Linux Audio

Check our new training course

In-person Linux kernel drivers training

Jun 16-20, 2025
Register
Loading...
v4.6
   1/*
   2 *  Copyright (c) 2001 The Regents of the University of Michigan.
   3 *  All rights reserved.
   4 *
   5 *  Kendrick Smith <kmsmith@umich.edu>
   6 *  Andy Adamson <andros@umich.edu>
   7 *
   8 *  Redistribution and use in source and binary forms, with or without
   9 *  modification, are permitted provided that the following conditions
  10 *  are met:
  11 *
  12 *  1. Redistributions of source code must retain the above copyright
  13 *     notice, this list of conditions and the following disclaimer.
  14 *  2. Redistributions in binary form must reproduce the above copyright
  15 *     notice, this list of conditions and the following disclaimer in the
  16 *     documentation and/or other materials provided with the distribution.
  17 *  3. Neither the name of the University nor the names of its
  18 *     contributors may be used to endorse or promote products derived
  19 *     from this software without specific prior written permission.
  20 *
  21 *  THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
  22 *  WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
  23 *  MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  24 *  DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
  25 *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
  26 *  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
  27 *  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
  28 *  BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
  29 *  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
  30 *  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  31 *  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  32 */
  33
 
  34#include <linux/sunrpc/clnt.h>
  35#include <linux/sunrpc/xprt.h>
  36#include <linux/sunrpc/svc_xprt.h>
  37#include <linux/slab.h>
  38#include "nfsd.h"
  39#include "state.h"
  40#include "netns.h"
 
  41#include "xdr4cb.h"
 
  42
  43#define NFSDDBG_FACILITY                NFSDDBG_PROC
  44
  45static void nfsd4_mark_cb_fault(struct nfs4_client *, int reason);
  46
  47#define NFSPROC4_CB_NULL 0
  48#define NFSPROC4_CB_COMPOUND 1
  49
  50/* Index of predefined Linux callback client operations */
  51
  52struct nfs4_cb_compound_hdr {
  53	/* args */
  54	u32		ident;	/* minorversion 0 only */
  55	u32		nops;
  56	__be32		*nops_p;
  57	u32		minorversion;
  58	/* res */
  59	int		status;
  60};
  61
  62/*
  63 * Handle decode buffer overflows out-of-line.
  64 */
  65static void print_overflow_msg(const char *func, const struct xdr_stream *xdr)
  66{
  67	dprintk("NFS: %s prematurely hit the end of our receive buffer. "
  68		"Remaining buffer length is %tu words.\n",
  69		func, xdr->end - xdr->p);
  70}
  71
  72static __be32 *xdr_encode_empty_array(__be32 *p)
  73{
  74	*p++ = xdr_zero;
  75	return p;
  76}
  77
  78/*
  79 * Encode/decode NFSv4 CB basic data types
  80 *
  81 * Basic NFSv4 callback data types are defined in section 15 of RFC
  82 * 3530: "Network File System (NFS) version 4 Protocol" and section
  83 * 20 of RFC 5661: "Network File System (NFS) Version 4 Minor Version
  84 * 1 Protocol"
  85 */
  86
  87/*
  88 *	nfs_cb_opnum4
  89 *
  90 *	enum nfs_cb_opnum4 {
  91 *		OP_CB_GETATTR		= 3,
  92 *		  ...
  93 *	};
  94 */
  95enum nfs_cb_opnum4 {
  96	OP_CB_GETATTR			= 3,
  97	OP_CB_RECALL			= 4,
  98	OP_CB_LAYOUTRECALL		= 5,
  99	OP_CB_NOTIFY			= 6,
 100	OP_CB_PUSH_DELEG		= 7,
 101	OP_CB_RECALL_ANY		= 8,
 102	OP_CB_RECALLABLE_OBJ_AVAIL	= 9,
 103	OP_CB_RECALL_SLOT		= 10,
 104	OP_CB_SEQUENCE			= 11,
 105	OP_CB_WANTS_CANCELLED		= 12,
 106	OP_CB_NOTIFY_LOCK		= 13,
 107	OP_CB_NOTIFY_DEVICEID		= 14,
 108	OP_CB_ILLEGAL			= 10044
 109};
 
 110
 111static void encode_nfs_cb_opnum4(struct xdr_stream *xdr, enum nfs_cb_opnum4 op)
 112{
 113	__be32 *p;
 114
 115	p = xdr_reserve_space(xdr, 4);
 116	*p = cpu_to_be32(op);
 117}
 118
 119/*
 120 * nfs_fh4
 121 *
 122 *	typedef opaque nfs_fh4<NFS4_FHSIZE>;
 123 */
 124static void encode_nfs_fh4(struct xdr_stream *xdr, const struct knfsd_fh *fh)
 125{
 126	u32 length = fh->fh_size;
 127	__be32 *p;
 128
 129	BUG_ON(length > NFS4_FHSIZE);
 130	p = xdr_reserve_space(xdr, 4 + length);
 131	xdr_encode_opaque(p, &fh->fh_base, length);
 132}
 133
 134/*
 135 * stateid4
 136 *
 137 *	struct stateid4 {
 138 *		uint32_t	seqid;
 139 *		opaque		other[12];
 140 *	};
 141 */
 142static void encode_stateid4(struct xdr_stream *xdr, const stateid_t *sid)
 143{
 144	__be32 *p;
 145
 146	p = xdr_reserve_space(xdr, NFS4_STATEID_SIZE);
 147	*p++ = cpu_to_be32(sid->si_generation);
 148	xdr_encode_opaque_fixed(p, &sid->si_opaque, NFS4_STATEID_OTHER_SIZE);
 149}
 150
 151/*
 152 * sessionid4
 153 *
 154 *	typedef opaque sessionid4[NFS4_SESSIONID_SIZE];
 155 */
 156static void encode_sessionid4(struct xdr_stream *xdr,
 157			      const struct nfsd4_session *session)
 158{
 159	__be32 *p;
 160
 161	p = xdr_reserve_space(xdr, NFS4_MAX_SESSIONID_LEN);
 162	xdr_encode_opaque_fixed(p, session->se_sessionid.data,
 163					NFS4_MAX_SESSIONID_LEN);
 164}
 165
 166/*
 167 * nfsstat4
 168 */
 169static const struct {
 170	int stat;
 171	int errno;
 172} nfs_cb_errtbl[] = {
 173	{ NFS4_OK,		0		},
 174	{ NFS4ERR_PERM,		-EPERM		},
 175	{ NFS4ERR_NOENT,	-ENOENT		},
 176	{ NFS4ERR_IO,		-EIO		},
 177	{ NFS4ERR_NXIO,		-ENXIO		},
 178	{ NFS4ERR_ACCESS,	-EACCES		},
 179	{ NFS4ERR_EXIST,	-EEXIST		},
 180	{ NFS4ERR_XDEV,		-EXDEV		},
 181	{ NFS4ERR_NOTDIR,	-ENOTDIR	},
 182	{ NFS4ERR_ISDIR,	-EISDIR		},
 183	{ NFS4ERR_INVAL,	-EINVAL		},
 184	{ NFS4ERR_FBIG,		-EFBIG		},
 185	{ NFS4ERR_NOSPC,	-ENOSPC		},
 186	{ NFS4ERR_ROFS,		-EROFS		},
 187	{ NFS4ERR_MLINK,	-EMLINK		},
 188	{ NFS4ERR_NAMETOOLONG,	-ENAMETOOLONG	},
 189	{ NFS4ERR_NOTEMPTY,	-ENOTEMPTY	},
 190	{ NFS4ERR_DQUOT,	-EDQUOT		},
 191	{ NFS4ERR_STALE,	-ESTALE		},
 192	{ NFS4ERR_BADHANDLE,	-EBADHANDLE	},
 193	{ NFS4ERR_BAD_COOKIE,	-EBADCOOKIE	},
 194	{ NFS4ERR_NOTSUPP,	-ENOTSUPP	},
 195	{ NFS4ERR_TOOSMALL,	-ETOOSMALL	},
 196	{ NFS4ERR_SERVERFAULT,	-ESERVERFAULT	},
 197	{ NFS4ERR_BADTYPE,	-EBADTYPE	},
 198	{ NFS4ERR_LOCKED,	-EAGAIN		},
 199	{ NFS4ERR_RESOURCE,	-EREMOTEIO	},
 200	{ NFS4ERR_SYMLINK,	-ELOOP		},
 201	{ NFS4ERR_OP_ILLEGAL,	-EOPNOTSUPP	},
 202	{ NFS4ERR_DEADLOCK,	-EDEADLK	},
 203	{ -1,			-EIO		}
 204};
 205
 206/*
 207 * If we cannot translate the error, the recovery routines should
 208 * handle it.
 209 *
 210 * Note: remaining NFSv4 error codes have values > 10000, so should
 211 * not conflict with native Linux error codes.
 212 */
 213static int nfs_cb_stat_to_errno(int status)
 214{
 215	int i;
 216
 217	for (i = 0; nfs_cb_errtbl[i].stat != -1; i++) {
 218		if (nfs_cb_errtbl[i].stat == status)
 219			return nfs_cb_errtbl[i].errno;
 220	}
 221
 222	dprintk("NFSD: Unrecognized NFS CB status value: %u\n", status);
 223	return -status;
 224}
 225
 226static int decode_cb_op_status(struct xdr_stream *xdr, enum nfs_opnum4 expected,
 227			       int *status)
 228{
 229	__be32 *p;
 230	u32 op;
 231
 232	p = xdr_inline_decode(xdr, 4 + 4);
 233	if (unlikely(p == NULL))
 234		goto out_overflow;
 235	op = be32_to_cpup(p++);
 236	if (unlikely(op != expected))
 237		goto out_unexpected;
 238	*status = nfs_cb_stat_to_errno(be32_to_cpup(p));
 239	return 0;
 240out_overflow:
 241	print_overflow_msg(__func__, xdr);
 242	return -EIO;
 243out_unexpected:
 244	dprintk("NFSD: Callback server returned operation %d but "
 245		"we issued a request for %d\n", op, expected);
 246	return -EIO;
 247}
 248
 249/*
 250 * CB_COMPOUND4args
 251 *
 252 *	struct CB_COMPOUND4args {
 253 *		utf8str_cs	tag;
 254 *		uint32_t	minorversion;
 255 *		uint32_t	callback_ident;
 256 *		nfs_cb_argop4	argarray<>;
 257 *	};
 258*/
 259static void encode_cb_compound4args(struct xdr_stream *xdr,
 260				    struct nfs4_cb_compound_hdr *hdr)
 261{
 262	__be32 * p;
 263
 264	p = xdr_reserve_space(xdr, 4 + 4 + 4 + 4);
 265	p = xdr_encode_empty_array(p);		/* empty tag */
 266	*p++ = cpu_to_be32(hdr->minorversion);
 267	*p++ = cpu_to_be32(hdr->ident);
 268
 269	hdr->nops_p = p;
 270	*p = cpu_to_be32(hdr->nops);		/* argarray element count */
 271}
 272
 273/*
 274 * Update argarray element count
 275 */
 276static void encode_cb_nops(struct nfs4_cb_compound_hdr *hdr)
 277{
 278	BUG_ON(hdr->nops > NFS4_MAX_BACK_CHANNEL_OPS);
 279	*hdr->nops_p = cpu_to_be32(hdr->nops);
 280}
 281
 282/*
 283 * CB_COMPOUND4res
 284 *
 285 *	struct CB_COMPOUND4res {
 286 *		nfsstat4	status;
 287 *		utf8str_cs	tag;
 288 *		nfs_cb_resop4	resarray<>;
 289 *	};
 290 */
 291static int decode_cb_compound4res(struct xdr_stream *xdr,
 292				  struct nfs4_cb_compound_hdr *hdr)
 293{
 294	u32 length;
 295	__be32 *p;
 296
 297	p = xdr_inline_decode(xdr, 4 + 4);
 298	if (unlikely(p == NULL))
 299		goto out_overflow;
 300	hdr->status = be32_to_cpup(p++);
 301	/* Ignore the tag */
 302	length = be32_to_cpup(p++);
 303	p = xdr_inline_decode(xdr, length + 4);
 304	if (unlikely(p == NULL))
 
