1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  *   Copyright (C) 2016 Namjae Jeon <linkinjeon@kernel.org>
4  *   Copyright (C) 2018 Samsung Electronics Co., Ltd.
5  */
6 
7 #include <crypto/sha2.h>
8 #include <linux/kernel.h>
9 #include <linux/fs.h>
10 #include <linux/filelock.h>
11 #include <linux/uaccess.h>
12 #include <linux/backing-dev.h>
13 #include <linux/writeback.h>
14 #include <linux/xattr.h>
15 #include <linux/falloc.h>
16 #include <linux/fsnotify.h>
17 #include <linux/dcache.h>
18 #include <linux/slab.h>
19 #include <linux/vmalloc.h>
20 #include <linux/sched/xacct.h>
21 #include <linux/crc32c.h>
22 #include <linux/namei.h>
23 
24 #include "glob.h"
25 #include "oplock.h"
26 #include "connection.h"
27 #include "vfs.h"
28 #include "vfs_cache.h"
29 #include "smbacl.h"
30 #include "ndr.h"
31 #include "auth.h"
32 #include "misc.h"
33 
34 #include "smb_common.h"
35 #include "mgmt/share_config.h"
36 #include "mgmt/tree_connect.h"
37 #include "mgmt/user_session.h"
38 #include "mgmt/user_config.h"
39 
40 static void ksmbd_vfs_inherit_owner(struct ksmbd_work *work,
41 				    struct inode *parent_inode,
42 				    struct inode *inode)
43 {
44 	if (!test_share_config_flag(work->tcon->share_conf,
45 				    KSMBD_SHARE_FLAG_INHERIT_OWNER))
46 		return;
47 
48 	i_uid_write(inode, i_uid_read(parent_inode));
49 }
50 
51 /**
52  * ksmbd_vfs_lock_parent() - lock parent dentry if it is stable
53  * @parent: parent dentry
54  * @child: child dentry
55  *
56  * Returns: %0 on success, %-ENOENT if the parent dentry is not stable
57  */
58 int ksmbd_vfs_lock_parent(struct dentry *parent, struct dentry *child)
59 {
60 	inode_lock_nested(d_inode(parent), I_MUTEX_PARENT);
61 	if (child->d_parent != parent) {
62 		inode_unlock(d_inode(parent));
63 		return -ENOENT;
64 	}
65 
66 	return 0;
67 }
68 
69 static int ksmbd_vfs_path_lookup_locked(struct ksmbd_share_config *share_conf,
70 					char *pathname, unsigned int flags,
71 					struct path *parent_path,
72 					struct path *path)
73 {
74 	struct qstr last;
75 	struct filename *filename;
76 	struct path *root_share_path = &share_conf->vfs_path;
77 	int err, type;
78 	struct dentry *d;
79 
80 	if (pathname[0] == '\0') {
81 		pathname = share_conf->path;
82 		root_share_path = NULL;
83 	} else {
84 		flags |= LOOKUP_BENEATH;
85 	}
86 
87 	filename = getname_kernel(pathname);
88 	if (IS_ERR(filename))
89 		return PTR_ERR(filename);
90 
91 	err = vfs_path_parent_lookup(filename, flags,
92 				     parent_path, &last, &type,
93 				     root_share_path);
94 	if (err) {
95 		putname(filename);
96 		return err;
97 	}
98 
99 	if (unlikely(type != LAST_NORM)) {
100 		path_put(parent_path);
101 		putname(filename);
102 		return -ENOENT;
103 	}
104 
105 	err = mnt_want_write(parent_path->mnt);
106 	if (err) {
107 		path_put(parent_path);
108 		putname(filename);
109 		return -ENOENT;
110 	}
111 
112 	inode_lock_nested(parent_path->dentry->d_inode, I_MUTEX_PARENT);
113 	d = lookup_one_qstr_excl(&last, parent_path->dentry, 0);
114 	if (IS_ERR(d))
115 		goto err_out;
116 
117 	path->dentry = d;
118 	path->mnt = mntget(parent_path->mnt);
119 
120 	if (test_share_config_flag(share_conf, KSMBD_SHARE_FLAG_CROSSMNT)) {
121 		err = follow_down(path, 0);
122 		if (err < 0) {
123 			path_put(path);
124 			goto err_out;
125 		}
126 	}
127 
128 	putname(filename);
129 	return 0;
130 
131 err_out:
132 	inode_unlock(d_inode(parent_path->dentry));
133 	mnt_drop_write(parent_path->mnt);
134 	path_put(parent_path);
135 	putname(filename);
136 	return -ENOENT;
137 }
138 
139 void ksmbd_vfs_query_maximal_access(struct mnt_idmap *idmap,
140 				   struct dentry *dentry, __le32 *daccess)
141 {
142 	*daccess = cpu_to_le32(FILE_READ_ATTRIBUTES | READ_CONTROL);
143 
144 	if (!inode_permission(idmap, d_inode(dentry), MAY_OPEN | MAY_WRITE))
145 		*daccess |= cpu_to_le32(WRITE_DAC | WRITE_OWNER | SYNCHRONIZE |
146 				FILE_WRITE_DATA | FILE_APPEND_DATA |
147 				FILE_WRITE_EA | FILE_WRITE_ATTRIBUTES |
148 				FILE_DELETE_CHILD);
149 
150 	if (!inode_permission(idmap, d_inode(dentry), MAY_OPEN | MAY_READ))
151 		*daccess |= FILE_READ_DATA_LE | FILE_READ_EA_LE;
152 
153 	if (!inode_permission(idmap, d_inode(dentry), MAY_OPEN | MAY_EXEC))
154 		*daccess |= FILE_EXECUTE_LE;
155 
156 	if (!inode_permission(idmap, d_inode(dentry->d_parent), MAY_EXEC | MAY_WRITE))
157 		*daccess |= FILE_DELETE_LE;
158 }
159 
160 /**
161  * ksmbd_vfs_create() - vfs helper for smb create file
162  * @work:	work
163  * @name:	file name that is relative to share
164  * @mode:	file create mode
165  *
166  * Return:	0 on success, otherwise error
167  */
168 int ksmbd_vfs_create(struct ksmbd_work *work, const char *name, umode_t mode)
169 {
170 	struct path path;
171 	struct dentry *dentry;
172 	int err;
173 
174 	dentry = ksmbd_vfs_kern_path_create(work, name,
175 					    LOOKUP_NO_SYMLINKS, &path);
176 	if (IS_ERR(dentry)) {
177 		err = PTR_ERR(dentry);
178 		if (err != -ENOENT)
179 			pr_err("path create failed for %s, err %d\n",
180 			       name, err);
181 		return err;
182 	}
183 
184 	mode |= S_IFREG;
185 	err = vfs_create(mnt_idmap(path.mnt), d_inode(path.dentry),
186 			 dentry, mode, true);
187 	if (!err) {
188 		ksmbd_vfs_inherit_owner(work, d_inode(path.dentry),
189 					d_inode(dentry));
190 	} else {
191 		pr_err("File(%s): creation failed (err:%d)\n", name, err);
192 	}
193 
194 	done_path_create(&path, dentry);
195 	return err;
196 }
197 
198 /**
199  * ksmbd_vfs_mkdir() - vfs helper for smb create directory
200  * @work:	work
201  * @name:	directory name that is relative to share
202  * @mode:	directory create mode
203  *
204  * Return:	0 on success, otherwise error
205  */
206 int ksmbd_vfs_mkdir(struct ksmbd_work *work, const char *name, umode_t mode)
207 {
208 	struct mnt_idmap *idmap;
209 	struct path path;
210 	struct dentry *dentry, *d;
211 	int err = 0;
212 
213 	dentry = ksmbd_vfs_kern_path_create(work, name,
214 					    LOOKUP_NO_SYMLINKS | LOOKUP_DIRECTORY,
215 					    &path);
216 	if (IS_ERR(dentry)) {
217 		err = PTR_ERR(dentry);
218 		if (err != -EEXIST)
219 			ksmbd_debug(VFS, "path create failed for %s, err %d\n",
220 				    name, err);
221 		return err;
222 	}
223 
224 	idmap = mnt_idmap(path.mnt);
225 	mode |= S_IFDIR;
226 	d = dentry;
227 	dentry = vfs_mkdir(idmap, d_inode(path.dentry), dentry, mode);
228 	if (IS_ERR(dentry))
229 		err = PTR_ERR(dentry);
230 	else if (d_is_negative(dentry))
231 		err = -ENOENT;
232 	if (!err && dentry != d)
233 		ksmbd_vfs_inherit_owner(work, d_inode(path.dentry), d_inode(dentry));
234 
235 	done_path_create(&path, dentry);
236 	if (err)
237 		pr_err("mkdir(%s): creation failed (err:%d)\n", name, err);
238 	return err;
239 }
240 
241 static ssize_t ksmbd_vfs_getcasexattr(struct mnt_idmap *idmap,
242 				      struct dentry *dentry, char *attr_name,
