xref: /openbmc/linux/fs/smb/client/smb2file.c (revision ecc23d0a422a3118fcf6e4f0a46e17a6c2047b02)
138c8a9a5SSteve French // SPDX-License-Identifier: LGPL-2.1
238c8a9a5SSteve French /*
338c8a9a5SSteve French  *
438c8a9a5SSteve French  *   Copyright (C) International Business Machines  Corp., 2002, 2011
538c8a9a5SSteve French  *   Author(s): Steve French (sfrench@us.ibm.com),
638c8a9a5SSteve French  *              Pavel Shilovsky ((pshilovsky@samba.org) 2012
738c8a9a5SSteve French  *
838c8a9a5SSteve French  */
938c8a9a5SSteve French #include <linux/fs.h>
1038c8a9a5SSteve French #include <linux/filelock.h>
1138c8a9a5SSteve French #include <linux/stat.h>
1238c8a9a5SSteve French #include <linux/slab.h>
1338c8a9a5SSteve French #include <linux/pagemap.h>
1438c8a9a5SSteve French #include <asm/div64.h>
1538c8a9a5SSteve French #include "cifsfs.h"
1638c8a9a5SSteve French #include "cifspdu.h"
1738c8a9a5SSteve French #include "cifsglob.h"
1838c8a9a5SSteve French #include "cifsproto.h"
1938c8a9a5SSteve French #include "cifs_debug.h"
2038c8a9a5SSteve French #include "cifs_fs_sb.h"
2138c8a9a5SSteve French #include "cifs_unicode.h"
2238c8a9a5SSteve French #include "fscache.h"
2338c8a9a5SSteve French #include "smb2proto.h"
2438c8a9a5SSteve French #include "smb2status.h"
2538c8a9a5SSteve French 
symlink_data(const struct kvec * iov)2638c8a9a5SSteve French static struct smb2_symlink_err_rsp *symlink_data(const struct kvec *iov)
2738c8a9a5SSteve French {
2838c8a9a5SSteve French 	struct smb2_err_rsp *err = iov->iov_base;
2938c8a9a5SSteve French 	struct smb2_symlink_err_rsp *sym = ERR_PTR(-EINVAL);
3038c8a9a5SSteve French 	u32 len;
3138c8a9a5SSteve French 
3238c8a9a5SSteve French 	if (err->ErrorContextCount) {
3338c8a9a5SSteve French 		struct smb2_error_context_rsp *p, *end;
3438c8a9a5SSteve French 
3538c8a9a5SSteve French 		len = (u32)err->ErrorContextCount * (offsetof(struct smb2_error_context_rsp,
3638c8a9a5SSteve French 							      ErrorContextData) +
3738c8a9a5SSteve French 						     sizeof(struct smb2_symlink_err_rsp));
3838c8a9a5SSteve French 		if (le32_to_cpu(err->ByteCount) < len || iov->iov_len < len + sizeof(*err) + 1)
3938c8a9a5SSteve French 			return ERR_PTR(-EINVAL);
4038c8a9a5SSteve French 
4138c8a9a5SSteve French 		p = (struct smb2_error_context_rsp *)err->ErrorData;
4238c8a9a5SSteve French 		end = (struct smb2_error_context_rsp *)((u8 *)err + iov->iov_len);
4338c8a9a5SSteve French 		do {
4438c8a9a5SSteve French 			if (le32_to_cpu(p->ErrorId) == SMB2_ERROR_ID_DEFAULT) {
4538c8a9a5SSteve French 				sym = (struct smb2_symlink_err_rsp *)&p->ErrorContextData;
4638c8a9a5SSteve French 				break;
4738c8a9a5SSteve French 			}
4838c8a9a5SSteve French 			cifs_dbg(FYI, "%s: skipping unhandled error context: 0x%x\n",
4938c8a9a5SSteve French 				 __func__, le32_to_cpu(p->ErrorId));
5038c8a9a5SSteve French 
5138c8a9a5SSteve French 			len = ALIGN(le32_to_cpu(p->ErrorDataLength), 8);
