struct xfs_growfs_data	 *in,
 82	compat_xfs_growfs_data_t __user *arg32)
 83{
 84	if (get_user(in->newblocks, &arg32->newblocks) ||
 85	    get_user(in->imaxpct,   &arg32->imaxpct))
 86		return -EFAULT;
 87	return 0;
 88}
 89
 90STATIC int
 91xfs_compat_growfs_rt_copyin(
 92	struct xfs_growfs_rt	 *in,
 93	compat_xfs_growfs_rt_t	__user *arg32)
 94{
 95	if (get_user(in->newblocks, &arg32->newblocks) ||
 96	    get_user(in->extsize,   &arg32->extsize))
 97		return -EFAULT;
 98	return 0;
 99}
100
101STATIC int
102xfs_inumbers_fmt_compat(
103	void			__user *ubuffer,
104	const struct xfs_inogrp	*buffer,
105	long			count,
106	long			*written)
107{
108	compat_xfs_inogrp_t	__user *p32 = ubuffer;
109	long			i;
110
111	for (i = 0; i < count; i++) {
112		if (put_user(buffer[i].xi_startino,   &p32[i].xi_startino) ||
113		    put_user(buffer[i].xi_alloccount, &p32[i].xi_alloccount) ||
114		    put_user(buffer[i].xi_allocmask,  &p32[i].xi_allocmask))
115			return -EFAULT;
116	}
117	*written = count * sizeof(*p32);
118	return 0;
119}
120
121#else
122#define xfs_inumbers_fmt_compat xfs_inumbers_fmt
123#endif	/* BROKEN_X86_ALIGNMENT */
124
125STATIC int
126xfs_ioctl32_bstime_copyin(
127	xfs_bstime_t		*bstime,
128	compat_xfs_bstime_t	__user *bstime32)
129{
130	compat_time_t		sec32;	/* tv_sec differs on 64 vs. 32 */
131
132	if (get_user(sec32,		&bstime32->tv_sec)	||
133	    get_user(bstime->tv_nsec,	&bstime32->tv_nsec))
134		return -EFAULT;
135	bstime->tv_sec = sec32;
136	return 0;
137}
138
139/* xfs_bstat_t has differing alignment on intel, & bstime_t sizes everywhere */
 
 
 
140STATIC int
141xfs_ioctl32_bstat_copyin(
142	xfs_bstat_t		*bstat,
143	compat_xfs_bstat_t	__user *bstat32)
144{
145	if (get_user(bstat->bs_ino,	&bstat32->bs_ino)	||
146	    get_user(bstat->bs_mode,	&bstat32->bs_mode)	||
147	    get_user(bstat->bs_nlink,	&bstat32->bs_nlink)	||
148	    get_user(bstat->bs_uid,	&bstat32->bs_uid)	||
149	    get_user(bstat->bs_gid,	&bstat32->bs_gid)	||
150	    get_user(bstat->bs_rdev,	&bstat32->bs_rdev)	||
151	    get_user(bstat->bs_blksize,	&bstat32->bs_blksize)	||
152	    get_user(bstat->bs_size,	&bstat32->bs_size)	||
153	    xfs_ioctl32_bstime_copyin(&bstat->bs_atime, &bstat32->bs_atime) ||
154	    xfs_ioctl32_bstime_copyin(&bstat->bs_mtime, &bstat32->bs_mtime) ||
155	    xfs_ioctl32_bstime_copyin(&bstat->bs_ctime, &bstat32->bs_ctime) ||
156	    get_user(bstat->bs_blocks,	&bstat32->bs_size)	||
157	    get_user(bstat->bs_xflags,	&bstat32->bs_size)	||
158	    get_user(bstat->bs_extsize,	&bstat32->bs_extsize)	||
159	    get_user(bstat->bs_extents,	&bstat32->bs_extents)	||
160	    get_user(bstat->bs_gen,	&bstat32->bs_gen)	||
161	    get_user(bstat->bs_projid_lo, &bstat32->bs_projid_lo) ||
162	    get_user(bstat->bs_projid_hi, &bstat32->bs_projid_hi) ||
163	    get_user(bstat->bs_forkoff,	&bstat32->bs_forkoff)	||
164	    get_user(bstat->bs_dmevmask, &bstat32->bs_dmevmask)	||
165	    get_user(bstat->bs_dmstate,	&bstat32->bs_dmstate)	||
166	    get_user(bstat->bs_aextents, &bstat32->bs_aextents))
167		return -EFAULT;
168	return 0;
169}
170
171/* XFS_IOC_FSBULKSTAT and friends */
172
173STATIC int
174xfs_bstime_store_compat(
175	compat_xfs_bstime_t	__user *p32,
176	const xfs_bstime_t	*p)
177{
178	__s32			sec32;
179
180	sec32 = p->tv_sec;
181	if (put_user(sec32, &p32->tv_sec) ||
182	    put_user(p->tv_nsec, &p32->tv_nsec))
183		return -EFAULT;
184	return 0;
185}
186
187/* Return 0 on success or positive error (to xfs_bulkstat()) */
188STATIC int
189xfs_bulkstat_one_fmt_compat(
190	void			__user *ubuffer,
191	int			ubsize,
192	int			*ubused,
193	const xfs_bstat_t	*buffer)
194{
195	compat_xfs_bstat_t	__user *p32 = ubuffer;
196
197	if (ubsize < sizeof(*p32))
198		return -ENOMEM;
199
200	if (put_user(buffer->bs_ino,	  &p32->bs_ino)		||
201	    put_user(buffer->bs_mode,	  &p32->bs_mode)	||
202	    put_user(buffer->bs_nlink,	  &p32->bs_nlink)	||
203	    put_user(buffer->bs_uid,	  &p32->bs_uid)		||
204	    put_user(buffer->bs_gid,	  &p32->bs_gid)		||
205	    put_user(buffer->bs_rdev,	  &p32->bs_rdev)	||
206	    put_user(buffer->bs_blksize,  &p32->bs_blksize)	||
207	    put_user(buffer->bs_size,	  &p32->bs_size)	||
208	    xfs_bstime_store_compat(&p32->bs_atime, &buffer->bs_atime) ||
209	    xfs_bstime_store_compat(&p32->bs_mtime, &buffer->bs_mtime) ||
210	    xfs_bstime_store_compat(&p32->bs_ctime, &buffer->bs_ctime) ||
211	    put_user(buffer->bs_blocks,	  &p32->bs_blocks)	||
212	    put_user(buffer->bs_xflags,	  &p32->bs_xflags)	||
213	    put_user(buffer->bs_extsize,  &p32->bs_extsize)	||
214	    put_user(buffer->bs_extents,  &p32->bs_extents)	||
215	    put_user(buffer->bs_gen,	  &p32->bs_gen)		||
216	    put_user(buffer->bs_projid,	  &p32->bs_projid)	||
217	    put_user(buffer->bs_projid_hi,	&p32->bs_projid_hi)	||
218	    put_user(buffer->bs_forkoff,  &p32->bs_forkoff)	||
219	    put_user(buffer->bs_dmevmask, &p32->bs_dmevmask)	||
220	    put_user(buffer->bs_dmstate,  &p32->bs_dmstate)	||
221	    put_user(buffer->bs_aextents, &p32->bs_aextents))
222		return -EFAULT;
223	if (ubused)
224		*ubused = sizeof(*p32);
225	return 0;
226}
227
228STATIC int
229xfs_bulkstat_one_compat(
230	xfs_mount_t	*mp,		/* mount point for filesystem */
231	xfs_ino_t	ino,		/* inode number to get data for */
232	void		__user *buffer,	/* buffer to place output in */
233	int		ubsize,		/* size of buffer */
234	int		*ubused,	/* bytes used by me */
235	int		*stat)		/* BULKSTAT_RV_... */
236{
237	return xfs_bulkstat_one_int(mp, ino, buffer, ubsize,
238				    xfs_bulkstat_one_fmt_compat,
239				    ubused, stat);
240}
241
242/* copied from xfs_ioctl.c */
243STATIC int
244xfs_compat_ioc_bulkstat(
245	xfs_mount_t		  *mp,
246	unsigned int		  cmd,
247	compat_xfs_fsop_bulkreq_t __user *p32)
248{
249	u32			addr;
250	xfs_fsop_bulkreq_t	bulkreq;
251	int			count;	/* # of records returned */
252	xfs_ino_t		inlast;	/* last inode number */
253	int			done;
 
