Loading...
1// SPDX-License-Identifier: GPL-2.0
2/*
3 * Copyright (c) 2004-2005 Silicon Graphics, Inc.
4 * All Rights Reserved.
5 */
6#include <linux/mount.h>
7#include <linux/fsmap.h>
8#include "xfs.h"
9#include "xfs_fs.h"
10#include "xfs_shared.h"
11#include "xfs_format.h"
12#include "xfs_log_format.h"
13#include "xfs_trans_resv.h"
14#include "xfs_mount.h"
15#include "xfs_inode.h"
16#include "xfs_iwalk.h"
17#include "xfs_itable.h"
18#include "xfs_fsops.h"
19#include "xfs_rtalloc.h"
20#include "xfs_da_format.h"
21#include "xfs_da_btree.h"
22#include "xfs_attr.h"
23#include "xfs_ioctl.h"
24#include "xfs_ioctl32.h"
25#include "xfs_trace.h"
26#include "xfs_sb.h"
27#include "xfs_handle.h"
28
29#define _NATIVE_IOC(cmd, type) \
30 _IOC(_IOC_DIR(cmd), _IOC_TYPE(cmd), _IOC_NR(cmd), sizeof(type))
31
32#ifdef BROKEN_X86_ALIGNMENT
33STATIC int
34xfs_compat_ioc_fsgeometry_v1(
35 struct xfs_mount *mp,
36 compat_xfs_fsop_geom_v1_t __user *arg32)
37{
38 struct xfs_fsop_geom fsgeo;
39
40 xfs_fs_geometry(mp, &fsgeo, 3);
41 /* The 32-bit variant simply has some padding at the end */
42 if (copy_to_user(arg32, &fsgeo, sizeof(struct compat_xfs_fsop_geom_v1)))
43 return -EFAULT;
44 return 0;
45}
46
47STATIC int
48xfs_compat_growfs_data_copyin(
49 struct xfs_growfs_data *in,
50 compat_xfs_growfs_data_t __user *arg32)
51{
52 if (get_user(in->newblocks, &arg32->newblocks) ||
53 get_user(in->imaxpct, &arg32->imaxpct))
54 return -EFAULT;
55 return 0;
56}
57
58STATIC int
59xfs_compat_growfs_rt_copyin(
60 struct xfs_growfs_rt *in,
61 compat_xfs_growfs_rt_t __user *arg32)
62{
63 if (get_user(in->newblocks, &arg32->newblocks) ||
64 get_user(in->extsize, &arg32->extsize))
65 return -EFAULT;
66 return 0;
67}
68
69STATIC int
70xfs_fsinumbers_fmt_compat(
71 struct xfs_ibulk *breq,
72 const struct xfs_inumbers *ig)
73{
74 struct compat_xfs_inogrp __user *p32 = breq->ubuffer;
75 struct xfs_inogrp ig1;
76 struct xfs_inogrp *igrp = &ig1;
77
78 xfs_inumbers_to_inogrp(&ig1, ig);
79
80 if (put_user(igrp->xi_startino, &p32->xi_startino) ||
81 put_user(igrp->xi_alloccount, &p32->xi_alloccount) ||
82 put_user(igrp->xi_allocmask, &p32->xi_allocmask))
83 return -EFAULT;
84
85 return xfs_ibulk_advance(breq, sizeof(struct compat_xfs_inogrp));
86}
87
88#else
89#define xfs_fsinumbers_fmt_compat xfs_fsinumbers_fmt
90#endif /* BROKEN_X86_ALIGNMENT */
91
92STATIC int
93xfs_ioctl32_bstime_copyin(
94 xfs_bstime_t *bstime,
95 compat_xfs_bstime_t __user *bstime32)
96{
97 old_time32_t sec32; /* tv_sec differs on 64 vs. 32 */
98
99 if (get_user(sec32, &bstime32->tv_sec) ||
100 get_user(bstime->tv_nsec, &bstime32->tv_nsec))
101 return -EFAULT;
102 bstime->tv_sec = sec32;
103 return 0;
104}
105
106/*
107 * struct xfs_bstat has differing alignment on intel, & bstime_t sizes
108 * everywhere
109 */
110STATIC int
111xfs_ioctl32_bstat_copyin(
112 struct xfs_bstat *bstat,
113 struct compat_xfs_bstat __user *bstat32)
114{
115 if (get_user(bstat->bs_ino, &bstat32->bs_ino) ||
116 get_user(bstat->bs_mode, &bstat32->bs_mode) ||
117 get_user(bstat->bs_nlink, &bstat32->bs_nlink) ||
118 get_user(bstat->bs_uid, &bstat32->bs_uid) ||
119 get_user(bstat->bs_gid, &bstat32->bs_gid) ||
120 get_user(bstat->bs_rdev, &bstat32->bs_rdev) ||
121 get_user(bstat->bs_blksize, &bstat32->bs_blksize) ||
122 get_user(bstat->bs_size, &bstat32->bs_size) ||
123 xfs_ioctl32_bstime_copyin(&bstat->bs_atime, &bstat32->bs_atime) ||
124 xfs_ioctl32_bstime_copyin(&bstat->bs_mtime, &bstat32->bs_mtime) ||
125 xfs_ioctl32_bstime_copyin(&bstat->bs_ctime, &bstat32->bs_ctime) ||
126 get_user(bstat->bs_blocks, &bstat32->bs_size) ||
127 get_user(bstat->bs_xflags, &bstat32->bs_size) ||
128 get_user(bstat->bs_extsize, &bstat32->bs_extsize) ||
129 get_user(bstat->bs_extents, &bstat32->bs_extents) ||
130 get_user(bstat->bs_gen, &bstat32->bs_gen) ||
131 get_user(bstat->bs_projid_lo, &bstat32->bs_projid_lo) ||
132 get_user(bstat->bs_projid_hi, &bstat32->bs_projid_hi) ||
133 get_user(bstat->bs_forkoff, &bstat32->bs_forkoff) ||
134 get_user(bstat->bs_dmevmask, &bstat32->bs_dmevmask) ||
135 get_user(bstat->bs_dmstate, &bstat32->bs_dmstate) ||
136 get_user(bstat->bs_aextents, &bstat32->bs_aextents))
137 return -EFAULT;
138 return 0;
139}
140
141/* XFS_IOC_FSBULKSTAT and friends */
142
143STATIC int
144xfs_bstime_store_compat(
145 compat_xfs_bstime_t __user *p32,
146 const xfs_bstime_t *p)
147{
148 __s32 sec32;
149
150 sec32 = p->tv_sec;
151 if (put_user(sec32, &p32->tv_sec) ||
152 put_user(p->tv_nsec, &p32->tv_nsec))
153 return -EFAULT;
