xattr.c 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620
  1. /*
  2. File: fs/xattr.c
  3. Extended attribute handling.
  4. Copyright (C) 2001 by Andreas Gruenbacher <a.gruenbacher@computer.org>
  5. Copyright (C) 2001 SGI - Silicon Graphics, Inc <linux-xfs@oss.sgi.com>
  6. Copyright (c) 2004 Red Hat, Inc., James Morris <jmorris@redhat.com>
  7. */
  8. #include <linux/fs.h>
  9. #include <linux/slab.h>
  10. #include <linux/file.h>
  11. #include <linux/xattr.h>
  12. #include <linux/namei.h>
  13. #include <linux/security.h>
  14. #include <linux/syscalls.h>
  15. #include <linux/module.h>
  16. #include <linux/fsnotify.h>
  17. #include <linux/audit.h>
  18. #include <asm/uaccess.h>
  19. /*
  20. * Check permissions for extended attribute access. This is a bit complicated
  21. * because different namespaces have very different rules.
  22. */
  23. static int
  24. xattr_permission(struct inode *inode, const char *name, int mask)
  25. {
  26. /*
  27. * We can never set or remove an extended attribute on a read-only
  28. * filesystem or on an immutable / append-only inode.
  29. */
  30. if (mask & MAY_WRITE) {
  31. if (IS_RDONLY(inode))
  32. return -EROFS;
  33. if (IS_IMMUTABLE(inode) || IS_APPEND(inode))
  34. return -EPERM;
  35. }
  36. /*
  37. * No restriction for security.* and system.* from the VFS. Decision
  38. * on these is left to the underlying filesystem / security module.
  39. */
  40. if (!strncmp(name, XATTR_SECURITY_PREFIX, XATTR_SECURITY_PREFIX_LEN) ||
  41. !strncmp(name, XATTR_SYSTEM_PREFIX, XATTR_SYSTEM_PREFIX_LEN))
  42. return 0;
  43. /*
  44. * The trusted.* namespace can only be accessed by a privileged user.
  45. */
  46. if (!strncmp(name, XATTR_TRUSTED_PREFIX, XATTR_TRUSTED_PREFIX_LEN))
  47. return (capable(CAP_SYS_ADMIN) ? 0 : -EPERM);
  48. /* In user.* namespace, only regular files and directories can have
  49. * extended attributes. For sticky directories, only the owner and
  50. * privileged user can write attributes.
  51. */
  52. if (!strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN)) {
  53. if (!S_ISREG(inode->i_mode) && !S_ISDIR(inode->i_mode))
  54. return -EPERM;
  55. if (S_ISDIR(inode->i_mode) && (inode->i_mode & S_ISVTX) &&
  56. (mask & MAY_WRITE) && !is_owner_or_cap(inode))
  57. return -EPERM;
  58. }
  59. return permission(inode, mask, NULL);
  60. }
  61. int
  62. vfs_setxattr(struct dentry *dentry, char *name, void *value,
  63. size_t size, int flags)
  64. {
  65. struct inode *inode = dentry->d_inode;
  66. int error;
  67. error = xattr_permission(inode, name, MAY_WRITE);
  68. if (error)
  69. return error;
  70. mutex_lock(&inode->i_mutex);
  71. error = security_inode_setxattr(dentry, name, value, size, flags);
  72. if (error)
  73. goto out;
  74. error = -EOPNOTSUPP;
  75. if (inode->i_op->setxattr) {
  76. error = inode->i_op->setxattr(dentry, name, value, size, flags);
  77. if (!error) {
  78. fsnotify_xattr(dentry);
  79. security_inode_post_setxattr(dentry, name, value,
  80. size, flags);
  81. }
  82. } else if (!strncmp(name, XATTR_SECURITY_PREFIX,
  83. XATTR_SECURITY_PREFIX_LEN)) {
  84. const char *suffix = name + XATTR_SECURITY_PREFIX_LEN;
  85. error = security_inode_setsecurity(inode, suffix, value,
  86. size, flags);
  87. if (!error)
  88. fsnotify_xattr(dentry);
  89. }
  90. out:
  91. mutex_unlock(&inode->i_mutex);
  92. return error;
  93. }
  94. EXPORT_SYMBOL_GPL(vfs_setxattr);
  95. ssize_t
  96. vfs_getxattr(struct dentry *dentry, char *name, void *value, size_t size)
  97. {
  98. struct inode *inode = dentry->d_inode;
  99. int error;
  100. error = xattr_permission(inode, name, MAY_READ);
  101. if (error)
  102. return error;
  103. error = security_inode_getxattr(dentry, name);
  104. if (error)
  105. return error;
  106. if (inode->i_op->getxattr)
  107. error = inode->i_op->getxattr(dentry, name, value, size);
  108. else
  109. error = -EOPNOTSUPP;
  110. if (!strncmp(name, XATTR_SECURITY_PREFIX,
  111. XATTR_SECURITY_PREFIX_LEN)) {
  112. const char *suffix = name + XATTR_SECURITY_PREFIX_LEN;
  113. int ret = security_inode_getsecurity(inode, suffix, value,
  114. size, error);
  115. /*
  116. * Only overwrite the return value if a security module
  117. * is actually active.
