nfs4recover.c 10.5 KB
Newer Older
NeilBrown's avatar
NeilBrown committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35
/*
*  linux/fs/nfsd/nfs4recover.c
*
*  Copyright (c) 2004 The Regents of the University of Michigan.
*  All rights reserved.
*
*  Andy Adamson <andros@citi.umich.edu>
*
*  Redistribution and use in source and binary forms, with or without
*  modification, are permitted provided that the following conditions
*  are met:
*
*  1. Redistributions of source code must retain the above copyright
*     notice, this list of conditions and the following disclaimer.
*  2. Redistributions in binary form must reproduce the above copyright
*     notice, this list of conditions and the following disclaimer in the
*     documentation and/or other materials provided with the distribution.
*  3. Neither the name of the University nor the names of its
*     contributors may be used to endorse or promote products derived
*     from this software without specific prior written permission.
*
*  THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
*  WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
*  MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
*  DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
*  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
*  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
*  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
*  BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
*  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
*  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
*  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*
*/

36
#include <linux/err.h>
NeilBrown's avatar
NeilBrown committed
37 38 39 40 41
#include <linux/sunrpc/svc.h>
#include <linux/nfsd/nfsd.h>
#include <linux/nfs4.h>
#include <linux/nfsd/state.h>
#include <linux/nfsd/xdr4.h>
42 43 44
#include <linux/param.h>
#include <linux/file.h>
#include <linux/namei.h>
NeilBrown's avatar
NeilBrown committed
45
#include <asm/uaccess.h>
46
#include <linux/scatterlist.h>
NeilBrown's avatar
NeilBrown committed
47
#include <linux/crypto.h>
Alexey Dobriyan's avatar
Alexey Dobriyan committed
48
#include <linux/sched.h>
49
#include <linux/mount.h>
NeilBrown's avatar
NeilBrown committed
50 51 52

#define NFSDDBG_FACILITY                NFSDDBG_PROC

53
/* Globals */
Al Viro's avatar
Al Viro committed
54
static struct path rec_dir;
55 56
static int rec_dir_init = 0;

57 58
static int
nfs4_save_creds(const struct cred **original_creds)
59
{
60 61 62 63 64 65 66 67 68 69 70
	struct cred *new;

	new = prepare_creds();
	if (!new)
		return -ENOMEM;

	new->fsuid = 0;
	new->fsgid = 0;
	*original_creds = override_creds(new);
	put_cred(new);
	return 0;
71 72 73
}

static void
74
nfs4_reset_creds(const struct cred *original)
75
{
76
	revert_creds(original);
77 78
}

NeilBrown's avatar
NeilBrown committed
79 80 81 82 83 84 85 86 87 88 89 90 91 92
static void
md5_to_hex(char *out, char *md5)
{
	int i;

	for (i=0; i<16; i++) {
		unsigned char c = md5[i];

		*out++ = '0' + ((c&0xf0)>>4) + (c>=0xa0)*('a'-'9'-1);
		*out++ = '0' + (c&0x0f) + ((c&0x0f)>=0x0a)*('a'-'9'-1);
	}
	*out = '\0';
}

93
__be32
NeilBrown's avatar
NeilBrown committed
94 95 96
nfs4_make_rec_clidname(char *dname, struct xdr_netobj *clname)
{
	struct xdr_netobj cksum;
97
	struct hash_desc desc;
Jens Axboe's avatar
Jens Axboe committed
98
	struct scatterlist sg;
99
	__be32 status = nfserr_resource;
NeilBrown's avatar
NeilBrown committed
100 101 102

	dprintk("NFSD: nfs4_make_rec_clidname for %.*s\n",
			clname->len, clname->data);
103 104 105 106 107
	desc.flags = CRYPTO_TFM_REQ_MAY_SLEEP;
	desc.tfm = crypto_alloc_hash("md5", 0, CRYPTO_ALG_ASYNC);
	if (IS_ERR(desc.tfm))
		goto out_no_tfm;
	cksum.len = crypto_hash_digestsize(desc.tfm);
NeilBrown's avatar
NeilBrown committed
108 109 110 111
	cksum.data = kmalloc(cksum.len, GFP_KERNEL);
	if (cksum.data == NULL)
 		goto out;