243 				      int attr_name_len, char **attr_value)
244 {
245 	char *name, *xattr_list = NULL;
246 	ssize_t value_len = -ENOENT, xattr_list_len;
247 
248 	xattr_list_len = ksmbd_vfs_listxattr(dentry, &xattr_list);
249 	if (xattr_list_len <= 0)
250 		goto out;
251 
252 	for (name = xattr_list; name - xattr_list < xattr_list_len;
253 			name += strlen(name) + 1) {
254 		ksmbd_debug(VFS, "%s, len %zd\n", name, strlen(name));
255 		if (strncasecmp(attr_name, name, attr_name_len))
256 			continue;
257 
258 		value_len = ksmbd_vfs_getxattr(idmap,
259 					       dentry,
260 					       name,
261 					       attr_value);
262 		if (value_len < 0)
263 			pr_err("failed to get xattr in file\n");
264 		break;
265 	}
266 
267 out:
268 	kvfree(xattr_list);
269 	return value_len;
270 }
271 
272 static int ksmbd_vfs_stream_read(struct ksmbd_file *fp, char *buf, loff_t *pos,
273 				 size_t count)
274 {
275 	ssize_t v_len;
276 	char *stream_buf = NULL;
277 
278 	ksmbd_debug(VFS, "read stream data pos : %llu, count : %zd\n",
279 		    *pos, count);
280 
281 	v_len = ksmbd_vfs_getcasexattr(file_mnt_idmap(fp->filp),
282 				       fp->filp->f_path.dentry,
283 				       fp->stream.name,
284 				       fp->stream.size,
285 				       &stream_buf);
286 	if ((int)v_len <= 0)
287 		return (int)v_len;
288 
289 	if (v_len <= *pos) {
290 		count = -EINVAL;
291 		goto free_buf;
292 	}
293 
294 	if (v_len - *pos < count)
295 		count = v_len - *pos;
296 
297 	memcpy(buf, &stream_buf[*pos], count);
298 
299 free_buf:
300 	kvfree(stream_buf);
301 	return count;
302 }
303 
304 /**
305  * check_lock_range() - vfs helper for smb byte range file locking
306  * @filp:	the file to apply the lock to
307  * @start:	lock start byte offset
308  * @end:	lock end byte offset
309  * @type:	byte range type read/write
310  *
311  * Return:	0 on success, otherwise error
312  */
313 static int check_lock_range(struct file *filp, loff_t start, loff_t end,
314 			    unsigned char type)
315 {
316 	struct file_lock *flock;
317 	struct file_lock_context *ctx = locks_inode_context(file_inode(filp));
318 	int error = 0;
319 
320 	if (!ctx || list_empty_careful(&ctx->flc_posix))
321 		return 0;
322 
323 	spin_lock(&ctx->flc_lock);
324 	for_each_file_lock(flock, &ctx->flc_posix) {
325 		/* check conflict locks */
326 		if (flock->fl_end >= start && end >= flock->fl_start) {
327 			if (lock_is_read(flock)) {
328 				if (type == WRITE) {
329 					pr_err("not allow write by shared lock\n");
330 					error = 1;
331 					goto out;
332 				}
333 			} else if (lock_is_write(flock)) {
334 				/* check owner in lock */
335 				if (flock->c.flc_file != filp) {
336 					error = 1;
337 					pr_err("not allow rw access by exclusive lock from other opens\n");
338 					goto out;
339 				}
340 			}
341 		}
342 	}
343 out:
344 	spin_unlock(&ctx->flc_lock);
345 	return error;
346 }
347 
348 /**
349  * ksmbd_vfs_read() - vfs helper for smb file read
350  * @work:	smb work
351  * @fp:		ksmbd file pointer
352  * @count:	read byte count
353  * @pos:	file pos
354  * @rbuf:	read data buffer
355  *
356  * Return:	number of read bytes on success, otherwise error
357  */
358 int ksmbd_vfs_read(struct ksmbd_work *work, struct ksmbd_file *fp, size_t count,
359 		   loff_t *pos, char *rbuf)
360 {
361 	struct file *filp = fp->filp;
362 	ssize_t nbytes = 0;
363 	struct inode *inode = file_inode(filp);
364 
365 	if (S_ISDIR(inode->i_mode))
366 		return -EISDIR;
367 
368 	if (unlikely(count == 0))
369 		return 0;
370 
371 	if (work->conn->connection_type) {
372 		if (!(fp->daccess & (FILE_READ_DATA_LE | FILE_EXECUTE_LE))) {
373 			pr_err("no right to read(%pD)\n", fp->filp);
374 			return -EACCES;
375 		}
376 	}
377 
378 	if (ksmbd_stream_fd(fp))
379 		return ksmbd_vfs_stream_read(fp, rbuf, pos, count);
380 
381 	if (!work->tcon->posix_extensions) {
382 		int ret;
383 
384 		ret = check_lock_range(filp, *pos, *pos + count - 1, READ);
385 		if (ret) {
386 			pr_err("unable to read due to lock\n");
387 			return -EAGAIN;
388 		}
389 	}
390 
391 	nbytes = kernel_read(filp, rbuf, count, pos);
392 	if (nbytes < 0) {
393 		pr_err("smb read failed, err = %zd\n", nbytes);
394 		return nbytes;
395 	}
396 
397 	filp->f_pos = *pos;
398 	return nbytes;
399 }
400 
401 static int ksmbd_vfs_stream_write(struct ksmbd_file *fp, char *buf, loff_t *pos,
402 				  size_t count)
403 {
404 	char *stream_buf = NULL, *wbuf;
405 	struct mnt_idmap *idmap = file_mnt_idmap(fp->filp);
406 	size_t size;
407 	ssize_t v_len;
408 	int err = 0;
409 
410 	ksmbd_debug(VFS, "write stream data pos : %llu, count : %zd\n",
411 		    *pos, count);
412 
413 	if (*pos >= XATTR_SIZE_MAX) {
414 		pr_err("stream write position %lld is out of bounds\n",	*pos);
415 		return -EINVAL;
416 	}
417 
418 	size = *pos + count;
419 	if (size > XATTR_SIZE_MAX) {
420 		size = XATTR_SIZE_MAX;
421 		count = XATTR_SIZE_MAX - *pos;
422 	}
423 
424 	v_len = ksmbd_vfs_getcasexattr(idmap,
425 				       fp->filp->f_path.dentry,
426 				       fp->stream.name,
427 				       fp->stream.size,
428 				       &stream_buf);
429 	if (v_len < 0) {
430 		pr_err("not found stream in xattr : %zd\n", v_len);
431 		err = v_len;
432 		goto out;
433 	}
434 
435 	if (v_len < size) {
436 		wbuf = kvzalloc(size, KSMBD_DEFAULT_GFP);
437 		if (!wbuf) {
438 			err = -ENOMEM;
439 			goto out;
440 		}
441 
442 		if (v_len > 0)
443 			memcpy(wbuf, stream_buf, v_len);
444 		kvfree(stream_buf);
445 		stream_buf = wbuf;
446 	}
447 
448 	memcpy(&stream_buf[*pos], buf, count);
449 
450 	err = ksmbd_vfs_setxattr(idmap,
451 				 &fp->filp->f_path,
452 				 fp->stream.name,
453 				 (void *)stream_buf,
454 				 size,
455 				 0,
456 				 true);
457 	if (err < 0)
458 		goto out;
459 
460 	fp->filp->f_pos = *pos;
461 	err = 0;
462 out:
463 	kvfree(stream_buf);
464 	return err;
465 }
466 
467 /**
468  * ksmbd_vfs_write() - vfs helper for smb file write
469  * @work:	work
470  * @fp:		ksmbd file pointer
471  * @buf:	buf containing data for writing
472  * @count:	read byte count
473  * @pos:	file pos
474  * @sync:	fsync after write
475  * @written:	number of bytes written
476  *
477  * Return:	0 on success, otherwise error
478  */
479 int ksmbd_vfs_write(struct ksmbd_work *work, struct ksmbd_file *fp,
480 		    char *buf, size_t count, loff_t *pos, bool sync,
481 		    ssize_t *written)
482 {
483 	struct file *filp;
484 	loff_t	offset = *pos;
485 	int err = 0;
486 
487 	if (work->conn->connection_type) {
488 		if (!(fp->daccess & (FILE_WRITE_DATA_LE | FILE_APPEND_DATA_LE)) ||
489 		    S_ISDIR(file_inode(fp->filp)->i_mode)) {
490 			pr_err("no right to write(%pD)\n", fp->filp);
491 			err = -EACCES;
492 			goto out;
493 		}
494 	}
495 
496 	filp = fp->filp;
497 
498 	if (ksmbd_stream_fd(fp)) {
499 		err = ksmbd_vfs_stream_write(fp, buf, pos, count);
500 		if (!err)
501 			*written = count;
502 		goto out;
503 	}
504 