 
 305		goto out_overflow;
 306	hdr->nops = be32_to_cpup(p);
 307	return 0;
 308out_overflow:
 309	print_overflow_msg(__func__, xdr);
 310	return -EIO;
 311}
 312
 313/*
 314 * CB_RECALL4args
 315 *
 316 *	struct CB_RECALL4args {
 317 *		stateid4	stateid;
 318 *		bool		truncate;
 319 *		nfs_fh4		fh;
 320 *	};
 321 */
 322static void encode_cb_recall4args(struct xdr_stream *xdr,
 323				  const struct nfs4_delegation *dp,
 324				  struct nfs4_cb_compound_hdr *hdr)
 325{
 326	__be32 *p;
 327
 328	encode_nfs_cb_opnum4(xdr, OP_CB_RECALL);
 329	encode_stateid4(xdr, &dp->dl_stid.sc_stateid);
 330
 331	p = xdr_reserve_space(xdr, 4);
 332	*p++ = xdr_zero;			/* truncate */
 333
 334	encode_nfs_fh4(xdr, &dp->dl_stid.sc_file->fi_fhandle);
 335
 336	hdr->nops++;
 337}
 338
 339/*
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 340 * CB_SEQUENCE4args
 341 *
 342 *	struct CB_SEQUENCE4args {
 343 *		sessionid4		csa_sessionid;
 344 *		sequenceid4		csa_sequenceid;
 345 *		slotid4			csa_slotid;
 346 *		slotid4			csa_highest_slotid;
 347 *		bool			csa_cachethis;
 348 *		referring_call_list4	csa_referring_call_lists<>;
 349 *	};
 350 */
 351static void encode_cb_sequence4args(struct xdr_stream *xdr,
 352				    const struct nfsd4_callback *cb,
 353				    struct nfs4_cb_compound_hdr *hdr)
 354{
 355	struct nfsd4_session *session = cb->cb_clp->cl_cb_session;
 356	__be32 *p;
 357
 358	if (hdr->minorversion == 0)
 359		return;
 360
 361	encode_nfs_cb_opnum4(xdr, OP_CB_SEQUENCE);
 362	encode_sessionid4(xdr, session);
 363
 364	p = xdr_reserve_space(xdr, 4 + 4 + 4 + 4 + 4);
 365	*p++ = cpu_to_be32(session->se_cb_seq_nr);	/* csa_sequenceid */
 366	*p++ = xdr_zero;			/* csa_slotid */
 367	*p++ = xdr_zero;			/* csa_highest_slotid */
 368	*p++ = xdr_zero;			/* csa_cachethis */
 369	xdr_encode_empty_array(p);		/* csa_referring_call_lists */
 370
 371	hdr->nops++;
 372}
 373
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 374/*
 375 * CB_SEQUENCE4resok
 376 *
 377 *	struct CB_SEQUENCE4resok {
 378 *		sessionid4	csr_sessionid;
 379 *		sequenceid4	csr_sequenceid;
 380 *		slotid4		csr_slotid;
 381 *		slotid4		csr_highest_slotid;
 382 *		slotid4		csr_target_highest_slotid;
 383 *	};
 384 *
 385 *	union CB_SEQUENCE4res switch (nfsstat4 csr_status) {
 386 *	case NFS4_OK:
 387 *		CB_SEQUENCE4resok	csr_resok4;
 388 *	default:
 389 *		void;
 390 *	};
 391 *
 392 * Our current back channel implmentation supports a single backchannel
 393 * with a single slot.
 394 */
 395static int decode_cb_sequence4resok(struct xdr_stream *xdr,
 396				    struct nfsd4_callback *cb)
 397{
 398	struct nfsd4_session *session = cb->cb_clp->cl_cb_session;
 399	struct nfs4_sessionid id;
 400	int status;
 401	__be32 *p;
 402	u32 dummy;
 403
 404	status = -ESERVERFAULT;
 405
 406	/*
 407	 * If the server returns different values for sessionID, slotID or
 408	 * sequence number, the server is looney tunes.
 409	 */
 410	p = xdr_inline_decode(xdr, NFS4_MAX_SESSIONID_LEN + 4 + 4 + 4 + 4);
 411	if (unlikely(p == NULL))
 412		goto out_overflow;
 413	memcpy(id.data, p, NFS4_MAX_SESSIONID_LEN);
 414	if (memcmp(id.data, session->se_sessionid.data,
 415					NFS4_MAX_SESSIONID_LEN) != 0) {
 416		dprintk("NFS: %s Invalid session id\n", __func__);
 417		goto out;
 418	}
 419	p += XDR_QUADLEN(NFS4_MAX_SESSIONID_LEN);
 420
 421	dummy = be32_to_cpup(p++);
 422	if (dummy != session->se_cb_seq_nr) {
 423		dprintk("NFS: %s Invalid sequence number\n", __func__);
 424		goto out;
 425	}
 426
 427	dummy = be32_to_cpup(p++);
 428	if (dummy != 0) {
 429		dprintk("NFS: %s Invalid slotid\n", __func__);
 430		goto out;
 431	}
 432
 433	/*
 434	 * FIXME: process highest slotid and target highest slotid
 435	 */
 
 436	status = 0;
 437out:
 438	cb->cb_seq_status = status;
 439	return status;
 440out_overflow:
 441	print_overflow_msg(__func__, xdr);
 442	status = -EIO;
 443	goto out;
 444}
 445
 446static int decode_cb_sequence4res(struct xdr_stream *xdr,
 447				  struct nfsd4_callback *cb)
 448{
 449	int status;
 450
 451	if (cb->cb_minorversion == 0)
 452		return 0;
 453
 454	status = decode_cb_op_status(xdr, OP_CB_SEQUENCE, &cb->cb_seq_status);
 455	if (unlikely(status || cb->cb_seq_status))
 456		return status;
 457
 458	return decode_cb_sequence4resok(xdr, cb);
 459}
 460
 461/*
 462 * NFSv4.0 and NFSv4.1 XDR encode functions
 463 *
 464 * NFSv4.0 callback argument types are defined in section 15 of RFC
 465 * 3530: "Network File System (NFS) version 4 Protocol" and section 20
 466 * of RFC 5661:  "Network File System (NFS) Version 4 Minor Version 1
 467 * Protocol".
 468 */
 469
 470/*
 471 * NB: Without this zero space reservation, callbacks over krb5p fail
 472 */
 473static void nfs4_xdr_enc_cb_null(struct rpc_rqst *req, struct xdr_stream *xdr,
 474				 void *__unused)
 475{
 476	xdr_reserve_space(xdr, 0);
 477}
 478
 479/*
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 480 * 20.2. Operation 4: CB_RECALL - Recall a Delegation
 481 */
 482static void nfs4_xdr_enc_cb_recall(struct rpc_rqst *req, struct xdr_stream *xdr,
 483				   const struct nfsd4_callback *cb)
 484{
 
 485	const struct nfs4_delegation *dp = cb_to_delegation(cb);
 486	struct nfs4_cb_compound_hdr hdr = {
 487		.ident = cb->cb_clp->cl_cb_ident,
 488		.minorversion = cb->cb_minorversion,
 489	};
 490
 491	encode_cb_compound4args(xdr, &hdr);
 492	encode_cb_sequence4args(xdr, cb, &hdr);
 493	encode_cb_recall4args(xdr, dp, &hdr);
 494	encode_cb_nops(&hdr);
 495}
 496
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 497
 498/*
 499 * NFSv4.0 and NFSv4.1 XDR decode functions
 500 *
 501 * NFSv4.0 callback result types are defined in section 15 of RFC
 502 * 3530: "Network File System (NFS) version 4 Protocol" and section 20
 503 * of RFC 5661:  "Network File System (NFS) Version 4 Minor Version 1
 504 * Protocol".
 505 */
 506
 507static int nfs4_xdr_dec_cb_null(struct rpc_rqst *req, struct xdr_stream *xdr,
 508				void *__unused)
 509{
 510	return 0;
 511}
 512
 513/*
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 514 * 20.2. Operation 4: CB_RECALL - Recall a Delegation
 515 */
 516static int nfs4_xdr_dec_cb_recall(struct rpc_rqst *rqstp,
 517				  struct xdr_stream *xdr,
 518				  struct nfsd4_callback *cb)
 519{
 
 520	struct nfs4_cb_compound_hdr hdr;
 521	int status;
 522
 523	status = decode_cb_compound4res(xdr, &hdr);
 524	if (unlikely(status))
 525		return status;
 526
 527	if (cb != NULL) {
 528		status = decode_cb_sequence4res(xdr, cb);
 529		if (unlikely(status || cb->cb_seq_status))
 530			return status;
 531	}
 532
 533	return decode_cb_op_status(xdr, OP_CB_RECALL, &cb->cb_status);
 534}
 535
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 536#ifdef CONFIG_NFSD_PNFS
 537/*
 538 * CB_LAYOUTRECALL4args
 539 *
 540 *	struct layoutrecall_file4 {
 541 *		nfs_fh4         lor_fh;
 542 *		offset4         lor_offset;
 543 *		length4         lor_length;
 544 *		stateid4        lor_stateid;
 545 *	};
 546 *
 547 *	union layoutrecall4 switch(layoutrecall_type4 lor_recalltype) {
 548 *	case LAYOUTRECALL4_FILE:
 549 *		layoutrecall_file4 lor_layout;
 550 *	case LAYOUTRECALL4_FSID:
 551 *		fsid4              lor_fsid;
 552 *	case LAYOUTRECALL4_ALL:
 553 *		void;
 554 *	};
 555 *
 556 *	struct CB_LAYOUTRECALL4args {
 557 *		layouttype4             clora_type;
 558 *		layoutiomode4           clora_iomode;
 559 *		bool                    clora_changed;
 560 *		layoutrecall4           clora_recall;
 561 *	};
 562 */
 563static void encode_cb_layout4args(struct xdr_stream *xdr,
 564				  const struct nfs4_layout_stateid *ls,
 565				  struct nfs4_cb_compound_hdr *hdr)
 566{
 567	__be32 *p;
 568
 569	BUG_ON(hdr->minorversion == 0);
 570
 571	p = xdr_reserve_space(xdr, 5 * 4);
 572	*p++ = cpu_to_be32(OP_CB_LAYOUTRECALL);
 573	*p++ = cpu_to_be32(ls->ls_layout_type);
 574	*p++ = cpu_to_be32(IOMODE_ANY);
 575	*p++ = cpu_to_be32(1);
 576	*p = cpu_to_be32(RETURN_FILE);
 577
 578	encode_nfs_fh4(xdr, &ls->ls_stid.sc_file->fi_fhandle);
 579
 580	p = xdr_reserve_space(xdr, 2 * 8);
 581	p = xdr_encode_hyper(p, 0);
 582	xdr_encode_hyper(p, NFS4_MAX_UINT64);
 583
 584	encode_stateid4(xdr, &ls->ls_recall_sid);
 585
 586	hdr->nops++;
 587}
 588
 589static void nfs4_xdr_enc_cb_layout(struct rpc_rqst *req,
 590				   struct xdr_stream *xdr,
 591				   const struct nfsd4_callback *cb)
 592{
 
 593	const struct nfs4_layout_stateid *ls =
 594		container_of(cb, struct nfs4_layout_stateid, ls_recall);
 595	struct nfs4_cb_compound_hdr hdr = {
 596		.ident = 0,
 597		.minorversion = cb->cb_minorversion,
 598	};
 599
 600	encode_cb_compound4args(xdr, &hdr);
 601	encode_cb_sequence4args(xdr, cb, &hdr);
 602	encode_cb_layout4args(xdr, ls, &hdr);
 603	encode_cb_nops(&hdr);
 604}
 605
 606static int nfs4_xdr_dec_cb_layout(struct rpc_rqst *rqstp,
 607				  struct xdr_stream *xdr,
 608				  struct nfsd4_callback *cb)
 609{
 
 610	struct nfs4_cb_compound_hdr hdr;
 611	int status;
 612
 613	status = decode_cb_compound4res(xdr, &hdr);
 614	if (unlikely(status))
 615		return status;
 616
 617	if (cb) {
 618		status = decode_cb_sequence4res(xdr, cb);
 619		if (unlikely(status || cb->cb_seq_status))
 620			return status;
 621	}
 622	return decode_cb_op_status(xdr, OP_CB_LAYOUTRECALL, &cb->cb_status);
 623}
 624#endif /* CONFIG_NFSD_PNFS */
 625
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 626/*
 627 * RPC procedure tables
 628 */
 629#define PROC(proc, call, argtype, restype)				\
 630[NFSPROC4_CLNT_##proc] = {						\
 631	.p_proc    = NFSPROC4_CB_##call,				\
 632	.p_encode  = (kxdreproc_t)nfs4_xdr_enc_##argtype,		\
 633	.p_decode  = (kxdrdproc_t)nfs4_xdr_dec_##restype,		\
 634	.p_arglen  = NFS4_enc_##argtype##_sz,				\
 635	.p_replen  = NFS4_dec_##restype##_sz,				\
 636	.p_statidx = NFSPROC4_CB_##call,				\
 637	.p_name    = #proc,						\
 638}
 639
 640static struct rpc_procinfo nfs4_cb_procedures[] = {
 641	PROC(CB_NULL,	NULL,		cb_null,	cb_null),
 642	PROC(CB_RECALL,	COMPOUND,	cb_recall,	cb_recall),
 643#ifdef CONFIG_NFSD_PNFS
 644	PROC(CB_LAYOUT,	COMPOUND,	cb_layout,	cb_layout),
 645#endif
 
 
 
 
 646};
 647
 648static struct rpc_version nfs_cb_version4 = {
 
 649/*
 650 * Note on the callback rpc program version number: despite language in rfc
 651 * 5661 section 18.36.3 requiring servers to use 4 in this field, the
 652 * official xdr descriptions for both 4.0 and 4.1 specify version 1, and
 653 * in practice that appears to be what implementations use.  The section
 654 * 18.36.3 language is expected to be fixed in an erratum.
 655 */
 656	.number			= 1,
 657	.nrprocs		= ARRAY_SIZE(nfs4_cb_procedures),
 658	.procs			= nfs4_cb_procedures
 
 659};
 660
 661static const struct rpc_version *nfs_cb_version[] = {
 662	&nfs_cb_version4,
 663};
 664
 665static const struct rpc_program cb_program;
 666
 667static struct rpc_stat cb_stats = {
 668	.program		= &cb_program
 669};
 670
 671#define NFS4_CALLBACK 0x40000000
 672static const struct rpc_program cb_program = {
 673	.name			= "nfs4_cb",
 674	.number			= NFS4_CALLBACK,
 675	.nrvers			= ARRAY_SIZE(nfs_cb_version),
 676	.version		= nfs_cb_version,
 677	.stats			= &cb_stats,
 678	.pipe_dir_name		= "nfsd4_cb",
 679};
 680
 681static int max_cb_time(struct net *net)
 682{
 683	struct nfsd_net *nn = net_generic(net, nfsd_net_id);
 684	return max(nn->nfsd4_lease/10, (time_t)1) * HZ;
 
 
 
 
 
 
 
 
 
 685}
 686
 687static struct rpc_cred *callback_cred;
 
 
 
 
 
 
 688
 689int set_callback_cred(void)
 690{
 691	if (callback_cred)
 692		return 0;
 693	callback_cred = rpc_lookup_machine_cred("nfs");
 694	if (!callback_cred)
 695		return -ENOMEM;
 696	return 0;
 697}
 698
 699static struct rpc_cred *get_backchannel_cred(struct nfs4_client *clp, struct rpc_clnt *client, struct nfsd4_session *ses)
 700{
 701	if (clp->cl_minorversion == 0) {
 702		return get_rpccred(callback_cred);
 703	} else {
 704		struct rpc_auth *auth = client->cl_auth;
 705		struct auth_cred acred = {};
 706
 707		acred.uid = ses->se_cb_sec.uid;
 708		acred.gid = ses->se_cb_sec.gid;
 709		return auth->au_ops->lookup_cred(client->cl_auth, &acred, 0);
 710	}
 711}
 712
 713static struct rpc_clnt *create_backchannel_client(struct rpc_create_args *args)
 714{
 715	struct rpc_xprt *xprt;
 