Jens Axboe's avatar
Jens Axboe committed
112
	sg_init_one(&sg, clname->data, clname->len);
NeilBrown's avatar
NeilBrown committed
113

Jens Axboe's avatar
Jens Axboe committed
114
	if (crypto_hash_digest(&desc, &sg, sg.length, cksum.data))
115
		goto out;
NeilBrown's avatar
NeilBrown committed
116 117 118 119 120 121

	md5_to_hex(dname, cksum.data);

	kfree(cksum.data);
	status = nfs_ok;
out:
122 123
	crypto_free_hash(desc.tfm);
out_no_tfm:
NeilBrown's avatar
NeilBrown committed
124 125
	return status;
}
126

127 128
static void
nfsd4_sync_rec_dir(void)
129
{
Al Viro's avatar
Al Viro committed
130 131 132
	mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
	nfsd_sync_dir(rec_dir.dentry);
	mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
133 134 135 136 137
}

int
nfsd4_create_clid_dir(struct nfs4_client *clp)
{
138
	const struct cred *original_cred;
139 140 141 142 143 144 145 146 147
	char *dname = clp->cl_recdir;
	struct dentry *dentry;
	int status;

	dprintk("NFSD: nfsd4_create_clid_dir for \"%s\"\n", dname);

	if (!rec_dir_init || clp->cl_firststate)
		return 0;

148 149 150
	status = nfs4_save_creds(&original_cred);
	if (status < 0)
		return status;
151 152

	/* lock the parent */
Al Viro's avatar
Al Viro committed
153
	mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
154

Al Viro's avatar
Al Viro committed
155
	dentry = lookup_one_len(dname, rec_dir.dentry, HEXDIR_LEN-1);
156 157 158 159 160 161 162 163 164
	if (IS_ERR(dentry)) {
		status = PTR_ERR(dentry);
		goto out_unlock;
	}
	status = -EEXIST;
	if (dentry->d_inode) {
		dprintk("NFSD: nfsd4_create_clid_dir: DIRECTORY EXISTS\n");
		goto out_put;
	}
Al Viro's avatar
Al Viro committed
165
	status = mnt_want_write(rec_dir.mnt);
166 167
	if (status)
		goto out_put;
Al Viro's avatar
Al Viro committed
168 169
	status = vfs_mkdir(rec_dir.dentry->d_inode, dentry, S_IRWXU);
	mnt_drop_write(rec_dir.mnt);
170 171 172
out_put:
	dput(dentry);
out_unlock:
Al Viro's avatar
Al Viro committed
173
	mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
174 175
	if (status == 0) {
		clp->cl_firststate = 1;
176
		nfsd4_sync_rec_dir();
177
	}
178
	nfs4_reset_creds(original_cred);
179 180 181 182
	dprintk("NFSD: nfsd4_create_clid_dir returns %d\n", status);
	return status;
}

183 184 185 186 187 188 189 190 191 192 193 194 195 196
typedef int (recdir_func)(struct dentry *, struct dentry *);

struct dentry_list {
	struct dentry *dentry;
	struct list_head list;
};

struct dentry_list_arg {
	struct list_head dentries;
	struct dentry *parent;
};

static int
nfsd4_build_dentrylist(void *arg, const char *name, int namlen,
197
		loff_t offset, u64 ino, unsigned int d_type)
198 199 200 201 202 203 204 205
{
	struct dentry_list_arg *dla = arg;
	struct list_head *dentries = &dla->dentries;
	struct dentry *parent = dla->parent;
	struct dentry *dentry;
	struct dentry_list *child;

	if (name && isdotent(name, namlen))
206
		return 0;
207 208 209 210 211 212 213 214 215 216 217 218 219 220
	dentry = lookup_one_len(name, parent, namlen);
	if (IS_ERR(dentry))
		return PTR_ERR(dentry);
	child = kmalloc(sizeof(*child), GFP_KERNEL);
	if (child == NULL)
		return -ENOMEM;
	child->dentry = dentry;
	list_add(&child->list, dentries);
	return 0;
}

static int
nfsd4_list_rec_dir(struct dentry *dir, recdir_func *f)
{
221
	const struct cred *original_cred;
222 223 224 225 226 227 228 229 230 231 232
	struct file *filp;
	struct dentry_list_arg dla = {
		.parent = dir,
	};
	struct list_head *dentries = &dla.dentries;
	struct dentry_list *child;
	int status;

	if (!rec_dir_init)
		return 0;

