namespace.c 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379
  1. /*
  2. * linux/fs/nfs/namespace.c
  3. *
  4. * Copyright (C) 2005 Trond Myklebust <Trond.Myklebust@netapp.com>
  5. * - Modified by David Howells <dhowells@redhat.com>
  6. *
  7. * NFS namespace
  8. */
  9. #include <linux/dcache.h>
  10. #include <linux/gfp.h>
  11. #include <linux/mount.h>
  12. #include <linux/namei.h>
  13. #include <linux/nfs_fs.h>
  14. #include <linux/string.h>
  15. #include <linux/sunrpc/clnt.h>
  16. #include <linux/vfs.h>
  17. #include <linux/sunrpc/gss_api.h>
  18. #include "internal.h"
  19. #define NFSDBG_FACILITY NFSDBG_VFS
  20. static void nfs_expire_automounts(struct work_struct *work);
  21. static LIST_HEAD(nfs_automount_list);
  22. static DECLARE_DELAYED_WORK(nfs_automount_task, nfs_expire_automounts);
  23. int nfs_mountpoint_expiry_timeout = 500 * HZ;
  24. static struct vfsmount *nfs_do_submount(struct dentry *dentry,
  25. struct nfs_fh *fh,
  26. struct nfs_fattr *fattr,
  27. rpc_authflavor_t authflavor);
  28. /*
  29. * nfs_path - reconstruct the path given an arbitrary dentry
  30. * @base - used to return pointer to the end of devname part of path
  31. * @dentry - pointer to dentry
  32. * @buffer - result buffer
  33. * @buflen - length of buffer
  34. *
  35. * Helper function for constructing the server pathname
  36. * by arbitrary hashed dentry.
  37. *
  38. * This is mainly for use in figuring out the path on the
  39. * server side when automounting on top of an existing partition
  40. * and in generating /proc/mounts and friends.
  41. */
  42. char *nfs_path(char **p, struct dentry *dentry, char *buffer, ssize_t buflen)
  43. {
  44. char *end;
  45. int namelen;
  46. unsigned seq;
  47. const char *base;
  48. rename_retry:
  49. end = buffer+buflen;
  50. *--end = '\0';
  51. buflen--;
  52. seq = read_seqbegin(&rename_lock);
  53. rcu_read_lock();
  54. while (1) {
  55. spin_lock(&dentry->d_lock);
  56. if (IS_ROOT(dentry))
  57. break;
  58. namelen = dentry->d_name.len;
  59. buflen -= namelen + 1;
  60. if (buflen < 0)
  61. goto Elong_unlock;
  62. end -= namelen;
  63. memcpy(end, dentry->d_name.name, namelen);
  64. *--end = '/';
  65. spin_unlock(&dentry->d_lock);
  66. dentry = dentry->d_parent;
  67. }
  68. if (read_seqretry(&rename_lock, seq)) {
  69. spin_unlock(&dentry->d_lock);
  70. rcu_read_unlock();
  71. goto rename_retry;
  72. }
  73. if (*end != '/') {
  74. if (--buflen < 0) {
  75. spin_unlock(&dentry->d_lock);
  76. rcu_read_unlock();
  77. goto Elong;
  78. }
  79. *--end = '/';
  80. }
  81. *p = end;
  82. base = dentry->d_fsdata;
  83. if (!base) {
  84. spin_unlock(&dentry->d_lock);
  85. rcu_read_unlock();
  86. WARN_ON(1);
  87. return end;
  88. }
  89. namelen = strlen(base);
  90. /* Strip off excess slashes in base string */
  91. while (namelen > 0 && base[namelen - 1] == '/')
  92. namelen--;
  93. buflen -= namelen;
  94. if (buflen < 0) {
  95. spin_unlock(&dentry->d_lock);
  96. rcu_read_unlock();
  97. goto Elong;
  98. }
  99. end -= namelen;
  100. memcpy(end, base, namelen);
  101. spin_unlock(&dentry->d_lock);
  102. rcu_read_unlock();
  103. return end;
  104. Elong_unlock:
  105. spin_unlock(&dentry->d_lock);
  106. rcu_read_unlock();
  107. if (read_seqretry(&rename_lock, seq))
  108. goto rename_retry;
  109. Elong:
  110. return ERR_PTR(-ENAMETOOLONG);
  111. }
  112. #ifdef CONFIG_NFS_V4