 
 716
 717	if (args->protocol != XPRT_TRANSPORT_BC_TCP)
 718		return rpc_create(args);
 
 
 
 719
 720	xprt = args->bc_xprt->xpt_bc_xprt;
 721	if (xprt) {
 722		xprt_get(xprt);
 723		return rpc_create_xprt(args, xprt);
 724	}
 725
 726	return rpc_create(args);
 
 
 
 
 
 
 
 727}
 728
 729static int setup_callback_client(struct nfs4_client *clp, struct nfs4_cb_conn *conn, struct nfsd4_session *ses)
 730{
 731	int maxtime = max_cb_time(clp->net);
 732	struct rpc_timeout	timeparms = {
 733		.to_initval	= maxtime,
 734		.to_retries	= 0,
 735		.to_maxval	= maxtime,
 736	};
 737	struct rpc_create_args args = {
 738		.net		= clp->net,
 739		.address	= (struct sockaddr *) &conn->cb_addr,
 740		.addrsize	= conn->cb_addrlen,
 741		.saddress	= (struct sockaddr *) &conn->cb_saddr,
 742		.timeout	= &timeparms,
 743		.program	= &cb_program,
 744		.version	= 0,
 745		.flags		= (RPC_CLNT_CREATE_NOPING | RPC_CLNT_CREATE_QUIET),
 
 746	};
 747	struct rpc_clnt *client;
 748	struct rpc_cred *cred;
 749
 750	if (clp->cl_minorversion == 0) {
 751		if (!clp->cl_cred.cr_principal &&
 752				(clp->cl_cred.cr_flavor >= RPC_AUTH_GSS_KRB5))
 
 753			return -EINVAL;
 
 754		args.client_name = clp->cl_cred.cr_principal;
 755		args.prognumber	= conn->cb_prog;
 756		args.protocol = XPRT_TRANSPORT_TCP;
 757		args.authflavor = clp->cl_cred.cr_flavor;
 758		clp->cl_cb_ident = conn->cb_ident;
 759	} else {
 760		if (!conn->cb_xprt)
 761			return -EINVAL;
 762		clp->cl_cb_conn.cb_xprt = conn->cb_xprt;
 763		clp->cl_cb_session = ses;
 764		args.bc_xprt = conn->cb_xprt;
 765		args.prognumber = clp->cl_cb_session->se_cb_prog;
 766		args.protocol = conn->cb_xprt->xpt_class->xcl_ident |
 767				XPRT_TRANSPORT_BC;
 768		args.authflavor = ses->se_cb_sec.flavor;
 769	}
 770	/* Create RPC client */
 771	client = create_backchannel_client(&args);
 772	if (IS_ERR(client)) {
 773		dprintk("NFSD: couldn't create callback client: %ld\n",
 774			PTR_ERR(client));
 775		return PTR_ERR(client);
 776	}
 777	cred = get_backchannel_cred(clp, client, ses);
 778	if (IS_ERR(cred)) {
 
 779		rpc_shutdown_client(client);
 780		return PTR_ERR(cred);
 781	}
 
 
 
 782	clp->cl_cb_client = client;
 783	clp->cl_cb_cred = cred;
 
 
 
 
 784	return 0;
 785}
 786
 787static void warn_no_callback_path(struct nfs4_client *clp, int reason)
 788{
 789	dprintk("NFSD: warning: no callback path to client %.*s: error %d\n",
 790		(int)clp->cl_name.len, clp->cl_name.data, reason);
 
 
 791}
 792
 793static void nfsd4_mark_cb_down(struct nfs4_client *clp, int reason)
 794{
 795	if (test_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags))
 796		return;
 797	clp->cl_cb_state = NFSD4_CB_DOWN;
 798	warn_no_callback_path(clp, reason);
 799}
 800
 801static void nfsd4_mark_cb_fault(struct nfs4_client *clp, int reason)
 802{
 803	if (test_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags))
 804		return;
 805	clp->cl_cb_state = NFSD4_CB_FAULT;
 806	warn_no_callback_path(clp, reason);
 807}
 808
 809static void nfsd4_cb_probe_done(struct rpc_task *task, void *calldata)
 810{
 811	struct nfs4_client *clp = container_of(calldata, struct nfs4_client, cl_cb_null);
 812
 813	if (task->tk_status)
 814		nfsd4_mark_cb_down(clp, task->tk_status);
 815	else
 816		clp->cl_cb_state = NFSD4_CB_UP;
 
 
 
 
 
 
 
 
 817}
 818
 819static const struct rpc_call_ops nfsd4_cb_probe_ops = {
 820	/* XXX: release method to ensure we set the cb channel down if
 821	 * necessary on early failure? */
 822	.rpc_call_done = nfsd4_cb_probe_done,
 
 823};
 824
 825static struct workqueue_struct *callback_wq;
 826
 827/*
 828 * Poke the callback thread to process any updates to the callback
 829 * parameters, and send a null probe.
 830 */
 831void nfsd4_probe_callback(struct nfs4_client *clp)
 832{
 833	clp->cl_cb_state = NFSD4_CB_UNKNOWN;
 
 834	set_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags);
 835	nfsd4_run_cb(&clp->cl_cb_null);
 836}
 837
 838void nfsd4_probe_callback_sync(struct nfs4_client *clp)
 839{
 840	nfsd4_probe_callback(clp);
 841	flush_workqueue(callback_wq);
 842}
 843
 844void nfsd4_change_callback(struct nfs4_client *clp, struct nfs4_cb_conn *conn)
 845{
 846	clp->cl_cb_state = NFSD4_CB_UNKNOWN;
 847	spin_lock(&clp->cl_lock);
 848	memcpy(&clp->cl_cb_conn, conn, sizeof(struct nfs4_cb_conn));
 849	spin_unlock(&clp->cl_lock);
 850}
 851
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 852/*
 853 * There's currently a single callback channel slot.
 854 * If the slot is available, then mark it busy.  Otherwise, set the
 855 * thread for sleeping on the callback RPC wait queue.
 856 */
 857static bool nfsd41_cb_get_slot(struct nfs4_client *clp, struct rpc_task *task)
 858{
 859	if (test_and_set_bit(0, &clp->cl_cb_slot_busy) != 0) {
 
 
 
 
 
 
 860		rpc_sleep_on(&clp->cl_cb_waitq, task, NULL);
 861		/* Race breaker */
 862		if (test_and_set_bit(0, &clp->cl_cb_slot_busy) != 0) {
 863			dprintk("%s slot is busy\n", __func__);
 864			return false;
 865		}
 866		rpc_wake_up_queued_task(&clp->cl_cb_waitq, task);
 867	}
 868	return true;
 869}
 870
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 871/*
 872 * TODO: cb_sequence should support referring call lists, cachethis, multiple
 873 * slots, and mark callback channel down on communication errors.
 874 */
 875static void nfsd4_cb_prepare(struct rpc_task *task, void *calldata)
 876{
 877	struct nfsd4_callback *cb = calldata;
 878	struct nfs4_client *clp = cb->cb_clp;
 879	u32 minorversion = clp->cl_minorversion;
 880
 881	cb->cb_minorversion = minorversion;
 882	/*
 883	 * cb_seq_status is only set in decode_cb_sequence4res,
 884	 * and so will remain 1 if an rpc level failure occurs.
 885	 */
 
 886	cb->cb_seq_status = 1;
 887	cb->cb_status = 0;
 888	if (minorversion) {
 889		if (!nfsd41_cb_get_slot(clp, task))
 890			return;
 891	}
 892	rpc_call_start(task);
 893}
 894
 895static bool nfsd4_cb_sequence_done(struct rpc_task *task, struct nfsd4_callback *cb)
 896{
 897	struct nfs4_client *clp = cb->cb_clp;
 898	struct nfsd4_session *session = clp->cl_cb_session;
 899	bool ret = true;
 900
 901	if (!clp->cl_minorversion) {
 902		/*
 903		 * If the backchannel connection was shut down while this
 904		 * task was queued, we need to resubmit it after setting up
 905		 * a new backchannel connection.
 906		 *
 907		 * Note that if we lost our callback connection permanently
 908		 * the submission code will error out, so we don't need to
 909		 * handle that case here.
 910		 */
 911		if (task->tk_flags & RPC_TASK_KILLED)
 912			goto need_restart;
 913
 914		return true;
 915	}
 916
 
 
 
 
 
 917	switch (cb->cb_seq_status) {
 918	case 0:
 919		/*
 920		 * No need for lock, access serialized in nfsd4_cb_prepare
 921		 *
 922		 * RFC5661 20.9.3
 923		 * If CB_SEQUENCE returns an error, then the state of the slot
 924		 * (sequence ID, cached reply) MUST NOT change.
 925		 */
 926		++session->se_cb_seq_nr;
 927		break;
 928	case -ESERVERFAULT:
 929		++session->se_cb_seq_nr;
 
 
 
 930	case 1:
 
 
 
 
 
 
 
 931	case -NFS4ERR_BADSESSION:
 932		nfsd4_mark_cb_fault(cb->cb_clp, cb->cb_seq_status);
 933		ret = false;
 934		break;
 935	case -NFS4ERR_DELAY:
 
 936		if (!rpc_restart_call(task))
 937			goto out;
 938
 939		rpc_delay(task, 2 * HZ);
 940		return false;
 941	case -NFS4ERR_BADSLOT:
 942		goto retry_nowait;
 943	case -NFS4ERR_SEQ_MISORDERED:
 944		if (session->se_cb_seq_nr != 1) {
 945			session->se_cb_seq_nr = 1;
 946			goto retry_nowait;
 947		}
 948		break;
 949	default:
 950		dprintk("%s: unprocessed error %d\n", __func__,
 951			cb->cb_seq_status);
 952	}
 
 
 953
 954	clear_bit(0, &clp->cl_cb_slot_busy);
 955	rpc_wake_up_next(&clp->cl_cb_waitq);
 956	dprintk("%s: freed slot, new seqid=%d\n", __func__,
 957		clp->cl_cb_session->se_cb_seq_nr);
 958
 959	if (task->tk_flags & RPC_TASK_KILLED)
 960		goto need_restart;
 961out:
 962	return ret;
 963retry_nowait:
 964	if (rpc_restart_call_prepare(task))
 965		ret = false;
 966	goto out;
 967need_restart:
 968	task->tk_status = 0;
 969	cb->cb_need_restart = true;
 
 
 
 970	return false;
 971}
 972
 973static void nfsd4_cb_done(struct rpc_task *task, void *calldata)
 974{
 975	struct nfsd4_callback *cb = calldata;
 976	struct nfs4_client *clp = cb->cb_clp;
 977
 978	dprintk("%s: minorversion=%d\n", __func__,
 979		clp->cl_minorversion);
 980
 981	if (!nfsd4_cb_sequence_done(task, cb))
 982		return;
 983
 984	if (cb->cb_status) {
 985		WARN_ON_ONCE(task->tk_status);
 
 986		task->tk_status = cb->cb_status;
 987	}
 988
 989	switch (cb->cb_ops->done(cb, task)) {
 990	case 0:
 991		task->tk_status = 0;
 992		rpc_restart_call_prepare(task);
 993		return;
 994	case 1:
 995		break;
 996	case -1:
 997		/* Network partition? */
 998		nfsd4_mark_cb_down(clp, task->tk_status);
 
 
 999		break;
1000	default:
1001		BUG();
1002	}
1003}
1004
1005static void nfsd4_cb_release(void *calldata)
1006{
1007	struct nfsd4_callback *cb = calldata;
1008
 
 
1009	if (cb->cb_need_restart)
1010		nfsd4_run_cb(cb);
1011	else
1012		cb->cb_ops->release(cb);
1013
1014}
1015
1016static const struct rpc_call_ops nfsd4_cb_ops = {
1017	.rpc_call_prepare = nfsd4_cb_prepare,
1018	.rpc_call_done = nfsd4_cb_done,
1019	.rpc_release = nfsd4_cb_release,
1020};
1021
1022int nfsd4_create_callback_queue(void)
1023{
1024	callback_wq = create_singlethread_workqueue("nfsd4_callbacks");
1025	if (!callback_wq)
1026		return -ENOMEM;
1027	return 0;
1028}
1029
1030void nfsd4_destroy_callback_queue(void)
1031{
1032	destroy_workqueue(callback_wq);
1033}
1034
1035/* must be called under the state lock */
1036void nfsd4_shutdown_callback(struct nfs4_client *clp)
1037{
 
 
 
1038	set_bit(NFSD4_CLIENT_CB_KILL, &clp->cl_flags);
1039	/*
1040	 * Note this won't actually result in a null callback;
1041	 * instead, nfsd4_run_cb_null() will detect the killed
1042	 * client, destroy the rpc client, and stop:
1043	 */
1044	nfsd4_run_cb(&clp->cl_cb_null);
1045	flush_workqueue(callback_wq);
 
1046}
1047
1048/* requires cl_lock: */
1049static struct nfsd4_conn * __nfsd4_find_backchannel(struct nfs4_client *clp)
1050{
1051	struct nfsd4_session *s;
1052	struct nfsd4_conn *c;
1053
 
 
1054	list_for_each_entry(s, &clp->cl_sessions, se_perclnt) {
1055		list_for_each_entry(c, &s->se_conns, cn_persession) {
1056			if (c->cn_flags & NFS4_CDFC4_BACK)
1057				return c;
1058		}
1059	}
1060	return NULL;
1061}
1062
 
 
 
 
 