233 234 235
	status = nfs4_save_creds(&original_cred);
	if (status < 0)
		return status;
236

237 238
	filp = dentry_open(dget(dir), mntget(rec_dir.mnt), O_RDONLY,
			   current_cred());
239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260
	status = PTR_ERR(filp);
	if (IS_ERR(filp))
		goto out;
	INIT_LIST_HEAD(dentries);
	status = vfs_readdir(filp, nfsd4_build_dentrylist, &dla);
	fput(filp);
	while (!list_empty(dentries)) {
		child = list_entry(dentries->next, struct dentry_list, list);
		status = f(dir, child->dentry);
		if (status)
			goto out;
		list_del(&child->list);
		dput(child->dentry);
		kfree(child);
	}
out:
	while (!list_empty(dentries)) {
		child = list_entry(dentries->next, struct dentry_list, list);
		list_del(&child->list);
		dput(child->dentry);
		kfree(child);
	}
261
	nfs4_reset_creds(original_cred);
262 263 264
	return status;
}

265 266 267 268 269 270 271 272 273
static int
nfsd4_remove_clid_file(struct dentry *dir, struct dentry *dentry)
{
	int status;

	if (!S_ISREG(dir->d_inode->i_mode)) {
		printk("nfsd4: non-file found in client recovery directory\n");
		return -EINVAL;
	}
274
	mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
275
	status = vfs_unlink(dir->d_inode, dentry);
276
	mutex_unlock(&dir->d_inode->i_mutex);
277 278 279 280 281 282 283 284 285 286 287 288
	return status;
}

static int
nfsd4_clear_clid_dir(struct dentry *dir, struct dentry *dentry)
{
	int status;

	/* For now this directory should already be empty, but we empty it of
	 * any regular files anyway, just in case the directory was created by
	 * a kernel from the future.... */
	nfsd4_list_rec_dir(dentry, nfsd4_remove_clid_file);
289
	mutex_lock_nested(&dir->d_inode->i_mutex, I_MUTEX_PARENT);
290
	status = vfs_rmdir(dir->d_inode, dentry);
291
	mutex_unlock(&dir->d_inode->i_mutex);
292 293 294 295 296 297 298 299 300 301 302
	return status;
}

static int
nfsd4_unlink_clid_dir(char *name, int namlen)
{
	struct dentry *dentry;
	int status;

	dprintk("NFSD: nfsd4_unlink_clid_dir. name %.*s\n", namlen, name);

Al Viro's avatar
Al Viro committed
303 304 305
	mutex_lock(&rec_dir.dentry->d_inode->i_mutex);
	dentry = lookup_one_len(name, rec_dir.dentry, namlen);
	mutex_unlock(&rec_dir.dentry->d_inode->i_mutex);
306 307 308 309 310 311 312 313
	if (IS_ERR(dentry)) {
		status = PTR_ERR(dentry);
		return status;
	}
	status = -ENOENT;
	if (!dentry->d_inode)
		goto out;

Al Viro's avatar
Al Viro committed
314
	status = nfsd4_clear_clid_dir(rec_dir.dentry, dentry);
315 316 317 318 319 320 321 322
out:
	dput(dentry);
	return status;
}

void
nfsd4_remove_clid_dir(struct nfs4_client *clp)
{
323
	const struct cred *original_cred;
324 325 326 327 328
	int status;

	if (!rec_dir_init || !clp->cl_firststate)
		return;

Al Viro's avatar
Al Viro committed
329
	status = mnt_want_write(rec_dir.mnt);
330 331
	if (status)
		goto out;
332
	clp->cl_firststate = 0;
333 334 335 336 337

	status = nfs4_save_creds(&original_cred);
	if (status < 0)
		goto out;