5238c8a9a5SSteve French 			p = (struct smb2_error_context_rsp *)((u8 *)&p->ErrorContextData + len);
5338c8a9a5SSteve French 		} while (p < end);
5438c8a9a5SSteve French 	} else if (le32_to_cpu(err->ByteCount) >= sizeof(*sym) &&
5538c8a9a5SSteve French 		   iov->iov_len >= SMB2_SYMLINK_STRUCT_SIZE) {
5638c8a9a5SSteve French 		sym = (struct smb2_symlink_err_rsp *)err->ErrorData;
5738c8a9a5SSteve French 	}
5838c8a9a5SSteve French 
5938c8a9a5SSteve French 	if (!IS_ERR(sym) && (le32_to_cpu(sym->SymLinkErrorTag) != SYMLINK_ERROR_TAG ||
6038c8a9a5SSteve French 			     le32_to_cpu(sym->ReparseTag) != IO_REPARSE_TAG_SYMLINK))
6138c8a9a5SSteve French 		sym = ERR_PTR(-EINVAL);
6238c8a9a5SSteve French 
6338c8a9a5SSteve French 	return sym;
6438c8a9a5SSteve French }
6538c8a9a5SSteve French 
smb2_parse_symlink_response(struct cifs_sb_info * cifs_sb,const struct kvec * iov,const char * full_path,char ** path)66*430afd3eSPali Rohár int smb2_parse_symlink_response(struct cifs_sb_info *cifs_sb, const struct kvec *iov,
67*430afd3eSPali Rohár 				const char *full_path, char **path)
6838c8a9a5SSteve French {
6938c8a9a5SSteve French 	struct smb2_symlink_err_rsp *sym;
7038c8a9a5SSteve French 	unsigned int sub_offs, sub_len;
7138c8a9a5SSteve French 	unsigned int print_offs, print_len;
7238c8a9a5SSteve French 
7338c8a9a5SSteve French 	if (!cifs_sb || !iov || !iov->iov_base || !iov->iov_len || !path)
7438c8a9a5SSteve French 		return -EINVAL;
7538c8a9a5SSteve French 
7638c8a9a5SSteve French 	sym = symlink_data(iov);
7738c8a9a5SSteve French 	if (IS_ERR(sym))
7838c8a9a5SSteve French 		return PTR_ERR(sym);
7938c8a9a5SSteve French 
8038c8a9a5SSteve French 	sub_len = le16_to_cpu(sym->SubstituteNameLength);
8138c8a9a5SSteve French 	sub_offs = le16_to_cpu(sym->SubstituteNameOffset);
8238c8a9a5SSteve French 	print_len = le16_to_cpu(sym->PrintNameLength);
8338c8a9a5SSteve French 	print_offs = le16_to_cpu(sym->PrintNameOffset);
8438c8a9a5SSteve French 
8538c8a9a5SSteve French 	if (iov->iov_len < SMB2_SYMLINK_STRUCT_SIZE + sub_offs + sub_len ||
8638c8a9a5SSteve French 	    iov->iov_len < SMB2_SYMLINK_STRUCT_SIZE + print_offs + print_len)
8738c8a9a5SSteve French 		return -EINVAL;
8838c8a9a5SSteve French 
89*430afd3eSPali Rohár 	return smb2_parse_native_symlink(path,
90*430afd3eSPali Rohár 					 (char *)sym->PathBuffer + sub_offs,
91*430afd3eSPali Rohár 					 sub_len,
92*430afd3eSPali Rohár 					 true,
93*430afd3eSPali Rohár 					 le32_to_cpu(sym->Flags) & SYMLINK_FLAG_RELATIVE,
94*430afd3eSPali Rohár 					 full_path,
95*430afd3eSPali Rohár 					 cifs_sb);
9638c8a9a5SSteve French }
9738c8a9a5SSteve French 
smb2_open_file(const unsigned int xid,struct cifs_open_parms * oparms,__u32 * oplock,void * buf)9838c8a9a5SSteve French int smb2_open_file(const unsigned int xid, struct cifs_open_parms *oparms, __u32 *oplock, void *buf)
9938c8a9a5SSteve French {