 
1063static void nfsd4_process_cb_update(struct nfsd4_callback *cb)
1064{
1065	struct nfs4_cb_conn conn;
1066	struct nfs4_client *clp = cb->cb_clp;
1067	struct nfsd4_session *ses = NULL;
1068	struct nfsd4_conn *c;
1069	int err;
1070
 
 
1071	/*
1072	 * This is either an update, or the client dying; in either case,
1073	 * kill the old client:
1074	 */
1075	if (clp->cl_cb_client) {
 
1076		rpc_shutdown_client(clp->cl_cb_client);
1077		clp->cl_cb_client = NULL;
1078		put_rpccred(clp->cl_cb_cred);
1079		clp->cl_cb_cred = NULL;
1080	}
1081	if (clp->cl_cb_conn.cb_xprt) {
1082		svc_xprt_put(clp->cl_cb_conn.cb_xprt);
1083		clp->cl_cb_conn.cb_xprt = NULL;
1084	}
1085	if (test_bit(NFSD4_CLIENT_CB_KILL, &clp->cl_flags))
1086		return;
 
1087	spin_lock(&clp->cl_lock);
1088	/*
1089	 * Only serialized callback code is allowed to clear these
1090	 * flags; main nfsd code can only set them:
1091	 */
1092	BUG_ON(!(clp->cl_flags & NFSD4_CLIENT_CB_FLAG_MASK));
1093	clear_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags);
 
1094	memcpy(&conn, &cb->cb_clp->cl_cb_conn, sizeof(struct nfs4_cb_conn));
1095	c = __nfsd4_find_backchannel(clp);
1096	if (c) {
1097		svc_xprt_get(c->cn_xprt);
1098		conn.cb_xprt = c->cn_xprt;
1099		ses = c->cn_session;
1100	}
1101	spin_unlock(&clp->cl_lock);
1102
1103	err = setup_callback_client(clp, &conn, ses);
1104	if (err) {
1105		nfsd4_mark_cb_down(clp, err);
 
 
1106		return;
1107	}
1108}
1109
1110static void
1111nfsd4_run_cb_work(struct work_struct *work)
1112{
1113	struct nfsd4_callback *cb =
1114		container_of(work, struct nfsd4_callback, cb_work);
1115	struct nfs4_client *clp = cb->cb_clp;
1116	struct rpc_clnt *clnt;
 
1117
1118	if (cb->cb_need_restart) {
1119		cb->cb_need_restart = false;
1120	} else {
1121		if (cb->cb_ops && cb->cb_ops->prepare)
1122			cb->cb_ops->prepare(cb);
1123	}
1124
1125	if (clp->cl_flags & NFSD4_CLIENT_CB_FLAG_MASK)
1126		nfsd4_process_cb_update(cb);
1127
1128	clnt = clp->cl_cb_client;
1129	if (!clnt) {
1130		/* Callback channel broken, or client killed; give up: */
1131		if (cb->cb_ops && cb->cb_ops->release)
1132			cb->cb_ops->release(cb);
 
 
1133		return;
1134	}
1135
1136	/*
1137	 * Don't send probe messages for 4.1 or later.
1138	 */
1139	if (!cb->cb_ops && clp->cl_minorversion) {
1140		clp->cl_cb_state = NFSD4_CB_UP;
 
1141		return;
1142	}
1143
 
 
 
 
 
 
1144	cb->cb_msg.rpc_cred = clp->cl_cb_cred;
1145	rpc_call_async(clnt, &cb->cb_msg, RPC_TASK_SOFT | RPC_TASK_SOFTCONN,
 
1146			cb->cb_ops ? &nfsd4_cb_ops : &nfsd4_cb_probe_ops, cb);
1147}
1148
1149void nfsd4_init_cb(struct nfsd4_callback *cb, struct nfs4_client *clp,
1150		const struct nfsd4_callback_ops *ops, enum nfsd4_cb_op op)
1151{
1152	cb->cb_clp = clp;
1153	cb->cb_msg.rpc_proc = &nfs4_cb_procedures[op];
1154	cb->cb_msg.rpc_argp = cb;
1155	cb->cb_msg.rpc_resp = cb;
1156	cb->cb_ops = ops;
1157	INIT_WORK(&cb->cb_work, nfsd4_run_cb_work);
1158	cb->cb_seq_status = 1;
1159	cb->cb_status = 0;
1160	cb->cb_need_restart = false;
 
1161}
1162
1163void nfsd4_run_cb(struct nfsd4_callback *cb)
 
 
 
 
 
 
 
1164{
1165	queue_work(callback_wq, &cb->cb_work);
 
 
 
 
 
 
 
1166}
v6.13.7
   1/*
   2 *  Copyright (c) 2001 The Regents of the University of Michigan.
   3 *  All rights reserved.
   4 *
   5 *  Kendrick Smith <kmsmith@umich.edu>
   6 *  Andy Adamson <andros@umich.edu>
   7 *
   8 *  Redistribution and use in source and binary forms, with or without
   9 *  modification, are permitted provided that the following conditions
  10 *  are met:
  11 *
  12 *  1. Redistributions of source code must retain the above copyright
  13 *     notice, this list of conditions and the following disclaimer.
  14 *  2. Redistributions in binary form must reproduce the above copyright
  15 *     notice, this list of conditions and the following disclaimer in the
  16 *     documentation and/or other materials provided with the distribution.
  17 *  3. Neither the name of the University nor the names of its
  18 *     contributors may be used to endorse or promote products derived
  19 *     from this software without specific prior written permission.
  20 *
  21 *  THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
  22 *  WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
  23 *  MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  24 *  DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
  25 *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
  26 *  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
  27 *  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
  28 *  BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
  29 *  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
  30 *  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  31 *  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  32 */
  33
  34#include <linux/nfs4.h>
  35#include <linux/sunrpc/clnt.h>
  36#include <linux/sunrpc/xprt.h>
  37#include <linux/sunrpc/svc_xprt.h>
  38#include <linux/slab.h>
  39#include "nfsd.h"
  40#include "state.h"
  41#include "netns.h"
  42#include "trace.h"
  43#include "xdr4cb.h"
  44#include "xdr4.h"
  45
  46#define NFSDDBG_FACILITY                NFSDDBG_PROC
  47
  48static void nfsd4_mark_cb_fault(struct nfs4_client *clp);
  49
  50#define NFSPROC4_CB_NULL 0
  51#define NFSPROC4_CB_COMPOUND 1
  52
  53/* Index of predefined Linux callback client operations */
  54
  55struct nfs4_cb_compound_hdr {
  56	/* args */
  57	u32		ident;	/* minorversion 0 only */
  58	u32		nops;
  59	__be32		*nops_p;
  60	u32		minorversion;
  61	/* res */
  62	int		status;
  63};
  64
 
 
 
 
 
 
 
 
 
 
  65static __be32 *xdr_encode_empty_array(__be32 *p)
  66{
  67	*p++ = xdr_zero;
  68	return p;
  69}
  70
  71/*
  72 * Encode/decode NFSv4 CB basic data types
  73 *
  74 * Basic NFSv4 callback data types are defined in section 15 of RFC
  75 * 3530: "Network File System (NFS) version 4 Protocol" and section
  76 * 20 of RFC 5661: "Network File System (NFS) Version 4 Minor Version
  77 * 1 Protocol"
  78 */
  79
  80static void encode_uint32(struct xdr_stream *xdr, u32 n)
  81{
  82	WARN_ON_ONCE(xdr_stream_encode_u32(xdr, n) < 0);
  83}
  84
  85static void encode_bitmap4(struct xdr_stream *xdr, const __u32 *bitmap,
  86			   size_t len)
  87{
  88	xdr_stream_encode_uint32_array(xdr, bitmap, len);
  89}
  90
  91static int decode_cb_fattr4(struct xdr_stream *xdr, uint32_t *bitmap,
  92				struct nfs4_cb_fattr *fattr)
  93{
  94	fattr->ncf_cb_change = 0;
  95	fattr->ncf_cb_fsize = 0;
  96	if (bitmap[0] & FATTR4_WORD0_CHANGE)
  97		if (xdr_stream_decode_u64(xdr, &fattr->ncf_cb_change) < 0)
  98			return -NFSERR_BAD_XDR;
  99	if (bitmap[0] & FATTR4_WORD0_SIZE)
 100		if (xdr_stream_decode_u64(xdr, &fattr->ncf_cb_fsize) < 0)
 101			return -NFSERR_BAD_XDR;
 102	return 0;
 103}
 104
 105static void encode_nfs_cb_opnum4(struct xdr_stream *xdr, enum nfs_cb_opnum4 op)
 106{
 107	__be32 *p;
 108
 109	p = xdr_reserve_space(xdr, 4);
 110	*p = cpu_to_be32(op);
 111}
 112
 113/*
 114 * nfs_fh4
 115 *
 116 *	typedef opaque nfs_fh4<NFS4_FHSIZE>;
 117 */
 118static void encode_nfs_fh4(struct xdr_stream *xdr, const struct knfsd_fh *fh)
 119{
 120	u32 length = fh->fh_size;
 121	__be32 *p;
 122
 123	BUG_ON(length > NFS4_FHSIZE);
 124	p = xdr_reserve_space(xdr, 4 + length);
 125	xdr_encode_opaque(p, &fh->fh_raw, length);
 126}
 127
 128/*
 129 * stateid4
 130 *
 131 *	struct stateid4 {
 132 *		uint32_t	seqid;
 133 *		opaque		other[12];
 134 *	};
 135 */
 136static void encode_stateid4(struct xdr_stream *xdr, const stateid_t *sid)
 137{
 138	__be32 *p;
 139
 140	p = xdr_reserve_space(xdr, NFS4_STATEID_SIZE);
 141	*p++ = cpu_to_be32(sid->si_generation);
 142	xdr_encode_opaque_fixed(p, &sid->si_opaque, NFS4_STATEID_OTHER_SIZE);
 143}
 144
 145/*
 146 * sessionid4
 147 *
 148 *	typedef opaque sessionid4[NFS4_SESSIONID_SIZE];
 149 */
 150static void encode_sessionid4(struct xdr_stream *xdr,
 151			      const struct nfsd4_session *session)
 152{
 153	__be32 *p;
 154
 155	p = xdr_reserve_space(xdr, NFS4_MAX_SESSIONID_LEN);
 156	xdr_encode_opaque_fixed(p, session->se_sessionid.data,
 157					NFS4_MAX_SESSIONID_LEN);
 158}
 159
 160/*
 161 * nfsstat4
 162 */
 163static const struct {
 164	int stat;
 165	int errno;
 166} nfs_cb_errtbl[] = {
 167	{ NFS4_OK,		0		},
 168	{ NFS4ERR_PERM,		-EPERM		},
 169	{ NFS4ERR_NOENT,	-ENOENT		},
 170	{ NFS4ERR_IO,		-EIO		},
 171	{ NFS4ERR_NXIO,		-ENXIO		},
 172	{ NFS4ERR_ACCESS,	-EACCES		},
 173	{ NFS4ERR_EXIST,	-EEXIST		},
 174	{ NFS4ERR_XDEV,		-EXDEV		},
 175	{ NFS4ERR_NOTDIR,	-ENOTDIR	},
 176	{ NFS4ERR_ISDIR,	-EISDIR		},
 177	{ NFS4ERR_INVAL,	-EINVAL		},
 178	{ NFS4ERR_FBIG,		-EFBIG		},
 179	{ NFS4ERR_NOSPC,	-ENOSPC		},
 180	{ NFS4ERR_ROFS,		-EROFS		},
 181	{ NFS4ERR_MLINK,	-EMLINK		},
 182	{ NFS4ERR_NAMETOOLONG,	-ENAMETOOLONG	},
 183	{ NFS4ERR_NOTEMPTY,	-ENOTEMPTY	},
 184	{ NFS4ERR_DQUOT,	-EDQUOT		},
 185	{ NFS4ERR_STALE,	-ESTALE		},
 186	{ NFS4ERR_BADHANDLE,	-EBADHANDLE	},
 187	{ NFS4ERR_BAD_COOKIE,	-EBADCOOKIE	},
 188	{ NFS4ERR_NOTSUPP,	-ENOTSUPP	},
 189	{ NFS4ERR_TOOSMALL,	-ETOOSMALL	},
 190	{ NFS4ERR_SERVERFAULT,	-ESERVERFAULT	},
 191	{ NFS4ERR_BADTYPE,	-EBADTYPE	},
 192	{ NFS4ERR_LOCKED,	-EAGAIN		},
 193	{ NFS4ERR_RESOURCE,	-EREMOTEIO	},
 194	{ NFS4ERR_SYMLINK,	-ELOOP		},
 195	{ NFS4ERR_OP_ILLEGAL,	-EOPNOTSUPP	},
 196	{ NFS4ERR_DEADLOCK,	-EDEADLK	},
 197	{ -1,			-EIO		}
 198};
 199
 200/*
 201 * If we cannot translate the error, the recovery routines should
 202 * handle it.
 203 *
 204 * Note: remaining NFSv4 error codes have values > 10000, so should
 205 * not conflict with native Linux error codes.
 206 */
 207static int nfs_cb_stat_to_errno(int status)
 208{
 209	int i;
 210
 211	for (i = 0; nfs_cb_errtbl[i].stat != -1; i++) {
 212		if (nfs_cb_errtbl[i].stat == status)
 213			return nfs_cb_errtbl[i].errno;
 214	}
 215
 216	dprintk("NFSD: Unrecognized NFS CB status value: %u\n", status);
 217	return -status;
 218}
 219
 220static int decode_cb_op_status(struct xdr_stream *xdr,
 221			       enum nfs_cb_opnum4 expected, int *status)
 222{
 223	__be32 *p;
 224	u32 op;
 225
 226	p = xdr_inline_decode(xdr, 4 + 4);
 227	if (unlikely(p == NULL))
 228		goto out_overflow;
 229	op = be32_to_cpup(p++);
 230	if (unlikely(op != expected))
 231		goto out_unexpected;
 232	*status = nfs_cb_stat_to_errno(be32_to_cpup(p));
 233	return 0;
 234out_overflow:
 