 
254	int			error;
255
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
256	/* done = 1 if there are more stats to get and if bulkstat */
257	/* should be called again (unused here, but used in dmapi) */
258
259	if (!capable(CAP_SYS_ADMIN))
260		return -EPERM;
261
262	if (XFS_FORCED_SHUTDOWN(mp))
263		return -EIO;
264
265	if (get_user(addr, &p32->lastip))
266		return -EFAULT;
267	bulkreq.lastip = compat_ptr(addr);
268	if (get_user(bulkreq.icount, &p32->icount) ||
269	    get_user(addr, &p32->ubuffer))
270		return -EFAULT;
271	bulkreq.ubuffer = compat_ptr(addr);
272	if (get_user(addr, &p32->ocount))
273		return -EFAULT;
274	bulkreq.ocount = compat_ptr(addr);
275
276	if (copy_from_user(&inlast, bulkreq.lastip, sizeof(__s64)))
277		return -EFAULT;
278
279	if ((count = bulkreq.icount) <= 0)
280		return -EINVAL;
281
282	if (bulkreq.ubuffer == NULL)
283		return -EINVAL;
284
 
 
 
 
 
 
 
 
 
 
 
 
 
 
285	if (cmd == XFS_IOC_FSINUMBERS_32) {
286		error = xfs_inumbers(mp, &inlast, &count,
287				bulkreq.ubuffer, xfs_inumbers_fmt_compat);
 
288	} else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE_32) {
289		int res;
290
291		error = xfs_bulkstat_one_compat(mp, inlast, bulkreq.ubuffer,
292				sizeof(compat_xfs_bstat_t), NULL, &res);
293	} else if (cmd == XFS_IOC_FSBULKSTAT_32) {
294		error = xfs_bulkstat(mp, &inlast, &count,
295			xfs_bulkstat_one_compat, sizeof(compat_xfs_bstat_t),
296			bulkreq.ubuffer, &done);
297	} else
298		error = -EINVAL;
 
299	if (error)
300		return error;
301
302	if (bulkreq.ocount != NULL) {
303		if (copy_to_user(bulkreq.lastip, &inlast,
304						sizeof(xfs_ino_t)))
305			return -EFAULT;
306
307		if (copy_to_user(bulkreq.ocount, &count, sizeof(count)))
308			return -EFAULT;
309	}
310
311	return 0;
312}
313
314STATIC int
315xfs_compat_handlereq_copyin(
316	xfs_fsop_handlereq_t		*hreq,
317	compat_xfs_fsop_handlereq_t	__user *arg32)
318{
319	compat_xfs_fsop_handlereq_t	hreq32;
320
321	if (copy_from_user(&hreq32, arg32, sizeof(compat_xfs_fsop_handlereq_t)))
322		return -EFAULT;
323
324	hreq->fd = hreq32.fd;
325	hreq->path = compat_ptr(hreq32.path);
326	hreq->oflags = hreq32.oflags;
327	hreq->ihandle = compat_ptr(hreq32.ihandle);
328	hreq->ihandlen = hreq32.ihandlen;
329	hreq->ohandle = compat_ptr(hreq32.ohandle);
330	hreq->ohandlen = compat_ptr(hreq32.ohandlen);
331
332	return 0;
333}
334
335STATIC struct dentry *
336xfs_compat_handlereq_to_dentry(
337	struct file		*parfilp,
338	compat_xfs_fsop_handlereq_t *hreq)
339{
340	return xfs_handle_to_dentry(parfilp,
341			compat_ptr(hreq->ihandle), hreq->ihandlen);
342}
343
344STATIC int
345xfs_compat_attrlist_by_handle(
346	struct file		*parfilp,
347	void			__user *arg)
348{
349	int			error;
350	attrlist_cursor_kern_t	*cursor;
 
351	compat_xfs_fsop_attrlist_handlereq_t al_hreq;
352	struct dentry		*dentry;
353	char			*kbuf;
354
355	if (!capable(CAP_SYS_ADMIN))
356		return -EPERM;
357	if (copy_from_user(&al_hreq, arg,
358			   sizeof(compat_xfs_fsop_attrlist_handlereq_t)))
359		return -EFAULT;
360	if (al_hreq.buflen < sizeof(struct attrlist) ||
361	    al_hreq.buflen > XFS_XATTR_LIST_MAX)
362		return -EINVAL;
363
364	/*
365	 * Reject flags, only allow namespaces.
366	 */
367	if (al_hreq.flags & ~(ATTR_ROOT | ATTR_SECURE))
368		return -EINVAL;
369
370	dentry = xfs_compat_handlereq_to_dentry(parfilp, &al_hreq.hreq);
371	if (IS_ERR(dentry))
372		return PTR_ERR(dentry);
373
374	error = -ENOMEM;
375	kbuf = kmem_zalloc_large(al_hreq.buflen, KM_SLEEP);
376	if (!kbuf)
377		goto out_dput;
378
379	cursor = (attrlist_cursor_kern_t *)&al_hreq.pos;
380	error = xfs_attr_list(XFS_I(d_inode(dentry)), kbuf, al_hreq.buflen,
381					al_hreq.flags, cursor);
382	if (error)
383		goto out_kfree;
384
 