505 	if (!work->tcon->posix_extensions) {
506 		err = check_lock_range(filp, *pos, *pos + count - 1, WRITE);
507 		if (err) {
508 			pr_err("unable to write due to lock\n");
509 			err = -EAGAIN;
510 			goto out;
511 		}
512 	}
513 
514 	/* Reserve lease break for parent dir at closing time */
515 	fp->reserve_lease_break = true;
516 
517 	/* Do we need to break any of a levelII oplock? */
518 	smb_break_all_levII_oplock(work, fp, 1);
519 
520 	err = kernel_write(filp, buf, count, pos);
521 	if (err < 0) {
522 		ksmbd_debug(VFS, "smb write failed, err = %d\n", err);
523 		goto out;
524 	}
525 
526 	filp->f_pos = *pos;
527 	*written = err;
528 	err = 0;
529 	if (sync) {
530 		err = vfs_fsync_range(filp, offset, offset + *written, 0);
531 		if (err < 0)
532 			pr_err("fsync failed for filename = %pD, err = %d\n",
533 			       fp->filp, err);
534 	}
535 
536 out:
537 	return err;
538 }
539 
540 /**
541  * ksmbd_vfs_getattr() - vfs helper for smb getattr
542  * @path:	path of dentry
543  * @stat:	pointer to returned kernel stat structure
544  * Return:	0 on success, otherwise error
545  */
546 int ksmbd_vfs_getattr(const struct path *path, struct kstat *stat)
547 {
548 	int err;
549 
550 	err = vfs_getattr(path, stat, STATX_BTIME, AT_STATX_SYNC_AS_STAT);
551 	if (err)
552 		pr_err("getattr failed, err %d\n", err);
553 	return err;
554 }
555 
556 /**
557  * ksmbd_vfs_fsync() - vfs helper for smb fsync
558  * @work:	work
559  * @fid:	file id of open file
560  * @p_id:	persistent file id
561  *
562  * Return:	0 on success, otherwise error
563  */
564 int ksmbd_vfs_fsync(struct ksmbd_work *work, u64 fid, u64 p_id)
565 {
566 	struct ksmbd_file *fp;
567 	int err;
568 
569 	fp = ksmbd_lookup_fd_slow(work, fid, p_id);
570 	if (!fp) {
571 		pr_err("failed to get filp for fid %llu\n", fid);
572 		return -ENOENT;
573 	}
574 	err = vfs_fsync(fp->filp, 0);
575 	if (err < 0)
576 		pr_err("smb fsync failed, err = %d\n", err);
577 	ksmbd_fd_put(work, fp);
578 	return err;
579 }
580 
581 /**
582  * ksmbd_vfs_remove_file() - vfs helper for smb rmdir or unlink
583  * @work:	work
584  * @path:	path of dentry
585  *
586  * Return:	0 on success, otherwise error
587  */
588 int ksmbd_vfs_remove_file(struct ksmbd_work *work, const struct path *path)
589 {
590 	struct mnt_idmap *idmap;
591 	struct dentry *parent = path->dentry->d_parent;
592 	int err;
593 
594 	if (ksmbd_override_fsids(work))
595 		return -ENOMEM;
596 
597 	if (!d_inode(path->dentry)->i_nlink) {
598 		err = -ENOENT;
599 		goto out_err;
600 	}
601 
602 	idmap = mnt_idmap(path->mnt);
603 	if (S_ISDIR(d_inode(path->dentry)->i_mode)) {
604 		err = vfs_rmdir(idmap, d_inode(parent), path->dentry);
605 		if (err && err != -ENOTEMPTY)
606 			ksmbd_debug(VFS, "rmdir failed, err %d\n", err);
607 	} else {
608 		err = vfs_unlink(idmap, d_inode(parent), path->dentry, NULL);
609 		if (err)
610 			ksmbd_debug(VFS, "unlink failed, err %d\n", err);
611 	}
612 
613 out_err:
614 	ksmbd_revert_fsids(work);
615 	return err;
616 }
617 
618 /**
619  * ksmbd_vfs_link() - vfs helper for creating smb hardlink
620  * @work:	work
621  * @oldname:	source file name
622  * @newname:	hardlink name that is relative to share
623  *
624  * Return:	0 on success, otherwise error
625  */
626 int ksmbd_vfs_link(struct ksmbd_work *work, const char *oldname,
627 		   const char *newname)
628 {
629 	struct path oldpath, newpath;
630 	struct dentry *dentry;
631 	int err;
632 
633 	if (ksmbd_override_fsids(work))
634 		return -ENOMEM;
635 
636 	err = kern_path(oldname, LOOKUP_NO_SYMLINKS, &oldpath);
637 	if (err) {
638 		pr_err("cannot get linux path for %s, err = %d\n",
639 		       oldname, err);
640 		goto out1;
641 	}
642 
643 	dentry = ksmbd_vfs_kern_path_create(work, newname,
644 					    LOOKUP_NO_SYMLINKS | LOOKUP_REVAL,
645 					    &newpath);
646 	if (IS_ERR(dentry)) {
647 		err = PTR_ERR(dentry);
648 		pr_err("path create err for %s, err %d\n", newname, err);
649 		goto out2;
650 	}
651 
652 	err = -EXDEV;
653 	if (oldpath.mnt != newpath.mnt) {
654 		pr_err("vfs_link failed err %d\n", err);
655 		goto out3;
656 	}
657 
658 	err = vfs_link(oldpath.dentry, mnt_idmap(newpath.mnt),
659 		       d_inode(newpath.dentry),
660 		       dentry, NULL);
661 	if (err)
662 		ksmbd_debug(VFS, "vfs_link failed err %d\n", err);
663 
664 out3:
665 	done_path_create(&newpath, dentry);
666 out2:
667 	path_put(&oldpath);
668 out1:
669 	ksmbd_revert_fsids(work);
670 	return err;
671 }
672 
673 int ksmbd_vfs_rename(struct ksmbd_work *work, const struct path *old_path,
674 		     char *newname, int flags)
675 {
676 	struct dentry *old_parent, *new_dentry, *trap;
677 	struct dentry *old_child = old_path->dentry;
678 	struct path new_path;
679 	struct qstr new_last;
680 	struct renamedata rd;
681 	struct filename *to;
682 	struct ksmbd_share_config *share_conf = work->tcon->share_conf;
683 	struct ksmbd_file *parent_fp;
684 	int new_type;
685 	int err, lookup_flags = LOOKUP_NO_SYMLINKS;
686 	int target_lookup_flags = LOOKUP_RENAME_TARGET | LOOKUP_CREATE;
687 
688 	if (ksmbd_override_fsids(work))
689 		return -ENOMEM;
690 
691 	to = getname_kernel(newname);
692 	if (IS_ERR(to)) {
693 		err = PTR_ERR(to);
694 		goto revert_fsids;
695 	}
696 
697 	/*
698 	 * explicitly handle file overwrite case, for compatibility with
699 	 * filesystems that may not support rename flags (e.g: fuse)
700 	 */
701 	if (flags & RENAME_NOREPLACE)
702 		target_lookup_flags |= LOOKUP_EXCL;
703 	flags &= ~(RENAME_NOREPLACE);
704 
705 retry:
706 	err = vfs_path_parent_lookup(to, lookup_flags | LOOKUP_BENEATH,
707 				     &new_path, &new_last, &new_type,
708 				     &share_conf->vfs_path);
709 	if (err)
710 		goto out1;
711 
712 	if (old_path->mnt != new_path.mnt) {
713 		err = -EXDEV;
714 		goto out2;
715 	}
716 
717 	err = mnt_want_write(old_path->mnt);
718 	if (err)
719 		goto out2;
720 
721 	trap = lock_rename_child(old_child, new_path.dentry);
722 	if (IS_ERR(trap)) {
723 		err = PTR_ERR(trap);
724 		goto out_drop_write;
725 	}
726 
727 	old_parent = dget(old_child->d_parent);
728 	if (d_unhashed(old_child)) {
729 		err = -EINVAL;
730 		goto out3;
731 	}
732 
733 	parent_fp = ksmbd_lookup_fd_inode(old_child->d_parent);
734 	if (parent_fp) {
735 		if (parent_fp->daccess & FILE_DELETE_LE) {
736 			pr_err("parent dir is opened with delete access\n");
737 			err = -ESHARE;
738 			ksmbd_fd_put(work, parent_fp);
739 			goto out3;
740 		}
741 		ksmbd_fd_put(work, parent_fp);
742 	}
743 
744 	new_dentry = lookup_one_qstr_excl(&new_last, new_path.dentry,
745 					  lookup_flags | target_lookup_flags);
746 	if (IS_ERR(new_dentry)) {
747 		err = PTR_ERR(new_dentry);
748 		goto out3;
749 	}
750 
751 	if (d_is_symlink(new_dentry)) {
752 		err = -EACCES;
753 		goto out4;
754 	}
755 
756 	if (old_child == trap) {
757 		err = -EINVAL;
758 		goto out4;
759 	}
760 
