xref: /openbmc/linux/fs/ext4/ioctl.c (revision 79906964)
1 /*
2  * linux/fs/ext4/ioctl.c
3  *
4  * Copyright (C) 1993, 1994, 1995
5  * Remy Card (card@masi.ibp.fr)
6  * Laboratoire MASI - Institut Blaise Pascal
7  * Universite Pierre et Marie Curie (Paris VI)
8  */
9 
10 #include <linux/fs.h>
11 #include <linux/jbd2.h>
12 #include <linux/capability.h>
13 #include <linux/time.h>
14 #include <linux/compat.h>
15 #include <linux/mount.h>
16 #include <linux/file.h>
17 #include <asm/uaccess.h>
18 #include "ext4_jbd2.h"
19 #include "ext4.h"
20 
21 #define MAX_32_NUM ((((unsigned long long) 1) << 32) - 1)
22 
23 long ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
24 {
25 	struct inode *inode = filp->f_dentry->d_inode;
26 	struct super_block *sb = inode->i_sb;
27 	struct ext4_inode_info *ei = EXT4_I(inode);
28 	unsigned int flags;
29 
30 	ext4_debug("cmd = %u, arg = %lu\n", cmd, arg);
31 
32 	switch (cmd) {
33 	case EXT4_IOC_GETFLAGS:
34 		ext4_get_inode_flags(ei);
35 		flags = ei->i_flags & EXT4_FL_USER_VISIBLE;
36 		return put_user(flags, (int __user *) arg);
37 	case EXT4_IOC_SETFLAGS: {
38 		handle_t *handle = NULL;
39 		int err, migrate = 0;
40 		struct ext4_iloc iloc;
41 		unsigned int oldflags, mask, i;
42 		unsigned int jflag;
43 
44 		if (!inode_owner_or_capable(inode))
45 			return -EACCES;
46 
47 		if (get_user(flags, (int __user *) arg))
48 			return -EFAULT;
49 
50 		err = mnt_want_write_file(filp);
51 		if (err)
52 			return err;
53 
54 		flags = ext4_mask_flags(inode->i_mode, flags);
55 
56 		err = -EPERM;
57 		mutex_lock(&inode->i_mutex);
58 		/* Is it quota file? Do not allow user to mess with it */
59 		if (IS_NOQUOTA(inode))
60 			goto flags_out;
61 
62 		oldflags = ei->i_flags;
63 
64 		/* The JOURNAL_DATA flag is modifiable only by root */
65 		jflag = flags & EXT4_JOURNAL_DATA_FL;
66 
67 		/*
68 		 * The IMMUTABLE and APPEND_ONLY flags can only be changed by
69 		 * the relevant capability.
70 		 *
71 		 * This test looks nicer. Thanks to Pauline Middelink
72 		 */
73 		if ((flags ^ oldflags) & (EXT4_APPEND_FL | EXT4_IMMUTABLE_FL)) {
74 			if (!capable(CAP_LINUX_IMMUTABLE))
75 				goto flags_out;
76 		}
77 
78 		/*
79 		 * The JOURNAL_DATA flag can only be changed by
80 		 * the relevant capability.
81 		 */
82 		if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
83 			if (!capable(CAP_SYS_RESOURCE))
84 				goto flags_out;
85 		}
86 		if (oldflags & EXT4_EXTENTS_FL) {
87 			/* We don't support clearning extent flags */
88 			if (!(flags & EXT4_EXTENTS_FL)) {
89 				err = -EOPNOTSUPP;
90 				goto flags_out;
91 			}
92 		} else if (flags & EXT4_EXTENTS_FL) {
93 			/* migrate the file */
94 			migrate = 1;
95 			flags &= ~EXT4_EXTENTS_FL;
96 		}
97 
98 		if (flags & EXT4_EOFBLOCKS_FL) {
99 			/* we don't support adding EOFBLOCKS flag */
100 			if (!(oldflags & EXT4_EOFBLOCKS_FL)) {
101 				err = -EOPNOTSUPP;
102 				goto flags_out;
103 			}
104 		} else if (oldflags & EXT4_EOFBLOCKS_FL)
105 			ext4_truncate(inode);
106 
107 		handle = ext4_journal_start(inode, 1);
108 		if (IS_ERR(handle)) {
109 			err = PTR_ERR(handle);
110 			goto flags_out;
111 		}
112 		if (IS_SYNC(inode))
113 			ext4_handle_sync(handle);
114 		err = ext4_reserve_inode_write(handle, inode, &iloc);
115 		if (err)
116 			goto flags_err;
117 
118 		for (i = 0, mask = 1; i < 32; i++, mask <<= 1) {
119 			if (!(mask & EXT4_FL_USER_MODIFIABLE))
120 				continue;
121 			if (mask & flags)
122 				ext4_set_inode_flag(inode, i);
123 			else
124 				ext4_clear_inode_flag(inode, i);
125 		}
126 		ei->i_flags = flags;
127 
128 		ext4_set_inode_flags(inode);