 
 
 
 
385	if (copy_to_user(compat_ptr(al_hreq.buffer), kbuf, al_hreq.buflen))
386		error = -EFAULT;
387
388out_kfree:
389	kmem_free(kbuf);
390out_dput:
391	dput(dentry);
392	return error;
393}
394
395STATIC int
396xfs_compat_attrmulti_by_handle(
397	struct file				*parfilp,
398	void					__user *arg)
399{
400	int					error;
401	compat_xfs_attr_multiop_t		*ops;
402	compat_xfs_fsop_attrmulti_handlereq_t	am_hreq;
403	struct dentry				*dentry;
404	unsigned int				i, size;
405	unsigned char				*attr_name;
406
407	if (!capable(CAP_SYS_ADMIN))
408		return -EPERM;
409	if (copy_from_user(&am_hreq, arg,
410			   sizeof(compat_xfs_fsop_attrmulti_handlereq_t)))
411		return -EFAULT;
412
413	/* overflow check */
414	if (am_hreq.opcount >= INT_MAX / sizeof(compat_xfs_attr_multiop_t))
415		return -E2BIG;
416
417	dentry = xfs_compat_handlereq_to_dentry(parfilp, &am_hreq.hreq);
418	if (IS_ERR(dentry))
419		return PTR_ERR(dentry);
420
421	error = -E2BIG;
422	size = am_hreq.opcount * sizeof(compat_xfs_attr_multiop_t);
423	if (!size || size > 16 * PAGE_SIZE)
424		goto out_dput;
425
426	ops = memdup_user(compat_ptr(am_hreq.ops), size);
427	if (IS_ERR(ops)) {
428		error = PTR_ERR(ops);
429		goto out_dput;
430	}
431
432	error = -ENOMEM;
433	attr_name = kmalloc(MAXNAMELEN, GFP_KERNEL);
434	if (!attr_name)
435		goto out_kfree_ops;
436
437	error = 0;
438	for (i = 0; i < am_hreq.opcount; i++) {
439		ops[i].am_error = strncpy_from_user((char *)attr_name,
440				compat_ptr(ops[i].am_attrname),
441				MAXNAMELEN);
442		if (ops[i].am_error == 0 || ops[i].am_error == MAXNAMELEN)
443			error = -ERANGE;
444		if (ops[i].am_error < 0)
445			break;
446
447		switch (ops[i].am_opcode) {
448		case ATTR_OP_GET:
449			ops[i].am_error = xfs_attrmulti_attr_get(
450					d_inode(dentry), attr_name,
451					compat_ptr(ops[i].am_attrvalue),
452					&ops[i].am_length, ops[i].am_flags);
453			break;
454		case ATTR_OP_SET:
455			ops[i].am_error = mnt_want_write_file(parfilp);
456			if (ops[i].am_error)
457				break;
458			ops[i].am_error = xfs_attrmulti_attr_set(
459					d_inode(dentry), attr_name,
460					compat_ptr(ops[i].am_attrvalue),
461					ops[i].am_length, ops[i].am_flags);
462			mnt_drop_write_file(parfilp);
463			break;
464		case ATTR_OP_REMOVE:
465			ops[i].am_error = mnt_want_write_file(parfilp);
466			if (ops[i].am_error)
467				break;
468			ops[i].am_error = xfs_attrmulti_attr_remove(
469					d_inode(dentry), attr_name,
470					ops[i].am_flags);
471			mnt_drop_write_file(parfilp);
472			break;
473		default:
474			ops[i].am_error = -EINVAL;
475		}
476	}
477
478	if (copy_to_user(compat_ptr(am_hreq.ops), ops, size))
479		error = -EFAULT;
480
481	kfree(attr_name);
482 out_kfree_ops:
483	kfree(ops);
484 out_dput:
485	dput(dentry);
486	return error;
487}
488
489STATIC int
490xfs_compat_fssetdm_by_handle(
491	struct file		*parfilp,
492	void			__user *arg)
493{
494	int			error;
495	struct fsdmidata	fsd;
496	compat_xfs_fsop_setdm_handlereq_t dmhreq;
497	struct dentry		*dentry;
498
499	if (!capable(CAP_MKNOD))
500		return -EPERM;
501	if (copy_from_user(&dmhreq, arg,
502			   sizeof(compat_xfs_fsop_setdm_handlereq_t)))
503		return -EFAULT;
504
505	dentry = xfs_compat_handlereq_to_dentry(parfilp, &dmhreq.hreq);
506	if (IS_ERR(dentry))
507		return PTR_ERR(dentry);
508
509	if (IS_IMMUTABLE(d_inode(dentry)) || IS_APPEND(d_inode(dentry))) {
510		error = -EPERM;
511		goto out;
512	}
513
514	if (copy_from_user(&fsd, compat_ptr(dmhreq.data), sizeof(fsd))) {
515		error = -EFAULT;
516		goto out;
517	}
518
519	error = xfs_set_dmattrs(XFS_I(d_inode(dentry)), fsd.fsd_dmevmask,
520				 fsd.fsd_dmstate);
521
522out:
523	dput(dentry);
524	return error;
525}
526
527long
528xfs_file_compat_ioctl(
529	struct file		*filp,
530	unsigned		cmd,
531	unsigned long		p)
532{
533	struct inode		*inode = file_inode(filp);
534	struct xfs_inode	*ip = XFS_I(inode);
535	struct xfs_mount	*mp = ip->i_mount;
536	void			__user *arg = (void __user *)p;
537	int			error;
538
539	trace_xfs_file_compat_ioctl(ip);
540
541	switch (cmd) {
542	/* No size or alignment issues on any arch */
543	case XFS_IOC_DIOINFO:
544	case XFS_IOC_FSGEOMETRY:
