namespace.c 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. /*
  2. * linux/fs/nfs/namespace.c
  3. *
  4. * Copyright (C) 2005 Trond Myklebust <Trond.Myklebust@netapp.com>
  5. * - Modified by David Howells <dhowells@redhat.com>
  6. *
  7. * NFS namespace
  8. */
  9. #include <linux/dcache.h>
  10. #include <linux/gfp.h>
  11. #include <linux/mount.h>
  12. #include <linux/namei.h>
  13. #include <linux/nfs_fs.h>
  14. #include <linux/string.h>
  15. #include <linux/sunrpc/clnt.h>
  16. #include <linux/vfs.h>
  17. #include <linux/sunrpc/gss_api.h>
  18. #include "internal.h"
  19. #define NFSDBG_FACILITY NFSDBG_VFS
  20. static void nfs_expire_automounts(struct work_struct *work);
  21. static LIST_HEAD(nfs_automount_list);
  22. static DECLARE_DELAYED_WORK(nfs_automount_task, nfs_expire_automounts);
  23. int nfs_mountpoint_expiry_timeout = 500 * HZ;
  24. static struct vfsmount *nfs_do_submount(struct dentry *dentry,
  25. struct nfs_fh *fh,
  26. struct nfs_fattr *fattr,
  27. rpc_authflavor_t authflavor);
  28. /*
  29. * nfs_path - reconstruct the path given an arbitrary dentry
  30. * @base - used to return pointer to the end of devname part of path
  31. * @dentry - pointer to dentry
  32. * @buffer - result buffer
  33. * @buflen - length of buffer
  34. *
  35. * Helper function for constructing the server pathname
  36. * by arbitrary hashed dentry.
  37. *
  38. * This is mainly for use in figuring out the path on the
  39. * server side when automounting on top of an existing partition
  40. * and in generating /proc/mounts and friends.
  41. */
  42. char *nfs_path(char **p, struct dentry *dentry, char *buffer, ssize_t buflen)
  43. {
  44. char *end;
  45. int namelen;
  46. unsigned seq;
  47. const char *base;
  48. rename_retry:
  49. end = buffer+buflen;
  50. *--end = '\0';
  51. buflen--;
  52. seq = read_seqbegin(&rename_lock);
  53. rcu_read_lock();
  54. while (1) {
  55. spin_lock(&dentry->d_lock);
  56. if (IS_ROOT(dentry))
  57. break;
  58. namelen = dentry->d_name.len;
  59. buflen -= namelen + 1;
  60. if (buflen < 0)
  61. goto Elong_unlock;
  62. end -= namelen;
  63. memcpy(end, dentry->d_name.name, namelen);
  64. *--end = '/';
  65. spin_unlock(&dentry->d_lock);
  66. dentry = dentry->d_parent;
  67. }
  68. if (read_seqretry(&rename_lock, seq)) {
  69. spin_unlock(&dentry->d_lock);
  70. rcu_read_unlock();
  71. goto rename_retry;
  72. }
  73. if (*end != '/') {
  74. if (--buflen < 0) {
  75. spin_unlock(&dentry->d_lock);
  76. rcu_read_unlock();
  77. goto Elong;
  78. }
  79. *--end = '/';
  80. }
  81. *p = end;
  82. base = dentry->d_fsdata;
  83. if (!base) {
  84. spin_unlock(&dentry->d_lock);
  85. rcu_read_unlock();
  86. WARN_ON(1);
  87. return end;
  88. }
  89. namelen = strlen(base);
  90. /* Strip off excess slashes in base string */
  91. while (namelen > 0 && base[namelen - 1] == '/')
  92. namelen--;
  93. buflen -= namelen;
  94. if (buflen < 0) {
  95. spin_unlock(&dentry->d_lock);
  96. rcu_read_unlock();
  97. goto Elong;
  98. }
  99. end -= namelen;
  100. memcpy(end, base, namelen);
  101. spin_unlock(&dentry->d_lock);
  102. rcu_read_unlock();
  103. return end;
  104. Elong_unlock:
  105. spin_unlock(&dentry->d_lock);
  106. rcu_read_unlock();
  107. if (read_seqretry(&rename_lock, seq))
  108. goto rename_retry;
  109. Elong:
  110. return ERR_PTR(-ENAMETOOLONG);
  111. }
  112. #ifdef CONFIG_NFS_V4