154 return 0;
155}
156
157/* Return 0 on success or positive error (to xfs_bulkstat()) */
158STATIC int
159xfs_fsbulkstat_one_fmt_compat(
160 struct xfs_ibulk *breq,
161 const struct xfs_bulkstat *bstat)
162{
163 struct compat_xfs_bstat __user *p32 = breq->ubuffer;
164 struct xfs_bstat bs1;
165 struct xfs_bstat *buffer = &bs1;
166
167 xfs_bulkstat_to_bstat(breq->mp, &bs1, bstat);
168
169 if (put_user(buffer->bs_ino, &p32->bs_ino) ||
170 put_user(buffer->bs_mode, &p32->bs_mode) ||
171 put_user(buffer->bs_nlink, &p32->bs_nlink) ||
172 put_user(buffer->bs_uid, &p32->bs_uid) ||
173 put_user(buffer->bs_gid, &p32->bs_gid) ||
174 put_user(buffer->bs_rdev, &p32->bs_rdev) ||
175 put_user(buffer->bs_blksize, &p32->bs_blksize) ||
176 put_user(buffer->bs_size, &p32->bs_size) ||
177 xfs_bstime_store_compat(&p32->bs_atime, &buffer->bs_atime) ||
178 xfs_bstime_store_compat(&p32->bs_mtime, &buffer->bs_mtime) ||
179 xfs_bstime_store_compat(&p32->bs_ctime, &buffer->bs_ctime) ||
180 put_user(buffer->bs_blocks, &p32->bs_blocks) ||
181 put_user(buffer->bs_xflags, &p32->bs_xflags) ||
182 put_user(buffer->bs_extsize, &p32->bs_extsize) ||
183 put_user(buffer->bs_extents, &p32->bs_extents) ||
184 put_user(buffer->bs_gen, &p32->bs_gen) ||
185 put_user(buffer->bs_projid, &p32->bs_projid) ||
186 put_user(buffer->bs_projid_hi, &p32->bs_projid_hi) ||
187 put_user(buffer->bs_forkoff, &p32->bs_forkoff) ||
188 put_user(buffer->bs_dmevmask, &p32->bs_dmevmask) ||
189 put_user(buffer->bs_dmstate, &p32->bs_dmstate) ||
190 put_user(buffer->bs_aextents, &p32->bs_aextents))
191 return -EFAULT;
192
193 return xfs_ibulk_advance(breq, sizeof(struct compat_xfs_bstat));
194}
195
196/* copied from xfs_ioctl.c */
197STATIC int
198xfs_compat_ioc_fsbulkstat(
199 struct file *file,
200 unsigned int cmd,
201 struct compat_xfs_fsop_bulkreq __user *p32)
202{
203 struct xfs_mount *mp = XFS_I(file_inode(file))->i_mount;
204 u32 addr;
205 struct xfs_fsop_bulkreq bulkreq;
206 struct xfs_ibulk breq = {
207 .mp = mp,
208 .idmap = file_mnt_idmap(file),
209 .ocount = 0,
210 };
211 xfs_ino_t lastino;
212 int error;
213
214 /*
215 * Output structure handling functions. Depending on the command,
216 * either the xfs_bstat and xfs_inogrp structures are written out
217 * to userpace memory via bulkreq.ubuffer. Normally the compat
218 * functions and structure size are the correct ones to use ...
219 */
220 inumbers_fmt_pf inumbers_func = xfs_fsinumbers_fmt_compat;
221 bulkstat_one_fmt_pf bs_one_func = xfs_fsbulkstat_one_fmt_compat;
222
223#ifdef CONFIG_X86_X32_ABI
224 if (in_x32_syscall()) {
225 /*
226 * ... but on x32 the input xfs_fsop_bulkreq has pointers
227 * which must be handled in the "compat" (32-bit) way, while
228 * the xfs_bstat and xfs_inogrp structures follow native 64-
229 * bit layout convention. So adjust accordingly, otherwise
230 * the data written out in compat layout will not match what
231 * x32 userspace expects.
232 */
233 inumbers_func = xfs_fsinumbers_fmt;
234 bs_one_func = xfs_fsbulkstat_one_fmt;
235 }
236#endif
237
238 /* done = 1 if there are more stats to get and if bulkstat */
239 /* should be called again (unused here, but used in dmapi) */
240
241 if (!capable(CAP_SYS_ADMIN))
242 return -EPERM;
243
244 if (xfs_is_shutdown(mp))
245 return -EIO;
246
247 if (get_user(addr, &p32->lastip))
248 return -EFAULT;
249 bulkreq.lastip = compat_ptr(addr);
250 if (get_user(bulkreq.icount, &p32->icount) ||
251 get_user(addr, &p32->ubuffer))
252 return -EFAULT;
253 bulkreq.ubuffer = compat_ptr(addr);
254 if (get_user(addr, &p32->ocount))
255 return -EFAULT;
256 bulkreq.ocount = compat_ptr(addr);
257
258 if (copy_from_user(&lastino, bulkreq.lastip, sizeof(__s64)))
259 return -EFAULT;
260
261 if (bulkreq.icount <= 0)
262 return -EINVAL;
263
264 if (bulkreq.ubuffer == NULL)
265 return -EINVAL;
266
267 breq.ubuffer = bulkreq.ubuffer;
268 breq.icount = bulkreq.icount;
269
270 /*
271 * FSBULKSTAT_SINGLE expects that *lastip contains the inode number
272 * that we want to stat. However, FSINUMBERS and FSBULKSTAT expect
273 * that *lastip contains either zero or the number of the last inode to
274 * be examined by the previous call and return results starting with
275 * the next inode after that. The new bulk request back end functions
276 * take the inode to start with, so we have to compute the startino
277 * parameter from lastino to maintain correct function. lastino == 0
278 * is a special case because it has traditionally meant "first inode
279 * in filesystem".