545	case XFS_IOC_FSGETXATTR:
546	case XFS_IOC_FSSETXATTR:
547	case XFS_IOC_FSGETXATTRA:
548	case XFS_IOC_FSSETDM:
549	case XFS_IOC_GETBMAP:
550	case XFS_IOC_GETBMAPA:
551	case XFS_IOC_GETBMAPX:
552	case XFS_IOC_FSCOUNTS:
553	case XFS_IOC_SET_RESBLKS:
554	case XFS_IOC_GET_RESBLKS:
555	case XFS_IOC_FSGROWFSLOG:
556	case XFS_IOC_GOINGDOWN:
557	case XFS_IOC_ERROR_INJECTION:
558	case XFS_IOC_ERROR_CLEARALL:
559	case FS_IOC_GETFSMAP:
560	case XFS_IOC_SCRUB_METADATA:
561		return xfs_file_ioctl(filp, cmd, p);
562#ifndef BROKEN_X86_ALIGNMENT
563	/* These are handled fine if no alignment issues */
564	case XFS_IOC_ALLOCSP:
565	case XFS_IOC_FREESP:
566	case XFS_IOC_RESVSP:
567	case XFS_IOC_UNRESVSP:
568	case XFS_IOC_ALLOCSP64:
569	case XFS_IOC_FREESP64:
570	case XFS_IOC_RESVSP64:
571	case XFS_IOC_UNRESVSP64:
572	case XFS_IOC_FSGEOMETRY_V1:
573	case XFS_IOC_FSGROWFSDATA:
574	case XFS_IOC_FSGROWFSRT:
575	case XFS_IOC_ZERO_RANGE:
576		return xfs_file_ioctl(filp, cmd, p);
577#else
578	case XFS_IOC_ALLOCSP_32:
579	case XFS_IOC_FREESP_32:
580	case XFS_IOC_ALLOCSP64_32:
581	case XFS_IOC_FREESP64_32:
582	case XFS_IOC_RESVSP_32:
583	case XFS_IOC_UNRESVSP_32:
584	case XFS_IOC_RESVSP64_32:
585	case XFS_IOC_UNRESVSP64_32:
586	case XFS_IOC_ZERO_RANGE_32: {
587		struct xfs_flock64	bf;
588
589		if (xfs_compat_flock64_copyin(&bf, arg))
590			return -EFAULT;
591		cmd = _NATIVE_IOC(cmd, struct xfs_flock64);
592		return xfs_ioc_space(filp, cmd, &bf);
593	}
594	case XFS_IOC_FSGEOMETRY_V1_32:
595		return xfs_compat_ioc_fsgeometry_v1(mp, arg);
596	case XFS_IOC_FSGROWFSDATA_32: {
597		struct xfs_growfs_data	in;
598
599		if (xfs_compat_growfs_data_copyin(&in, arg))
600			return -EFAULT;
601		error = mnt_want_write_file(filp);
602		if (error)
603			return error;
604		error = xfs_growfs_data(mp, &in);
605		mnt_drop_write_file(filp);
606		return error;
607	}
608	case XFS_IOC_FSGROWFSRT_32: {
609		struct xfs_growfs_rt	in;
610
611		if (xfs_compat_growfs_rt_copyin(&in, arg))
612			return -EFAULT;
613		error = mnt_want_write_file(filp);
614		if (error)
615			return error;
616		error = xfs_growfs_rt(mp, &in);
617		mnt_drop_write_file(filp);
618		return error;
619	}
620#endif
621	/* long changes size, but xfs only copiese out 32 bits */
622	case XFS_IOC_GETXFLAGS_32:
623	case XFS_IOC_SETXFLAGS_32:
624	case XFS_IOC_GETVERSION_32:
625		cmd = _NATIVE_IOC(cmd, long);
626		return xfs_file_ioctl(filp, cmd, p);
627	case XFS_IOC_SWAPEXT_32: {
628		struct xfs_swapext	  sxp;
629		struct compat_xfs_swapext __user *sxu = arg;
630
631		/* Bulk copy in up to the sx_stat field, then copy bstat */
632		if (copy_from_user(&sxp, sxu,
633				   offsetof(struct xfs_swapext, sx_stat)) ||
634		    xfs_ioctl32_bstat_copyin(&sxp.sx_stat, &sxu->sx_stat))
635			return -EFAULT;
636		error = mnt_want_write_file(filp);
637		if (error)
638			return error;
639		error = xfs_ioc_swapext(&sxp);
640		mnt_drop_write_file(filp);
641		return error;
642	}
643	case XFS_IOC_FSBULKSTAT_32:
644	case XFS_IOC_FSBULKSTAT_SINGLE_32:
645	case XFS_IOC_FSINUMBERS_32:
646		return xfs_compat_ioc_bulkstat(mp, cmd, arg);
647	case XFS_IOC_FD_TO_HANDLE_32:
648	case XFS_IOC_PATH_TO_HANDLE_32:
649	case XFS_IOC_PATH_TO_FSHANDLE_32: {
650		struct xfs_fsop_handlereq	hreq;
651
652		if (xfs_compat_handlereq_copyin(&hreq, arg))
653			return -EFAULT;
654		cmd = _NATIVE_IOC(cmd, struct xfs_fsop_handlereq);
655		return xfs_find_handle(cmd, &hreq);
656	}
657	case XFS_IOC_OPEN_BY_HANDLE_32: {
658		struct xfs_fsop_handlereq	hreq;
659
660		if (xfs_compat_handlereq_copyin(&hreq, arg))
661			return -EFAULT;
662		return xfs_open_by_handle(filp, &hreq);
663	}
664	case XFS_IOC_READLINK_BY_HANDLE_32: {
665		struct xfs_fsop_handlereq	hreq;
666
667		if (xfs_compat_handlereq_copyin(&hreq, arg))
668			return -EFAULT;
669		return xfs_readlink_by_handle(filp, &hreq);
670	}
671	case XFS_IOC_ATTRLIST_BY_HANDLE_32:
672		return xfs_compat_attrlist_by_handle(filp, arg);
673	case XFS_IOC_ATTRMULTI_BY_HANDLE_32:
674		return xfs_compat_attrmulti_by_handle(filp, arg);
675	case XFS_IOC_FSSETDM_BY_HANDLE_32:
676		return xfs_compat_fssetdm_by_handle(filp, arg);
677	default:
678		return -ENOIOCTLCMD;
 