  113. static rpc_authflavor_t nfs_find_best_sec(struct nfs4_secinfo_flavors *flavors, struct inode *inode)
  114. {
  115. struct gss_api_mech *mech;
  116. struct xdr_netobj oid;
  117. int i;
  118. rpc_authflavor_t pseudoflavor = RPC_AUTH_UNIX;
  119. for (i = 0; i < flavors->num_flavors; i++) {
  120. struct nfs4_secinfo_flavor *flavor;
  121. flavor = &flavors->flavors[i];
  122. if (flavor->flavor == RPC_AUTH_NULL || flavor->flavor == RPC_AUTH_UNIX) {
  123. pseudoflavor = flavor->flavor;
  124. break;
  125. } else if (flavor->flavor == RPC_AUTH_GSS) {
  126. oid.len = flavor->gss.sec_oid4.len;
  127. oid.data = flavor->gss.sec_oid4.data;
  128. mech = gss_mech_get_by_OID(&oid);
  129. if (!mech)
  130. continue;
  131. pseudoflavor = gss_svc_to_pseudoflavor(mech, flavor->gss.service);
  132. gss_mech_put(mech);
  133. break;
  134. }
  135. }
  136. return pseudoflavor;
  137. }
  138. static rpc_authflavor_t nfs_negotiate_security(const struct dentry *parent, const struct dentry *dentry)
  139. {
  140. int status = 0;
  141. struct page *page;
  142. struct nfs4_secinfo_flavors *flavors;
  143. int (*secinfo)(struct inode *, const struct qstr *, struct nfs4_secinfo_flavors *);
  144. rpc_authflavor_t flavor = RPC_AUTH_UNIX;
  145. secinfo = NFS_PROTO(parent->d_inode)->secinfo;
  146. if (secinfo != NULL) {
  147. page = alloc_page(GFP_KERNEL);
  148. if (!page) {
  149. status = -ENOMEM;
  150. goto out;
  151. }
  152. flavors = page_address(page);
  153. status = secinfo(parent->d_inode, &dentry->d_name, flavors);
  154. flavor = nfs_find_best_sec(flavors, dentry->d_inode);
  155. put_page(page);
  156. }
  157. return flavor;
  158. out:
  159. status = -ENOMEM;
  160. return status;
  161. }
  162. static rpc_authflavor_t nfs_lookup_with_sec(struct nfs_server *server, struct dentry *parent,
  163. struct dentry *dentry, struct path *path,
  164. struct nfs_fh *fh, struct nfs_fattr *fattr)
  165. {
  166. rpc_authflavor_t flavor;
  167. struct rpc_clnt *clone;
  168. struct rpc_auth *auth;
  169. int err;
  170. flavor = nfs_negotiate_security(parent, path->dentry);
  171. if (flavor < 0)
  172. goto out;
  173. clone = rpc_clone_client(server->client);
  174. auth = rpcauth_create(flavor, clone);
  175. if (!auth) {
  176. flavor = -EIO;
  177. goto out_shutdown;
  178. }
  179. err = server->nfs_client->rpc_ops->lookup(clone, parent->d_inode,
  180. &path->dentry->d_name,
  181. fh, fattr);
  182. if (err < 0)
  183. flavor = err;
  184. out_shutdown:
  185. rpc_shutdown_client(clone);
  186. out:
  187. return flavor;
  188. }
  189. #else /* CONFIG_NFS_V4 */
  190. static inline rpc_authflavor_t nfs_lookup_with_sec(struct nfs_server *server,
  191. struct dentry *parent, struct dentry *dentry,
  192. struct path *path, struct nfs_fh *fh,
  193. struct nfs_fattr *fattr)
  194. {
  195. return -EPERM;
  196. }
  197. #endif /* CONFIG_NFS_V4 */
  198. /*
  199. * nfs_d_automount - Handle crossing a mountpoint on the server
  200. * @path - The mountpoint
  201. *
  202. * When we encounter a mountpoint on the server, we want to set up
  203. * a mountpoint on the client too, to prevent inode numbers from
  204. * colliding, and to allow "df" to work properly.
  205. * On NFSv4, we also want to allow for the fact that different
  206. * filesystems may be migrated to different servers in a failover
  207. * situation, and that different filesystems may want to use
  208. * different security flavours.