280 */
281 if (cmd == XFS_IOC_FSINUMBERS_32) {
282 breq.startino = lastino ? lastino + 1 : 0;
283 error = xfs_inumbers(&breq, inumbers_func);
284 lastino = breq.startino - 1;
285 } else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE_32) {
286 breq.startino = lastino;
287 breq.icount = 1;
288 error = xfs_bulkstat_one(&breq, bs_one_func);
289 lastino = breq.startino;
290 } else if (cmd == XFS_IOC_FSBULKSTAT_32) {
291 breq.startino = lastino ? lastino + 1 : 0;
292 error = xfs_bulkstat(&breq, bs_one_func);
293 lastino = breq.startino - 1;
294 } else {
295 error = -EINVAL;
296 }
297 if (error)
298 return error;
299
300 if (bulkreq.lastip != NULL &&
301 copy_to_user(bulkreq.lastip, &lastino, sizeof(xfs_ino_t)))
302 return -EFAULT;
303
304 if (bulkreq.ocount != NULL &&
305 copy_to_user(bulkreq.ocount, &breq.ocount, sizeof(__s32)))
306 return -EFAULT;
307
308 return 0;
309}
310
311STATIC int
312xfs_compat_handlereq_copyin(
313 xfs_fsop_handlereq_t *hreq,
314 compat_xfs_fsop_handlereq_t __user *arg32)
315{
316 compat_xfs_fsop_handlereq_t hreq32;
317
318 if (copy_from_user(&hreq32, arg32, sizeof(compat_xfs_fsop_handlereq_t)))
319 return -EFAULT;
320
321 hreq->fd = hreq32.fd;
322 hreq->path = compat_ptr(hreq32.path);
323 hreq->oflags = hreq32.oflags;
324 hreq->ihandle = compat_ptr(hreq32.ihandle);
325 hreq->ihandlen = hreq32.ihandlen;
326 hreq->ohandle = compat_ptr(hreq32.ohandle);
327 hreq->ohandlen = compat_ptr(hreq32.ohandlen);
328
329 return 0;
330}
331
332STATIC struct dentry *
333xfs_compat_handlereq_to_dentry(
334 struct file *parfilp,
335 compat_xfs_fsop_handlereq_t *hreq)
336{
337 return xfs_handle_to_dentry(parfilp,
338 compat_ptr(hreq->ihandle), hreq->ihandlen);
339}
340
341STATIC int
342xfs_compat_attrlist_by_handle(
343 struct file *parfilp,
344 compat_xfs_fsop_attrlist_handlereq_t __user *p)
345{
346 compat_xfs_fsop_attrlist_handlereq_t al_hreq;
347 struct dentry *dentry;
348 int error;
349
350 if (!capable(CAP_SYS_ADMIN))
351 return -EPERM;
352 if (copy_from_user(&al_hreq, p, sizeof(al_hreq)))
353 return -EFAULT;
354
355 dentry = xfs_compat_handlereq_to_dentry(parfilp, &al_hreq.hreq);
356 if (IS_ERR(dentry))
357 return PTR_ERR(dentry);
358
359 error = xfs_ioc_attr_list(XFS_I(d_inode(dentry)),
360 compat_ptr(al_hreq.buffer), al_hreq.buflen,
361 al_hreq.flags, &p->pos);
362 dput(dentry);
363 return error;
364}
365
366STATIC int
367xfs_compat_attrmulti_by_handle(
368 struct file *parfilp,
369 void __user *arg)
370{
371 int error;
372 compat_xfs_attr_multiop_t *ops;
373 compat_xfs_fsop_attrmulti_handlereq_t am_hreq;
374 struct dentry *dentry;
375 unsigned int i, size;
376
377 if (!capable(CAP_SYS_ADMIN))
378 return -EPERM;
379 if (copy_from_user(&am_hreq, arg,
380 sizeof(compat_xfs_fsop_attrmulti_handlereq_t)))
381 return -EFAULT;
382
383 /* overflow check */
384 if (am_hreq.opcount >= INT_MAX / sizeof(compat_xfs_attr_multiop_t))
385 return -E2BIG;
386
387 dentry = xfs_compat_handlereq_to_dentry(parfilp, &am_hreq.hreq);
388 if (IS_ERR(dentry))
389 return PTR_ERR(dentry);
390
391 error = -E2BIG;
392 size = am_hreq.opcount * sizeof(compat_xfs_attr_multiop_t);
393 if (!size || size > 16 * PAGE_SIZE)
394 goto out_dput;
395
396 ops = memdup_user(compat_ptr(am_hreq.ops), size);
397 if (IS_ERR(ops)) {
398 error = PTR_ERR(ops);
399 goto out_dput;
400 }
401
402 error = 0;
403 for (i = 0; i < am_hreq.opcount; i++) {
404 ops[i].am_error = xfs_ioc_attrmulti_one(parfilp,
405 d_inode(dentry), ops[i].am_opcode,
406 compat_ptr(ops[i].am_attrname),
407 compat_ptr(ops[i].am_attrvalue),
408 &ops[i].am_length, ops[i].am_flags);
409 }
410
411 if (copy_to_user(compat_ptr(am_hreq.ops), ops, size))
412 error = -EFAULT;
413
414 kfree(ops);
415 out_dput:
416 dput(dentry);
417 return error;
418}
419
420long
421xfs_file_compat_ioctl(
422 struct file *filp,
423 unsigned cmd,
424 unsigned long p)
425{
426 struct inode *inode = file_inode(filp);
427 struct xfs_inode *ip = XFS_I(inode);
428 void __user *arg = compat_ptr(p);
429 int error;
430
431 trace_xfs_file_compat_ioctl(ip);
432
433 switch (cmd) {
434#if defined(BROKEN_X86_ALIGNMENT)
435 case XFS_IOC_FSGEOMETRY_V1_32:
436 return xfs_compat_ioc_fsgeometry_v1(ip->i_mount, arg);
437 case XFS_IOC_FSGROWFSDATA_32: {
438 struct xfs_growfs_data in;
439
440 if (xfs_compat_growfs_data_copyin(&in, arg))
441 return -EFAULT;