679	}
680}
v5.4
  1// SPDX-License-Identifier: GPL-2.0
  2/*
  3 * Copyright (c) 2004-2005 Silicon Graphics, Inc.
  4 * All Rights Reserved.
 
 
 
 
 
 
 
 
 
 
 
 
 
  5 */
 
 
  6#include <linux/mount.h>
 
 
  7#include <linux/fsmap.h>
  8#include "xfs.h"
  9#include "xfs_fs.h"
 10#include "xfs_shared.h"
 11#include "xfs_format.h"
 12#include "xfs_log_format.h"
 13#include "xfs_trans_resv.h"
 14#include "xfs_mount.h"
 15#include "xfs_inode.h"
 16#include "xfs_iwalk.h"
 17#include "xfs_itable.h"
 
 18#include "xfs_fsops.h"
 
 19#include "xfs_rtalloc.h"
 20#include "xfs_attr.h"
 21#include "xfs_ioctl.h"
 22#include "xfs_ioctl32.h"
 23#include "xfs_trace.h"
 24#include "xfs_sb.h"
 25
 26#define  _NATIVE_IOC(cmd, type) \
 27	  _IOC(_IOC_DIR(cmd), _IOC_TYPE(cmd), _IOC_NR(cmd), sizeof(type))
 28
 29#ifdef BROKEN_X86_ALIGNMENT
 30STATIC int
 31xfs_compat_flock64_copyin(
 32	xfs_flock64_t		*bf,
 33	compat_xfs_flock64_t	__user *arg32)
 34{
 35	if (get_user(bf->l_type,	&arg32->l_type) ||
 36	    get_user(bf->l_whence,	&arg32->l_whence) ||
 37	    get_user(bf->l_start,	&arg32->l_start) ||
 38	    get_user(bf->l_len,		&arg32->l_len) ||
 39	    get_user(bf->l_sysid,	&arg32->l_sysid) ||
 40	    get_user(bf->l_pid,		&arg32->l_pid) ||
 41	    copy_from_user(bf->l_pad,	&arg32->l_pad,	4*sizeof(u32)))
 42		return -EFAULT;
 43	return 0;
 44}
 45
 46STATIC int
 47xfs_compat_ioc_fsgeometry_v1(
 48	struct xfs_mount	  *mp,
 49	compat_xfs_fsop_geom_v1_t __user *arg32)
 50{
 51	struct xfs_fsop_geom	  fsgeo;
 
 52
 53	xfs_fs_geometry(&mp->m_sb, &fsgeo, 3);
 
 
 54	/* The 32-bit variant simply has some padding at the end */
 55	if (copy_to_user(arg32, &fsgeo, sizeof(struct compat_xfs_fsop_geom_v1)))
 56		return -EFAULT;
 57	return 0;
 58}
 59
 60STATIC int
 61xfs_compat_growfs_data_copyin(
 62	struct xfs_growfs_data	 *in,
 63	compat_xfs_growfs_data_t __user *arg32)
 64{
 65	if (get_user(in->newblocks, &arg32->newblocks) ||
 66	    get_user(in->imaxpct,   &arg32->imaxpct))
 67		return -EFAULT;
 68	return 0;
 69}
 70
 71STATIC int
 72xfs_compat_growfs_rt_copyin(
 73	struct xfs_growfs_rt	 *in,
 74	compat_xfs_growfs_rt_t	__user *arg32)
 75{
 76	if (get_user(in->newblocks, &arg32->newblocks) ||
 77	    get_user(in->extsize,   &arg32->extsize))
 78		return -EFAULT;
 79	return 0;
 80}
 81
 82STATIC int
 83xfs_fsinumbers_fmt_compat(
 84	struct xfs_ibulk		*breq,
 85	const struct xfs_inumbers	*ig)
 86{
 87	struct compat_xfs_inogrp __user	*p32 = breq->ubuffer;
 88	struct xfs_inogrp		ig1;
 89	struct xfs_inogrp		*igrp = &ig1;
 90
 91	xfs_inumbers_to_inogrp(&ig1, ig);
 92
 93	if (put_user(igrp->xi_startino,   &p32->xi_startino) ||
 94	    put_user(igrp->xi_alloccount, &p32->xi_alloccount) ||
 95	    put_user(igrp->xi_allocmask,  &p32->xi_allocmask))
 96		return -EFAULT;
 97
 98	return xfs_ibulk_advance(breq, sizeof(struct compat_xfs_inogrp));
 
 99}
100
101#else
102#define xfs_fsinumbers_fmt_compat xfs_fsinumbers_fmt
103#endif	/* BROKEN_X86_ALIGNMENT */
104
105STATIC int
106xfs_ioctl32_bstime_copyin(
107	xfs_bstime_t		*bstime,
108	compat_xfs_bstime_t	__user *bstime32)
109{
110	compat_time_t		sec32;	/* tv_sec differs on 64 vs. 32 */
111
112	if (get_user(sec32,		&bstime32->tv_sec)	||
113	    get_user(bstime->tv_nsec,	&bstime32->tv_nsec))
114		return -EFAULT;
115	bstime->tv_sec = sec32;
116	return 0;
117}
118
119/*
120 * struct xfs_bstat has differing alignment on intel, & bstime_t sizes
121 * everywhere
122 */
123STATIC int
124xfs_ioctl32_bstat_copyin(
125	struct xfs_bstat		*bstat,
126	struct compat_xfs_bstat	__user	*bstat32)
127{
128	if (get_user(bstat->bs_ino,	&bstat32->bs_ino)	||
129	    get_user(bstat->bs_mode,	&bstat32->bs_mode)	||
130	    get_user(bstat->bs_nlink,	&bstat32->bs_nlink)	||
131	    get_user(bstat->bs_uid,	&bstat32->bs_uid)	||
132	    get_user(bstat->bs_gid,	&bstat32->bs_gid)	||
133	    get_user(bstat->bs_rdev,	&bstat32->bs_rdev)	||
134	    get_user(bstat->bs_blksize,	&bstat32->bs_blksize)	||
135	    get_user(bstat->bs_size,	&bstat32->bs_size)	||
136	    xfs_ioctl32_bstime_copyin(&bstat->bs_atime, &bstat32->bs_atime) ||
137	    xfs_ioctl32_bstime_copyin(&bstat->bs_mtime, &bstat32->bs_mtime) ||
138	    xfs_ioctl32_bstime_copyin(&bstat->bs_ctime, &bstat32->bs_ctime) ||
139	    get_user(bstat->bs_blocks,	&bstat32->bs_size)	||
140	    get_user(bstat->bs_xflags,	&bstat32->bs_size)	||
141	    get_user(bstat->bs_extsize,	&bstat32->bs_extsize)	||
142	    get_user(bstat->bs_extents,	&bstat32->bs_extents)	||
143	    get_user(bstat->bs_gen,	&bstat32->bs_gen)	||
144	    get_user(bstat->bs_projid_lo, &bstat32->bs_projid_lo) ||
145	    get_user(bstat->bs_projid_hi, &bstat32->bs_projid_hi) ||
146	    get_user(bstat->bs_forkoff,	&bstat32->bs_forkoff)	||
147	    get_user(bstat->bs_dmevmask, &bstat32->bs_dmevmask)	||
148	    get_user(bstat->bs_dmstate,	&bstat32->bs_dmstate)	||
149	    get_user(bstat->bs_aextents, &bstat32->bs_aextents))
150		return -EFAULT;
151	return 0;
152}
153
154/* XFS_IOC_FSBULKSTAT and friends */
155
156STATIC int
157xfs_bstime_store_compat(
158	compat_xfs_bstime_t	__user *p32,
159	const xfs_bstime_t	*p)
160{
161	__s32			sec32;
162
163	sec32 = p->tv_sec;
164	if (put_user(sec32, &p32->tv_sec) ||
165	    put_user(p->tv_nsec, &p32->tv_nsec))
166		return -EFAULT;
167	return 0;
168}
169
170/* Return 0 on success or positive error (to xfs_bulkstat()) */
171STATIC int
172xfs_fsbulkstat_one_fmt_compat(
173	struct xfs_ibulk		*breq,
174	const struct xfs_bulkstat	*bstat)
175{
176	struct compat_xfs_bstat	__user	*p32 = breq->ubuffer;
177	struct xfs_bstat		bs1;
178	struct xfs_bstat		*buffer = &bs1;
179
180	xfs_bulkstat_to_bstat(breq->mp, &bs1, bstat);
 