 235	return -EIO;
 236out_unexpected:
 237	dprintk("NFSD: Callback server returned operation %d but "
 238		"we issued a request for %d\n", op, expected);
 239	return -EIO;
 240}
 241
 242/*
 243 * CB_COMPOUND4args
 244 *
 245 *	struct CB_COMPOUND4args {
 246 *		utf8str_cs	tag;
 247 *		uint32_t	minorversion;
 248 *		uint32_t	callback_ident;
 249 *		nfs_cb_argop4	argarray<>;
 250 *	};
 251*/
 252static void encode_cb_compound4args(struct xdr_stream *xdr,
 253				    struct nfs4_cb_compound_hdr *hdr)
 254{
 255	__be32 * p;
 256
 257	p = xdr_reserve_space(xdr, 4 + 4 + 4 + 4);
 258	p = xdr_encode_empty_array(p);		/* empty tag */
 259	*p++ = cpu_to_be32(hdr->minorversion);
 260	*p++ = cpu_to_be32(hdr->ident);
 261
 262	hdr->nops_p = p;
 263	*p = cpu_to_be32(hdr->nops);		/* argarray element count */
 264}
 265
 266/*
 267 * Update argarray element count
 268 */
 269static void encode_cb_nops(struct nfs4_cb_compound_hdr *hdr)
 270{
 271	BUG_ON(hdr->nops > NFS4_MAX_BACK_CHANNEL_OPS);
 272	*hdr->nops_p = cpu_to_be32(hdr->nops);
 273}
 274
 275/*
 276 * CB_COMPOUND4res
 277 *
 278 *	struct CB_COMPOUND4res {
 279 *		nfsstat4	status;
 280 *		utf8str_cs	tag;
 281 *		nfs_cb_resop4	resarray<>;
 282 *	};
 283 */
 284static int decode_cb_compound4res(struct xdr_stream *xdr,
 285				  struct nfs4_cb_compound_hdr *hdr)
 286{
 287	u32 length;
 288	__be32 *p;
 289
 290	p = xdr_inline_decode(xdr, XDR_UNIT);
 291	if (unlikely(p == NULL))
 292		goto out_overflow;
 293	hdr->status = be32_to_cpup(p);
 294	/* Ignore the tag */
 295	if (xdr_stream_decode_u32(xdr, &length) < 0)
 296		goto out_overflow;
 297	if (xdr_inline_decode(xdr, length) == NULL)
 298		goto out_overflow;
 299	if (xdr_stream_decode_u32(xdr, &hdr->nops) < 0)
 300		goto out_overflow;
 
 301	return 0;
 302out_overflow:
 
 303	return -EIO;
 304}
 305
 306/*
 307 * CB_RECALL4args
 308 *
 309 *	struct CB_RECALL4args {
 310 *		stateid4	stateid;
 311 *		bool		truncate;
 312 *		nfs_fh4		fh;
 313 *	};
 314 */
 315static void encode_cb_recall4args(struct xdr_stream *xdr,
 316				  const struct nfs4_delegation *dp,
 317				  struct nfs4_cb_compound_hdr *hdr)
 318{
 319	__be32 *p;
 320
 321	encode_nfs_cb_opnum4(xdr, OP_CB_RECALL);
 322	encode_stateid4(xdr, &dp->dl_stid.sc_stateid);
 323
 324	p = xdr_reserve_space(xdr, 4);
 325	*p++ = xdr_zero;			/* truncate */
 326
 327	encode_nfs_fh4(xdr, &dp->dl_stid.sc_file->fi_fhandle);
 328
 329	hdr->nops++;
 330}
 331
 332/*
 333 * CB_RECALLANY4args
 334 *
 335 *	struct CB_RECALLANY4args {
 336 *		uint32_t	craa_objects_to_keep;
 337 *		bitmap4		craa_type_mask;
 338 *	};
 339 */
 340static void
 341encode_cb_recallany4args(struct xdr_stream *xdr,
 342	struct nfs4_cb_compound_hdr *hdr, struct nfsd4_cb_recall_any *ra)
 343{
 344	encode_nfs_cb_opnum4(xdr, OP_CB_RECALL_ANY);
 345	encode_uint32(xdr, ra->ra_keep);
 346	encode_bitmap4(xdr, ra->ra_bmval, ARRAY_SIZE(ra->ra_bmval));
 347	hdr->nops++;
 348}
 349
 350/*
 351 * CB_GETATTR4args
 352 *	struct CB_GETATTR4args {
 353 *	   nfs_fh4 fh;
 354 *	   bitmap4 attr_request;
 355 *	};
 356 *
 357 * The size and change attributes are the only one
 358 * guaranteed to be serviced by the client.
 359 */
 360static void
 361encode_cb_getattr4args(struct xdr_stream *xdr, struct nfs4_cb_compound_hdr *hdr,
 362			struct nfs4_cb_fattr *fattr)
 363{
 364	struct nfs4_delegation *dp =
 365		container_of(fattr, struct nfs4_delegation, dl_cb_fattr);
 366	struct knfsd_fh *fh = &dp->dl_stid.sc_file->fi_fhandle;
 367	u32 bmap[1];
 368
 369	bmap[0] = FATTR4_WORD0_CHANGE | FATTR4_WORD0_SIZE;
 370
 371	encode_nfs_cb_opnum4(xdr, OP_CB_GETATTR);
 372	encode_nfs_fh4(xdr, fh);
 373	encode_bitmap4(xdr, bmap, ARRAY_SIZE(bmap));
 374	hdr->nops++;
 375}
 376
 377static u32 highest_slotid(struct nfsd4_session *ses)
 378{
 379	u32 idx;
 380
 381	spin_lock(&ses->se_lock);
 382	idx = fls(~ses->se_cb_slot_avail);
 383	if (idx > 0)
 384		--idx;
 385	idx = max(idx, ses->se_cb_highest_slot);
 386	spin_unlock(&ses->se_lock);
 387	return idx;
 388}
 389
 390/*
 391 * CB_SEQUENCE4args
 392 *
 393 *	struct CB_SEQUENCE4args {
 394 *		sessionid4		csa_sessionid;
 395 *		sequenceid4		csa_sequenceid;
 396 *		slotid4			csa_slotid;
 397 *		slotid4			csa_highest_slotid;
 398 *		bool			csa_cachethis;
 399 *		referring_call_list4	csa_referring_call_lists<>;
 400 *	};
 401 */
 402static void encode_cb_sequence4args(struct xdr_stream *xdr,
 403				    const struct nfsd4_callback *cb,
 404				    struct nfs4_cb_compound_hdr *hdr)
 405{
 406	struct nfsd4_session *session = cb->cb_clp->cl_cb_session;
 407	__be32 *p;
 408
 409	if (hdr->minorversion == 0)
 410		return;
 411
 412	encode_nfs_cb_opnum4(xdr, OP_CB_SEQUENCE);
 413	encode_sessionid4(xdr, session);
 414
 415	p = xdr_reserve_space(xdr, 4 + 4 + 4 + 4 + 4);
 416	*p++ = cpu_to_be32(session->se_cb_seq_nr[cb->cb_held_slot]);	/* csa_sequenceid */
 417	*p++ = cpu_to_be32(cb->cb_held_slot);		/* csa_slotid */
 418	*p++ = cpu_to_be32(highest_slotid(session)); /* csa_highest_slotid */
 419	*p++ = xdr_zero;			/* csa_cachethis */
 420	xdr_encode_empty_array(p);		/* csa_referring_call_lists */
 421
 422	hdr->nops++;
 423}
 424
 425static void update_cb_slot_table(struct nfsd4_session *ses, u32 target)
 426{
 427	/* No need to do anything if nothing changed */
 428	if (likely(target == READ_ONCE(ses->se_cb_highest_slot)))
 429		return;
 430
 431	spin_lock(&ses->se_lock);
 432	if (target > ses->se_cb_highest_slot) {
 433		int i;
 434
 435		target = min(target, NFSD_BC_SLOT_TABLE_SIZE - 1);
 436
 437		/*
 438		 * Growing the slot table. Reset any new sequences to 1.
 439		 *
 440		 * NB: There is some debate about whether the RFC requires this,
 441		 *     but the Linux client expects it.
 442		 */
 443		for (i = ses->se_cb_highest_slot + 1; i <= target; ++i)
 444			ses->se_cb_seq_nr[i] = 1;
 445	}
 446	ses->se_cb_highest_slot = target;
 447	spin_unlock(&ses->se_lock);
 448}
 449
 450/*
 451 * CB_SEQUENCE4resok
 452 *
 453 *	struct CB_SEQUENCE4resok {
 454 *		sessionid4	csr_sessionid;
 455 *		sequenceid4	csr_sequenceid;
 456 *		slotid4		csr_slotid;
 457 *		slotid4		csr_highest_slotid;
 458 *		slotid4		csr_target_highest_slotid;
 459 *	};
 460 *
 461 *	union CB_SEQUENCE4res switch (nfsstat4 csr_status) {
 462 *	case NFS4_OK:
 463 *		CB_SEQUENCE4resok	csr_resok4;
 464 *	default:
 465 *		void;
 466 *	};
 467 *
 468 * Our current back channel implmentation supports a single backchannel
 469 * with a single slot.
 470 */
 471static int decode_cb_sequence4resok(struct xdr_stream *xdr,
 472				    struct nfsd4_callback *cb)
 473{
 474	struct nfsd4_session *session = cb->cb_clp->cl_cb_session;
 475	int status = -ESERVERFAULT;
 
 476	__be32 *p;
 477	u32 seqid, slotid, target;
 
 
 478
 479	/*
 480	 * If the server returns different values for sessionID, slotID or
 481	 * sequence number, the server is looney tunes.
 482	 */
 483	p = xdr_inline_decode(xdr, NFS4_MAX_SESSIONID_LEN + 4 + 4 + 4 + 4);
 484	if (unlikely(p == NULL))
 485		goto out_overflow;
 486
 487	if (memcmp(p, session->se_sessionid.data, NFS4_MAX_SESSIONID_LEN)) {
 
 488		dprintk("NFS: %s Invalid session id\n", __func__);
 489		goto out;
 490	}
 491	p += XDR_QUADLEN(NFS4_MAX_SESSIONID_LEN);
 492
 493	seqid = be32_to_cpup(p++);
 494	if (seqid != session->se_cb_seq_nr[cb->cb_held_slot]) {
 495		dprintk("NFS: %s Invalid sequence number\n", __func__);
 496		goto out;
 497	}
 498
 499	slotid = be32_to_cpup(p++);
 500	if (slotid != cb->cb_held_slot) {
 501		dprintk("NFS: %s Invalid slotid\n", __func__);
 502		goto out;
 503	}
 504
 505	p++; // ignore current highest slot value
 506
 507	target = be32_to_cpup(p++);
 508	update_cb_slot_table(session, target);
 509	status = 0;
 510out:
 511	cb->cb_seq_status = status;
 512	return status;
 513out_overflow:
 