338
	status = nfsd4_unlink_clid_dir(clp->cl_recdir, HEXDIR_LEN-1);
339
	nfs4_reset_creds(original_cred);
340
	if (status == 0)
341
		nfsd4_sync_rec_dir();
Al Viro's avatar
Al Viro committed
342
	mnt_drop_write(rec_dir.mnt);
343
out:
344 345 346 347 348 349 350 351 352 353 354 355
	if (status)
		printk("NFSD: Failed to remove expired client state directory"
				" %.*s\n", HEXDIR_LEN, clp->cl_recdir);
	return;
}

static int
purge_old(struct dentry *parent, struct dentry *child)
{
	int status;

	if (nfs4_has_reclaimed_state(child->d_name.name))
356
		return 0;
357 358 359 360 361 362

	status = nfsd4_clear_clid_dir(parent, child);
	if (status)
		printk("failed to remove client recovery directory %s\n",
				child->d_name.name);
	/* Keep trying, success or failure: */
363
	return 0;
364 365 366 367 368 369 370 371
}

void
nfsd4_recdir_purge_old(void) {
	int status;

	if (!rec_dir_init)
		return;
Al Viro's avatar
Al Viro committed
372
	status = mnt_want_write(rec_dir.mnt);
373 374
	if (status)
		goto out;
Al Viro's avatar
Al Viro committed
375
	status = nfsd4_list_rec_dir(rec_dir.dentry, purge_old);
376
	if (status == 0)
377
		nfsd4_sync_rec_dir();
Al Viro's avatar
Al Viro committed
378
	mnt_drop_write(rec_dir.mnt);
379
out:
380 381
	if (status)
		printk("nfsd4: failed to purge old clients from recovery"
Al Viro's avatar
Al Viro committed
382
			" directory %s\n", rec_dir.dentry->d_name.name);
383 384
}

385 386 387 388 389 390 391
static int
load_recdir(struct dentry *parent, struct dentry *child)
{
	if (child->d_name.len != HEXDIR_LEN - 1) {
		printk("nfsd4: illegal name %s in recovery directory\n",
				child->d_name.name);
		/* Keep trying; maybe the others are OK: */
392
		return 0;
393 394
	}
	nfs4_client_to_reclaim(child->d_name.name);
395
	return 0;
396 397 398 399 400 401
}

int
nfsd4_recdir_load(void) {
	int status;

Al Viro's avatar
Al Viro committed
402
	status = nfsd4_list_rec_dir(rec_dir.dentry, load_recdir);
403 404
	if (status)
		printk("nfsd4: failed loading clients from recovery"
Al Viro's avatar
Al Viro committed
405
			" directory %s\n", rec_dir.dentry->d_name.name);
406 407 408 409 410 411 412 413 414 415
	return status;
}

/*
 * Hold reference to the recovery directory.
 */

void
nfsd4_init_recdir(char *rec_dirname)
{
416 417
	const struct cred *original_cred;
	int status;
418 419 420 421 422 423

	printk("NFSD: Using %s as the NFSv4 state recovery directory\n",
			rec_dirname);

	BUG_ON(rec_dir_init);

424 425 426 427 428 429 430
	status = nfs4_save_creds(&original_cred);
	if (status < 0) {
		printk("NFSD: Unable to change credentials to find recovery"
		       " directory: error %d\n",
		       status);
		return;
	}
431

Al Viro's avatar
Al Viro committed
432
	status = kern_path(rec_dirname, LOOKUP_FOLLOW | LOOKUP_DIRECTORY,
433 434 435
			&rec_dir);
	if (status)
		printk("NFSD: unable to find recovery directory %s\n",
436 437 438 439
				rec_dirname);

	if (!status)
		rec_dir_init = 1;
440
	nfs4_reset_creds(original_cred);
441 442 443 444 445 446 447 448
}

void
nfsd4_shutdown_recdir(void)
{
	if (!rec_dir_init)
		return;
	rec_dir_init = 0;
Al Viro's avatar
Al Viro committed
449
	path_put(&rec_dir);
450
}