10038c8a9a5SSteve French 	int rc;
10138c8a9a5SSteve French 	__le16 *smb2_path;
10238c8a9a5SSteve French 	__u8 smb2_oplock;
10338c8a9a5SSteve French 	struct cifs_open_info_data *data = buf;
10438c8a9a5SSteve French 	struct smb2_file_all_info file_info = {};
10538c8a9a5SSteve French 	struct smb2_file_all_info *smb2_data = data ? &file_info : NULL;
10638c8a9a5SSteve French 	struct kvec err_iov = {};
10738c8a9a5SSteve French 	int err_buftype = CIFS_NO_BUFFER;
10838c8a9a5SSteve French 	struct cifs_fid *fid = oparms->fid;
10938c8a9a5SSteve French 	struct network_resiliency_req nr_ioctl_req;
11038c8a9a5SSteve French 
11138c8a9a5SSteve French 	smb2_path = cifs_convert_path_to_utf16(oparms->path, oparms->cifs_sb);
11238c8a9a5SSteve French 	if (smb2_path == NULL)
11338c8a9a5SSteve French 		return -ENOMEM;
11438c8a9a5SSteve French 
11538c8a9a5SSteve French 	oparms->desired_access |= FILE_READ_ATTRIBUTES;
11638c8a9a5SSteve French 	smb2_oplock = SMB2_OPLOCK_LEVEL_BATCH;
11738c8a9a5SSteve French 
11838c8a9a5SSteve French 	rc = SMB2_open(xid, oparms, smb2_path, &smb2_oplock, smb2_data, NULL, &err_iov,
11938c8a9a5SSteve French 		       &err_buftype);
12038c8a9a5SSteve French 	if (rc && data) {
12138c8a9a5SSteve French 		struct smb2_hdr *hdr = err_iov.iov_base;
12238c8a9a5SSteve French 
12338c8a9a5SSteve French 		if (unlikely(!err_iov.iov_base || err_buftype == CIFS_NO_BUFFER))
12438c8a9a5SSteve French 			goto out;
12538c8a9a5SSteve French 		if (hdr->Status == STATUS_STOPPED_ON_SYMLINK) {
12638c8a9a5SSteve French 			rc = smb2_parse_symlink_response(oparms->cifs_sb, &err_iov,
127*430afd3eSPali Rohár 							 oparms->path,
12838c8a9a5SSteve French 							 &data->symlink_target);
12938c8a9a5SSteve French 			if (!rc) {
13038c8a9a5SSteve French 				memset(smb2_data, 0, sizeof(*smb2_data));
13138c8a9a5SSteve French 				oparms->create_options |= OPEN_REPARSE_POINT;
13238c8a9a5SSteve French 				rc = SMB2_open(xid, oparms, smb2_path, &smb2_oplock, smb2_data,
13338c8a9a5SSteve French 					       NULL, NULL, NULL);
13438c8a9a5SSteve French 				oparms->create_options &= ~OPEN_REPARSE_POINT;
13538c8a9a5SSteve French 			}
13638c8a9a5SSteve French 		}
13738c8a9a5SSteve French 	}
13838c8a9a5SSteve French 
13938c8a9a5SSteve French 	if (rc)
14038c8a9a5SSteve French 		goto out;
14138c8a9a5SSteve French 
14238c8a9a5SSteve French 	if (oparms->tcon->use_resilient) {
14338c8a9a5SSteve French 		/* default timeout is 0, servers pick default (120 seconds) */
14438c8a9a5SSteve French 		nr_ioctl_req.Timeout =
14538c8a9a5SSteve French 			cpu_to_le32(oparms->tcon->handle_timeout);
14638c8a9a5SSteve French 		nr_ioctl_req.Reserved = 0;
14738c8a9a5SSteve French 		rc = SMB2_ioctl(xid, oparms->tcon, fid->persistent_fid,
14838c8a9a5SSteve French 			fid->volatile_fid, FSCTL_LMR_REQUEST_RESILIENCY,
14938c8a9a5SSteve French 			(char *)&nr_ioctl_req, sizeof(nr_ioctl_req),