129 		inode->i_ctime = ext4_current_time(inode);
130 
131 		err = ext4_mark_iloc_dirty(handle, inode, &iloc);
132 flags_err:
133 		ext4_journal_stop(handle);
134 		if (err)
135 			goto flags_out;
136 
137 		if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL))
138 			err = ext4_change_inode_journal_flag(inode, jflag);
139 		if (err)
140 			goto flags_out;
141 		if (migrate)
142 			err = ext4_ext_migrate(inode);
143 flags_out:
144 		mutex_unlock(&inode->i_mutex);
145 		mnt_drop_write_file(filp);
146 		return err;
147 	}
148 	case EXT4_IOC_GETVERSION:
149 	case EXT4_IOC_GETVERSION_OLD:
150 		return put_user(inode->i_generation, (int __user *) arg);
151 	case EXT4_IOC_SETVERSION:
152 	case EXT4_IOC_SETVERSION_OLD: {
153 		handle_t *handle;
154 		struct ext4_iloc iloc;
155 		__u32 generation;
156 		int err;
157 
158 		if (!inode_owner_or_capable(inode))
159 			return -EPERM;
160 
161 		if (EXT4_HAS_RO_COMPAT_FEATURE(inode->i_sb,
162 				EXT4_FEATURE_RO_COMPAT_METADATA_CSUM)) {
163 			ext4_warning(sb, "Setting inode version is not "
164 				     "supported with metadata_csum enabled.");
165 			return -ENOTTY;
166 		}
167 
168 		err = mnt_want_write_file(filp);
169 		if (err)
170 			return err;
171 		if (get_user(generation, (int __user *) arg)) {
172 			err = -EFAULT;
173 			goto setversion_out;
174 		}
175 
176 		mutex_lock(&inode->i_mutex);
177 		handle = ext4_journal_start(inode, 1);
178 		if (IS_ERR(handle)) {
179 			err = PTR_ERR(handle);
180 			goto unlock_out;
181 		}
182 		err = ext4_reserve_inode_write(handle, inode, &iloc);
183 		if (err == 0) {
184 			inode->i_ctime = ext4_current_time(inode);
185 			inode->i_generation = generation;
186 			err = ext4_mark_iloc_dirty(handle, inode, &iloc);
187 		}
188 		ext4_journal_stop(handle);
189 
190 unlock_out:
191 		mutex_unlock(&inode->i_mutex);
192 setversion_out:
193 		mnt_drop_write_file(filp);
194 		return err;
195 	}
196 	case EXT4_IOC_GROUP_EXTEND: {
197 		ext4_fsblk_t n_blocks_count;
198 		int err, err2=0;
199 
200 		err = ext4_resize_begin(sb);
201 		if (err)
202 			return err;
203 
204 		if (get_user(n_blocks_count, (__u32 __user *)arg)) {
205 			err = -EFAULT;
206 			goto group_extend_out;
207 		}
208 
209 		if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
210 			       EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
211 			ext4_msg(sb, KERN_ERR,
212 				 "Online resizing not supported with bigalloc");
213 			err = -EOPNOTSUPP;
214 			goto group_extend_out;
215 		}
216 
217 		err = mnt_want_write_file(filp);
218 		if (err)
219 			goto group_extend_out;
220 
221 		err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
222 		if (EXT4_SB(sb)->s_journal) {
223 			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
224 			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
225 			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
226 		}
227 		if (err == 0)
228 			err = err2;
229 		mnt_drop_write_file(filp);
230 group_extend_out:
231 		ext4_resize_end(sb);
232 		return err;
233 	}
234 
235 	case EXT4_IOC_MOVE_EXT: {
236 		struct move_extent me;
237 		struct file *donor_filp;
238 		int err;
239 
240 		if (!(filp->f_mode & FMODE_READ) ||
241 		    !(filp->f_mode & FMODE_WRITE))
242 			return -EBADF;
243 
244 		if (copy_from_user(&me,
245 			(struct move_extent __user *)arg, sizeof(me)))
246 			return -EFAULT;
247 		me.moved_len = 0;
248 
249 		donor_filp = fget(me.donor_fd);
250 		if (!donor_filp)
251 			return -EBADF;
252 
253 		if (!(donor_filp->f_mode & FMODE_WRITE)) {
254 			err = -EBADF;
255 			goto mext_out;
256 		}
257 
258 		if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