  113. static rpc_authflavor_t nfs_find_best_sec(struct nfs4_secinfo_flavors *flavors, struct inode *inode)
  114. {
  115. struct gss_api_mech *mech;
  116. struct xdr_netobj oid;
  117. int i;
  118. rpc_authflavor_t pseudoflavor = RPC_AUTH_UNIX;
  119. for (i = 0; i < flavors->num_flavors; i++) {
  120. struct nfs4_secinfo_flavor *flavor;
  121. flavor = &flavors->flavors[i];
  122. if (flavor->flavor == RPC_AUTH_NULL || flavor->flavor == RPC_AUTH_UNIX) {
  123. pseudoflavor = flavor->flavor;
  124. break;
  125. } else if (flavor->flavor == RPC_AUTH_GSS) {
  126. oid.len = flavor->gss.sec_oid4.len;
  127. oid.data = flavor->gss.sec_oid4.data;
  128. mech = gss_mech_get_by_OID(&oid);
  129. if (!mech)
  130. continue;
  131. pseudoflavor = gss_svc_to_pseudoflavor(mech, flavor->gss.service);
  132. gss_mech_put(mech);
  133. break;
  134. }
  135. }
  136. return pseudoflavor;
  137. }
  138. static rpc_authflavor_t nfs_negotiate_security(const struct dentry *parent, const struct dentry *dentry)
  139. {
  140. int status = 0;
  141. struct page *page;
  142. struct nfs4_secinfo_flavors *flavors;
  143. int (*secinfo)(struct inode *, const struct qstr *, struct nfs4_secinfo_flavors *);
  144. rpc_authflavor_t flavor = RPC_AUTH_UNIX;
  145. secinfo = NFS_PROTO(parent->d_inode)->secinfo;
  146. if (secinfo != NULL) {
  147. page = alloc_page(GFP_KERNEL);
  148. if (!page) {
  149. status = -ENOMEM;
  150. goto out;
  151. }
  152. flavors = page_address(page);
  153. status = secinfo(parent->d_inode, &dentry->d_name, flavors);
  154. flavor = nfs_find_best_sec(flavors, dentry->d_inode);
  155. put_page(page);
  156. }
  157. return flavor;
  158. out:
  159. status = -ENOMEM;
  160. return status;
  161. }
  162. static rpc_authflavor_t nfs_lookup_with_sec(struct nfs_server *server, struct dentry *parent,
  163. struct dentry *dentry, struct path *path,
  164. struct nfs_fh *fh, struct nfs_fattr *fattr)
  165. {
  166. rpc_authflavor_t flavor;
  167. struct rpc_clnt *clone;
  168. struct rpc_auth *auth;
  169. int err;
  170. flavor = nfs_negotiate_security(parent, path->dentry);
  171. if (flavor < 0)
  172. goto out;
  173. clone = rpc_clone_client(server->client);
  174. auth = rpcauth_create(flavor, clone);
  175. if (!auth) {
  176. flavor = -EIO;
  177. goto out;
  178. }
  179. err = server->nfs_client->rpc_ops->lookup(clone, parent->d_inode,
  180. &path->dentry->d_name,
  181. fh, fattr);
  182. if (err < 0)
  183. flavor = err;
  184. out:
  185. return flavor;
  186. }
  187. #else /* CONFIG_NFS_V4 */
  188. static inline rpc_authflavor_t nfs_lookup_with_sec(struct nfs_server *server,
  189. struct dentry *parent, struct dentry *dentry,
  190. struct path *path, struct nfs_fh *fh,
  191. struct nfs_fattr *fattr)
  192. {
  193. return -EPERM;
  194. }
  195. #endif /* CONFIG_NFS_V4 */
  196. /*
  197. * nfs_d_automount - Handle crossing a mountpoint on the server
  198. * @path - The mountpoint
  199. *
  200. * When we encounter a mountpoint on the server, we want to set up
  201. * a mountpoint on the client too, to prevent inode numbers from
  202. * colliding, and to allow "df" to work properly.
  203. * On NFSv4, we also want to allow for the fact that different
  204. * filesystems may be migrated to different servers in a failover
  205. * situation, and that different filesystems may want to use
  206. * different security flavours.