15038c8a9a5SSteve French 			CIFSMaxBufSize, NULL, NULL /* no return info */);
15138c8a9a5SSteve French 		if (rc == -EOPNOTSUPP) {
15238c8a9a5SSteve French 			cifs_dbg(VFS,
15338c8a9a5SSteve French 			     "resiliency not supported by server, disabling\n");
15438c8a9a5SSteve French 			oparms->tcon->use_resilient = false;
15538c8a9a5SSteve French 		} else if (rc)
15638c8a9a5SSteve French 			cifs_dbg(FYI, "error %d setting resiliency\n", rc);
15738c8a9a5SSteve French 
15838c8a9a5SSteve French 		rc = 0;
15938c8a9a5SSteve French 	}
16038c8a9a5SSteve French 
16138c8a9a5SSteve French 	if (smb2_data) {
16238c8a9a5SSteve French 		/* if open response does not have IndexNumber field - get it */
16338c8a9a5SSteve French 		if (smb2_data->IndexNumber == 0) {
16438c8a9a5SSteve French 			rc = SMB2_get_srv_num(xid, oparms->tcon,
16538c8a9a5SSteve French 				      fid->persistent_fid,
16638c8a9a5SSteve French 				      fid->volatile_fid,
16738c8a9a5SSteve French 				      &smb2_data->IndexNumber);
16838c8a9a5SSteve French 			if (rc) {
16938c8a9a5SSteve French 				/*
17038c8a9a5SSteve French 				 * let get_inode_info disable server inode
17138c8a9a5SSteve French 				 * numbers
17238c8a9a5SSteve French 				 */
17338c8a9a5SSteve French 				smb2_data->IndexNumber = 0;
17438c8a9a5SSteve French 				rc = 0;
17538c8a9a5SSteve French 			}
17638c8a9a5SSteve French 		}
17738c8a9a5SSteve French 		memcpy(&data->fi, smb2_data, sizeof(data->fi));
17838c8a9a5SSteve French 	}
17938c8a9a5SSteve French 
18038c8a9a5SSteve French 	*oplock = smb2_oplock;
18138c8a9a5SSteve French out:
18238c8a9a5SSteve French 	free_rsp_buf(err_buftype, err_iov.iov_base);
18338c8a9a5SSteve French 	kfree(smb2_path);
18438c8a9a5SSteve French 	return rc;
18538c8a9a5SSteve French }
18638c8a9a5SSteve French 
18738c8a9a5SSteve French int
smb2_unlock_range(struct cifsFileInfo * cfile,struct file_lock * flock,const unsigned int xid)18838c8a9a5SSteve French smb2_unlock_range(struct cifsFileInfo *cfile, struct file_lock *flock,
18938c8a9a5SSteve French 		  const unsigned int xid)
19038c8a9a5SSteve French {
19138c8a9a5SSteve French 	int rc = 0, stored_rc;
19238c8a9a5SSteve French 	unsigned int max_num, num = 0, max_buf;
19338c8a9a5SSteve French 	struct smb2_lock_element *buf, *cur;
19438c8a9a5SSteve French 	struct cifs_tcon *tcon = tlink_tcon(cfile->tlink);
19538c8a9a5SSteve French 	struct cifsInodeInfo *cinode = CIFS_I(d_inode(cfile->dentry));
19638c8a9a5SSteve French 	struct cifsLockInfo *li, *tmp;
19738c8a9a5SSteve French 	__u64 length = 1 + flock->fl_end - flock->fl_start;
19838c8a9a5SSteve French 	struct list_head tmp_llist;
19938c8a9a5SSteve French 
20038c8a9a5SSteve French 	INIT_LIST_HEAD(&tmp_llist);
20138c8a9a5SSteve French 
20238c8a9a5SSteve French 	/*
20338c8a9a5SSteve French 	 * Accessing maxBuf is racy with cifs_reconnect - need to store value
20438c8a9a5SSteve French 	 * and check it before using.