 514	status = -EIO;
 515	goto out;
 516}
 517
 518static int decode_cb_sequence4res(struct xdr_stream *xdr,
 519				  struct nfsd4_callback *cb)
 520{
 521	int status;
 522
 523	if (cb->cb_clp->cl_minorversion == 0)
 524		return 0;
 525
 526	status = decode_cb_op_status(xdr, OP_CB_SEQUENCE, &cb->cb_seq_status);
 527	if (unlikely(status || cb->cb_seq_status))
 528		return status;
 529
 530	return decode_cb_sequence4resok(xdr, cb);
 531}
 532
 533/*
 534 * NFSv4.0 and NFSv4.1 XDR encode functions
 535 *
 536 * NFSv4.0 callback argument types are defined in section 15 of RFC
 537 * 3530: "Network File System (NFS) version 4 Protocol" and section 20
 538 * of RFC 5661:  "Network File System (NFS) Version 4 Minor Version 1
 539 * Protocol".
 540 */
 541
 542/*
 543 * NB: Without this zero space reservation, callbacks over krb5p fail
 544 */
 545static void nfs4_xdr_enc_cb_null(struct rpc_rqst *req, struct xdr_stream *xdr,
 546				 const void *__unused)
 547{
 548	xdr_reserve_space(xdr, 0);
 549}
 550
 551/*
 552 * 20.1.  Operation 3: CB_GETATTR - Get Attributes
 553 */
 554static void nfs4_xdr_enc_cb_getattr(struct rpc_rqst *req,
 555		struct xdr_stream *xdr, const void *data)
 556{
 557	const struct nfsd4_callback *cb = data;
 558	struct nfs4_cb_fattr *ncf =
 559		container_of(cb, struct nfs4_cb_fattr, ncf_getattr);
 560	struct nfs4_cb_compound_hdr hdr = {
 561		.ident = cb->cb_clp->cl_cb_ident,
 562		.minorversion = cb->cb_clp->cl_minorversion,
 563	};
 564
 565	encode_cb_compound4args(xdr, &hdr);
 566	encode_cb_sequence4args(xdr, cb, &hdr);
 567	encode_cb_getattr4args(xdr, &hdr, ncf);
 568	encode_cb_nops(&hdr);
 569}
 570
 571/*
 572 * 20.2. Operation 4: CB_RECALL - Recall a Delegation
 573 */
 574static void nfs4_xdr_enc_cb_recall(struct rpc_rqst *req, struct xdr_stream *xdr,
 575				   const void *data)
 576{
 577	const struct nfsd4_callback *cb = data;
 578	const struct nfs4_delegation *dp = cb_to_delegation(cb);
 579	struct nfs4_cb_compound_hdr hdr = {
 580		.ident = cb->cb_clp->cl_cb_ident,
 581		.minorversion = cb->cb_clp->cl_minorversion,
 582	};
 583
 584	encode_cb_compound4args(xdr, &hdr);
 585	encode_cb_sequence4args(xdr, cb, &hdr);
 586	encode_cb_recall4args(xdr, dp, &hdr);
 587	encode_cb_nops(&hdr);
 588}
 589
 590/*
 591 * 20.6. Operation 8: CB_RECALL_ANY - Keep Any N Recallable Objects
 592 */
 593static void
 594nfs4_xdr_enc_cb_recall_any(struct rpc_rqst *req,
 595		struct xdr_stream *xdr, const void *data)
 596{
 597	const struct nfsd4_callback *cb = data;
 598	struct nfsd4_cb_recall_any *ra;
 599	struct nfs4_cb_compound_hdr hdr = {
 600		.ident = cb->cb_clp->cl_cb_ident,
 601		.minorversion = cb->cb_clp->cl_minorversion,
 602	};
 603
 604	ra = container_of(cb, struct nfsd4_cb_recall_any, ra_cb);
 605	encode_cb_compound4args(xdr, &hdr);
 606	encode_cb_sequence4args(xdr, cb, &hdr);
 607	encode_cb_recallany4args(xdr, &hdr, ra);
 608	encode_cb_nops(&hdr);
 609}
 610
 611/*
 612 * NFSv4.0 and NFSv4.1 XDR decode functions
 613 *
 614 * NFSv4.0 callback result types are defined in section 15 of RFC
 615 * 3530: "Network File System (NFS) version 4 Protocol" and section 20
 616 * of RFC 5661:  "Network File System (NFS) Version 4 Minor Version 1
 617 * Protocol".
 618 */
 619
 620static int nfs4_xdr_dec_cb_null(struct rpc_rqst *req, struct xdr_stream *xdr,
 621				void *__unused)
 622{
 623	return 0;
 624}
 625
 626/*
 627 * 20.1.  Operation 3: CB_GETATTR - Get Attributes
 628 */
 629static int nfs4_xdr_dec_cb_getattr(struct rpc_rqst *rqstp,
 630				  struct xdr_stream *xdr,
 631				  void *data)
 632{
 633	struct nfsd4_callback *cb = data;
 634	struct nfs4_cb_compound_hdr hdr;
 635	int status;
 636	u32 bitmap[3] = {0};
 637	u32 attrlen;
 638	struct nfs4_cb_fattr *ncf =
 639		container_of(cb, struct nfs4_cb_fattr, ncf_getattr);
 640
 641	status = decode_cb_compound4res(xdr, &hdr);
 642	if (unlikely(status))
 643		return status;
 644
 645	status = decode_cb_sequence4res(xdr, cb);
 646	if (unlikely(status || cb->cb_seq_status))
 647		return status;
 648
 649	status = decode_cb_op_status(xdr, OP_CB_GETATTR, &cb->cb_status);
 650	if (status)
 651		return status;
 652	if (xdr_stream_decode_uint32_array(xdr, bitmap, 3) < 0)
 653		return -NFSERR_BAD_XDR;
 654	if (xdr_stream_decode_u32(xdr, &attrlen) < 0)
 655		return -NFSERR_BAD_XDR;
 656	if (attrlen > (sizeof(ncf->ncf_cb_change) + sizeof(ncf->ncf_cb_fsize)))
 657		return -NFSERR_BAD_XDR;
 658	status = decode_cb_fattr4(xdr, bitmap, ncf);
 659	return status;
 660}
 661
 662/*
 663 * 20.2. Operation 4: CB_RECALL - Recall a Delegation
 664 */
 665static int nfs4_xdr_dec_cb_recall(struct rpc_rqst *rqstp,
 666				  struct xdr_stream *xdr,
 667				  void *data)
 668{
 669	struct nfsd4_callback *cb = data;
 670	struct nfs4_cb_compound_hdr hdr;
 671	int status;
 672
 673	status = decode_cb_compound4res(xdr, &hdr);
 674	if (unlikely(status))
 675		return status;
 676
 677	status = decode_cb_sequence4res(xdr, cb);
 678	if (unlikely(status || cb->cb_seq_status))
 679		return status;
 
 
 680
 681	return decode_cb_op_status(xdr, OP_CB_RECALL, &cb->cb_status);
 682}
 683
 684/*
 685 * 20.6. Operation 8: CB_RECALL_ANY - Keep Any N Recallable Objects
 686 */
 687static int
 688nfs4_xdr_dec_cb_recall_any(struct rpc_rqst *rqstp,
 689				  struct xdr_stream *xdr,
 690				  void *data)
 691{
 692	struct nfsd4_callback *cb = data;
 693	struct nfs4_cb_compound_hdr hdr;
 694	int status;
 695
 696	status = decode_cb_compound4res(xdr, &hdr);
 697	if (unlikely(status))
 698		return status;
 699	status = decode_cb_sequence4res(xdr, cb);
 700	if (unlikely(status || cb->cb_seq_status))
 701		return status;
 702	status =  decode_cb_op_status(xdr, OP_CB_RECALL_ANY, &cb->cb_status);
 703	return status;
 704}
 705
 706#ifdef CONFIG_NFSD_PNFS
 707/*
 708 * CB_LAYOUTRECALL4args
 709 *
 710 *	struct layoutrecall_file4 {
 711 *		nfs_fh4         lor_fh;
 712 *		offset4         lor_offset;
 713 *		length4         lor_length;
 714 *		stateid4        lor_stateid;
 715 *	};
 716 *
 717 *	union layoutrecall4 switch(layoutrecall_type4 lor_recalltype) {
 718 *	case LAYOUTRECALL4_FILE:
 719 *		layoutrecall_file4 lor_layout;
 720 *	case LAYOUTRECALL4_FSID:
 721 *		fsid4              lor_fsid;
 722 *	case LAYOUTRECALL4_ALL:
 723 *		void;
 724 *	};
 725 *
 726 *	struct CB_LAYOUTRECALL4args {
 727 *		layouttype4             clora_type;
 728 *		layoutiomode4           clora_iomode;
 729 *		bool                    clora_changed;
 730 *		layoutrecall4           clora_recall;
 731 *	};
 732 */
 733static void encode_cb_layout4args(struct xdr_stream *xdr,
 734				  const struct nfs4_layout_stateid *ls,
 735				  struct nfs4_cb_compound_hdr *hdr)
 736{
 737	__be32 *p;
 738
 739	BUG_ON(hdr->minorversion == 0);
 740
 741	p = xdr_reserve_space(xdr, 5 * 4);
 742	*p++ = cpu_to_be32(OP_CB_LAYOUTRECALL);
 743	*p++ = cpu_to_be32(ls->ls_layout_type);
 744	*p++ = cpu_to_be32(IOMODE_ANY);
 745	*p++ = cpu_to_be32(1);
 746	*p = cpu_to_be32(RETURN_FILE);
 747
 748	encode_nfs_fh4(xdr, &ls->ls_stid.sc_file->fi_fhandle);
 749
 750	p = xdr_reserve_space(xdr, 2 * 8);
 751	p = xdr_encode_hyper(p, 0);
 752	xdr_encode_hyper(p, NFS4_MAX_UINT64);
 753
 754	encode_stateid4(xdr, &ls->ls_recall_sid);
 755
 756	hdr->nops++;
 757}
 758
 759static void nfs4_xdr_enc_cb_layout(struct rpc_rqst *req,
 760				   struct xdr_stream *xdr,
 761				   const void *data)
 762{
 763	const struct nfsd4_callback *cb = data;
 764	const struct nfs4_layout_stateid *ls =
 765		container_of(cb, struct nfs4_layout_stateid, ls_recall);
 766	struct nfs4_cb_compound_hdr hdr = {
 767		.ident = 0,
 768		.minorversion = cb->cb_clp->cl_minorversion,
 769	};
 770
 771	encode_cb_compound4args(xdr, &hdr);
 772	encode_cb_sequence4args(xdr, cb, &hdr);
 773	encode_cb_layout4args(xdr, ls, &hdr);
 774	encode_cb_nops(&hdr);
 775}
 776
 777static int nfs4_xdr_dec_cb_layout(struct rpc_rqst *rqstp,
 778				  struct xdr_stream *xdr,
 779				  void *data)
 780{
 781	struct nfsd4_callback *cb = data;
 782	struct nfs4_cb_compound_hdr hdr;
 783	int status;
 784
 785	status = decode_cb_compound4res(xdr, &hdr);
 786	if (unlikely(status))
 787		return status;
 788
 789	status = decode_cb_sequence4res(xdr, cb);
 790	if (unlikely(status || cb->cb_seq_status))
 791		return status;
 792
 
 793	return decode_cb_op_status(xdr, OP_CB_LAYOUTRECALL, &cb->cb_status);
 794}
 795#endif /* CONFIG_NFSD_PNFS */
 796
 797static void encode_stateowner(struct xdr_stream *xdr, struct nfs4_stateowner *so)
 798{
 799	__be32	*p;
 800
 801	p = xdr_reserve_space(xdr, 8 + 4 + so->so_owner.len);
 802	p = xdr_encode_opaque_fixed(p, &so->so_client->cl_clientid, 8);
 803	xdr_encode_opaque(p, so->so_owner.data, so->so_owner.len);
 804}
 805
 806static void nfs4_xdr_enc_cb_notify_lock(struct rpc_rqst *req,
 807					struct xdr_stream *xdr,
 808					const void *data)
 809{
 810	const struct nfsd4_callback *cb = data;
 811	const struct nfsd4_blocked_lock *nbl =
 812		container_of(cb, struct nfsd4_blocked_lock, nbl_cb);
 813	struct nfs4_lockowner *lo = (struct nfs4_lockowner *)nbl->nbl_lock.c.flc_owner;
 814	struct nfs4_cb_compound_hdr hdr = {
 815		.ident = 0,
 816		.minorversion = cb->cb_clp->cl_minorversion,
 817	};
 818
 819	__be32 *p;
 820
 821	BUG_ON(hdr.minorversion == 0);
 822
 823	encode_cb_compound4args(xdr, &hdr);
 824	encode_cb_sequence4args(xdr, cb, &hdr);
 825
 826	p = xdr_reserve_space(xdr, 4);
 827	*p = cpu_to_be32(OP_CB_NOTIFY_LOCK);
 828	encode_nfs_fh4(xdr, &nbl->nbl_fh);
 829	encode_stateowner(xdr, &lo->lo_owner);
 830	hdr.nops++;
 831
 832	encode_cb_nops(&hdr);
 833}
 834
 835static int nfs4_xdr_dec_cb_notify_lock(struct rpc_rqst *rqstp,
 836					struct xdr_stream *xdr,
 837					void *data)
 838{
 839	struct nfsd4_callback *cb = data;
 840	struct nfs4_cb_compound_hdr hdr;
 841	int status;
 842
 843	status = decode_cb_compound4res(xdr, &hdr);
 844	if (unlikely(status))
 845		return status;
 846
 847	status = decode_cb_sequence4res(xdr, cb);
 848	if (unlikely(status || cb->cb_seq_status))
 849		return status;
 850
 851	return decode_cb_op_status(xdr, OP_CB_NOTIFY_LOCK, &cb->cb_status);
 852}
 853
 854/*
 855 * struct write_response4 {
 856 *	stateid4	wr_callback_id<1>;
 857 *	length4		wr_count;
 858 *	stable_how4	wr_committed;
 859 *	verifier4	wr_writeverf;
 860 * };
 861 * union offload_info4 switch (nfsstat4 coa_status) {
 862 *	case NFS4_OK:
 863 *		write_response4	coa_resok4;
 864 *	default:
 865 *		length4		coa_bytes_copied;
 866 * };
 867 * struct CB_OFFLOAD4args {
 868 *	nfs_fh4		coa_fh;
 869 *	stateid4	coa_stateid;
 870 *	offload_info4	coa_offload_info;
 871 * };
 872 */
 873static void encode_offload_info4(struct xdr_stream *xdr,
 874				 const struct nfsd4_cb_offload *cbo)
 875{
 876	__be32 *p;
 877
 878	p = xdr_reserve_space(xdr, 4);
 879	*p = cbo->co_nfserr;
 880	switch (cbo->co_nfserr) {
 881	case nfs_ok:
 882		p = xdr_reserve_space(xdr, 4 + 8 + 4 + NFS4_VERIFIER_SIZE);
 883		p = xdr_encode_empty_array(p);
 884		p = xdr_encode_hyper(p, cbo->co_res.wr_bytes_written);
 885		*p++ = cpu_to_be32(cbo->co_res.wr_stable_how);
 886		p = xdr_encode_opaque_fixed(p, cbo->co_res.wr_verifier.data,
 887					    NFS4_VERIFIER_SIZE);
 888		break;
 889	default:
 890		p = xdr_reserve_space(xdr, 8);
 891		/* We always return success if bytes were written */
 892		p = xdr_encode_hyper(p, 0);
 893	}
 894}
 895
 896static void encode_cb_offload4args(struct xdr_stream *xdr,
 897				   const struct nfsd4_cb_offload *cbo,
 898				   struct nfs4_cb_compound_hdr *hdr)
 899{
 900	__be32 *p;
 901
 902	p = xdr_reserve_space(xdr, 4);
 903	*p = cpu_to_be32(OP_CB_OFFLOAD);
 904	encode_nfs_fh4(xdr, &cbo->co_fh);
 905	encode_stateid4(xdr, &cbo->co_res.cb_stateid);
 906	encode_offload_info4(xdr, cbo);
 907
 908	hdr->nops++;
 909}
 910
 911static void nfs4_xdr_enc_cb_offload(struct rpc_rqst *req,
 912				    struct xdr_stream *xdr,
 913				    const void *data)
 914{
 915	const struct nfsd4_callback *cb = data;
 916	const struct nfsd4_cb_offload *cbo =
 917		container_of(cb, struct nfsd4_cb_offload, co_cb);
 918	struct nfs4_cb_compound_hdr hdr = {
 919		.ident = 0,
 920		.minorversion = cb->cb_clp->cl_minorversion,
 921	};
 922
 923	encode_cb_compound4args(xdr, &hdr);
 924	encode_cb_sequence4args(xdr, cb, &hdr);
 925	encode_cb_offload4args(xdr, cbo, &hdr);
 926	encode_cb_nops(&hdr);
 927}
 928
 929static int nfs4_xdr_dec_cb_offload(struct rpc_rqst *rqstp,
 930				   struct xdr_stream *xdr,
 931				   void *data)
 932{
 933	struct nfsd4_callback *cb = data;
 934	struct nfs4_cb_compound_hdr hdr;
 935	int status;
 936
 937	status = decode_cb_compound4res(xdr, &hdr);
 938	if (unlikely(status))
 939		return status;
 940
 941	status = decode_cb_sequence4res(xdr, cb);
 942	if (unlikely(status || cb->cb_seq_status))
 943		return status;
 944
 945	return decode_cb_op_status(xdr, OP_CB_OFFLOAD, &cb->cb_status);
 946}
 947/*
 948 * RPC procedure tables
 949 */
 950#define PROC(proc, call, argtype, restype)				\
 951[NFSPROC4_CLNT_##proc] = {						\
 952	.p_proc    = NFSPROC4_CB_##call,				\
 953	.p_encode  = nfs4_xdr_enc_##argtype,		\
 954	.p_decode  = nfs4_xdr_dec_##restype,				\
 955	.p_arglen  = NFS4_enc_##argtype##_sz,				\
 956	.p_replen  = NFS4_dec_##restype##_sz,				\
 957	.p_statidx = NFSPROC4_CB_##call,				\
 958	.p_name    = #proc,						\
 959}
 960
 961static const struct rpc_procinfo nfs4_cb_procedures[] = {
 962	PROC(CB_NULL,	NULL,		cb_null,	cb_null),
 963	PROC(CB_RECALL,	COMPOUND,	cb_recall,	cb_recall),
 964#ifdef CONFIG_NFSD_PNFS
 965	PROC(CB_LAYOUT,	COMPOUND,	cb_layout,	cb_layout),
 966#endif
 967	PROC(CB_NOTIFY_LOCK,	COMPOUND,	cb_notify_lock,	cb_notify_lock),
 968	PROC(CB_OFFLOAD,	COMPOUND,	cb_offload,	cb_offload),
 969	PROC(CB_RECALL_ANY,	COMPOUND,	cb_recall_any,	cb_recall_any),
 970	PROC(CB_GETATTR,	COMPOUND,	cb_getattr,	cb_getattr),
 971};
 972
 973static unsigned int nfs4_cb_counts[ARRAY_SIZE(nfs4_cb_procedures)];
 974static const struct rpc_version nfs_cb_version4 = {
 975/*
 976 * Note on the callback rpc program version number: despite language in rfc
 977 * 5661 section 18.36.3 requiring servers to use 4 in this field, the
 978 * official xdr descriptions for both 4.0 and 4.1 specify version 1, and
 979 * in practice that appears to be what implementations use.  The section
 980 * 18.36.3 language is expected to be fixed in an erratum.
 981 */
 982	.number			= 1,
 983	.nrprocs		= ARRAY_SIZE(nfs4_cb_procedures),
 984	.procs			= nfs4_cb_procedures,
 985	.counts			= nfs4_cb_counts,
 986};
 987
 988static const struct rpc_version *nfs_cb_version[2] = {
 989	[1] = &nfs_cb_version4,
 990};
 991
 992static const struct rpc_program cb_program;
 993
 994static struct rpc_stat cb_stats = {
 995	.program		= &cb_program
 996};
 997
 998#define NFS4_CALLBACK 0x40000000
 999static const struct rpc_program cb_program = {
1000	.name			= "nfs4_cb",
1001	.number			= NFS4_CALLBACK,
1002	.nrvers			= ARRAY_SIZE(nfs_cb_version),
1003	.version		= nfs_cb_version,
1004	.stats			= &cb_stats,
1005	.pipe_dir_name		= "nfsd4_cb",
1006};
1007
1008static int max_cb_time(struct net *net)
1009{
1010	struct nfsd_net *nn = net_generic(net, nfsd_net_id);
1011
1012	/*
1013	 * nfsd4_lease is set to at most one hour in __nfsd4_write_time,
1014	 * so we can use 32-bit math on it. Warn if that assumption
1015	 * ever stops being true.
1016	 */
1017	if (WARN_ON_ONCE(nn->nfsd4_lease > 3600))
1018		return 360 * HZ;
1019
1020	return max(((u32)nn->nfsd4_lease)/10, 1u) * HZ;
1021}
1022
1023static bool nfsd4_queue_cb(struct nfsd4_callback *cb)
1024{
1025	struct nfs4_client *clp = cb->cb_clp;
1026
1027	trace_nfsd_cb_queue(clp, cb);
1028	return queue_work(clp->cl_callback_wq, &cb->cb_work);
1029}
1030
1031static void nfsd41_cb_inflight_begin(struct nfs4_client *clp)
1032{
1033	atomic_inc(&clp->cl_cb_inflight);
 