  207. */
  208. struct vfsmount *nfs_d_automount(struct path *path)
  209. {
  210. struct vfsmount *mnt;
  211. struct nfs_server *server = NFS_SERVER(path->dentry->d_inode);
  212. struct dentry *parent;
  213. struct nfs_fh *fh = NULL;
  214. struct nfs_fattr *fattr = NULL;
  215. int err;
  216. rpc_authflavor_t flavor = 1;
  217. dprintk("--> nfs_d_automount()\n");
  218. mnt = ERR_PTR(-ESTALE);
  219. if (IS_ROOT(path->dentry))
  220. goto out_nofree;
  221. mnt = ERR_PTR(-ENOMEM);
  222. fh = nfs_alloc_fhandle();
  223. fattr = nfs_alloc_fattr();
  224. if (fh == NULL || fattr == NULL)
  225. goto out;
  226. dprintk("%s: enter\n", __func__);
  227. /* Look it up again to get its attributes */
  228. parent = dget_parent(path->dentry);
  229. err = server->nfs_client->rpc_ops->lookup(server->client, parent->d_inode,
  230. &path->dentry->d_name,
  231. fh, fattr);
  232. if (err == -EPERM) {
  233. flavor = nfs_lookup_with_sec(server, parent, path->dentry, path, fh, fattr);
  234. if (flavor < 0)
  235. err = flavor;
  236. else
  237. err = 0;
  238. }
  239. dput(parent);
  240. if (err != 0) {
  241. mnt = ERR_PTR(err);
  242. goto out;
  243. }
  244. if (fattr->valid & NFS_ATTR_FATTR_V4_REFERRAL)
  245. mnt = nfs_do_refmount(path->dentry);
  246. else
  247. mnt = nfs_do_submount(path->dentry, fh, fattr, flavor);
  248. if (IS_ERR(mnt))
  249. goto out;
  250. dprintk("%s: done, success\n", __func__);
  251. mntget(mnt); /* prevent immediate expiration */
  252. mnt_set_expiry(mnt, &nfs_automount_list);
  253. schedule_delayed_work(&nfs_automount_task, nfs_mountpoint_expiry_timeout);
  254. out:
  255. nfs_free_fattr(fattr);
  256. nfs_free_fhandle(fh);
  257. out_nofree:
  258. dprintk("<-- nfs_follow_mountpoint() = %p\n", mnt);
  259. return mnt;
  260. }
  261. const struct inode_operations nfs_mountpoint_inode_operations = {
  262. .getattr = nfs_getattr,
  263. };
  264. const struct inode_operations nfs_referral_inode_operations = {
  265. };
  266. static void nfs_expire_automounts(struct work_struct *work)
  267. {
  268. struct list_head *list = &nfs_automount_list;
  269. mark_mounts_for_expiry(list);
  270. if (!list_empty(list))
  271. schedule_delayed_work(&nfs_automount_task, nfs_mountpoint_expiry_timeout);
  272. }
  273. void nfs_release_automount_timer(void)
  274. {
  275. if (list_empty(&nfs_automount_list))
  276. cancel_delayed_work(&nfs_automount_task);
  277. }
  278. /*
  279. * Clone a mountpoint of the appropriate type
  280. */
  281. static struct vfsmount *nfs_do_clone_mount(struct nfs_server *server,
  282. const char *devname,
  283. struct nfs_clone_mount *mountdata)
  284. {
  285. #ifdef CONFIG_NFS_V4
  286. struct vfsmount *mnt = ERR_PTR(-EINVAL);
  287. switch (server->nfs_client->rpc_ops->version) {
  288. case 2:
  289. case 3:
  290. mnt = vfs_kern_mount(&nfs_xdev_fs_type, 0, devname, mountdata);
  291. break;
  292. case 4:
  293. mnt = vfs_kern_mount(&nfs4_xdev_fs_type, 0, devname, mountdata);
  294. }
  295. return mnt;
  296. #else
  297. return vfs_kern_mount(&nfs_xdev_fs_type, 0, devname, mountdata);
  298. #endif
  299. }
  300. /**
  301. * nfs_do_submount - set up mountpoint when crossing a filesystem boundary
  302. * @dentry - parent directory
  303. * @fh - filehandle for new root dentry
  304. * @fattr - attributes for new root inode
  305. * @authflavor - security flavor to use when performing the mount
  306. *
  307. */
  308. static struct vfsmount *nfs_do_submount(struct dentry *dentry,
  309. struct nfs_fh *fh,
  310. struct nfs_fattr *fattr,
  311. rpc_authflavor_t authflavor)
  312. {
  313. struct nfs_clone_mount mountdata = {
  314. .sb = dentry->d_sb,
  315. .dentry = dentry,
  316. .fh = fh,
  317. .fattr = fattr,
  318. .authflavor = authflavor,
  319. };
  320. struct vfsmount *mnt = ERR_PTR(-ENOMEM);
  321. char *page = (char *) __get_free_page(GFP_USER);
  322. char *devname;
  323. dprintk("--> nfs_do_submount()\n");
  324. dprintk("%s: submounting on %s/%s\n", __func__,
  325. dentry->d_parent->d_name.name,
  326. dentry->d_name.name);
  327. if (page == NULL)
  328. goto out;
  329. devname = nfs_devname(dentry, page, PAGE_SIZE);
  330. mnt = (struct vfsmount *)devname;
  331. if (IS_ERR(devname))
  332. goto free_page;
  333. mnt = nfs_do_clone_mount(NFS_SB(dentry->d_sb), devname, &mountdata);
  334. free_page:
  335. free_page((unsigned long)page);
  336. out:
  337. dprintk("%s: done\n", __func__);
  338. dprintk("<-- nfs_do_submount() = %p\n", mnt);
  339. return mnt;
  340. }