20538c8a9a5SSteve French 	 */
20638c8a9a5SSteve French 	max_buf = tcon->ses->server->maxBuf;
20738c8a9a5SSteve French 	if (max_buf < sizeof(struct smb2_lock_element))
20838c8a9a5SSteve French 		return -EINVAL;
20938c8a9a5SSteve French 
21038c8a9a5SSteve French 	BUILD_BUG_ON(sizeof(struct smb2_lock_element) > PAGE_SIZE);
21138c8a9a5SSteve French 	max_buf = min_t(unsigned int, max_buf, PAGE_SIZE);
21238c8a9a5SSteve French 	max_num = max_buf / sizeof(struct smb2_lock_element);
21338c8a9a5SSteve French 	buf = kcalloc(max_num, sizeof(struct smb2_lock_element), GFP_KERNEL);
21438c8a9a5SSteve French 	if (!buf)
21538c8a9a5SSteve French 		return -ENOMEM;
21638c8a9a5SSteve French 
21738c8a9a5SSteve French 	cur = buf;
21838c8a9a5SSteve French 
21938c8a9a5SSteve French 	cifs_down_write(&cinode->lock_sem);
22038c8a9a5SSteve French 	list_for_each_entry_safe(li, tmp, &cfile->llist->locks, llist) {
22138c8a9a5SSteve French 		if (flock->fl_start > li->offset ||
22238c8a9a5SSteve French 		    (flock->fl_start + length) <
22338c8a9a5SSteve French 		    (li->offset + li->length))
22438c8a9a5SSteve French 			continue;
22538c8a9a5SSteve French 		if (current->tgid != li->pid)
22638c8a9a5SSteve French 			/*
22738c8a9a5SSteve French 			 * flock and OFD lock are associated with an open
22838c8a9a5SSteve French 			 * file description, not the process.
22938c8a9a5SSteve French 			 */
23038c8a9a5SSteve French 			if (!(flock->fl_flags & (FL_FLOCK | FL_OFDLCK)))
23138c8a9a5SSteve French 				continue;
23238c8a9a5SSteve French 		if (cinode->can_cache_brlcks) {
23338c8a9a5SSteve French 			/*
23438c8a9a5SSteve French 			 * We can cache brlock requests - simply remove a lock
23538c8a9a5SSteve French 			 * from the file's list.
23638c8a9a5SSteve French 			 */
23738c8a9a5SSteve French 			list_del(&li->llist);
23838c8a9a5SSteve French 			cifs_del_lock_waiters(li);
23938c8a9a5SSteve French 			kfree(li);
24038c8a9a5SSteve French 			continue;
24138c8a9a5SSteve French 		}
24238c8a9a5SSteve French 		cur->Length = cpu_to_le64(li->length);
24338c8a9a5SSteve French 		cur->Offset = cpu_to_le64(li->offset);
24438c8a9a5SSteve French 		cur->Flags = cpu_to_le32(SMB2_LOCKFLAG_UNLOCK);
24538c8a9a5SSteve French 		/*
24638c8a9a5SSteve French 		 * We need to save a lock here to let us add it again to the
24738c8a9a5SSteve French 		 * file's list if the unlock range request fails on the server.
24838c8a9a5SSteve French 		 */
24938c8a9a5SSteve French 		list_move(&li->llist, &tmp_llist);
25038c8a9a5SSteve French 		if (++num == max_num) {
25138c8a9a5SSteve French 			stored_rc = smb2_lockv(xid, tcon,
25238c8a9a5SSteve French 					       cfile->fid.persistent_fid,
25338c8a9a5SSteve French 					       cfile->fid.volatile_fid,
25438c8a9a5SSteve French 					       current->tgid, num, buf);
25538c8a9a5SSteve French 			if (stored_rc) {
25638c8a9a5SSteve French 				/*
25738c8a9a5SSteve French 				 * We failed on the unlock range request - add
25838c8a9a5SSteve French 				 * all locks from the tmp list to the head of
25938c8a9a5SSteve French 				 * the file's list.