181
182	if (put_user(buffer->bs_ino,	  &p32->bs_ino)		||
183	    put_user(buffer->bs_mode,	  &p32->bs_mode)	||
184	    put_user(buffer->bs_nlink,	  &p32->bs_nlink)	||
185	    put_user(buffer->bs_uid,	  &p32->bs_uid)		||
186	    put_user(buffer->bs_gid,	  &p32->bs_gid)		||
187	    put_user(buffer->bs_rdev,	  &p32->bs_rdev)	||
188	    put_user(buffer->bs_blksize,  &p32->bs_blksize)	||
189	    put_user(buffer->bs_size,	  &p32->bs_size)	||
190	    xfs_bstime_store_compat(&p32->bs_atime, &buffer->bs_atime) ||
191	    xfs_bstime_store_compat(&p32->bs_mtime, &buffer->bs_mtime) ||
192	    xfs_bstime_store_compat(&p32->bs_ctime, &buffer->bs_ctime) ||
193	    put_user(buffer->bs_blocks,	  &p32->bs_blocks)	||
194	    put_user(buffer->bs_xflags,	  &p32->bs_xflags)	||
195	    put_user(buffer->bs_extsize,  &p32->bs_extsize)	||
196	    put_user(buffer->bs_extents,  &p32->bs_extents)	||
197	    put_user(buffer->bs_gen,	  &p32->bs_gen)		||
198	    put_user(buffer->bs_projid,	  &p32->bs_projid)	||
199	    put_user(buffer->bs_projid_hi,	&p32->bs_projid_hi)	||
200	    put_user(buffer->bs_forkoff,  &p32->bs_forkoff)	||
201	    put_user(buffer->bs_dmevmask, &p32->bs_dmevmask)	||
202	    put_user(buffer->bs_dmstate,  &p32->bs_dmstate)	||
203	    put_user(buffer->bs_aextents, &p32->bs_aextents))
204		return -EFAULT;
 
 
 
 
205
206	return xfs_ibulk_advance(breq, sizeof(struct compat_xfs_bstat));
 
 
 
 
 
 
 
 
 
 
 
207}
208
209/* copied from xfs_ioctl.c */
210STATIC int
211xfs_compat_ioc_fsbulkstat(
212	xfs_mount_t		  *mp,
213	unsigned int		  cmd,
214	struct compat_xfs_fsop_bulkreq __user *p32)
215{
216	u32			addr;
217	struct xfs_fsop_bulkreq	bulkreq;
218	struct xfs_ibulk	breq = {
219		.mp		= mp,
220		.ocount		= 0,
221	};
222	xfs_ino_t		lastino;
223	int			error;
224
225	/*
226	 * Output structure handling functions.  Depending on the command,
227	 * either the xfs_bstat and xfs_inogrp structures are written out
228	 * to userpace memory via bulkreq.ubuffer.  Normally the compat
229	 * functions and structure size are the correct ones to use ...
230	 */
231	inumbers_fmt_pf		inumbers_func = xfs_fsinumbers_fmt_compat;
232	bulkstat_one_fmt_pf	bs_one_func = xfs_fsbulkstat_one_fmt_compat;
233
234#ifdef CONFIG_X86_X32
235	if (in_x32_syscall()) {
236		/*
237		 * ... but on x32 the input xfs_fsop_bulkreq has pointers
238		 * which must be handled in the "compat" (32-bit) way, while
239		 * the xfs_bstat and xfs_inogrp structures follow native 64-
240		 * bit layout convention.  So adjust accordingly, otherwise
241		 * the data written out in compat layout will not match what
242		 * x32 userspace expects.
243		 */
244		inumbers_func = xfs_fsinumbers_fmt;
245		bs_one_func = xfs_fsbulkstat_one_fmt;
246	}
247#endif
248
249	/* done = 1 if there are more stats to get and if bulkstat */
250	/* should be called again (unused here, but used in dmapi) */
251
252	if (!capable(CAP_SYS_ADMIN))
253		return -EPERM;
254
255	if (XFS_FORCED_SHUTDOWN(mp))
256		return -EIO;
257
258	if (get_user(addr, &p32->lastip))
259		return -EFAULT;
260	bulkreq.lastip = compat_ptr(addr);
261	if (get_user(bulkreq.icount, &p32->icount) ||
262	    get_user(addr, &p32->ubuffer))
263		return -EFAULT;
264	bulkreq.ubuffer = compat_ptr(addr);
265	if (get_user(addr, &p32->ocount))
266		return -EFAULT;
267	bulkreq.ocount = compat_ptr(addr);
268
269	if (copy_from_user(&lastino, bulkreq.lastip, sizeof(__s64)))
270		return -EFAULT;
271
272	if (bulkreq.icount <= 0)
273		return -EINVAL;
274
275	if (bulkreq.ubuffer == NULL)
276		return -EINVAL;
277
278	breq.ubuffer = bulkreq.ubuffer;
279	breq.icount = bulkreq.icount;
280
281	/*
282	 * FSBULKSTAT_SINGLE expects that *lastip contains the inode number
283	 * that we want to stat.  However, FSINUMBERS and FSBULKSTAT expect
284	 * that *lastip contains either zero or the number of the last inode to
285	 * be examined by the previous call and return results starting with
286	 * the next inode after that.  The new bulk request back end functions
287	 * take the inode to start with, so we have to compute the startino
288	 * parameter from lastino to maintain correct function.  lastino == 0
289	 * is a special case because it has traditionally meant "first inode
290	 * in filesystem".
291	 */
292	if (cmd == XFS_IOC_FSINUMBERS_32) {
293		breq.startino = lastino ? lastino + 1 : 0;
294		error = xfs_inumbers(&breq, inumbers_func);
295		lastino = breq.startino - 1;
296	} else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE_32) {
297		breq.startino = lastino;
298		breq.icount = 1;
299		error = xfs_bulkstat_one(&breq, bs_one_func);
300		lastino = breq.startino;
301	} else if (cmd == XFS_IOC_FSBULKSTAT_32) {
302		breq.startino = lastino ? lastino + 1 : 0;
303		error = xfs_bulkstat(&breq, bs_one_func);
304		lastino = breq.startino - 1;
305	} else {
306		error = -EINVAL;
307	}
308	if (error)
309		return error;
310
311	if (bulkreq.lastip != NULL &&
312	    copy_to_user(bulkreq.lastip, &lastino, sizeof(xfs_ino_t)))
313		return -EFAULT;
 