  209. */
  210. struct vfsmount *nfs_d_automount(struct path *path)
  211. {
  212. struct vfsmount *mnt;
  213. struct nfs_server *server = NFS_SERVER(path->dentry->d_inode);
  214. struct dentry *parent;
  215. struct nfs_fh *fh = NULL;
  216. struct nfs_fattr *fattr = NULL;
  217. int err;
  218. rpc_authflavor_t flavor = 1;
  219. dprintk("--> nfs_d_automount()\n");
  220. mnt = ERR_PTR(-ESTALE);
  221. if (IS_ROOT(path->dentry))
  222. goto out_nofree;
  223. mnt = ERR_PTR(-ENOMEM);
  224. fh = nfs_alloc_fhandle();
  225. fattr = nfs_alloc_fattr();
  226. if (fh == NULL || fattr == NULL)
  227. goto out;
  228. dprintk("%s: enter\n", __func__);
  229. /* Look it up again to get its attributes */
  230. parent = dget_parent(path->dentry);
  231. err = server->nfs_client->rpc_ops->lookup(server->client, parent->d_inode,
  232. &path->dentry->d_name,
  233. fh, fattr);
  234. if (err == -EPERM) {
  235. flavor = nfs_lookup_with_sec(server, parent, path->dentry, path, fh, fattr);
  236. if (flavor < 0)
  237. err = flavor;
  238. else
  239. err = 0;
  240. }
  241. dput(parent);
  242. if (err != 0) {
  243. mnt = ERR_PTR(err);
  244. goto out;
  245. }
  246. if (fattr->valid & NFS_ATTR_FATTR_V4_REFERRAL)
  247. mnt = nfs_do_refmount(path->dentry);
  248. else
  249. mnt = nfs_do_submount(path->dentry, fh, fattr, flavor);
  250. if (IS_ERR(mnt))
  251. goto out;
  252. dprintk("%s: done, success\n", __func__);
  253. mntget(mnt); /* prevent immediate expiration */
  254. mnt_set_expiry(mnt, &nfs_automount_list);
  255. schedule_delayed_work(&nfs_automount_task, nfs_mountpoint_expiry_timeout);
  256. out:
  257. nfs_free_fattr(fattr);
  258. nfs_free_fhandle(fh);
  259. out_nofree:
  260. dprintk("<-- nfs_follow_mountpoint() = %p\n", mnt);
  261. return mnt;
  262. }
  263. const struct inode_operations nfs_mountpoint_inode_operations = {
  264. .getattr = nfs_getattr,
  265. };
  266. const struct inode_operations nfs_referral_inode_operations = {
  267. };
  268. static void nfs_expire_automounts(struct work_struct *work)
  269. {
  270. struct list_head *list = &nfs_automount_list;
  271. mark_mounts_for_expiry(list);
  272. if (!list_empty(list))
  273. schedule_delayed_work(&nfs_automount_task, nfs_mountpoint_expiry_timeout);
  274. }
  275. void nfs_release_automount_timer(void)
  276. {
  277. if (list_empty(&nfs_automount_list))
  278. cancel_delayed_work(&nfs_automount_task);
  279. }
  280. /*
  281. * Clone a mountpoint of the appropriate type
  282. */
  283. static struct vfsmount *nfs_do_clone_mount(struct nfs_server *server,
  284. const char *devname,
  285. struct nfs_clone_mount *mountdata)
  286. {
  287. #ifdef CONFIG_NFS_V4
  288. struct vfsmount *mnt = ERR_PTR(-EINVAL);
  289. switch (server->nfs_client->rpc_ops->version) {
  290. case 2:
  291. case 3:
  292. mnt = vfs_kern_mount(&nfs_xdev_fs_type, 0, devname, mountdata);
  293. break;
  294. case 4:
  295. mnt = vfs_kern_mount(&nfs4_xdev_fs_type, 0, devname, mountdata);
  296. }
  297. return mnt;
  298. #else
  299. return vfs_kern_mount(&nfs_xdev_fs_type, 0, devname, mountdata);
  300. #endif
  301. }
  302. /**
  303. * nfs_do_submount - set up mountpoint when crossing a filesystem boundary
  304. * @dentry - parent directory
  305. * @fh - filehandle for new root dentry
  306. * @fattr - attributes for new root inode
  307. * @authflavor - security flavor to use when performing the mount
  308. *
  309. */
  310. static struct vfsmount *nfs_do_submount(struct dentry *dentry,
  311. struct nfs_fh *fh,
  312. struct nfs_fattr *fattr,
  313. rpc_authflavor_t authflavor)
  314. {
  315. struct nfs_clone_mount mountdata = {
  316. .sb = dentry->d_sb,
  317. .dentry = dentry,
  318. .fh = fh,
  319. .fattr = fattr,
  320. .authflavor = authflavor,
  321. };
  322. struct vfsmount *mnt = ERR_PTR(-ENOMEM);
  323. char *page = (char *) __get_free_page(GFP_USER);
  324. char *devname;
  325. dprintk("--> nfs_do_submount()\n");
  326. dprintk("%s: submounting on %s/%s\n", __func__,
  327. dentry->d_parent->d_name.name,
  328. dentry->d_name.name);
  329. if (page == NULL)
  330. goto out;
  331. devname = nfs_devname(dentry, page, PAGE_SIZE);
  332. mnt = (struct vfsmount *)devname;
  333. if (IS_ERR(devname))
  334. goto free_page;
  335. mnt = nfs_do_clone_mount(NFS_SB(dentry->d_sb), devname, &mountdata);
  336. free_page:
  337. free_page((unsigned long)page);
  338. out:
  339. dprintk("%s: done\n", __func__);
  340. dprintk("<-- nfs_do_submount() = %p\n", mnt);
  341. return mnt;
  342. }