442 error = mnt_want_write_file(filp);
443 if (error)
444 return error;
445 error = xfs_growfs_data(ip->i_mount, &in);
446 mnt_drop_write_file(filp);
447 return error;
448 }
449 case XFS_IOC_FSGROWFSRT_32: {
450 struct xfs_growfs_rt in;
451
452 if (xfs_compat_growfs_rt_copyin(&in, arg))
453 return -EFAULT;
454 error = mnt_want_write_file(filp);
455 if (error)
456 return error;
457 error = xfs_growfs_rt(ip->i_mount, &in);
458 mnt_drop_write_file(filp);
459 return error;
460 }
461#endif
462 /* long changes size, but xfs only copiese out 32 bits */
463 case XFS_IOC_GETVERSION_32:
464 cmd = _NATIVE_IOC(cmd, long);
465 return xfs_file_ioctl(filp, cmd, p);
466 case XFS_IOC_SWAPEXT_32: {
467 struct xfs_swapext sxp;
468 struct compat_xfs_swapext __user *sxu = arg;
469
470 /* Bulk copy in up to the sx_stat field, then copy bstat */
471 if (copy_from_user(&sxp, sxu,
472 offsetof(struct xfs_swapext, sx_stat)) ||
473 xfs_ioctl32_bstat_copyin(&sxp.sx_stat, &sxu->sx_stat))
474 return -EFAULT;
475 error = mnt_want_write_file(filp);
476 if (error)
477 return error;
478 error = xfs_ioc_swapext(&sxp);
479 mnt_drop_write_file(filp);
480 return error;
481 }
482 case XFS_IOC_FSBULKSTAT_32:
483 case XFS_IOC_FSBULKSTAT_SINGLE_32:
484 case XFS_IOC_FSINUMBERS_32:
485 return xfs_compat_ioc_fsbulkstat(filp, cmd, arg);
486 case XFS_IOC_FD_TO_HANDLE_32:
487 case XFS_IOC_PATH_TO_HANDLE_32:
488 case XFS_IOC_PATH_TO_FSHANDLE_32: {
489 struct xfs_fsop_handlereq hreq;
490
491 if (xfs_compat_handlereq_copyin(&hreq, arg))
492 return -EFAULT;
493 cmd = _NATIVE_IOC(cmd, struct xfs_fsop_handlereq);
494 return xfs_find_handle(cmd, &hreq);
495 }
496 case XFS_IOC_OPEN_BY_HANDLE_32: {
497 struct xfs_fsop_handlereq hreq;
498
499 if (xfs_compat_handlereq_copyin(&hreq, arg))
500 return -EFAULT;
501 return xfs_open_by_handle(filp, &hreq);
502 }
503 case XFS_IOC_READLINK_BY_HANDLE_32: {
504 struct xfs_fsop_handlereq hreq;
505
506 if (xfs_compat_handlereq_copyin(&hreq, arg))
507 return -EFAULT;
508 return xfs_readlink_by_handle(filp, &hreq);
509 }
510 case XFS_IOC_ATTRLIST_BY_HANDLE_32:
511 return xfs_compat_attrlist_by_handle(filp, arg);
512 case XFS_IOC_ATTRMULTI_BY_HANDLE_32:
513 return xfs_compat_attrmulti_by_handle(filp, arg);
514 default:
515 /* try the native version */
516 return xfs_file_ioctl(filp, cmd, (unsigned long)arg);
517 }
518}
1/*
2 * Copyright (c) 2004-2005 Silicon Graphics, Inc.
3 * All Rights Reserved.
4 *
5 * This program is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU General Public License as
7 * published by the Free Software Foundation.
8 *
9 * This program is distributed in the hope that it would be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write the Free Software Foundation,
16 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
17 */
18#include <linux/compat.h>
19#include <linux/ioctl.h>
20#include <linux/mount.h>
21#include <linux/slab.h>
22#include <linux/uaccess.h>
23#include "xfs.h"
24#include "xfs_fs.h"
25#include "xfs_format.h"
26#include "xfs_log_format.h"
27#include "xfs_trans_resv.h"
28#include "xfs_mount.h"
29#include "xfs_inode.h"
30#include "xfs_itable.h"
31#include "xfs_error.h"
32#include "xfs_fsops.h"
33#include "xfs_alloc.h"
34#include "xfs_rtalloc.h"
35#include "xfs_attr.h"
36#include "xfs_ioctl.h"
37#include "xfs_ioctl32.h"
38#include "xfs_trace.h"
39
40#define _NATIVE_IOC(cmd, type) \
41 _IOC(_IOC_DIR(cmd), _IOC_TYPE(cmd), _IOC_NR(cmd), sizeof(type))
42
43#ifdef BROKEN_X86_ALIGNMENT
44STATIC int
45xfs_compat_flock64_copyin(
46 xfs_flock64_t *bf,
47 compat_xfs_flock64_t __user *arg32)
48{
49 if (get_user(bf->l_type, &arg32->l_type) ||
50 get_user(bf->l_whence, &arg32->l_whence) ||
51 get_user(bf->l_start, &arg32->l_start) ||
52 get_user(bf->l_len, &arg32->l_len) ||
53 get_user(bf->l_sysid, &arg32->l_sysid) ||
54 get_user(bf->l_pid, &arg32->l_pid) ||
55 copy_from_user(bf->l_pad, &arg32->l_pad, 4*sizeof(u32)))
56 return -EFAULT;
57 return 0;
58}
59
60STATIC int
61xfs_compat_ioc_fsgeometry_v1(
62 struct xfs_mount *mp,
63 compat_xfs_fsop_geom_v1_t __user *arg32)
64{
65 xfs_fsop_geom_t fsgeo;
66 int error;
67
68 error = xfs_fs_geometry(mp, &fsgeo, 3);
69 if (error)
70 return error;
71 /* The 32-bit variant simply has some padding at the end */
72 if (copy_to_user(arg32, &fsgeo, sizeof(struct compat_xfs_fsop_geom_v1)))
73 return -EFAULT;