314
315	if (bulkreq.ocount != NULL &&
316	    copy_to_user(bulkreq.ocount, &breq.ocount, sizeof(__s32)))
317		return -EFAULT;
318
319	return 0;
320}
321
322STATIC int
323xfs_compat_handlereq_copyin(
324	xfs_fsop_handlereq_t		*hreq,
325	compat_xfs_fsop_handlereq_t	__user *arg32)
326{
327	compat_xfs_fsop_handlereq_t	hreq32;
328
329	if (copy_from_user(&hreq32, arg32, sizeof(compat_xfs_fsop_handlereq_t)))
330		return -EFAULT;
331
332	hreq->fd = hreq32.fd;
333	hreq->path = compat_ptr(hreq32.path);
334	hreq->oflags = hreq32.oflags;
335	hreq->ihandle = compat_ptr(hreq32.ihandle);
336	hreq->ihandlen = hreq32.ihandlen;
337	hreq->ohandle = compat_ptr(hreq32.ohandle);
338	hreq->ohandlen = compat_ptr(hreq32.ohandlen);
339
340	return 0;
341}
342
343STATIC struct dentry *
344xfs_compat_handlereq_to_dentry(
345	struct file		*parfilp,
346	compat_xfs_fsop_handlereq_t *hreq)
347{
348	return xfs_handle_to_dentry(parfilp,
349			compat_ptr(hreq->ihandle), hreq->ihandlen);
350}
351
352STATIC int
353xfs_compat_attrlist_by_handle(
354	struct file		*parfilp,
355	void			__user *arg)
356{
357	int			error;
358	attrlist_cursor_kern_t	*cursor;
359	compat_xfs_fsop_attrlist_handlereq_t __user *p = arg;
360	compat_xfs_fsop_attrlist_handlereq_t al_hreq;
361	struct dentry		*dentry;
362	char			*kbuf;
363
364	if (!capable(CAP_SYS_ADMIN))
365		return -EPERM;
366	if (copy_from_user(&al_hreq, arg,
367			   sizeof(compat_xfs_fsop_attrlist_handlereq_t)))
368		return -EFAULT;
369	if (al_hreq.buflen < sizeof(struct attrlist) ||
370	    al_hreq.buflen > XFS_XATTR_LIST_MAX)
371		return -EINVAL;
372
373	/*
374	 * Reject flags, only allow namespaces.
375	 */
376	if (al_hreq.flags & ~(ATTR_ROOT | ATTR_SECURE))
377		return -EINVAL;
378
379	dentry = xfs_compat_handlereq_to_dentry(parfilp, &al_hreq.hreq);
380	if (IS_ERR(dentry))
381		return PTR_ERR(dentry);
382
383	error = -ENOMEM;
384	kbuf = kmem_zalloc_large(al_hreq.buflen, 0);
385	if (!kbuf)
386		goto out_dput;
387
388	cursor = (attrlist_cursor_kern_t *)&al_hreq.pos;
389	error = xfs_attr_list(XFS_I(d_inode(dentry)), kbuf, al_hreq.buflen,
390					al_hreq.flags, cursor);
391	if (error)
392		goto out_kfree;
393
394	if (copy_to_user(&p->pos, cursor, sizeof(attrlist_cursor_kern_t))) {
395		error = -EFAULT;
396		goto out_kfree;
397	}
398
399	if (copy_to_user(compat_ptr(al_hreq.buffer), kbuf, al_hreq.buflen))
400		error = -EFAULT;
401
402out_kfree:
403	kmem_free(kbuf);
404out_dput:
405	dput(dentry);
406	return error;
407}
408
409STATIC int
410xfs_compat_attrmulti_by_handle(
411	struct file				*parfilp,
412	void					__user *arg)
413{
414	int					error;
415	compat_xfs_attr_multiop_t		*ops;
416	compat_xfs_fsop_attrmulti_handlereq_t	am_hreq;
417	struct dentry				*dentry;
418	unsigned int				i, size;
419	unsigned char				*attr_name;
420
421	if (!capable(CAP_SYS_ADMIN))
422		return -EPERM;
423	if (copy_from_user(&am_hreq, arg,
424			   sizeof(compat_xfs_fsop_attrmulti_handlereq_t)))
425		return -EFAULT;
426
427	/* overflow check */
428	if (am_hreq.opcount >= INT_MAX / sizeof(compat_xfs_attr_multiop_t))
429		return -E2BIG;
430
431	dentry = xfs_compat_handlereq_to_dentry(parfilp, &am_hreq.hreq);
432	if (IS_ERR(dentry))
433		return PTR_ERR(dentry);
434
435	error = -E2BIG;
436	size = am_hreq.opcount * sizeof(compat_xfs_attr_multiop_t);
437	if (!size || size > 16 * PAGE_SIZE)
438		goto out_dput;
439
440	ops = memdup_user(compat_ptr(am_hreq.ops), size);
441	if (IS_ERR(ops)) {
442		error = PTR_ERR(ops);
443		goto out_dput;
444	}
445
446	error = -ENOMEM;
447	attr_name = kmalloc(MAXNAMELEN, GFP_KERNEL);
448	if (!attr_name)
449		goto out_kfree_ops;
450
451	error = 0;
452	for (i = 0; i < am_hreq.opcount; i++) {
453		ops[i].am_error = strncpy_from_user((char *)attr_name,
454				compat_ptr(ops[i].am_attrname),
455				MAXNAMELEN);
456		if (ops[i].am_error == 0 || ops[i].am_error == MAXNAMELEN)
457			error = -ERANGE;
458		if (ops[i].am_error < 0)
459			break;
460
461		switch (ops[i].am_opcode) {
462		case ATTR_OP_GET:
463			ops[i].am_error = xfs_attrmulti_attr_get(
464					d_inode(dentry), attr_name,
465					compat_ptr(ops[i].am_attrvalue),
466					&ops[i].am_length, ops[i].am_flags);
467			break;
468		case ATTR_OP_SET:
469			ops[i].am_error = mnt_want_write_file(parfilp);
470			if (ops[i].am_error)
471				break;
472			ops[i].am_error = xfs_attrmulti_attr_set(
473					d_inode(dentry), attr_name,
474					compat_ptr(ops[i].am_attrvalue),
475					ops[i].am_length, ops[i].am_flags);
476			mnt_drop_write_file(parfilp);
477			break;
478		case ATTR_OP_REMOVE:
479			ops[i].am_error = mnt_want_write_file(parfilp);
480			if (ops[i].am_error)
481				break;
482			ops[i].am_error = xfs_attrmulti_attr_remove(
483					d_inode(dentry), attr_name,
484					ops[i].am_flags);
485			mnt_drop_write_file(parfilp);
486			break;
487		default:
488			ops[i].am_error = -EINVAL;