26038c8a9a5SSteve French 				 */
26138c8a9a5SSteve French 				cifs_move_llist(&tmp_llist,
26238c8a9a5SSteve French 						&cfile->llist->locks);
26338c8a9a5SSteve French 				rc = stored_rc;
26438c8a9a5SSteve French 			} else
26538c8a9a5SSteve French 				/*
26638c8a9a5SSteve French 				 * The unlock range request succeed - free the
26738c8a9a5SSteve French 				 * tmp list.
26838c8a9a5SSteve French 				 */
26938c8a9a5SSteve French 				cifs_free_llist(&tmp_llist);
27038c8a9a5SSteve French 			cur = buf;
27138c8a9a5SSteve French 			num = 0;
27238c8a9a5SSteve French 		} else
27338c8a9a5SSteve French 			cur++;
27438c8a9a5SSteve French 	}
27538c8a9a5SSteve French 	if (num) {
27638c8a9a5SSteve French 		stored_rc = smb2_lockv(xid, tcon, cfile->fid.persistent_fid,
27738c8a9a5SSteve French 				       cfile->fid.volatile_fid, current->tgid,
27838c8a9a5SSteve French 				       num, buf);
27938c8a9a5SSteve French 		if (stored_rc) {
28038c8a9a5SSteve French 			cifs_move_llist(&tmp_llist, &cfile->llist->locks);
28138c8a9a5SSteve French 			rc = stored_rc;
28238c8a9a5SSteve French 		} else
28338c8a9a5SSteve French 			cifs_free_llist(&tmp_llist);
28438c8a9a5SSteve French 	}
28538c8a9a5SSteve French 	up_write(&cinode->lock_sem);
28638c8a9a5SSteve French 
28738c8a9a5SSteve French 	kfree(buf);
28838c8a9a5SSteve French 	return rc;
28938c8a9a5SSteve French }
29038c8a9a5SSteve French 
29138c8a9a5SSteve French static int
smb2_push_mand_fdlocks(struct cifs_fid_locks * fdlocks,const unsigned int xid,struct smb2_lock_element * buf,unsigned int max_num)29238c8a9a5SSteve French smb2_push_mand_fdlocks(struct cifs_fid_locks *fdlocks, const unsigned int xid,
29338c8a9a5SSteve French 		       struct smb2_lock_element *buf, unsigned int max_num)
29438c8a9a5SSteve French {
29538c8a9a5SSteve French 	int rc = 0, stored_rc;
29638c8a9a5SSteve French 	struct cifsFileInfo *cfile = fdlocks->cfile;
29738c8a9a5SSteve French 	struct cifsLockInfo *li;
29838c8a9a5SSteve French 	unsigned int num = 0;
29938c8a9a5SSteve French 	struct smb2_lock_element *cur = buf;
30038c8a9a5SSteve French 	struct cifs_tcon *tcon = tlink_tcon(cfile->tlink);
30138c8a9a5SSteve French 
30238c8a9a5SSteve French 	list_for_each_entry(li, &fdlocks->locks, llist) {
30338c8a9a5SSteve French 		cur->Length = cpu_to_le64(li->length);
30438c8a9a5SSteve French 		cur->Offset = cpu_to_le64(li->offset);
30538c8a9a5SSteve French 		cur->Flags = cpu_to_le32(li->type |
30638c8a9a5SSteve French 						SMB2_LOCKFLAG_FAIL_IMMEDIATELY);
30738c8a9a5SSteve French 		if (++num == max_num) {
30838c8a9a5SSteve French 			stored_rc = smb2_lockv(xid, tcon,
30938c8a9a5SSteve French 					       cfile->fid.persistent_fid,
31038c8a9a5SSteve French 					       cfile->fid.volatile_fid,
31138c8a9a5SSteve French 					       current->tgid, num, buf);
31238c8a9a5SSteve French 			if (stored_rc)