74 return 0;
75}
76
77STATIC int
78xfs_compat_growfs_data_copyin(
79 struct xfs_growfs_data *in,
80 compat_xfs_growfs_data_t __user *arg32)
81{
82 if (get_user(in->newblocks, &arg32->newblocks) ||
83 get_user(in->imaxpct, &arg32->imaxpct))
84 return -EFAULT;
85 return 0;
86}
87
88STATIC int
89xfs_compat_growfs_rt_copyin(
90 struct xfs_growfs_rt *in,
91 compat_xfs_growfs_rt_t __user *arg32)
92{
93 if (get_user(in->newblocks, &arg32->newblocks) ||
94 get_user(in->extsize, &arg32->extsize))
95 return -EFAULT;
96 return 0;
97}
98
99STATIC int
100xfs_inumbers_fmt_compat(
101 void __user *ubuffer,
102 const struct xfs_inogrp *buffer,
103 long count,
104 long *written)
105{
106 compat_xfs_inogrp_t __user *p32 = ubuffer;
107 long i;
108
109 for (i = 0; i < count; i++) {
110 if (put_user(buffer[i].xi_startino, &p32[i].xi_startino) ||
111 put_user(buffer[i].xi_alloccount, &p32[i].xi_alloccount) ||
112 put_user(buffer[i].xi_allocmask, &p32[i].xi_allocmask))
113 return -EFAULT;
114 }
115 *written = count * sizeof(*p32);
116 return 0;
117}
118
119#else
120#define xfs_inumbers_fmt_compat xfs_inumbers_fmt
121#endif /* BROKEN_X86_ALIGNMENT */
122
123STATIC int
124xfs_ioctl32_bstime_copyin(
125 xfs_bstime_t *bstime,
126 compat_xfs_bstime_t __user *bstime32)
127{
128 compat_time_t sec32; /* tv_sec differs on 64 vs. 32 */
129
130 if (get_user(sec32, &bstime32->tv_sec) ||
131 get_user(bstime->tv_nsec, &bstime32->tv_nsec))
132 return -EFAULT;
133 bstime->tv_sec = sec32;
134 return 0;
135}
136
137/* xfs_bstat_t has differing alignment on intel, & bstime_t sizes everywhere */
138STATIC int
139xfs_ioctl32_bstat_copyin(
140 xfs_bstat_t *bstat,
141 compat_xfs_bstat_t __user *bstat32)
142{
143 if (get_user(bstat->bs_ino, &bstat32->bs_ino) ||
144 get_user(bstat->bs_mode, &bstat32->bs_mode) ||
145 get_user(bstat->bs_nlink, &bstat32->bs_nlink) ||
146 get_user(bstat->bs_uid, &bstat32->bs_uid) ||
147 get_user(bstat->bs_gid, &bstat32->bs_gid) ||
148 get_user(bstat->bs_rdev, &bstat32->bs_rdev) ||
149 get_user(bstat->bs_blksize, &bstat32->bs_blksize) ||
150 get_user(bstat->bs_size, &bstat32->bs_size) ||
151 xfs_ioctl32_bstime_copyin(&bstat->bs_atime, &bstat32->bs_atime) ||
152 xfs_ioctl32_bstime_copyin(&bstat->bs_mtime, &bstat32->bs_mtime) ||
153 xfs_ioctl32_bstime_copyin(&bstat->bs_ctime, &bstat32->bs_ctime) ||
154 get_user(bstat->bs_blocks, &bstat32->bs_size) ||
155 get_user(bstat->bs_xflags, &bstat32->bs_size) ||
156 get_user(bstat->bs_extsize, &bstat32->bs_extsize) ||
157 get_user(bstat->bs_extents, &bstat32->bs_extents) ||
158 get_user(bstat->bs_gen, &bstat32->bs_gen) ||
159 get_user(bstat->bs_projid_lo, &bstat32->bs_projid_lo) ||
160 get_user(bstat->bs_projid_hi, &bstat32->bs_projid_hi) ||
161 get_user(bstat->bs_forkoff, &bstat32->bs_forkoff) ||
162 get_user(bstat->bs_dmevmask, &bstat32->bs_dmevmask) ||
163 get_user(bstat->bs_dmstate, &bstat32->bs_dmstate) ||
164 get_user(bstat->bs_aextents, &bstat32->bs_aextents))
165 return -EFAULT;
166 return 0;
167}
168
169/* XFS_IOC_FSBULKSTAT and friends */
170
171STATIC int
172xfs_bstime_store_compat(
173 compat_xfs_bstime_t __user *p32,
174 const xfs_bstime_t *p)
175{
176 __s32 sec32;
177
178 sec32 = p->tv_sec;
179 if (put_user(sec32, &p32->tv_sec) ||
180 put_user(p->tv_nsec, &p32->tv_nsec))
181 return -EFAULT;
182 return 0;
183}
184
185/* Return 0 on success or positive error (to xfs_bulkstat()) */
186STATIC int
187xfs_bulkstat_one_fmt_compat(
188 void __user *ubuffer,
189 int ubsize,
190 int *ubused,
191 const xfs_bstat_t *buffer)
192{
193 compat_xfs_bstat_t __user *p32 = ubuffer;
194
195 if (ubsize < sizeof(*p32))
196 return -ENOMEM;
197
198 if (put_user(buffer->bs_ino, &p32->bs_ino) ||
199 put_user(buffer->bs_mode, &p32->bs_mode) ||
200 put_user(buffer->bs_nlink, &p32->bs_nlink) ||
201 put_user(buffer->bs_uid, &p32->bs_uid) ||
202 put_user(buffer->bs_gid, &p32->bs_gid) ||
203 put_user(buffer->bs_rdev, &p32->bs_rdev) ||
204 put_user(buffer->bs_blksize, &p32->bs_blksize) ||
205 put_user(buffer->bs_size, &p32->bs_size) ||
206 xfs_bstime_store_compat(&p32->bs_atime, &buffer->bs_atime) ||
207 xfs_bstime_store_compat(&p32->bs_mtime, &buffer->bs_mtime) ||
208 xfs_bstime_store_compat(&p32->bs_ctime, &buffer->bs_ctime) ||
209 put_user(buffer->bs_blocks, &p32->bs_blocks) ||
210 put_user(buffer->bs_xflags, &p32->bs_xflags) ||