259 			       EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
260 			ext4_msg(sb, KERN_ERR,
261 				 "Online defrag not supported with bigalloc");
262 			return -EOPNOTSUPP;
263 		}
264 
265 		err = mnt_want_write_file(filp);
266 		if (err)
267 			goto mext_out;
268 
269 		err = ext4_move_extents(filp, donor_filp, me.orig_start,
270 					me.donor_start, me.len, &me.moved_len);
271 		mnt_drop_write_file(filp);
272 		mnt_drop_write(filp->f_path.mnt);
273 
274 		if (copy_to_user((struct move_extent __user *)arg,
275 				 &me, sizeof(me)))
276 			err = -EFAULT;
277 mext_out:
278 		fput(donor_filp);
279 		return err;
280 	}
281 
282 	case EXT4_IOC_GROUP_ADD: {
283 		struct ext4_new_group_data input;
284 		int err, err2=0;
285 
286 		err = ext4_resize_begin(sb);
287 		if (err)
288 			return err;
289 
290 		if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
291 				sizeof(input))) {
292 			err = -EFAULT;
293 			goto group_add_out;
294 		}
295 
296 		if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
297 			       EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
298 			ext4_msg(sb, KERN_ERR,
299 				 "Online resizing not supported with bigalloc");
300 			err = -EOPNOTSUPP;
301 			goto group_add_out;
302 		}
303 
304 		err = mnt_want_write_file(filp);
305 		if (err)
306 			goto group_add_out;
307 
308 		err = ext4_group_add(sb, &input);
309 		if (EXT4_SB(sb)->s_journal) {
310 			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
311 			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
312 			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
313 		}
314 		if (err == 0)
315 			err = err2;
316 		mnt_drop_write_file(filp);
317 group_add_out:
318 		ext4_resize_end(sb);
319 		return err;
320 	}
321 
322 	case EXT4_IOC_MIGRATE:
323 	{
324 		int err;
325 		if (!inode_owner_or_capable(inode))
326 			return -EACCES;
327 
328 		err = mnt_want_write_file(filp);
329 		if (err)
330 			return err;
331 		/*
332 		 * inode_mutex prevent write and truncate on the file.
333 		 * Read still goes through. We take i_data_sem in
334 		 * ext4_ext_swap_inode_data before we switch the
335 		 * inode format to prevent read.
336 		 */
337 		mutex_lock(&(inode->i_mutex));
338 		err = ext4_ext_migrate(inode);
339 		mutex_unlock(&(inode->i_mutex));
340 		mnt_drop_write_file(filp);
341 		return err;
342 	}
343 
344 	case EXT4_IOC_ALLOC_DA_BLKS:
345 	{
346 		int err;
347 		if (!inode_owner_or_capable(inode))
348 			return -EACCES;
349 
350 		err = mnt_want_write_file(filp);
351 		if (err)
352 			return err;
353 		err = ext4_alloc_da_blocks(inode);
354 		mnt_drop_write_file(filp);
355 		return err;
356 	}
357 
358 	case EXT4_IOC_RESIZE_FS: {
359 		ext4_fsblk_t n_blocks_count;
360 		struct super_block *sb = inode->i_sb;
361 		int err = 0, err2 = 0;
362 
363 		if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
364 			       EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
365 			ext4_msg(sb, KERN_ERR,
366 				 "Online resizing not (yet) supported with bigalloc");
367 			return -EOPNOTSUPP;
368 		}
369 
370 		if (EXT4_HAS_INCOMPAT_FEATURE(sb,
371 			       EXT4_FEATURE_INCOMPAT_META_BG)) {
372 			ext4_msg(sb, KERN_ERR,
373 				 "Online resizing not (yet) supported with meta_bg");
374 			return -EOPNOTSUPP;
375 		}
376 
377 		if (copy_from_user(&n_blocks_count, (__u64 __user *)arg,
378 				   sizeof(__u64))) {
379 			return -EFAULT;
380 		}
381 
382 		if (n_blocks_count > MAX_32_NUM &&
383 		    !EXT4_HAS_INCOMPAT_FEATURE(sb,
384 					       EXT4_FEATURE_INCOMPAT_64BIT)) {
385 			ext4_msg(sb, KERN_ERR,
386 				 "File system only supports 32-bit block numbers");