761 	if (new_dentry == trap) {
762 		err = -ENOTEMPTY;
763 		goto out4;
764 	}
765 
766 	rd.old_mnt_idmap	= mnt_idmap(old_path->mnt),
767 	rd.old_dir		= d_inode(old_parent),
768 	rd.old_dentry		= old_child,
769 	rd.new_mnt_idmap	= mnt_idmap(new_path.mnt),
770 	rd.new_dir		= new_path.dentry->d_inode,
771 	rd.new_dentry		= new_dentry,
772 	rd.flags		= flags,
773 	rd.delegated_inode	= NULL,
774 	err = vfs_rename(&rd);
775 	if (err)
776 		ksmbd_debug(VFS, "vfs_rename failed err %d\n", err);
777 
778 out4:
779 	dput(new_dentry);
780 out3:
781 	dput(old_parent);
782 	unlock_rename(old_parent, new_path.dentry);
783 out_drop_write:
784 	mnt_drop_write(old_path->mnt);
785 out2:
786 	path_put(&new_path);
787 
788 	if (retry_estale(err, lookup_flags)) {
789 		lookup_flags |= LOOKUP_REVAL;
790 		goto retry;
791 	}
792 out1:
793 	putname(to);
794 revert_fsids:
795 	ksmbd_revert_fsids(work);
796 	return err;
797 }
798 
799 /**
800  * ksmbd_vfs_truncate() - vfs helper for smb file truncate
801  * @work:	work
802  * @fp:		ksmbd file pointer
803  * @size:	truncate to given size
804  *
805  * Return:	0 on success, otherwise error
806  */
807 int ksmbd_vfs_truncate(struct ksmbd_work *work,
808 		       struct ksmbd_file *fp, loff_t size)
809 {
810 	int err = 0;
811 	struct file *filp;
812 
813 	filp = fp->filp;
814 
815 	/* Do we need to break any of a levelII oplock? */
816 	smb_break_all_levII_oplock(work, fp, 1);
817 
818 	if (!work->tcon->posix_extensions) {
819 		struct inode *inode = file_inode(filp);
820 
821 		if (size < inode->i_size) {
822 			err = check_lock_range(filp, size,
823 					       inode->i_size - 1, WRITE);
824 		} else {
825 			err = check_lock_range(filp, inode->i_size,
826 					       size - 1, WRITE);
827 		}
828 
829 		if (err) {
830 			pr_err("failed due to lock\n");
831 			return -EAGAIN;
832 		}
833 	}
834 
835 	err = vfs_truncate(&filp->f_path, size);
836 	if (err)
837 		pr_err("truncate failed, err %d\n", err);
838 	return err;
839 }
840 
841 /**
842  * ksmbd_vfs_listxattr() - vfs helper for smb list extended attributes
843  * @dentry:	dentry of file for listing xattrs
844  * @list:	destination buffer
845  *
846  * Return:	xattr list length on success, otherwise error
847  */
848 ssize_t ksmbd_vfs_listxattr(struct dentry *dentry, char **list)
849 {
850 	ssize_t size;
851 	char *vlist = NULL;
852 
853 	size = vfs_listxattr(dentry, NULL, 0);
854 	if (size <= 0)
855 		return size;
856 
857 	vlist = kvzalloc(size, KSMBD_DEFAULT_GFP);
858 	if (!vlist)
859 		return -ENOMEM;
860 
861 	*list = vlist;
862 	size = vfs_listxattr(dentry, vlist, size);
863 	if (size < 0) {
864 		ksmbd_debug(VFS, "listxattr failed\n");
865 		kvfree(vlist);
866 		*list = NULL;
867 	}
868 
869 	return size;
870 }
871 
872 static ssize_t ksmbd_vfs_xattr_len(struct mnt_idmap *idmap,
873 				   struct dentry *dentry, char *xattr_name)
874 {
875 	return vfs_getxattr(idmap, dentry, xattr_name, NULL, 0);
876 }
877 
878 /**
879  * ksmbd_vfs_getxattr() - vfs helper for smb get extended attributes value
880  * @idmap:	idmap
881  * @dentry:	dentry of file for getting xattrs
882  * @xattr_name:	name of xattr name to query
883  * @xattr_buf:	destination buffer xattr value
884  *
885  * Return:	read xattr value length on success, otherwise error
886  */
887 ssize_t ksmbd_vfs_getxattr(struct mnt_idmap *idmap,
888 			   struct dentry *dentry,
889 			   char *xattr_name, char **xattr_buf)
890 {
891 	ssize_t xattr_len;
892 	char *buf;
893 
894 	*xattr_buf = NULL;
895 	xattr_len = ksmbd_vfs_xattr_len(idmap, dentry, xattr_name);
896 	if (xattr_len < 0)
897 		return xattr_len;
898 
899 	buf = kmalloc(xattr_len + 1, KSMBD_DEFAULT_GFP);
900 	if (!buf)
901 		return -ENOMEM;
902 
903 	xattr_len = vfs_getxattr(idmap, dentry, xattr_name,
904 				 (void *)buf, xattr_len);
905 	if (xattr_len > 0)
906 		*xattr_buf = buf;
907 	else
908 		kfree(buf);
909 	return xattr_len;
910 }
911 
912 /**
913  * ksmbd_vfs_setxattr() - vfs helper for smb set extended attributes value
914  * @idmap:	idmap of the relevant mount
915  * @path:	path of dentry to set XATTR at
916  * @attr_name:	xattr name for setxattr
917  * @attr_value:	xattr value to set
918  * @attr_size:	size of xattr value
919  * @flags:	destination buffer length
920  * @get_write:	get write access to a mount
921  *
922  * Return:	0 on success, otherwise error
923  */
924 int ksmbd_vfs_setxattr(struct mnt_idmap *idmap,
925 		       const struct path *path, const char *attr_name,
926 		       void *attr_value, size_t attr_size, int flags,
927 		       bool get_write)
928 {
929 	int err;
930 
931 	if (get_write == true) {
932 		err = mnt_want_write(path->mnt);
933 		if (err)
934 			return err;
935 	}
936 
937 	err = vfs_setxattr(idmap,
938 			   path->dentry,
939 			   attr_name,
940 			   attr_value,
941 			   attr_size,
942 			   flags);
943 	if (err)
944 		ksmbd_debug(VFS, "setxattr failed, err %d\n", err);
945 	if (get_write == true)
946 		mnt_drop_write(path->mnt);
947 	return err;
948 }
949 
950 /**
951  * ksmbd_vfs_set_fadvise() - convert smb IO caching options to linux options
952  * @filp:	file pointer for IO
953  * @option:	smb IO options
954  */
955 void ksmbd_vfs_set_fadvise(struct file *filp, __le32 option)
956 {
957 	struct address_space *mapping;
958 
959 	mapping = filp->f_mapping;
960 
961 	if (!option || !mapping)
962 		return;
963 
964 	if (option & FILE_WRITE_THROUGH_LE) {
965 		filp->f_flags |= O_SYNC;
966 	} else if (option & FILE_SEQUENTIAL_ONLY_LE) {
967 		filp->f_ra.ra_pages = inode_to_bdi(mapping->host)->ra_pages * 2;
968 		spin_lock(&filp->f_lock);
969 		filp->f_mode &= ~FMODE_RANDOM;
970 		spin_unlock(&filp->f_lock);
971 	} else if (option & FILE_RANDOM_ACCESS_LE) {
972 		spin_lock(&filp->f_lock);
973 		filp->f_mode |= FMODE_RANDOM;
974 		spin_unlock(&filp->f_lock);
975 	}
976 }
977 
978 int ksmbd_vfs_zero_data(struct ksmbd_work *work, struct ksmbd_file *fp,
979 			loff_t off, loff_t len)
980 {
981 	smb_break_all_levII_oplock(work, fp, 1);
982 	if (fp->f_ci->m_fattr & FILE_ATTRIBUTE_SPARSE_FILE_LE)
983 		return vfs_fallocate(fp->filp,
984 				     FALLOC_FL_PUNCH_HOLE | FALLOC_FL_KEEP_SIZE,
985 				     off, len);
986 
987 	return vfs_fallocate(fp->filp,
988 			     FALLOC_FL_ZERO_RANGE | FALLOC_FL_KEEP_SIZE,
989 			     off, len);
990 }
991 
992 int ksmbd_vfs_fqar_lseek(struct ksmbd_file *fp, loff_t start, loff_t length,
993 			 struct file_allocated_range_buffer *ranges,
994 			 unsigned int in_count, unsigned int *out_count)
995 {
996 	struct file *f = fp->filp;
997 	struct inode *inode = file_inode(fp->filp);
998 	loff_t maxbytes = (u64)inode->i_sb->s_maxbytes, end;
999 	loff_t extent_start, extent_end;
1000 	int ret = 0;
1001 
1002 	if (start > maxbytes)
1003 		return -EFBIG;
1004 
1005 	if (!in_count)
1006 		return 0;
1007 
1008 	/*
1009 	 * Shrink request scope to what the fs can actually handle.