489		}
490	}
491
492	if (copy_to_user(compat_ptr(am_hreq.ops), ops, size))
493		error = -EFAULT;
494
495	kfree(attr_name);
496 out_kfree_ops:
497	kfree(ops);
498 out_dput:
499	dput(dentry);
500	return error;
501}
502
503STATIC int
504xfs_compat_fssetdm_by_handle(
505	struct file		*parfilp,
506	void			__user *arg)
507{
508	int			error;
509	struct fsdmidata	fsd;
510	compat_xfs_fsop_setdm_handlereq_t dmhreq;
511	struct dentry		*dentry;
512
513	if (!capable(CAP_MKNOD))
514		return -EPERM;
515	if (copy_from_user(&dmhreq, arg,
516			   sizeof(compat_xfs_fsop_setdm_handlereq_t)))
517		return -EFAULT;
518
519	dentry = xfs_compat_handlereq_to_dentry(parfilp, &dmhreq.hreq);
520	if (IS_ERR(dentry))
521		return PTR_ERR(dentry);
522
523	if (IS_IMMUTABLE(d_inode(dentry)) || IS_APPEND(d_inode(dentry))) {
524		error = -EPERM;
525		goto out;
526	}
527
528	if (copy_from_user(&fsd, compat_ptr(dmhreq.data), sizeof(fsd))) {
529		error = -EFAULT;
530		goto out;
531	}
532
533	error = xfs_set_dmattrs(XFS_I(d_inode(dentry)), fsd.fsd_dmevmask,
534				 fsd.fsd_dmstate);
535
536out:
537	dput(dentry);
538	return error;
539}
540
541long
542xfs_file_compat_ioctl(
543	struct file		*filp,
544	unsigned		cmd,
545	unsigned long		p)
546{
547	struct inode		*inode = file_inode(filp);
548	struct xfs_inode	*ip = XFS_I(inode);
549	struct xfs_mount	*mp = ip->i_mount;
550	void			__user *arg = compat_ptr(p);
551	int			error;
552
553	trace_xfs_file_compat_ioctl(ip);
554
555	switch (cmd) {
556#if defined(BROKEN_X86_ALIGNMENT)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
557	case XFS_IOC_ALLOCSP_32:
558	case XFS_IOC_FREESP_32:
559	case XFS_IOC_ALLOCSP64_32:
560	case XFS_IOC_FREESP64_32:
561	case XFS_IOC_RESVSP_32:
562	case XFS_IOC_UNRESVSP_32:
563	case XFS_IOC_RESVSP64_32:
564	case XFS_IOC_UNRESVSP64_32:
565	case XFS_IOC_ZERO_RANGE_32: {
566		struct xfs_flock64	bf;
567
568		if (xfs_compat_flock64_copyin(&bf, arg))
569			return -EFAULT;
570		cmd = _NATIVE_IOC(cmd, struct xfs_flock64);
571		return xfs_ioc_space(filp, cmd, &bf);
572	}
573	case XFS_IOC_FSGEOMETRY_V1_32:
574		return xfs_compat_ioc_fsgeometry_v1(mp, arg);
575	case XFS_IOC_FSGROWFSDATA_32: {
576		struct xfs_growfs_data	in;
577
578		if (xfs_compat_growfs_data_copyin(&in, arg))
579			return -EFAULT;
580		error = mnt_want_write_file(filp);
581		if (error)
582			return error;
583		error = xfs_growfs_data(mp, &in);
584		mnt_drop_write_file(filp);
585		return error;
586	}
587	case XFS_IOC_FSGROWFSRT_32: {
588		struct xfs_growfs_rt	in;
589
590		if (xfs_compat_growfs_rt_copyin(&in, arg))
591			return -EFAULT;
592		error = mnt_want_write_file(filp);
593		if (error)
594			return error;
595		error = xfs_growfs_rt(mp, &in);
596		mnt_drop_write_file(filp);
597		return error;
598	}
599#endif
600	/* long changes size, but xfs only copiese out 32 bits */
601	case XFS_IOC_GETXFLAGS_32:
602	case XFS_IOC_SETXFLAGS_32:
603	case XFS_IOC_GETVERSION_32:
604		cmd = _NATIVE_IOC(cmd, long);
605		return xfs_file_ioctl(filp, cmd, p);
606	case XFS_IOC_SWAPEXT_32: {
607		struct xfs_swapext	  sxp;
608		struct compat_xfs_swapext __user *sxu = arg;
609
610		/* Bulk copy in up to the sx_stat field, then copy bstat */
611		if (copy_from_user(&sxp, sxu,
612				   offsetof(struct xfs_swapext, sx_stat)) ||
613		    xfs_ioctl32_bstat_copyin(&sxp.sx_stat, &sxu->sx_stat))
614			return -EFAULT;
615		error = mnt_want_write_file(filp);
616		if (error)
617			return error;
618		error = xfs_ioc_swapext(&sxp);
619		mnt_drop_write_file(filp);
620		return error;
621	}
622	case XFS_IOC_FSBULKSTAT_32:
623	case XFS_IOC_FSBULKSTAT_SINGLE_32:
624	case XFS_IOC_FSINUMBERS_32:
625		return xfs_compat_ioc_fsbulkstat(mp, cmd, arg);
626	case XFS_IOC_FD_TO_HANDLE_32:
627	case XFS_IOC_PATH_TO_HANDLE_32:
628	case XFS_IOC_PATH_TO_FSHANDLE_32: {
629		struct xfs_fsop_handlereq	hreq;
630
631		if (xfs_compat_handlereq_copyin(&hreq, arg))
632			return -EFAULT;
633		cmd = _NATIVE_IOC(cmd, struct xfs_fsop_handlereq);
634		return xfs_find_handle(cmd, &hreq);
635	}
636	case XFS_IOC_OPEN_BY_HANDLE_32: {
637		struct xfs_fsop_handlereq	hreq;
638
639		if (xfs_compat_handlereq_copyin(&hreq, arg))
640			return -EFAULT;
641		return xfs_open_by_handle(filp, &hreq);
642	}
643	case XFS_IOC_READLINK_BY_HANDLE_32: {
644		struct xfs_fsop_handlereq	hreq;
645
646		if (xfs_compat_handlereq_copyin(&hreq, arg))
647			return -EFAULT;
648		return xfs_readlink_by_handle(filp, &hreq);
649	}
650	case XFS_IOC_ATTRLIST_BY_HANDLE_32:
651		return xfs_compat_attrlist_by_handle(filp, arg);
652	case XFS_IOC_ATTRMULTI_BY_HANDLE_32:
653		return xfs_compat_attrmulti_by_handle(filp, arg);
654	case XFS_IOC_FSSETDM_BY_HANDLE_32:
655		return xfs_compat_fssetdm_by_handle(filp, arg);
656	default:
657		/* try the native version */
658		return xfs_file_ioctl(filp, cmd, (unsigned long)arg);
659	}
660}