211 put_user(buffer->bs_extsize, &p32->bs_extsize) ||
212 put_user(buffer->bs_extents, &p32->bs_extents) ||
213 put_user(buffer->bs_gen, &p32->bs_gen) ||
214 put_user(buffer->bs_projid, &p32->bs_projid) ||
215 put_user(buffer->bs_projid_hi, &p32->bs_projid_hi) ||
216 put_user(buffer->bs_forkoff, &p32->bs_forkoff) ||
217 put_user(buffer->bs_dmevmask, &p32->bs_dmevmask) ||
218 put_user(buffer->bs_dmstate, &p32->bs_dmstate) ||
219 put_user(buffer->bs_aextents, &p32->bs_aextents))
220 return -EFAULT;
221 if (ubused)
222 *ubused = sizeof(*p32);
223 return 0;
224}
225
226STATIC int
227xfs_bulkstat_one_compat(
228 xfs_mount_t *mp, /* mount point for filesystem */
229 xfs_ino_t ino, /* inode number to get data for */
230 void __user *buffer, /* buffer to place output in */
231 int ubsize, /* size of buffer */
232 int *ubused, /* bytes used by me */
233 int *stat) /* BULKSTAT_RV_... */
234{
235 return xfs_bulkstat_one_int(mp, ino, buffer, ubsize,
236 xfs_bulkstat_one_fmt_compat,
237 ubused, stat);
238}
239
240/* copied from xfs_ioctl.c */
241STATIC int
242xfs_compat_ioc_bulkstat(
243 xfs_mount_t *mp,
244 unsigned int cmd,
245 compat_xfs_fsop_bulkreq_t __user *p32)
246{
247 u32 addr;
248 xfs_fsop_bulkreq_t bulkreq;
249 int count; /* # of records returned */
250 xfs_ino_t inlast; /* last inode number */
251 int done;
252 int error;
253
254 /* done = 1 if there are more stats to get and if bulkstat */
255 /* should be called again (unused here, but used in dmapi) */
256
257 if (!capable(CAP_SYS_ADMIN))
258 return -EPERM;
259
260 if (XFS_FORCED_SHUTDOWN(mp))
261 return -EIO;
262
263 if (get_user(addr, &p32->lastip))
264 return -EFAULT;
265 bulkreq.lastip = compat_ptr(addr);
266 if (get_user(bulkreq.icount, &p32->icount) ||
267 get_user(addr, &p32->ubuffer))
268 return -EFAULT;
269 bulkreq.ubuffer = compat_ptr(addr);
270 if (get_user(addr, &p32->ocount))
271 return -EFAULT;
272 bulkreq.ocount = compat_ptr(addr);
273
274 if (copy_from_user(&inlast, bulkreq.lastip, sizeof(__s64)))
275 return -EFAULT;
276
277 if ((count = bulkreq.icount) <= 0)
278 return -EINVAL;
279
280 if (bulkreq.ubuffer == NULL)
281 return -EINVAL;
282
283 if (cmd == XFS_IOC_FSINUMBERS_32) {
284 error = xfs_inumbers(mp, &inlast, &count,
285 bulkreq.ubuffer, xfs_inumbers_fmt_compat);
286 } else if (cmd == XFS_IOC_FSBULKSTAT_SINGLE_32) {
287 int res;
288
289 error = xfs_bulkstat_one_compat(mp, inlast, bulkreq.ubuffer,
290 sizeof(compat_xfs_bstat_t), NULL, &res);
291 } else if (cmd == XFS_IOC_FSBULKSTAT_32) {
292 error = xfs_bulkstat(mp, &inlast, &count,
293 xfs_bulkstat_one_compat, sizeof(compat_xfs_bstat_t),
294 bulkreq.ubuffer, &done);
295 } else
296 error = -EINVAL;
297 if (error)
298 return error;
299
300 if (bulkreq.ocount != NULL) {
301 if (copy_to_user(bulkreq.lastip, &inlast,
302 sizeof(xfs_ino_t)))
303 return -EFAULT;
304
305 if (copy_to_user(bulkreq.ocount, &count, sizeof(count)))
306 return -EFAULT;
307 }
308
309 return 0;
310}
311
312STATIC int
313xfs_compat_handlereq_copyin(
314 xfs_fsop_handlereq_t *hreq,
315 compat_xfs_fsop_handlereq_t __user *arg32)
316{
317 compat_xfs_fsop_handlereq_t hreq32;
318
319 if (copy_from_user(&hreq32, arg32, sizeof(compat_xfs_fsop_handlereq_t)))
320 return -EFAULT;
321
322 hreq->fd = hreq32.fd;
323 hreq->path = compat_ptr(hreq32.path);
324 hreq->oflags = hreq32.oflags;
325 hreq->ihandle = compat_ptr(hreq32.ihandle);
326 hreq->ihandlen = hreq32.ihandlen;
327 hreq->ohandle = compat_ptr(hreq32.ohandle);
328 hreq->ohandlen = compat_ptr(hreq32.ohandlen);
329
330 return 0;
331}
332
333STATIC struct dentry *
334xfs_compat_handlereq_to_dentry(
335 struct file *parfilp,
336 compat_xfs_fsop_handlereq_t *hreq)
337{
338 return xfs_handle_to_dentry(parfilp,
339 compat_ptr(hreq->ihandle), hreq->ihandlen);
340}
341
342STATIC int
343xfs_compat_attrlist_by_handle(
344 struct file *parfilp,
345 void __user *arg)
346{
347 int error;
348 attrlist_cursor_kern_t *cursor;
349 compat_xfs_fsop_attrlist_handlereq_t al_hreq;
350 struct dentry *dentry;
351 char *kbuf;
352
353 if (!capable(CAP_SYS_ADMIN))
354 return -EPERM;
355 if (copy_from_user(&al_hreq, arg,
356 sizeof(compat_xfs_fsop_attrlist_handlereq_t)))
357 return -EFAULT;
358 if (al_hreq.buflen < sizeof(struct attrlist) ||
359 al_hreq.buflen > XFS_XATTR_LIST_MAX)
360 return -EINVAL;
361
362 /*
363 * Reject flags, only allow namespaces.