1010 	 */
1011 	if (length > maxbytes || (maxbytes - length) < start)
1012 		length = maxbytes - start;
1013 
1014 	if (start + length > inode->i_size)
1015 		length = inode->i_size - start;
1016 
1017 	*out_count = 0;
1018 	end = start + length;
1019 	while (start < end && *out_count < in_count) {
1020 		extent_start = vfs_llseek(f, start, SEEK_DATA);
1021 		if (extent_start < 0) {
1022 			if (extent_start != -ENXIO)
1023 				ret = (int)extent_start;
1024 			break;
1025 		}
1026 
1027 		if (extent_start >= end)
1028 			break;
1029 
1030 		extent_end = vfs_llseek(f, extent_start, SEEK_HOLE);
1031 		if (extent_end < 0) {
1032 			if (extent_end != -ENXIO)
1033 				ret = (int)extent_end;
1034 			break;
1035 		} else if (extent_start >= extent_end) {
1036 			break;
1037 		}
1038 
1039 		ranges[*out_count].file_offset = cpu_to_le64(extent_start);
1040 		ranges[(*out_count)++].length =
1041 			cpu_to_le64(min(extent_end, end) - extent_start);
1042 
1043 		start = extent_end;
1044 	}
1045 
1046 	return ret;
1047 }
1048 
1049 int ksmbd_vfs_remove_xattr(struct mnt_idmap *idmap,
1050 			   const struct path *path, char *attr_name,
1051 			   bool get_write)
1052 {
1053 	int err;
1054 
1055 	if (get_write == true) {
1056 		err = mnt_want_write(path->mnt);
1057 		if (err)
1058 			return err;
1059 	}
1060 
1061 	err = vfs_removexattr(idmap, path->dentry, attr_name);
1062 
1063 	if (get_write == true)
1064 		mnt_drop_write(path->mnt);
1065 
1066 	return err;
1067 }
1068 
1069 int ksmbd_vfs_unlink(struct file *filp)
1070 {
1071 	int err = 0;
1072 	struct dentry *dir, *dentry = filp->f_path.dentry;
1073 	struct mnt_idmap *idmap = file_mnt_idmap(filp);
1074 
1075 	err = mnt_want_write(filp->f_path.mnt);
1076 	if (err)
1077 		return err;
1078 
1079 	dir = dget_parent(dentry);
1080 	err = ksmbd_vfs_lock_parent(dir, dentry);
1081 	if (err)
1082 		goto out;
1083 	dget(dentry);
1084 
1085 	if (S_ISDIR(d_inode(dentry)->i_mode))
1086 		err = vfs_rmdir(idmap, d_inode(dir), dentry);
1087 	else
1088 		err = vfs_unlink(idmap, d_inode(dir), dentry, NULL);
1089 
1090 	dput(dentry);
1091 	inode_unlock(d_inode(dir));
1092 	if (err)
1093 		ksmbd_debug(VFS, "failed to delete, err %d\n", err);
1094 out:
1095 	dput(dir);
1096 	mnt_drop_write(filp->f_path.mnt);
1097 
1098 	return err;
1099 }
1100 
1101 static bool __dir_empty(struct dir_context *ctx, const char *name, int namlen,
1102 		       loff_t offset, u64 ino, unsigned int d_type)
1103 {
1104 	struct ksmbd_readdir_data *buf;
1105 
1106 	buf = container_of(ctx, struct ksmbd_readdir_data, ctx);
1107 	if (!is_dot_dotdot(name, namlen))
1108 		buf->dirent_count++;
1109 
1110 	return !buf->dirent_count;
1111 }
1112 
1113 /**
1114  * ksmbd_vfs_empty_dir() - check for empty directory
1115  * @fp:	ksmbd file pointer
1116  *
1117  * Return:	true if directory empty, otherwise false
1118  */
1119 int ksmbd_vfs_empty_dir(struct ksmbd_file *fp)
1120 {
1121 	int err;
1122 	struct ksmbd_readdir_data readdir_data;
1123 
1124 	memset(&readdir_data, 0, sizeof(struct ksmbd_readdir_data));
1125 
1126 	set_ctx_actor(&readdir_data.ctx, __dir_empty);
1127 	readdir_data.dirent_count = 0;
1128 
1129 	err = iterate_dir(fp->filp, &readdir_data.ctx);
1130 	if (readdir_data.dirent_count)
1131 		err = -ENOTEMPTY;
1132 	else
1133 		err = 0;
1134 	return err;
1135 }
1136 
1137 static bool __caseless_lookup(struct dir_context *ctx, const char *name,
1138 			     int namlen, loff_t offset, u64 ino,
1139 			     unsigned int d_type)
1140 {
1141 	struct ksmbd_readdir_data *buf;
1142 	int cmp = -EINVAL;
1143 
1144 	buf = container_of(ctx, struct ksmbd_readdir_data, ctx);
1145 
1146 	if (buf->used != namlen)
1147 		return true;
1148 	if (IS_ENABLED(CONFIG_UNICODE) && buf->um) {
1149 		const struct qstr q_buf = {.name = buf->private,
1150 					   .len = buf->used};
1151 		const struct qstr q_name = {.name = name,
1152 					    .len = namlen};
1153 
1154 		cmp = utf8_strncasecmp(buf->um, &q_buf, &q_name);
1155 	}
1156 	if (cmp < 0)
1157 		cmp = strncasecmp((char *)buf->private, name, namlen);
1158 	if (!cmp) {
1159 		memcpy((char *)buf->private, name, buf->used);
1160 		buf->dirent_count = 1;
1161 		return false;
1162 	}
1163 	return true;
1164 }
1165 
1166 /**
1167  * ksmbd_vfs_lookup_in_dir() - lookup a file in a directory
1168  * @dir:	path info
1169  * @name:	filename to lookup
1170  * @namelen:	filename length
1171  * @um:		&struct unicode_map to use
1172  *
1173  * Return:	0 on success, otherwise error
1174  */
1175 static int ksmbd_vfs_lookup_in_dir(const struct path *dir, char *name,
1176 				   size_t namelen, struct unicode_map *um)
1177 {
1178 	int ret;
1179 	struct file *dfilp;
1180 	int flags = O_RDONLY | O_LARGEFILE;
1181 	struct ksmbd_readdir_data readdir_data = {
1182 		.ctx.actor	= __caseless_lookup,
1183 		.private	= name,
1184 		.used		= namelen,
1185 		.dirent_count	= 0,
1186 		.um		= um,
1187 	};
1188 
1189 	dfilp = dentry_open(dir, flags, current_cred());
1190 	if (IS_ERR(dfilp))
1191 		return PTR_ERR(dfilp);
1192 
1193 	ret = iterate_dir(dfilp, &readdir_data.ctx);
1194 	if (readdir_data.dirent_count > 0)
1195 		ret = 0;
1196 	fput(dfilp);
1197 	return ret;
1198 }
1199 
1200 /**
1201  * ksmbd_vfs_kern_path_locked() - lookup a file and get path info
1202  * @work:	work
1203  * @name:		file path that is relative to share
1204  * @flags:		lookup flags
1205  * @parent_path:	if lookup succeed, return parent_path info
1206  * @path:		if lookup succeed, return path info
1207  * @caseless:	caseless filename lookup
1208  *
1209  * Return:	0 on success, otherwise error
1210  */
1211 int ksmbd_vfs_kern_path_locked(struct ksmbd_work *work, char *name,
1212 			       unsigned int flags, struct path *parent_path,
1213 			       struct path *path, bool caseless)
1214 {
1215 	struct ksmbd_share_config *share_conf = work->tcon->share_conf;
1216 	int err;
1217 
1218 	err = ksmbd_vfs_path_lookup_locked(share_conf, name, flags, parent_path,
1219 					   path);
1220 	if (!err)
1221 		return 0;
1222 
1223 	if (caseless) {
1224 		char *filepath;
1225 		size_t path_len, remain_len;
1226 
1227 		filepath = name;
1228 		path_len = strlen(filepath);
1229 		remain_len = path_len;
1230 
1231 		*parent_path = share_conf->vfs_path;
1232 		path_get(parent_path);
1233 
1234 		while (d_can_lookup(parent_path->dentry)) {
1235 			char *filename = filepath + path_len - remain_len;
1236 			char *next = strchrnul(filename, '/');
1237 			size_t filename_len = next - filename;
1238 			bool is_last = !next[0];
1239 
1240 			if (filename_len == 0)
1241 				break;
1242 