 
 
 
 
1034}
1035
1036static void nfsd41_cb_inflight_end(struct nfs4_client *clp)
1037{
 
 
 
 
 
1038
1039	if (atomic_dec_and_test(&clp->cl_cb_inflight))
1040		wake_up_var(&clp->cl_cb_inflight);
 
 
1041}
1042
1043static void nfsd41_cb_inflight_wait_complete(struct nfs4_client *clp)
1044{
1045	wait_var_event(&clp->cl_cb_inflight,
1046			!atomic_read(&clp->cl_cb_inflight));
1047}
1048
1049static const struct cred *get_backchannel_cred(struct nfs4_client *clp, struct rpc_clnt *client, struct nfsd4_session *ses)
1050{
1051	if (clp->cl_minorversion == 0) {
1052		client->cl_principal = clp->cl_cred.cr_targ_princ ?
1053			clp->cl_cred.cr_targ_princ : "nfs";
1054
1055		return get_cred(rpc_machine_cred());
1056	} else {
1057		struct cred *kcred;
 
 
1058
1059		kcred = prepare_kernel_cred(&init_task);
1060		if (!kcred)
1061			return NULL;
1062
1063		kcred->fsuid = ses->se_cb_sec.uid;
1064		kcred->fsgid = ses->se_cb_sec.gid;
1065		return kcred;
1066	}
1067}
1068
1069static int setup_callback_client(struct nfs4_client *clp, struct nfs4_cb_conn *conn, struct nfsd4_session *ses)
1070{
1071	int maxtime = max_cb_time(clp->net);
1072	struct rpc_timeout	timeparms = {
1073		.to_initval	= maxtime,
1074		.to_retries	= 0,
1075		.to_maxval	= maxtime,
1076	};
1077	struct rpc_create_args args = {
1078		.net		= clp->net,
1079		.address	= (struct sockaddr *) &conn->cb_addr,
1080		.addrsize	= conn->cb_addrlen,
1081		.saddress	= (struct sockaddr *) &conn->cb_saddr,
1082		.timeout	= &timeparms,
1083		.program	= &cb_program,
1084		.version	= 1,
1085		.flags		= (RPC_CLNT_CREATE_NOPING | RPC_CLNT_CREATE_QUIET),
1086		.cred		= current_cred(),
1087	};
1088	struct rpc_clnt *client;
1089	const struct cred *cred;
1090
1091	if (clp->cl_minorversion == 0) {
1092		if (!clp->cl_cred.cr_principal &&
1093		    (clp->cl_cred.cr_flavor >= RPC_AUTH_GSS_KRB5)) {
1094			trace_nfsd_cb_setup_err(clp, -EINVAL);
1095			return -EINVAL;
1096		}
1097		args.client_name = clp->cl_cred.cr_principal;
1098		args.prognumber	= conn->cb_prog;
1099		args.protocol = XPRT_TRANSPORT_TCP;
1100		args.authflavor = clp->cl_cred.cr_flavor;
1101		clp->cl_cb_ident = conn->cb_ident;
1102	} else {
1103		if (!conn->cb_xprt || !ses)
1104			return -EINVAL;
 
1105		clp->cl_cb_session = ses;
1106		args.bc_xprt = conn->cb_xprt;
1107		args.prognumber = clp->cl_cb_session->se_cb_prog;
1108		args.protocol = conn->cb_xprt->xpt_class->xcl_ident |
1109				XPRT_TRANSPORT_BC;
1110		args.authflavor = ses->se_cb_sec.flavor;
1111	}
1112	/* Create RPC client */
1113	client = rpc_create(&args);
1114	if (IS_ERR(client)) {
1115		trace_nfsd_cb_setup_err(clp, PTR_ERR(client));
 
1116		return PTR_ERR(client);
1117	}
1118	cred = get_backchannel_cred(clp, client, ses);
1119	if (!cred) {
1120		trace_nfsd_cb_setup_err(clp, -ENOMEM);
1121		rpc_shutdown_client(client);
1122		return -ENOMEM;
1123	}
1124
1125	if (clp->cl_minorversion != 0)
1126		clp->cl_cb_conn.cb_xprt = conn->cb_xprt;
1127	clp->cl_cb_client = client;
1128	clp->cl_cb_cred = cred;
1129	rcu_read_lock();
1130	trace_nfsd_cb_setup(clp, rpc_peeraddr2str(client, RPC_DISPLAY_NETID),
1131			    args.authflavor);
1132	rcu_read_unlock();
1133	return 0;
1134}
1135
1136static void nfsd4_mark_cb_state(struct nfs4_client *clp, int newstate)
1137{
1138	if (clp->cl_cb_state != newstate) {
1139		clp->cl_cb_state = newstate;
1140		trace_nfsd_cb_new_state(clp);
1141	}
1142}
1143
1144static void nfsd4_mark_cb_down(struct nfs4_client *clp)
1145{
1146	if (test_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags))
1147		return;
1148	nfsd4_mark_cb_state(clp, NFSD4_CB_DOWN);
 
1149}
1150
1151static void nfsd4_mark_cb_fault(struct nfs4_client *clp)
1152{
1153	if (test_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags))
1154		return;
1155	nfsd4_mark_cb_state(clp, NFSD4_CB_FAULT);
 
1156}
1157
1158static void nfsd4_cb_probe_done(struct rpc_task *task, void *calldata)
1159{
1160	struct nfs4_client *clp = container_of(calldata, struct nfs4_client, cl_cb_null);
1161
1162	if (task->tk_status)
1163		nfsd4_mark_cb_down(clp);
1164	else
1165		nfsd4_mark_cb_state(clp, NFSD4_CB_UP);
1166}
1167
1168static void nfsd4_cb_probe_release(void *calldata)
1169{
1170	struct nfs4_client *clp = container_of(calldata, struct nfs4_client, cl_cb_null);
1171
1172	nfsd41_cb_inflight_end(clp);
1173
1174}
1175
1176static const struct rpc_call_ops nfsd4_cb_probe_ops = {
1177	/* XXX: release method to ensure we set the cb channel down if
1178	 * necessary on early failure? */
1179	.rpc_call_done = nfsd4_cb_probe_done,
1180	.rpc_release = nfsd4_cb_probe_release,
1181};
1182
 
 
1183/*
1184 * Poke the callback thread to process any updates to the callback
1185 * parameters, and send a null probe.
1186 */
1187void nfsd4_probe_callback(struct nfs4_client *clp)
1188{
1189	trace_nfsd_cb_probe(clp);
1190	nfsd4_mark_cb_state(clp, NFSD4_CB_UNKNOWN);
1191	set_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags);
1192	nfsd4_run_cb(&clp->cl_cb_null);
1193}
1194
1195void nfsd4_probe_callback_sync(struct nfs4_client *clp)
1196{
1197	nfsd4_probe_callback(clp);
1198	flush_workqueue(clp->cl_callback_wq);
1199}
1200
1201void nfsd4_change_callback(struct nfs4_client *clp, struct nfs4_cb_conn *conn)
1202{
1203	nfsd4_mark_cb_state(clp, NFSD4_CB_UNKNOWN);
1204	spin_lock(&clp->cl_lock);
1205	memcpy(&clp->cl_cb_conn, conn, sizeof(struct nfs4_cb_conn));
1206	spin_unlock(&clp->cl_lock);
1207}
1208
1209static int grab_slot(struct nfsd4_session *ses)
1210{
1211	int idx;
1212
1213	spin_lock(&ses->se_lock);
1214	idx = ffs(ses->se_cb_slot_avail) - 1;
1215	if (idx < 0 || idx > ses->se_cb_highest_slot) {
1216		spin_unlock(&ses->se_lock);
1217		return -1;
1218	}
1219	/* clear the bit for the slot */
1220	ses->se_cb_slot_avail &= ~BIT(idx);
1221	spin_unlock(&ses->se_lock);
1222	return idx;
1223}
1224
1225/*
1226 * There's currently a single callback channel slot.
1227 * If the slot is available, then mark it busy.  Otherwise, set the
1228 * thread for sleeping on the callback RPC wait queue.
1229 */
1230static bool nfsd41_cb_get_slot(struct nfsd4_callback *cb, struct rpc_task *task)
1231{
1232	struct nfs4_client *clp = cb->cb_clp;
1233	struct nfsd4_session *ses = clp->cl_cb_session;
1234
1235	if (cb->cb_held_slot >= 0)
1236		return true;
1237	cb->cb_held_slot = grab_slot(ses);
1238	if (cb->cb_held_slot < 0) {
1239		rpc_sleep_on(&clp->cl_cb_waitq, task, NULL);
1240		/* Race breaker */
1241		cb->cb_held_slot = grab_slot(ses);
1242		if (cb->cb_held_slot < 0)
1243			return false;
 