387 			return -EOPNOTSUPP;
388 		}
389 
390 		err = ext4_resize_begin(sb);
391 		if (err)
392 			return err;
393 
394 		err = mnt_want_write(filp->f_path.mnt);
395 		if (err)
396 			goto resizefs_out;
397 
398 		err = ext4_resize_fs(sb, n_blocks_count);
399 		if (EXT4_SB(sb)->s_journal) {
400 			jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
401 			err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
402 			jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
403 		}
404 		if (err == 0)
405 			err = err2;
406 		mnt_drop_write(filp->f_path.mnt);
407 resizefs_out:
408 		ext4_resize_end(sb);
409 		return err;
410 	}
411 
412 	case FITRIM:
413 	{
414 		struct request_queue *q = bdev_get_queue(sb->s_bdev);
415 		struct fstrim_range range;
416 		int ret = 0;
417 
418 		if (!capable(CAP_SYS_ADMIN))
419 			return -EPERM;
420 
421 		if (!blk_queue_discard(q))
422 			return -EOPNOTSUPP;
423 
424 		if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
425 			       EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
426 			ext4_msg(sb, KERN_ERR,
427 				 "FITRIM not supported with bigalloc");
428 			return -EOPNOTSUPP;
429 		}
430 
431 		if (copy_from_user(&range, (struct fstrim_range __user *)arg,
432 		    sizeof(range)))
433 			return -EFAULT;
434 
435 		range.minlen = max((unsigned int)range.minlen,
436 				   q->limits.discard_granularity);
437 		ret = ext4_trim_fs(sb, &range);
438 		if (ret < 0)
439 			return ret;
440 
441 		if (copy_to_user((struct fstrim_range __user *)arg, &range,
442 		    sizeof(range)))
443 			return -EFAULT;
444 
445 		return 0;
446 	}
447 
448 	default:
449 		return -ENOTTY;
450 	}
451 }
452 
453 #ifdef CONFIG_COMPAT
454 long ext4_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
455 {
456 	/* These are just misnamed, they actually get/put from/to user an int */
457 	switch (cmd) {
458 	case EXT4_IOC32_GETFLAGS:
459 		cmd = EXT4_IOC_GETFLAGS;
460 		break;
461 	case EXT4_IOC32_SETFLAGS:
462 		cmd = EXT4_IOC_SETFLAGS;
463 		break;
464 	case EXT4_IOC32_GETVERSION:
465 		cmd = EXT4_IOC_GETVERSION;
466 		break;
467 	case EXT4_IOC32_SETVERSION:
468 		cmd = EXT4_IOC_SETVERSION;
469 		break;
470 	case EXT4_IOC32_GROUP_EXTEND:
471 		cmd = EXT4_IOC_GROUP_EXTEND;
472 		break;
473 	case EXT4_IOC32_GETVERSION_OLD:
474 		cmd = EXT4_IOC_GETVERSION_OLD;
475 		break;
476 	case EXT4_IOC32_SETVERSION_OLD:
477 		cmd = EXT4_IOC_SETVERSION_OLD;
478 		break;
479 	case EXT4_IOC32_GETRSVSZ:
480 		cmd = EXT4_IOC_GETRSVSZ;
481 		break;
482 	case EXT4_IOC32_SETRSVSZ:
483 		cmd = EXT4_IOC_SETRSVSZ;
484 		break;
485 	case EXT4_IOC32_GROUP_ADD: {
486 		struct compat_ext4_new_group_input __user *uinput;
487 		struct ext4_new_group_input input;
488 		mm_segment_t old_fs;
489 		int err;
490 
491 		uinput = compat_ptr(arg);
492 		err = get_user(input.group, &uinput->group);
493 		err |= get_user(input.block_bitmap, &uinput->block_bitmap);
494 		err |= get_user(input.inode_bitmap, &uinput->inode_bitmap);
495 		err |= get_user(input.inode_table, &uinput->inode_table);
496 		err |= get_user(input.blocks_count, &uinput->blocks_count);
497 		err |= get_user(input.reserved_blocks,
498 				&uinput->reserved_blocks);
499 		if (err)
500 			return -EFAULT;
501 		old_fs = get_fs();
502 		set_fs(KERNEL_DS);
503 		err = ext4_ioctl(file, EXT4_IOC_GROUP_ADD,
504 				 (unsigned long) &input);
505 		set_fs(old_fs);
506 		return err;
507 	}
508 	case EXT4_IOC_MOVE_EXT:
509 	case FITRIM:
510 	case EXT4_IOC_RESIZE_FS:
511 		break;
512 	default:
513 		return -ENOIOCTLCMD;
514 	}
515 	return ext4_ioctl(file, cmd, (unsigned long) compat_ptr(arg));
516 }
517 #endif
518