1243 			err = ksmbd_vfs_lookup_in_dir(parent_path, filename,
1244 						      filename_len,
1245 						      work->conn->um);
1246 			if (err)
1247 				goto out2;
1248 
1249 			next[0] = '\0';
1250 
1251 			err = vfs_path_lookup(share_conf->vfs_path.dentry,
1252 					      share_conf->vfs_path.mnt,
1253 					      filepath,
1254 					      flags,
1255 					      path);
1256 			if (!is_last)
1257 				next[0] = '/';
1258 			if (err)
1259 				goto out2;
1260 			else if (is_last)
1261 				goto out1;
1262 			path_put(parent_path);
1263 			*parent_path = *path;
1264 
1265 			remain_len -= filename_len + 1;
1266 		}
1267 
1268 		err = -EINVAL;
1269 out2:
1270 		path_put(parent_path);
1271 	}
1272 
1273 out1:
1274 	if (!err) {
1275 		err = mnt_want_write(parent_path->mnt);
1276 		if (err) {
1277 			path_put(path);
1278 			path_put(parent_path);
1279 			return err;
1280 		}
1281 
1282 		err = ksmbd_vfs_lock_parent(parent_path->dentry, path->dentry);
1283 		if (err) {
1284 			path_put(path);
1285 			path_put(parent_path);
1286 		}
1287 	}
1288 	return err;
1289 }
1290 
1291 void ksmbd_vfs_kern_path_unlock(struct path *parent_path, struct path *path)
1292 {
1293 	inode_unlock(d_inode(parent_path->dentry));
1294 	mnt_drop_write(parent_path->mnt);
1295 	path_put(path);
1296 	path_put(parent_path);
1297 }
1298 
1299 struct dentry *ksmbd_vfs_kern_path_create(struct ksmbd_work *work,
1300 					  const char *name,
1301 					  unsigned int flags,
1302 					  struct path *path)
1303 {
1304 	char *abs_name;
1305 	struct dentry *dent;
1306 
1307 	abs_name = convert_to_unix_name(work->tcon->share_conf, name);
1308 	if (!abs_name)
1309 		return ERR_PTR(-ENOMEM);
1310 
1311 	dent = kern_path_create(AT_FDCWD, abs_name, path, flags);
1312 	kfree(abs_name);
1313 	return dent;
1314 }
1315 
1316 int ksmbd_vfs_remove_acl_xattrs(struct mnt_idmap *idmap,
1317 				const struct path *path)
1318 {
1319 	char *name, *xattr_list = NULL;
1320 	ssize_t xattr_list_len;
1321 	int err = 0;
1322 
1323 	xattr_list_len = ksmbd_vfs_listxattr(path->dentry, &xattr_list);
1324 	if (xattr_list_len < 0) {
1325 		goto out;
1326 	} else if (!xattr_list_len) {
1327 		ksmbd_debug(SMB, "empty xattr in the file\n");
1328 		goto out;
1329 	}
1330 
1331 	err = mnt_want_write(path->mnt);
1332 	if (err)
1333 		goto out;
1334 
1335 	for (name = xattr_list; name - xattr_list < xattr_list_len;
1336 	     name += strlen(name) + 1) {
1337 		ksmbd_debug(SMB, "%s, len %zd\n", name, strlen(name));
1338 
1339 		if (!strncmp(name, XATTR_NAME_POSIX_ACL_ACCESS,
1340 			     sizeof(XATTR_NAME_POSIX_ACL_ACCESS) - 1) ||
1341 		    !strncmp(name, XATTR_NAME_POSIX_ACL_DEFAULT,
1342 			     sizeof(XATTR_NAME_POSIX_ACL_DEFAULT) - 1)) {
1343 			err = vfs_remove_acl(idmap, path->dentry, name);
1344 			if (err)
1345 				ksmbd_debug(SMB,
1346 					    "remove acl xattr failed : %s\n", name);
1347 		}
1348 	}
1349 	mnt_drop_write(path->mnt);
1350 
1351 out:
1352 	kvfree(xattr_list);
1353 	return err;
1354 }
1355 
1356 int ksmbd_vfs_remove_sd_xattrs(struct mnt_idmap *idmap, const struct path *path)
1357 {
1358 	char *name, *xattr_list = NULL;
1359 	ssize_t xattr_list_len;
1360 	int err = 0;
1361 
1362 	xattr_list_len = ksmbd_vfs_listxattr(path->dentry, &xattr_list);
1363 	if (xattr_list_len < 0) {
1364 		goto out;
1365 	} else if (!xattr_list_len) {
1366 		ksmbd_debug(SMB, "empty xattr in the file\n");
1367 		goto out;
1368 	}
1369 
1370 	for (name = xattr_list; name - xattr_list < xattr_list_len;
1371 			name += strlen(name) + 1) {
1372 		ksmbd_debug(SMB, "%s, len %zd\n", name, strlen(name));
1373 
1374 		if (!strncmp(name, XATTR_NAME_SD, XATTR_NAME_SD_LEN)) {
1375 			err = ksmbd_vfs_remove_xattr(idmap, path, name, true);
1376 			if (err)
1377 				ksmbd_debug(SMB, "remove xattr failed : %s\n", name);
1378 		}
1379 	}
1380 out:
1381 	kvfree(xattr_list);
1382 	return err;
1383 }
1384 
1385 static struct xattr_smb_acl *ksmbd_vfs_make_xattr_posix_acl(struct mnt_idmap *idmap,
1386 							    struct inode *inode,
1387 							    int acl_type)
1388 {
1389 	struct xattr_smb_acl *smb_acl = NULL;
1390 	struct posix_acl *posix_acls;
1391 	struct posix_acl_entry *pa_entry;
1392 	struct xattr_acl_entry *xa_entry;
1393 	int i;
1394 
1395 	if (!IS_ENABLED(CONFIG_FS_POSIX_ACL))
1396 		return NULL;
1397 
1398 	posix_acls = get_inode_acl(inode, acl_type);
1399 	if (IS_ERR_OR_NULL(posix_acls))
1400 		return NULL;
1401 
1402 	smb_acl = kzalloc(sizeof(struct xattr_smb_acl) +
1403 			  sizeof(struct xattr_acl_entry) * posix_acls->a_count,
1404 			  KSMBD_DEFAULT_GFP);
1405 	if (!smb_acl)
1406 		goto out;
1407 
1408 	smb_acl->count = posix_acls->a_count;
1409 	pa_entry = posix_acls->a_entries;
1410 	xa_entry = smb_acl->entries;
1411 	for (i = 0; i < posix_acls->a_count; i++, pa_entry++, xa_entry++) {
1412 		switch (pa_entry->e_tag) {
1413 		case ACL_USER:
1414 			xa_entry->type = SMB_ACL_USER;
1415 			xa_entry->uid = posix_acl_uid_translate(idmap, pa_entry);
1416 			break;
1417 		case ACL_USER_OBJ:
1418 			xa_entry->type = SMB_ACL_USER_OBJ;
1419 			break;
1420 		case ACL_GROUP:
1421 			xa_entry->type = SMB_ACL_GROUP;
1422 			xa_entry->gid = posix_acl_gid_translate(idmap, pa_entry);
1423 			break;
1424 		case ACL_GROUP_OBJ:
1425 			xa_entry->type = SMB_ACL_GROUP_OBJ;
1426 			break;
1427 		case ACL_OTHER:
1428 			xa_entry->type = SMB_ACL_OTHER;
1429 			break;
1430 		case ACL_MASK:
1431 			xa_entry->type = SMB_ACL_MASK;
1432 			break;
1433 		default:
1434 			pr_err("unknown type : 0x%x\n", pa_entry->e_tag);
1435 			goto out;
1436 		}
1437 
1438 		if (pa_entry->e_perm & ACL_READ)
1439 			xa_entry->perm |= SMB_ACL_READ;
1440 		if (pa_entry->e_perm & ACL_WRITE)
1441 			xa_entry->perm |= SMB_ACL_WRITE;
1442 		if (pa_entry->e_perm & ACL_EXECUTE)
1443 			xa_entry->perm |= SMB_ACL_EXECUTE;
1444 	}
1445 out:
1446 	posix_acl_release(posix_acls);
1447 	return smb_acl;
1448 }
1449 
1450 int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
1451 			   struct mnt_idmap *idmap,
1452 			   const struct path *path,
1453 			   struct smb_ntsd *pntsd, int len,
1454 			   bool get_write)
1455 {
1456 	int rc;
1457 	struct ndr sd_ndr = {0}, acl_ndr = {0};
1458 	struct xattr_ntacl acl = {0};
1459 	struct xattr_smb_acl *smb_acl, *def_smb_acl = NULL;
1460 	struct dentry *dentry = path->dentry;
1461 	struct inode *inode = d_inode(dentry);
1462 
1463 	acl.version = 4;
1464 	acl.hash_type = XATTR_SD_HASH_TYPE_SHA256;
1465 	acl.current_time = ksmbd_UnixTimeToNT(current_time(inode));
1466 
1467 	memcpy(acl.desc, "posix_acl", 9);
1468 	acl.desc_len = 10;
1469 
1470 	pntsd->osidoffset =