1244		rpc_wake_up_queued_task(&clp->cl_cb_waitq, task);
1245	}
1246	return true;
1247}
1248
1249static void nfsd41_cb_release_slot(struct nfsd4_callback *cb)
1250{
1251	struct nfs4_client *clp = cb->cb_clp;
1252	struct nfsd4_session *ses = clp->cl_cb_session;
1253
1254	if (cb->cb_held_slot >= 0) {
1255		spin_lock(&ses->se_lock);
1256		ses->se_cb_slot_avail |= BIT(cb->cb_held_slot);
1257		spin_unlock(&ses->se_lock);
1258		cb->cb_held_slot = -1;
1259		rpc_wake_up_next(&clp->cl_cb_waitq);
1260	}
1261}
1262
1263static void nfsd41_destroy_cb(struct nfsd4_callback *cb)
1264{
1265	struct nfs4_client *clp = cb->cb_clp;
1266
1267	trace_nfsd_cb_destroy(clp, cb);
1268	nfsd41_cb_release_slot(cb);
1269	if (cb->cb_ops && cb->cb_ops->release)
1270		cb->cb_ops->release(cb);
1271	nfsd41_cb_inflight_end(clp);
1272}
1273
1274/*
1275 * TODO: cb_sequence should support referring call lists, cachethis,
1276 * and mark callback channel down on communication errors.
1277 */
1278static void nfsd4_cb_prepare(struct rpc_task *task, void *calldata)
1279{
1280	struct nfsd4_callback *cb = calldata;
1281	struct nfs4_client *clp = cb->cb_clp;
1282	u32 minorversion = clp->cl_minorversion;
1283
 
1284	/*
1285	 * cb_seq_status is only set in decode_cb_sequence4res,
1286	 * and so will remain 1 if an rpc level failure occurs.
1287	 */
1288	trace_nfsd_cb_rpc_prepare(clp);
1289	cb->cb_seq_status = 1;
1290	cb->cb_status = 0;
1291	if (minorversion && !nfsd41_cb_get_slot(cb, task))
1292		return;
 
 
1293	rpc_call_start(task);
1294}
1295
1296static bool nfsd4_cb_sequence_done(struct rpc_task *task, struct nfsd4_callback *cb)
1297{
1298	struct nfs4_client *clp = cb->cb_clp;
1299	struct nfsd4_session *session = clp->cl_cb_session;
1300	bool ret = true;
1301
1302	if (!clp->cl_minorversion) {
1303		/*
1304		 * If the backchannel connection was shut down while this
1305		 * task was queued, we need to resubmit it after setting up
1306		 * a new backchannel connection.
1307		 *
1308		 * Note that if we lost our callback connection permanently
1309		 * the submission code will error out, so we don't need to
1310		 * handle that case here.
1311		 */
1312		if (RPC_SIGNALLED(task))
1313			goto need_restart;
1314
1315		return true;
1316	}
1317
1318	if (cb->cb_held_slot < 0)
1319		goto need_restart;
1320
1321	/* This is the operation status code for CB_SEQUENCE */
1322	trace_nfsd_cb_seq_status(task, cb);
1323	switch (cb->cb_seq_status) {
1324	case 0:
1325		/*
1326		 * No need for lock, access serialized in nfsd4_cb_prepare
1327		 *
1328		 * RFC5661 20.9.3
1329		 * If CB_SEQUENCE returns an error, then the state of the slot
1330		 * (sequence ID, cached reply) MUST NOT change.
1331		 */
1332		++session->se_cb_seq_nr[cb->cb_held_slot];
1333		break;
1334	case -ESERVERFAULT:
1335		++session->se_cb_seq_nr[cb->cb_held_slot];
1336		nfsd4_mark_cb_fault(cb->cb_clp);
1337		ret = false;
1338		break;
1339	case 1:
1340		/*
1341		 * cb_seq_status remains 1 if an RPC Reply was never
1342		 * received. NFSD can't know if the client processed
1343		 * the CB_SEQUENCE operation. Ask the client to send a
1344		 * DESTROY_SESSION to recover.
1345		 */
1346		fallthrough;
1347	case -NFS4ERR_BADSESSION:
1348		nfsd4_mark_cb_fault(cb->cb_clp);
1349		ret = false;
1350		goto need_restart;
1351	case -NFS4ERR_DELAY:
1352		cb->cb_seq_status = 1;
1353		if (!rpc_restart_call(task))
1354			goto out;
1355
1356		rpc_delay(task, 2 * HZ);
1357		return false;
1358	case -NFS4ERR_BADSLOT:
1359		goto retry_nowait;
1360	case -NFS4ERR_SEQ_MISORDERED:
1361		if (session->se_cb_seq_nr[cb->cb_held_slot] != 1) {
1362			session->se_cb_seq_nr[cb->cb_held_slot] = 1;
1363			goto retry_nowait;
1364		}
1365		break;
1366	default:
1367		nfsd4_mark_cb_fault(cb->cb_clp);
 
1368	}
1369	trace_nfsd_cb_free_slot(task, cb);
1370	nfsd41_cb_release_slot(cb);
1371
1372	if (RPC_SIGNALLED(task))
 
 
 
 
 
1373		goto need_restart;
1374out:
1375	return ret;
1376retry_nowait:
1377	if (rpc_restart_call_prepare(task))
1378		ret = false;
1379	goto out;
1380need_restart:
1381	if (!test_bit(NFSD4_CLIENT_CB_KILL, &clp->cl_flags)) {
1382		trace_nfsd_cb_restart(clp, cb);
1383		task->tk_status = 0;
1384		cb->cb_need_restart = true;
1385	}
1386	return false;
1387}
1388
1389static void nfsd4_cb_done(struct rpc_task *task, void *calldata)
1390{
1391	struct nfsd4_callback *cb = calldata;
1392	struct nfs4_client *clp = cb->cb_clp;
1393
1394	trace_nfsd_cb_rpc_done(clp);
 
1395
1396	if (!nfsd4_cb_sequence_done(task, cb))
1397		return;
1398
1399	if (cb->cb_status) {
1400		WARN_ONCE(task->tk_status, "cb_status=%d tk_status=%d",
1401			  cb->cb_status, task->tk_status);
1402		task->tk_status = cb->cb_status;
1403	}
1404
1405	switch (cb->cb_ops->done(cb, task)) {
1406	case 0:
1407		task->tk_status = 0;
1408		rpc_restart_call_prepare(task);
1409		return;
1410	case 1:
1411		switch (task->tk_status) {
1412		case -EIO:
1413		case -ETIMEDOUT:
1414		case -EACCES:
1415			nfsd4_mark_cb_down(clp);
1416		}
1417		break;
1418	default:
1419		BUG();
1420	}
1421}
1422
1423static void nfsd4_cb_release(void *calldata)
1424{
1425	struct nfsd4_callback *cb = calldata;
1426
1427	trace_nfsd_cb_rpc_release(cb->cb_clp);
1428
1429	if (cb->cb_need_restart)
1430		nfsd4_queue_cb(cb);
1431	else
1432		nfsd41_destroy_cb(cb);
1433
1434}
1435
1436static const struct rpc_call_ops nfsd4_cb_ops = {
1437	.rpc_call_prepare = nfsd4_cb_prepare,
1438	.rpc_call_done = nfsd4_cb_done,
1439	.rpc_release = nfsd4_cb_release,
1440};
1441
 
 
 
 
 
 
 
 
 
 
 
 
 
1442/* must be called under the state lock */
1443void nfsd4_shutdown_callback(struct nfs4_client *clp)
1444{
1445	if (clp->cl_cb_state != NFSD4_CB_UNKNOWN)
1446		trace_nfsd_cb_shutdown(clp);
1447
1448	set_bit(NFSD4_CLIENT_CB_KILL, &clp->cl_flags);
1449	/*
1450	 * Note this won't actually result in a null callback;
1451	 * instead, nfsd4_run_cb_null() will detect the killed
1452	 * client, destroy the rpc client, and stop:
1453	 */
1454	nfsd4_run_cb(&clp->cl_cb_null);
1455	flush_workqueue(clp->cl_callback_wq);
1456	nfsd41_cb_inflight_wait_complete(clp);
1457}
1458
 
1459static struct nfsd4_conn * __nfsd4_find_backchannel(struct nfs4_client *clp)
1460{
1461	struct nfsd4_session *s;
1462	struct nfsd4_conn *c;
1463
1464	lockdep_assert_held(&clp->cl_lock);
1465
1466	list_for_each_entry(s, &clp->cl_sessions, se_perclnt) {
1467		list_for_each_entry(c, &s->se_conns, cn_persession) {
1468			if (c->cn_flags & NFS4_CDFC4_BACK)
1469				return c;
1470		}
1471	}
1472	return NULL;
1473}
1474
1475/*
1476 * Note there isn't a lot of locking in this code; instead we depend on
1477 * the fact that it is run from clp->cl_callback_wq, which won't run two
1478 * work items at once.  So, for example, clp->cl_callback_wq handles all
1479 * access of cl_cb_client and all calls to rpc_create or rpc_shutdown_client.
1480 */
1481static void nfsd4_process_cb_update(struct nfsd4_callback *cb)
1482{
1483	struct nfs4_cb_conn conn;
1484	struct nfs4_client *clp = cb->cb_clp;
1485	struct nfsd4_session *ses = NULL;
1486	struct nfsd4_conn *c;
1487	int err;
1488
1489	trace_nfsd_cb_bc_update(clp, cb);
1490
1491	/*
1492	 * This is either an update, or the client dying; in either case,
1493	 * kill the old client:
1494	 */
1495	if (clp->cl_cb_client) {
1496		trace_nfsd_cb_bc_shutdown(clp, cb);
1497		rpc_shutdown_client(clp->cl_cb_client);
1498		clp->cl_cb_client = NULL;
1499		put_cred(clp->cl_cb_cred);
1500		clp->cl_cb_cred = NULL;
1501	}
1502	if (clp->cl_cb_conn.cb_xprt) {
1503		svc_xprt_put(clp->cl_cb_conn.cb_xprt);
1504		clp->cl_cb_conn.cb_xprt = NULL;
1505	}
1506	if (test_bit(NFSD4_CLIENT_CB_KILL, &clp->cl_flags))
1507		return;
1508
1509	spin_lock(&clp->cl_lock);
1510	/*
1511	 * Only serialized callback code is allowed to clear these
1512	 * flags; main nfsd code can only set them:
1513	 */
1514	WARN_ON(!(clp->cl_flags & NFSD4_CLIENT_CB_FLAG_MASK));
1515	clear_bit(NFSD4_CLIENT_CB_UPDATE, &clp->cl_flags);
1516
1517	memcpy(&conn, &cb->cb_clp->cl_cb_conn, sizeof(struct nfs4_cb_conn));
1518	c = __nfsd4_find_backchannel(clp);
1519	if (c) {
1520		svc_xprt_get(c->cn_xprt);
1521		conn.cb_xprt = c->cn_xprt;
1522		ses = c->cn_session;
1523	}
1524	spin_unlock(&clp->cl_lock);
1525
1526	err = setup_callback_client(clp, &conn, ses);
1527	if (err) {
1528		nfsd4_mark_cb_down(clp);
1529		if (c)
1530			svc_xprt_put(c->cn_xprt);
1531		return;
1532	}
1533}
1534
1535static void
1536nfsd4_run_cb_work(struct work_struct *work)
1537{
1538	struct nfsd4_callback *cb =
1539		container_of(work, struct nfsd4_callback, cb_work);
1540	struct nfs4_client *clp = cb->cb_clp;
1541	struct rpc_clnt *clnt;
1542	int flags;
1543
1544	trace_nfsd_cb_start(clp);
 
 
 
 
 
1545
1546	if (clp->cl_flags & NFSD4_CLIENT_CB_FLAG_MASK)
1547		nfsd4_process_cb_update(cb);
1548
1549	clnt = clp->cl_cb_client;
1550	if (!clnt || clp->cl_state == NFSD4_COURTESY) {
1551		/*
1552		 * Callback channel broken, client killed or
1553		 * nfs4_client in courtesy state; give up.
1554		 */
1555		nfsd41_destroy_cb(cb);
1556		return;
1557	}
1558
1559	/*
1560	 * Don't send probe messages for 4.1 or later.
1561	 */
1562	if (!cb->cb_ops && clp->cl_minorversion) {
1563		nfsd4_mark_cb_state(clp, NFSD4_CB_UP);
1564		nfsd41_destroy_cb(cb);
1565		return;
1566	}
1567
1568	if (cb->cb_need_restart) {
1569		cb->cb_need_restart = false;
1570	} else {
1571		if (cb->cb_ops && cb->cb_ops->prepare)
1572			cb->cb_ops->prepare(cb);
1573	}
1574	cb->cb_msg.rpc_cred = clp->cl_cb_cred;
1575	flags = clp->cl_minorversion ? RPC_TASK_NOCONNECT : RPC_TASK_SOFTCONN;
1576	rpc_call_async(clnt, &cb->cb_msg, RPC_TASK_SOFT | flags,
1577			cb->cb_ops ? &nfsd4_cb_ops : &nfsd4_cb_probe_ops, cb);
1578}
1579
1580void nfsd4_init_cb(struct nfsd4_callback *cb, struct nfs4_client *clp,
1581		const struct nfsd4_callback_ops *ops, enum nfsd4_cb_op op)
1582{
1583	cb->cb_clp = clp;
1584	cb->cb_msg.rpc_proc = &nfs4_cb_procedures[op];
1585	cb->cb_msg.rpc_argp = cb;
1586	cb->cb_msg.rpc_resp = cb;
1587	cb->cb_ops = ops;
1588	INIT_WORK(&cb->cb_work, nfsd4_run_cb_work);
 
1589	cb->cb_status = 0;
1590	cb->cb_need_restart = false;
1591	cb->cb_held_slot = -1;
1592}
1593
1594/**
1595 * nfsd4_run_cb - queue up a callback job to run
1596 * @cb: callback to queue
1597 *
1598 * Kick off a callback to do its thing. Returns false if it was already
1599 * on a queue, true otherwise.
1600 */
1601bool nfsd4_run_cb(struct nfsd4_callback *cb)
1602{
1603	struct nfs4_client *clp = cb->cb_clp;
1604	bool queued;
1605
1606	nfsd41_cb_inflight_begin(clp);
1607	queued = nfsd4_queue_cb(cb);
1608	if (!queued)
1609		nfsd41_cb_inflight_end(clp);
1610	return queued;
1611}