  118. */
  119. if (ret != -EOPNOTSUPP)
  120. error = ret;
  121. }
  122. return error;
  123. }
  124. EXPORT_SYMBOL_GPL(vfs_getxattr);
  125. ssize_t
  126. vfs_listxattr(struct dentry *d, char *list, size_t size)
  127. {
  128. ssize_t error;
  129. error = security_inode_listxattr(d);
  130. if (error)
  131. return error;
  132. error = -EOPNOTSUPP;
  133. if (d->d_inode->i_op && d->d_inode->i_op->listxattr) {
  134. error = d->d_inode->i_op->listxattr(d, list, size);
  135. } else {
  136. error = security_inode_listsecurity(d->d_inode, list, size);
  137. if (size && error > size)
  138. error = -ERANGE;
  139. }
  140. return error;
  141. }
  142. EXPORT_SYMBOL_GPL(vfs_listxattr);
  143. int
  144. vfs_removexattr(struct dentry *dentry, char *name)
  145. {
  146. struct inode *inode = dentry->d_inode;
  147. int error;
  148. if (!inode->i_op->removexattr)
  149. return -EOPNOTSUPP;
  150. error = xattr_permission(inode, name, MAY_WRITE);
  151. if (error)
  152. return error;
  153. error = security_inode_removexattr(dentry, name);
  154. if (error)
  155. return error;
  156. mutex_lock(&inode->i_mutex);
  157. error = inode->i_op->removexattr(dentry, name);
  158. mutex_unlock(&inode->i_mutex);
  159. if (!error)
  160. fsnotify_xattr(dentry);
  161. return error;
  162. }
  163. EXPORT_SYMBOL_GPL(vfs_removexattr);
  164. /*
  165. * Extended attribute SET operations
  166. */
  167. static long
  168. setxattr(struct dentry *d, char __user *name, void __user *value,
  169. size_t size, int flags)
  170. {
  171. int error;
  172. void *kvalue = NULL;
  173. char kname[XATTR_NAME_MAX + 1];
  174. if (flags & ~(XATTR_CREATE|XATTR_REPLACE))
  175. return -EINVAL;
  176. error = strncpy_from_user(kname, name, sizeof(kname));
  177. if (error == 0 || error == sizeof(kname))
  178. error = -ERANGE;
  179. if (error < 0)
  180. return error;
  181. if (size) {
  182. if (size > XATTR_SIZE_MAX)
  183. return -E2BIG;
  184. kvalue = kmalloc(size, GFP_KERNEL);
  185. if (!kvalue)
  186. return -ENOMEM;
  187. if (copy_from_user(kvalue, value, size)) {
  188. kfree(kvalue);
  189. return -EFAULT;
  190. }
  191. }
  192. error = vfs_setxattr(d, kname, kvalue, size, flags);
  193. kfree(kvalue);
  194. return error;
  195. }
  196. asmlinkage long
  197. sys_setxattr(char __user *path, char __user *name, void __user *value,
  198. size_t size, int flags)
  199. {
  200. struct nameidata nd;
  201. int error;
  202. error = user_path_walk(path, &nd);
  203. if (error)
  204. return error;
  205. error = setxattr(nd.dentry, name, value, size, flags);
  206. path_release(&nd);
  207. return error;
  208. }
  209. asmlinkage long
  210. sys_lsetxattr(char __user *path, char __user *name, void __user *value,
  211. size_t size, int flags)
  212. {
  213. struct nameidata nd;
  214. int error;
  215. error = user_path_walk_link(path, &nd);
  216. if (error)
  217. return error;
  218. error = setxattr(nd.dentry, name, value, size, flags);
  219. path_release(&nd);
  220. return error;
  221. }
  222. asmlinkage long
  223. sys_fsetxattr(int fd, char __user *name, void __user *value,
  224. size_t size, int flags)
  225. {