1471 		cpu_to_le32(le32_to_cpu(pntsd->osidoffset) + NDR_NTSD_OFFSETOF);
1472 	pntsd->gsidoffset =
1473 		cpu_to_le32(le32_to_cpu(pntsd->gsidoffset) + NDR_NTSD_OFFSETOF);
1474 	pntsd->dacloffset =
1475 		cpu_to_le32(le32_to_cpu(pntsd->dacloffset) + NDR_NTSD_OFFSETOF);
1476 
1477 	acl.sd_buf = (char *)pntsd;
1478 	acl.sd_size = len;
1479 
1480 	sha256(acl.sd_buf, acl.sd_size, acl.hash);
1481 
1482 	smb_acl = ksmbd_vfs_make_xattr_posix_acl(idmap, inode,
1483 						 ACL_TYPE_ACCESS);
1484 	if (S_ISDIR(inode->i_mode))
1485 		def_smb_acl = ksmbd_vfs_make_xattr_posix_acl(idmap, inode,
1486 							     ACL_TYPE_DEFAULT);
1487 
1488 	rc = ndr_encode_posix_acl(&acl_ndr, idmap, inode,
1489 				  smb_acl, def_smb_acl);
1490 	if (rc) {
1491 		pr_err("failed to encode ndr to posix acl\n");
1492 		goto out;
1493 	}
1494 
1495 	sha256(acl_ndr.data, acl_ndr.offset, acl.posix_acl_hash);
1496 
1497 	rc = ndr_encode_v4_ntacl(&sd_ndr, &acl);
1498 	if (rc) {
1499 		pr_err("failed to encode ndr to posix acl\n");
1500 		goto out;
1501 	}
1502 
1503 	rc = ksmbd_vfs_setxattr(idmap, path,
1504 				XATTR_NAME_SD, sd_ndr.data,
1505 				sd_ndr.offset, 0, get_write);
1506 	if (rc < 0)
1507 		pr_err("Failed to store XATTR ntacl :%d\n", rc);
1508 
1509 	kfree(sd_ndr.data);
1510 out:
1511 	kfree(acl_ndr.data);
1512 	kfree(smb_acl);
1513 	kfree(def_smb_acl);
1514 	return rc;
1515 }
1516 
1517 int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
1518 			   struct mnt_idmap *idmap,
1519 			   struct dentry *dentry,
1520 			   struct smb_ntsd **pntsd)
1521 {
1522 	int rc;
1523 	struct ndr n;
1524 	struct inode *inode = d_inode(dentry);
1525 	struct ndr acl_ndr = {0};
1526 	struct xattr_ntacl acl;
1527 	struct xattr_smb_acl *smb_acl = NULL, *def_smb_acl = NULL;
1528 	__u8 cmp_hash[XATTR_SD_HASH_SIZE] = {0};
1529 
1530 	rc = ksmbd_vfs_getxattr(idmap, dentry, XATTR_NAME_SD, &n.data);
1531 	if (rc <= 0)
1532 		return rc;
1533 
1534 	n.length = rc;
1535 	rc = ndr_decode_v4_ntacl(&n, &acl);
1536 	if (rc)
1537 		goto free_n_data;
1538 
1539 	smb_acl = ksmbd_vfs_make_xattr_posix_acl(idmap, inode,
1540 						 ACL_TYPE_ACCESS);
1541 	if (S_ISDIR(inode->i_mode))
1542 		def_smb_acl = ksmbd_vfs_make_xattr_posix_acl(idmap, inode,
1543 							     ACL_TYPE_DEFAULT);
1544 
1545 	rc = ndr_encode_posix_acl(&acl_ndr, idmap, inode, smb_acl,
1546 				  def_smb_acl);
1547 	if (rc) {
1548 		pr_err("failed to encode ndr to posix acl\n");
1549 		goto out_free;
1550 	}
1551 
1552 	sha256(acl_ndr.data, acl_ndr.offset, cmp_hash);
1553 
1554 	if (memcmp(cmp_hash, acl.posix_acl_hash, XATTR_SD_HASH_SIZE)) {
1555 		pr_err("hash value diff\n");
1556 		rc = -EINVAL;
1557 		goto out_free;
1558 	}
1559 
1560 	*pntsd = acl.sd_buf;
1561 	if (acl.sd_size < sizeof(struct smb_ntsd)) {
1562 		pr_err("sd size is invalid\n");
1563 		goto out_free;
1564 	}
1565 
1566 	(*pntsd)->osidoffset = cpu_to_le32(le32_to_cpu((*pntsd)->osidoffset) -
1567 					   NDR_NTSD_OFFSETOF);
1568 	(*pntsd)->gsidoffset = cpu_to_le32(le32_to_cpu((*pntsd)->gsidoffset) -
1569 					   NDR_NTSD_OFFSETOF);
1570 	(*pntsd)->dacloffset = cpu_to_le32(le32_to_cpu((*pntsd)->dacloffset) -
1571 					   NDR_NTSD_OFFSETOF);
1572 
1573 	rc = acl.sd_size;
1574 out_free:
1575 	kfree(acl_ndr.data);
1576 	kfree(smb_acl);
1577 	kfree(def_smb_acl);
1578 	if (rc < 0) {
1579 		kfree(acl.sd_buf);
1580 		*pntsd = NULL;
1581 	}
1582 
1583 free_n_data:
1584 	kfree(n.data);
1585 	return rc;
1586 }
1587 
1588 int ksmbd_vfs_set_dos_attrib_xattr(struct mnt_idmap *idmap,
1589 				   const struct path *path,
1590 				   struct xattr_dos_attrib *da,
1591 				   bool get_write)
1592 {
1593 	struct ndr n;
1594 	int err;
1595 
1596 	err = ndr_encode_dos_attr(&n, da);
1597 	if (err)
1598 		return err;
1599 
1600 	err = ksmbd_vfs_setxattr(idmap, path, XATTR_NAME_DOS_ATTRIBUTE,
1601 				 (void *)n.data, n.offset, 0, get_write);
1602 	if (err)
1603 		ksmbd_debug(SMB, "failed to store dos attribute in xattr\n");
1604 	kfree(n.data);
1605 
1606 	return err;
1607 }
1608 
1609 int ksmbd_vfs_get_dos_attrib_xattr(struct mnt_idmap *idmap,
1610 				   struct dentry *dentry,
1611 				   struct xattr_dos_attrib *da)
1612 {
1613 	struct ndr n;
1614 	int err;
1615 
1616 	err = ksmbd_vfs_getxattr(idmap, dentry, XATTR_NAME_DOS_ATTRIBUTE,
1617 				 (char **)&n.data);
1618 	if (err > 0) {
1619 		n.length = err;
1620 		if (ndr_decode_dos_attr(&n, da))
1621 			err = -EINVAL;
1622 		kfree(n.data);
1623 	} else {
1624 		ksmbd_debug(SMB, "failed to load dos attribute in xattr\n");
1625 	}
1626 
1627 	return err;
1628 }
1629 
1630 /**
1631  * ksmbd_vfs_init_kstat() - convert unix stat information to smb stat format
1632  * @p:          destination buffer
1633  * @ksmbd_kstat:      ksmbd kstat wrapper
1634  *
1635  * Returns: pointer to the converted &struct file_directory_info
1636  */
1637 void *ksmbd_vfs_init_kstat(char **p, struct ksmbd_kstat *ksmbd_kstat)
1638 {
1639 	struct file_directory_info *info = (struct file_directory_info *)(*p);
1640 	struct kstat *kstat = ksmbd_kstat->kstat;
1641 	u64 time;
1642 
1643 	info->FileIndex = 0;
1644 	info->CreationTime = cpu_to_le64(ksmbd_kstat->create_time);
1645 	time = ksmbd_UnixTimeToNT(kstat->atime);
1646 	info->LastAccessTime = cpu_to_le64(time);
1647 	time = ksmbd_UnixTimeToNT(kstat->mtime);
1648 	info->LastWriteTime = cpu_to_le64(time);
1649 	time = ksmbd_UnixTimeToNT(kstat->ctime);
1650 	info->ChangeTime = cpu_to_le64(time);
1651 
1652 	if (ksmbd_kstat->file_attributes & FILE_ATTRIBUTE_DIRECTORY_LE) {
1653 		info->EndOfFile = 0;
1654 		info->AllocationSize = 0;
1655 	} else {
1656 		info->EndOfFile = cpu_to_le64(kstat->size);
1657 		info->AllocationSize = cpu_to_le64(kstat->blocks << 9);
1658 	}
1659 	info->ExtFileAttributes = ksmbd_kstat->file_attributes;
1660 
1661 	return info;
1662 }
1663 
1664 int ksmbd_vfs_fill_dentry_attrs(struct ksmbd_work *work,
1665 				struct mnt_idmap *idmap,
1666 				struct dentry *dentry,
1667 				struct ksmbd_kstat *ksmbd_kstat)
1668 {
1669 	struct ksmbd_share_config *share_conf = work->tcon->share_conf;
1670 	u64 time;
1671 	int rc;
1672 	struct path path = {
1673 		.mnt = share_conf->vfs_path.mnt,
1674 		.dentry = dentry,
1675 	};
1676 
1677 	rc = vfs_getattr(&path, ksmbd_kstat->kstat,
1678 			 STATX_BASIC_STATS | STATX_BTIME,
1679 			 AT_STATX_SYNC_AS_STAT);
1680 	if (rc)
1681 		return rc;
1682 
1683 	time = ksmbd_UnixTimeToNT(ksmbd_kstat->kstat->ctime);
1684 	ksmbd_kstat->create_time = time;
1685 
1686 	/*
1687 	 * set default value for the case that store dos attributes is not yes
1688 	 * or that acl is disable in server's filesystem and the config is yes.