31338c8a9a5SSteve French 				rc = stored_rc;
31438c8a9a5SSteve French 			cur = buf;
31538c8a9a5SSteve French 			num = 0;
31638c8a9a5SSteve French 		} else
31738c8a9a5SSteve French 			cur++;
31838c8a9a5SSteve French 	}
31938c8a9a5SSteve French 	if (num) {
32038c8a9a5SSteve French 		stored_rc = smb2_lockv(xid, tcon,
32138c8a9a5SSteve French 				       cfile->fid.persistent_fid,
32238c8a9a5SSteve French 				       cfile->fid.volatile_fid,
32338c8a9a5SSteve French 				       current->tgid, num, buf);
32438c8a9a5SSteve French 		if (stored_rc)
32538c8a9a5SSteve French 			rc = stored_rc;
32638c8a9a5SSteve French 	}
32738c8a9a5SSteve French 
32838c8a9a5SSteve French 	return rc;
32938c8a9a5SSteve French }
33038c8a9a5SSteve French 
33138c8a9a5SSteve French int
smb2_push_mandatory_locks(struct cifsFileInfo * cfile)33238c8a9a5SSteve French smb2_push_mandatory_locks(struct cifsFileInfo *cfile)
33338c8a9a5SSteve French {
33438c8a9a5SSteve French 	int rc = 0, stored_rc;
33538c8a9a5SSteve French 	unsigned int xid;
33638c8a9a5SSteve French 	unsigned int max_num, max_buf;
33738c8a9a5SSteve French 	struct smb2_lock_element *buf;
33838c8a9a5SSteve French 	struct cifsInodeInfo *cinode = CIFS_I(d_inode(cfile->dentry));
33938c8a9a5SSteve French 	struct cifs_fid_locks *fdlocks;
34038c8a9a5SSteve French 
34138c8a9a5SSteve French 	xid = get_xid();
34238c8a9a5SSteve French 
34338c8a9a5SSteve French 	/*
34438c8a9a5SSteve French 	 * Accessing maxBuf is racy with cifs_reconnect - need to store value
34538c8a9a5SSteve French 	 * and check it for zero before using.
34638c8a9a5SSteve French 	 */
34738c8a9a5SSteve French 	max_buf = tlink_tcon(cfile->tlink)->ses->server->maxBuf;
34838c8a9a5SSteve French 	if (max_buf < sizeof(struct smb2_lock_element)) {
34938c8a9a5SSteve French 		free_xid(xid);
35038c8a9a5SSteve French 		return -EINVAL;
35138c8a9a5SSteve French 	}
35238c8a9a5SSteve French 
35338c8a9a5SSteve French 	BUILD_BUG_ON(sizeof(struct smb2_lock_element) > PAGE_SIZE);
35438c8a9a5SSteve French 	max_buf = min_t(unsigned int, max_buf, PAGE_SIZE);
35538c8a9a5SSteve French 	max_num = max_buf / sizeof(struct smb2_lock_element);
35638c8a9a5SSteve French 	buf = kcalloc(max_num, sizeof(struct smb2_lock_element), GFP_KERNEL);
35738c8a9a5SSteve French 	if (!buf) {
35838c8a9a5SSteve French 		free_xid(xid);
35938c8a9a5SSteve French 		return -ENOMEM;
36038c8a9a5SSteve French 	}
36138c8a9a5SSteve French 
36238c8a9a5SSteve French 	list_for_each_entry(fdlocks, &cinode->llist, llist) {
36338c8a9a5SSteve French 		stored_rc = smb2_push_mand_fdlocks(fdlocks, xid, buf, max_num);
36438c8a9a5SSteve French 		if (stored_rc)
36538c8a9a5SSteve French 			rc = stored_rc;
36638c8a9a5SSteve French 	}
36738c8a9a5SSteve French 
36838c8a9a5SSteve French 	kfree(buf);
36938c8a9a5SSteve French 	free_xid(xid);
37038c8a9a5SSteve French 	return rc;
37138c8a9a5SSteve French }
372