  226. struct file *f;
  227. struct dentry *dentry;
  228. int error = -EBADF;
  229. f = fget(fd);
  230. if (!f)
  231. return error;
  232. dentry = f->f_path.dentry;
  233. audit_inode(NULL, dentry->d_inode);
  234. error = setxattr(dentry, name, value, size, flags);
  235. fput(f);
  236. return error;
  237. }
  238. /*
  239. * Extended attribute GET operations
  240. */
  241. static ssize_t
  242. getxattr(struct dentry *d, char __user *name, void __user *value, size_t size)
  243. {
  244. ssize_t error;
  245. void *kvalue = NULL;
  246. char kname[XATTR_NAME_MAX + 1];
  247. error = strncpy_from_user(kname, name, sizeof(kname));
  248. if (error == 0 || error == sizeof(kname))
  249. error = -ERANGE;
  250. if (error < 0)
  251. return error;
  252. if (size) {
  253. if (size > XATTR_SIZE_MAX)
  254. size = XATTR_SIZE_MAX;
  255. kvalue = kzalloc(size, GFP_KERNEL);
  256. if (!kvalue)
  257. return -ENOMEM;
  258. }
  259. error = vfs_getxattr(d, kname, kvalue, size);
  260. if (error > 0) {
  261. if (size && copy_to_user(value, kvalue, error))
  262. error = -EFAULT;
  263. } else if (error == -ERANGE && size >= XATTR_SIZE_MAX) {
  264. /* The file system tried to returned a value bigger
  265. than XATTR_SIZE_MAX bytes. Not possible. */
  266. error = -E2BIG;
  267. }
  268. kfree(kvalue);
  269. return error;
  270. }
  271. asmlinkage ssize_t
  272. sys_getxattr(char __user *path, char __user *name, void __user *value,
  273. size_t size)
  274. {
  275. struct nameidata nd;
  276. ssize_t error;
  277. error = user_path_walk(path, &nd);
  278. if (error)
  279. return error;
  280. error = getxattr(nd.dentry, name, value, size);
  281. path_release(&nd);
  282. return error;
  283. }
  284. asmlinkage ssize_t
  285. sys_lgetxattr(char __user *path, char __user *name, void __user *value,
  286. size_t size)
  287. {
  288. struct nameidata nd;
  289. ssize_t error;
  290. error = user_path_walk_link(path, &nd);
  291. if (error)
  292. return error;
  293. error = getxattr(nd.dentry, name, value, size);
  294. path_release(&nd);
  295. return error;
  296. }
  297. asmlinkage ssize_t
  298. sys_fgetxattr(int fd, char __user *name, void __user *value, size_t size)
  299. {
  300. struct file *f;
  301. ssize_t error = -EBADF;
  302. f = fget(fd);
  303. if (!f)
  304. return error;
  305. audit_inode(NULL, f->f_path.dentry->d_inode);
  306. error = getxattr(f->f_path.dentry, name, value, size);
  307. fput(f);
  308. return error;
  309. }
  310. /*
  311. * Extended attribute LIST operations
  312. */
  313. static ssize_t
  314. listxattr(struct dentry *d, char __user *list, size_t size)
  315. {
  316. ssize_t error;
  317. char *klist = NULL;
  318. if (size) {
  319. if (size > XATTR_LIST_MAX)
  320. size = XATTR_LIST_MAX;
  321. klist = kmalloc(size, GFP_KERNEL);
  322. if (!klist)
  323. return -ENOMEM;
  324. }
  325. error = vfs_listxattr(d, klist, size);
  326. if (error > 0) {
  327. if (size && copy_to_user(list, klist, error))
  328. error = -EFAULT;
  329. } else if (error == -ERANGE && size >= XATTR_LIST_MAX) {
  330. /* The file system tried to returned a list bigger