1689 	 */
1690 	if (S_ISDIR(ksmbd_kstat->kstat->mode))
1691 		ksmbd_kstat->file_attributes = FILE_ATTRIBUTE_DIRECTORY_LE;
1692 	else
1693 		ksmbd_kstat->file_attributes = FILE_ATTRIBUTE_ARCHIVE_LE;
1694 
1695 	if (test_share_config_flag(work->tcon->share_conf,
1696 				   KSMBD_SHARE_FLAG_STORE_DOS_ATTRS)) {
1697 		struct xattr_dos_attrib da;
1698 
1699 		rc = ksmbd_vfs_get_dos_attrib_xattr(idmap, dentry, &da);
1700 		if (rc > 0) {
1701 			ksmbd_kstat->file_attributes = cpu_to_le32(da.attr);
1702 			ksmbd_kstat->create_time = da.create_time;
1703 		} else {
1704 			ksmbd_debug(VFS, "fail to load dos attribute.\n");
1705 		}
1706 	}
1707 
1708 	return 0;
1709 }
1710 
1711 ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
1712 				struct dentry *dentry, char *attr_name,
1713 				int attr_name_len)
1714 {
1715 	char *name, *xattr_list = NULL;
1716 	ssize_t value_len = -ENOENT, xattr_list_len;
1717 
1718 	xattr_list_len = ksmbd_vfs_listxattr(dentry, &xattr_list);
1719 	if (xattr_list_len <= 0)
1720 		goto out;
1721 
1722 	for (name = xattr_list; name - xattr_list < xattr_list_len;
1723 			name += strlen(name) + 1) {
1724 		ksmbd_debug(VFS, "%s, len %zd\n", name, strlen(name));
1725 		if (strncasecmp(attr_name, name, attr_name_len))
1726 			continue;
1727 
1728 		value_len = ksmbd_vfs_xattr_len(idmap, dentry, name);
1729 		break;
1730 	}
1731 
1732 out:
1733 	kvfree(xattr_list);
1734 	return value_len;
1735 }
1736 
1737 int ksmbd_vfs_xattr_stream_name(char *stream_name, char **xattr_stream_name,
1738 				size_t *xattr_stream_name_size, int s_type)
1739 {
1740 	char *type, *buf;
1741 
1742 	if (s_type == DIR_STREAM)
1743 		type = ":$INDEX_ALLOCATION";
1744 	else
1745 		type = ":$DATA";
1746 
1747 	buf = kasprintf(KSMBD_DEFAULT_GFP, "%s%s%s",
1748 			XATTR_NAME_STREAM, stream_name,	type);
1749 	if (!buf)
1750 		return -ENOMEM;
1751 
1752 	*xattr_stream_name = buf;
1753 	*xattr_stream_name_size = strlen(buf) + 1;
1754 
1755 	return 0;
1756 }
1757 
1758 int ksmbd_vfs_copy_file_ranges(struct ksmbd_work *work,
1759 			       struct ksmbd_file *src_fp,
1760 			       struct ksmbd_file *dst_fp,
1761 			       struct srv_copychunk *chunks,
1762 			       unsigned int chunk_count,
1763 			       unsigned int *chunk_count_written,
1764 			       unsigned int *chunk_size_written,
1765 			       loff_t *total_size_written)
1766 {
1767 	unsigned int i;
1768 	loff_t src_off, dst_off, src_file_size;
1769 	size_t len;
1770 	int ret;
1771 
1772 	*chunk_count_written = 0;
1773 	*chunk_size_written = 0;
1774 	*total_size_written = 0;
1775 
1776 	if (!(src_fp->daccess & (FILE_READ_DATA_LE | FILE_EXECUTE_LE))) {
1777 		pr_err("no right to read(%pD)\n", src_fp->filp);
1778 		return -EACCES;
1779 	}
1780 	if (!(dst_fp->daccess & (FILE_WRITE_DATA_LE | FILE_APPEND_DATA_LE))) {
1781 		pr_err("no right to write(%pD)\n", dst_fp->filp);
1782 		return -EACCES;
1783 	}
1784 
1785 	if (ksmbd_stream_fd(src_fp) || ksmbd_stream_fd(dst_fp))
1786 		return -EBADF;
1787 
1788 	smb_break_all_levII_oplock(work, dst_fp, 1);
1789 
1790 	if (!work->tcon->posix_extensions) {
1791 		for (i = 0; i < chunk_count; i++) {
1792 			src_off = le64_to_cpu(chunks[i].SourceOffset);
1793 			dst_off = le64_to_cpu(chunks[i].TargetOffset);
1794 			len = le32_to_cpu(chunks[i].Length);
1795 
1796 			if (check_lock_range(src_fp->filp, src_off,
1797 					     src_off + len - 1, READ))
1798 				return -EAGAIN;
1799 			if (check_lock_range(dst_fp->filp, dst_off,
1800 					     dst_off + len - 1, WRITE))
1801 				return -EAGAIN;
1802 		}
1803 	}
1804 
1805 	src_file_size = i_size_read(file_inode(src_fp->filp));
1806 
1807 	for (i = 0; i < chunk_count; i++) {
1808 		src_off = le64_to_cpu(chunks[i].SourceOffset);
1809 		dst_off = le64_to_cpu(chunks[i].TargetOffset);
1810 		len = le32_to_cpu(chunks[i].Length);
1811 
1812 		if (src_off + len > src_file_size)
1813 			return -E2BIG;
1814 
1815 		ret = vfs_copy_file_range(src_fp->filp, src_off,
1816 					  dst_fp->filp, dst_off, len, 0);
1817 		if (ret == -EOPNOTSUPP || ret == -EXDEV)
1818 			ret = vfs_copy_file_range(src_fp->filp, src_off,
1819 						  dst_fp->filp, dst_off, len,
1820 						  COPY_FILE_SPLICE);
1821 		if (ret < 0)
1822 			return ret;
1823 
1824 		*chunk_count_written += 1;
1825 		*total_size_written += ret;
1826 	}
1827 	return 0;
1828 }
1829 
1830 void ksmbd_vfs_posix_lock_wait(struct file_lock *flock)
1831 {
1832 	wait_event(flock->c.flc_wait, !flock->c.flc_blocker);
1833 }
1834 
1835 void ksmbd_vfs_posix_lock_unblock(struct file_lock *flock)
1836 {
1837 	locks_delete_block(flock);
1838 }
1839 
1840 int ksmbd_vfs_set_init_posix_acl(struct mnt_idmap *idmap,
1841 				 struct path *path)
1842 {
1843 	struct posix_acl_state acl_state;
1844 	struct posix_acl *acls;
1845 	struct dentry *dentry = path->dentry;
1846 	struct inode *inode = d_inode(dentry);
1847 	int rc;
1848 
1849 	if (!IS_ENABLED(CONFIG_FS_POSIX_ACL))
1850 		return -EOPNOTSUPP;
1851 
1852 	ksmbd_debug(SMB, "Set posix acls\n");
1853 	rc = init_acl_state(&acl_state, 1);
1854 	if (rc)
1855 		return rc;
1856 
1857 	/* Set default owner group */
1858 	acl_state.owner.allow = (inode->i_mode & 0700) >> 6;
1859 	acl_state.group.allow = (inode->i_mode & 0070) >> 3;
1860 	acl_state.other.allow = inode->i_mode & 0007;
1861 	acl_state.users->aces[acl_state.users->n].uid = inode->i_uid;
1862 	acl_state.users->aces[acl_state.users->n++].perms.allow =
1863 		acl_state.owner.allow;
1864 	acl_state.groups->aces[acl_state.groups->n].gid = inode->i_gid;
1865 	acl_state.groups->aces[acl_state.groups->n++].perms.allow =
1866 		acl_state.group.allow;
1867 	acl_state.mask.allow = 0x07;
1868 
1869 	acls = posix_acl_alloc(6, KSMBD_DEFAULT_GFP);
1870 	if (!acls) {
1871 		free_acl_state(&acl_state);
1872 		return -ENOMEM;
1873 	}
1874 	posix_state_to_acl(&acl_state, acls->a_entries);
1875 
1876 	rc = set_posix_acl(idmap, dentry, ACL_TYPE_ACCESS, acls);
1877 	if (rc < 0)
1878 		ksmbd_debug(SMB, "Set posix acl(ACL_TYPE_ACCESS) failed, rc : %d\n",
1879 			    rc);
1880 	else if (S_ISDIR(inode->i_mode)) {
1881 		posix_state_to_acl(&acl_state, acls->a_entries);
1882 		rc = set_posix_acl(idmap, dentry, ACL_TYPE_DEFAULT, acls);
1883 		if (rc < 0)
1884 			ksmbd_debug(SMB, "Set posix acl(ACL_TYPE_DEFAULT) failed, rc : %d\n",
1885 				    rc);
1886 	}
1887 
1888 	free_acl_state(&acl_state);
1889 	posix_acl_release(acls);
1890 	return rc;
1891 }
1892 
1893 int ksmbd_vfs_inherit_posix_acl(struct mnt_idmap *idmap,
1894 				struct path *path, struct inode *parent_inode)
1895 {
1896 	struct posix_acl *acls;
1897 	struct posix_acl_entry *pace;
1898 	struct dentry *dentry = path->dentry;
1899 	struct inode *inode = d_inode(dentry);
1900 	int rc, i;
1901 
1902 	if (!IS_ENABLED(CONFIG_FS_POSIX_ACL))
1903 		return -EOPNOTSUPP;
1904 
1905 	acls = get_inode_acl(parent_inode, ACL_TYPE_DEFAULT);
1906 	if (IS_ERR_OR_NULL(acls))
1907 		return -ENOENT;
1908 	pace = acls->a_entries;
1909 
1910 	for (i = 0; i < acls->a_count; i++, pace++) {
1911 		if (pace->e_tag == ACL_MASK) {
1912 			pace->e_perm = 0x07;
1913 			break;
1914 		}
1915 	}
1916 
1917 	rc = set_posix_acl(idmap, dentry, ACL_TYPE_ACCESS, acls);
1918 	if (rc < 0)
1919 		ksmbd_debug(SMB, "Set posix acl(ACL_TYPE_ACCESS) failed, rc : %d\n",
1920 			    rc);
1921 	if (S_ISDIR(inode->i_mode)) {
1922 		rc = set_posix_acl(idmap, dentry, ACL_TYPE_DEFAULT,
1923 				   acls);
1924 		if (rc < 0)
1925 			ksmbd_debug(SMB, "Set posix acl(ACL_TYPE_DEFAULT) failed, rc : %d\n",
1926 				    rc);
1927 	}
1928 
1929 	posix_acl_release(acls);
1930 	return rc;
1931 }
1932