364 */
365 if (al_hreq.flags & ~(ATTR_ROOT | ATTR_SECURE))
366 return -EINVAL;
367
368 dentry = xfs_compat_handlereq_to_dentry(parfilp, &al_hreq.hreq);
369 if (IS_ERR(dentry))
370 return PTR_ERR(dentry);
371
372 error = -ENOMEM;
373 kbuf = kmem_zalloc_large(al_hreq.buflen, KM_SLEEP);
374 if (!kbuf)
375 goto out_dput;
376
377 cursor = (attrlist_cursor_kern_t *)&al_hreq.pos;
378 error = xfs_attr_list(XFS_I(d_inode(dentry)), kbuf, al_hreq.buflen,
379 al_hreq.flags, cursor);
380 if (error)
381 goto out_kfree;
382
383 if (copy_to_user(compat_ptr(al_hreq.buffer), kbuf, al_hreq.buflen))
384 error = -EFAULT;
385
386out_kfree:
387 kmem_free(kbuf);
388out_dput:
389 dput(dentry);
390 return error;
391}
392
393STATIC int
394xfs_compat_attrmulti_by_handle(
395 struct file *parfilp,
396 void __user *arg)
397{
398 int error;
399 compat_xfs_attr_multiop_t *ops;
400 compat_xfs_fsop_attrmulti_handlereq_t am_hreq;
401 struct dentry *dentry;
402 unsigned int i, size;
403 unsigned char *attr_name;
404
405 if (!capable(CAP_SYS_ADMIN))
406 return -EPERM;
407 if (copy_from_user(&am_hreq, arg,
408 sizeof(compat_xfs_fsop_attrmulti_handlereq_t)))
409 return -EFAULT;
410
411 /* overflow check */
412 if (am_hreq.opcount >= INT_MAX / sizeof(compat_xfs_attr_multiop_t))
413 return -E2BIG;
414
415 dentry = xfs_compat_handlereq_to_dentry(parfilp, &am_hreq.hreq);
416 if (IS_ERR(dentry))
417 return PTR_ERR(dentry);
418
419 error = -E2BIG;
420 size = am_hreq.opcount * sizeof(compat_xfs_attr_multiop_t);
421 if (!size || size > 16 * PAGE_SIZE)
422 goto out_dput;
423
424 ops = memdup_user(compat_ptr(am_hreq.ops), size);
425 if (IS_ERR(ops)) {
426 error = PTR_ERR(ops);
427 goto out_dput;
428 }
429
430 error = -ENOMEM;
431 attr_name = kmalloc(MAXNAMELEN, GFP_KERNEL);
432 if (!attr_name)
433 goto out_kfree_ops;
434
435 error = 0;
436 for (i = 0; i < am_hreq.opcount; i++) {
437 ops[i].am_error = strncpy_from_user((char *)attr_name,
438 compat_ptr(ops[i].am_attrname),
439 MAXNAMELEN);
440 if (ops[i].am_error == 0 || ops[i].am_error == MAXNAMELEN)
441 error = -ERANGE;
442 if (ops[i].am_error < 0)
443 break;
444
445 switch (ops[i].am_opcode) {
446 case ATTR_OP_GET:
447 ops[i].am_error = xfs_attrmulti_attr_get(
448 d_inode(dentry), attr_name,
449 compat_ptr(ops[i].am_attrvalue),
450 &ops[i].am_length, ops[i].am_flags);
451 break;
452 case ATTR_OP_SET:
453 ops[i].am_error = mnt_want_write_file(parfilp);
454 if (ops[i].am_error)
455 break;
456 ops[i].am_error = xfs_attrmulti_attr_set(
457 d_inode(dentry), attr_name,
458 compat_ptr(ops[i].am_attrvalue),
459 ops[i].am_length, ops[i].am_flags);
460 mnt_drop_write_file(parfilp);
461 break;
462 case ATTR_OP_REMOVE:
463 ops[i].am_error = mnt_want_write_file(parfilp);
464 if (ops[i].am_error)
465 break;
466 ops[i].am_error = xfs_attrmulti_attr_remove(
467 d_inode(dentry), attr_name,
468 ops[i].am_flags);
469 mnt_drop_write_file(parfilp);
470 break;
471 default:
472 ops[i].am_error = -EINVAL;
473 }
474 }
475
476 if (copy_to_user(compat_ptr(am_hreq.ops), ops, size))
477 error = -EFAULT;
478
479 kfree(attr_name);
480 out_kfree_ops:
481 kfree(ops);
482 out_dput:
483 dput(dentry);
484 return error;
485}
486
487STATIC int
488xfs_compat_fssetdm_by_handle(
489 struct file *parfilp,
490 void __user *arg)
491{
492 int error;
493 struct fsdmidata fsd;
494 compat_xfs_fsop_setdm_handlereq_t dmhreq;
495 struct dentry *dentry;
496
497 if (!capable(CAP_MKNOD))
498 return -EPERM;
499 if (copy_from_user(&dmhreq, arg,
500 sizeof(compat_xfs_fsop_setdm_handlereq_t)))
501 return -EFAULT;
502
503 dentry = xfs_compat_handlereq_to_dentry(parfilp, &dmhreq.hreq);
504 if (IS_ERR(dentry))
505 return PTR_ERR(dentry);
506
507 if (IS_IMMUTABLE(d_inode(dentry)) || IS_APPEND(d_inode(dentry))) {
508 error = -EPERM;
509 goto out;
510 }
511
512 if (copy_from_user(&fsd, compat_ptr(dmhreq.data), sizeof(fsd))) {
513 error = -EFAULT;
514 goto out;
515 }
516
517 error = xfs_set_dmattrs(XFS_I(d_inode(dentry)), fsd.fsd_dmevmask,
518 fsd.fsd_dmstate);
519
520out:
521 dput(dentry);
522 return error;
523}
524
525long
526xfs_file_compat_ioctl(
527 struct file *filp,
528 unsigned cmd,
529 unsigned long p)
530{
531 struct inode *inode = file_inode(filp);
532 struct xfs_inode *ip = XFS_I(inode);
533 struct xfs_mount *mp = ip->i_mount;