  331. than XATTR_LIST_MAX bytes. Not possible. */
  332. error = -E2BIG;
  333. }
  334. kfree(klist);
  335. return error;
  336. }
  337. asmlinkage ssize_t
  338. sys_listxattr(char __user *path, char __user *list, size_t size)
  339. {
  340. struct nameidata nd;
  341. ssize_t error;
  342. error = user_path_walk(path, &nd);
  343. if (error)
  344. return error;
  345. error = listxattr(nd.dentry, list, size);
  346. path_release(&nd);
  347. return error;
  348. }
  349. asmlinkage ssize_t
  350. sys_llistxattr(char __user *path, char __user *list, size_t size)
  351. {
  352. struct nameidata nd;
  353. ssize_t error;
  354. error = user_path_walk_link(path, &nd);
  355. if (error)
  356. return error;
  357. error = listxattr(nd.dentry, list, size);
  358. path_release(&nd);
  359. return error;
  360. }
  361. asmlinkage ssize_t
  362. sys_flistxattr(int fd, char __user *list, size_t size)
  363. {
  364. struct file *f;
  365. ssize_t error = -EBADF;
  366. f = fget(fd);
  367. if (!f)
  368. return error;
  369. audit_inode(NULL, f->f_path.dentry->d_inode);
  370. error = listxattr(f->f_path.dentry, list, size);
  371. fput(f);
  372. return error;
  373. }
  374. /*
  375. * Extended attribute REMOVE operations
  376. */
  377. static long
  378. removexattr(struct dentry *d, char __user *name)
  379. {
  380. int error;
  381. char kname[XATTR_NAME_MAX + 1];
  382. error = strncpy_from_user(kname, name, sizeof(kname));
  383. if (error == 0 || error == sizeof(kname))
  384. error = -ERANGE;
  385. if (error < 0)
  386. return error;
  387. return vfs_removexattr(d, kname);
  388. }
  389. asmlinkage long
  390. sys_removexattr(char __user *path, char __user *name)
  391. {
  392. struct nameidata nd;
  393. int error;
  394. error = user_path_walk(path, &nd);
  395. if (error)
  396. return error;
  397. error = removexattr(nd.dentry, name);
  398. path_release(&nd);
  399. return error;
  400. }
  401. asmlinkage long
  402. sys_lremovexattr(char __user *path, char __user *name)
  403. {
  404. struct nameidata nd;
  405. int error;
  406. error = user_path_walk_link(path, &nd);
  407. if (error)
  408. return error;
  409. error = removexattr(nd.dentry, name);
  410. path_release(&nd);
  411. return error;
  412. }
  413. asmlinkage long
  414. sys_fremovexattr(int fd, char __user *name)
  415. {
  416. struct file *f;
  417. struct dentry *dentry;
  418. int error = -EBADF;
  419. f = fget(fd);
  420. if (!f)
  421. return error;
  422. dentry = f->f_path.dentry;
  423. audit_inode(NULL, dentry->d_inode);
  424. error = removexattr(dentry, name);
  425. fput(f);
  426. return error;
  427. }
  428. static const char *
  429. strcmp_prefix(const char *a, const char *a_prefix)
  430. {
  431. while (*a_prefix && *a == *a_prefix) {
  432. a++;
  433. a_prefix++;
  434. }
  435. return *a_prefix ? NULL : a;
  436. }
  437. /*
  438. * In order to implement different sets of xattr operations for each xattr
  439. * prefix with the generic xattr API, a filesystem should create a
  440. * null-terminated array of struct xattr_handler (one for each prefix) and
  441. * hang a pointer to it off of the s_xattr field of the superblock.