534 void __user *arg = (void __user *)p;
535 int error;
536
537 trace_xfs_file_compat_ioctl(ip);
538
539 switch (cmd) {
540 /* No size or alignment issues on any arch */
541 case XFS_IOC_DIOINFO:
542 case XFS_IOC_FSGEOMETRY:
543 case XFS_IOC_FSGETXATTR:
544 case XFS_IOC_FSSETXATTR:
545 case XFS_IOC_FSGETXATTRA:
546 case XFS_IOC_FSSETDM:
547 case XFS_IOC_GETBMAP:
548 case XFS_IOC_GETBMAPA:
549 case XFS_IOC_GETBMAPX:
550 case XFS_IOC_FSCOUNTS:
551 case XFS_IOC_SET_RESBLKS:
552 case XFS_IOC_GET_RESBLKS:
553 case XFS_IOC_FSGROWFSLOG:
554 case XFS_IOC_GOINGDOWN:
555 case XFS_IOC_ERROR_INJECTION:
556 case XFS_IOC_ERROR_CLEARALL:
557 return xfs_file_ioctl(filp, cmd, p);
558#ifndef BROKEN_X86_ALIGNMENT
559 /* These are handled fine if no alignment issues */
560 case XFS_IOC_ALLOCSP:
561 case XFS_IOC_FREESP:
562 case XFS_IOC_RESVSP:
563 case XFS_IOC_UNRESVSP:
564 case XFS_IOC_ALLOCSP64:
565 case XFS_IOC_FREESP64:
566 case XFS_IOC_RESVSP64:
567 case XFS_IOC_UNRESVSP64:
568 case XFS_IOC_FSGEOMETRY_V1:
569 case XFS_IOC_FSGROWFSDATA:
570 case XFS_IOC_FSGROWFSRT:
571 case XFS_IOC_ZERO_RANGE:
572 return xfs_file_ioctl(filp, cmd, p);
573#else
574 case XFS_IOC_ALLOCSP_32:
575 case XFS_IOC_FREESP_32:
576 case XFS_IOC_ALLOCSP64_32:
577 case XFS_IOC_FREESP64_32:
578 case XFS_IOC_RESVSP_32:
579 case XFS_IOC_UNRESVSP_32:
580 case XFS_IOC_RESVSP64_32:
581 case XFS_IOC_UNRESVSP64_32:
582 case XFS_IOC_ZERO_RANGE_32: {
583 struct xfs_flock64 bf;
584
585 if (xfs_compat_flock64_copyin(&bf, arg))
586 return -EFAULT;
587 cmd = _NATIVE_IOC(cmd, struct xfs_flock64);
588 return xfs_ioc_space(filp, cmd, &bf);
589 }
590 case XFS_IOC_FSGEOMETRY_V1_32:
591 return xfs_compat_ioc_fsgeometry_v1(mp, arg);
592 case XFS_IOC_FSGROWFSDATA_32: {
593 struct xfs_growfs_data in;
594
595 if (xfs_compat_growfs_data_copyin(&in, arg))
596 return -EFAULT;
597 error = mnt_want_write_file(filp);
598 if (error)
599 return error;
600 error = xfs_growfs_data(mp, &in);
601 mnt_drop_write_file(filp);
602 return error;
603 }
604 case XFS_IOC_FSGROWFSRT_32: {
605 struct xfs_growfs_rt in;
606
607 if (xfs_compat_growfs_rt_copyin(&in, arg))
608 return -EFAULT;
609 error = mnt_want_write_file(filp);
610 if (error)
611 return error;
612 error = xfs_growfs_rt(mp, &in);
613 mnt_drop_write_file(filp);
614 return error;
615 }
616#endif
617 /* long changes size, but xfs only copiese out 32 bits */
618 case XFS_IOC_GETXFLAGS_32:
619 case XFS_IOC_SETXFLAGS_32:
620 case XFS_IOC_GETVERSION_32:
621 cmd = _NATIVE_IOC(cmd, long);
622 return xfs_file_ioctl(filp, cmd, p);
623 case XFS_IOC_SWAPEXT_32: {
624 struct xfs_swapext sxp;
625 struct compat_xfs_swapext __user *sxu = arg;
626
627 /* Bulk copy in up to the sx_stat field, then copy bstat */
628 if (copy_from_user(&sxp, sxu,
629 offsetof(struct xfs_swapext, sx_stat)) ||
630 xfs_ioctl32_bstat_copyin(&sxp.sx_stat, &sxu->sx_stat))
631 return -EFAULT;
632 error = mnt_want_write_file(filp);
633 if (error)
634 return error;
635 error = xfs_ioc_swapext(&sxp);
636 mnt_drop_write_file(filp);
637 return error;
638 }
639 case XFS_IOC_FSBULKSTAT_32:
640 case XFS_IOC_FSBULKSTAT_SINGLE_32:
641 case XFS_IOC_FSINUMBERS_32:
642 return xfs_compat_ioc_bulkstat(mp, cmd, arg);
643 case XFS_IOC_FD_TO_HANDLE_32:
644 case XFS_IOC_PATH_TO_HANDLE_32:
645 case XFS_IOC_PATH_TO_FSHANDLE_32: {
646 struct xfs_fsop_handlereq hreq;
647
648 if (xfs_compat_handlereq_copyin(&hreq, arg))
649 return -EFAULT;
650 cmd = _NATIVE_IOC(cmd, struct xfs_fsop_handlereq);
651 return xfs_find_handle(cmd, &hreq);
652 }
653 case XFS_IOC_OPEN_BY_HANDLE_32: {
654 struct xfs_fsop_handlereq hreq;
655
656 if (xfs_compat_handlereq_copyin(&hreq, arg))
657 return -EFAULT;
658 return xfs_open_by_handle(filp, &hreq);
659 }
660 case XFS_IOC_READLINK_BY_HANDLE_32: {
661 struct xfs_fsop_handlereq hreq;
662
663 if (xfs_compat_handlereq_copyin(&hreq, arg))
664 return -EFAULT;
665 return xfs_readlink_by_handle(filp, &hreq);
666 }
667 case XFS_IOC_ATTRLIST_BY_HANDLE_32:
668 return xfs_compat_attrlist_by_handle(filp, arg);
669 case XFS_IOC_ATTRMULTI_BY_HANDLE_32:
670 return xfs_compat_attrmulti_by_handle(filp, arg);
671 case XFS_IOC_FSSETDM_BY_HANDLE_32:
672 return xfs_compat_fssetdm_by_handle(filp, arg);
673 default:
674 return -ENOIOCTLCMD;
675 }
676}