  442. *
  443. * The generic_fooxattr() functions will use this list to dispatch xattr
  444. * operations to the correct xattr_handler.
  445. */
  446. #define for_each_xattr_handler(handlers, handler) \
  447. for ((handler) = *(handlers)++; \
  448. (handler) != NULL; \
  449. (handler) = *(handlers)++)
  450. /*
  451. * Find the xattr_handler with the matching prefix.
  452. */
  453. static struct xattr_handler *
  454. xattr_resolve_name(struct xattr_handler **handlers, const char **name)
  455. {
  456. struct xattr_handler *handler;
  457. if (!*name)
  458. return NULL;
  459. for_each_xattr_handler(handlers, handler) {
  460. const char *n = strcmp_prefix(*name, handler->prefix);
  461. if (n) {
  462. *name = n;
  463. break;
  464. }
  465. }
  466. return handler;
  467. }
  468. /*
  469. * Find the handler for the prefix and dispatch its get() operation.
  470. */
  471. ssize_t
  472. generic_getxattr(struct dentry *dentry, const char *name, void *buffer, size_t size)
  473. {
  474. struct xattr_handler *handler;
  475. struct inode *inode = dentry->d_inode;
  476. handler = xattr_resolve_name(inode->i_sb->s_xattr, &name);
  477. if (!handler)
  478. return -EOPNOTSUPP;
  479. return handler->get(inode, name, buffer, size);
  480. }
  481. /*
  482. * Combine the results of the list() operation from every xattr_handler in the
  483. * list.
  484. */
  485. ssize_t
  486. generic_listxattr(struct dentry *dentry, char *buffer, size_t buffer_size)
  487. {
  488. struct inode *inode = dentry->d_inode;
  489. struct xattr_handler *handler, **handlers = inode->i_sb->s_xattr;
  490. unsigned int size = 0;
  491. if (!buffer) {
  492. for_each_xattr_handler(handlers, handler)
  493. size += handler->list(inode, NULL, 0, NULL, 0);
  494. } else {
  495. char *buf = buffer;
  496. for_each_xattr_handler(handlers, handler) {
  497. size = handler->list(inode, buf, buffer_size, NULL, 0);
  498. if (size > buffer_size)
  499. return -ERANGE;
  500. buf += size;
  501. buffer_size -= size;
  502. }
  503. size = buf - buffer;
  504. }
  505. return size;
  506. }
  507. /*
  508. * Find the handler for the prefix and dispatch its set() operation.
  509. */
  510. int
  511. generic_setxattr(struct dentry *dentry, const char *name, const void *value, size_t size, int flags)
  512. {
  513. struct xattr_handler *handler;
  514. struct inode *inode = dentry->d_inode;
  515. if (size == 0)
  516. value = ""; /* empty EA, do not remove */
  517. handler = xattr_resolve_name(inode->i_sb->s_xattr, &name);
  518. if (!handler)
  519. return -EOPNOTSUPP;
  520. return handler->set(inode, name, value, size, flags);
  521. }
  522. /*
  523. * Find the handler for the prefix and dispatch its set() operation to remove
  524. * any associated extended attribute.
  525. */
  526. int
  527. generic_removexattr(struct dentry *dentry, const char *name)
  528. {
  529. struct xattr_handler *handler;
  530. struct inode *inode = dentry->d_inode;
  531. handler = xattr_resolve_name(inode->i_sb->s_xattr, &name);
  532. if (!handler)
  533. return -EOPNOTSUPP;
  534. return handler->set(inode, name, NULL, 0, XATTR_REPLACE);
  535. }
  536. EXPORT_SYMBOL(generic_getxattr);
  537. EXPORT_SYMBOL(generic_listxattr);
  538. EXPORT_SYMBOL(generic_setxattr);
  539. EXPORT_SYMBOL(generic_removexattr);