1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * linux/fs/msdos/namei.c 4 * 5 * Written 1992,1993 by Werner Almesberger 6 * Hidden files 1995 by Albert Cahalan <albert@ccs.neu.edu> <adc@coe.neu.edu> 7 * Rewritten for constant inumbers 1999 by Al Viro 8 */ 9 10 #include <linux/module.h> 11 #include <linux/iversion.h> 12 #include "fat.h" 13 14 /* Characters that are undesirable in an MS-DOS file name */ 15 static unsigned char bad_chars[] = "*?<>|\""; 16 static unsigned char bad_if_strict[] = "+=,; "; 17 18 /***** Formats an MS-DOS file name. Rejects invalid names. */ 19 static int msdos_format_name(const unsigned char *name, int len, 20 unsigned char *res, struct fat_mount_options *opts) 21 /* 22 * name is the proposed name, len is its length, res is 23 * the resulting name, opts->name_check is either (r)elaxed, 24 * (n)ormal or (s)trict, opts->dotsOK allows dots at the 25 * beginning of name (for hidden files) 26 */ 27 { 28 unsigned char *walk; 29 unsigned char c; 30 int space; 31 32 if (name[0] == '.') { /* dotfile because . and .. already done */ 33 if (opts->dotsOK) { 34 /* Get rid of dot - test for it elsewhere */ 35 name++; 36 len--; 37 } else 38 return -EINVAL; 39 } 40 /* 41 * disallow names that _really_ start with a dot 42 */ 43 space = 1; 44 c = 0; 45 for (walk = res; len && walk - res < 8; walk++) { 46 c = *name++; 47 len--; 48 if (opts->name_check != 'r' && strchr(bad_chars, c)) 49 return -EINVAL; 50 if (opts->name_check == 's' && strchr(bad_if_strict, c)) 51 return -EINVAL; 52 if (c >= 'A' && c <= 'Z' && opts->name_check == 's') 53 return -EINVAL; 54 if (c < ' ' || c == ':' || c == '\\') 55 return -EINVAL; 56 /* 57 * 0xE5 is legal as a first character, but we must substitute 58 * 0x05 because 0xE5 marks deleted files. Yes, DOS really 59 * does this. 60 * It seems that Microsoft hacked DOS to support non-US 61 * characters after the 0xE5 character was already in use to 62 * mark deleted files. 63 */ 64 if ((res == walk) && (c == 0xE5)) 65 c = 0x05; 66 if (c == '.') 67 break; 68 space = (c == ' '); 69 *walk = (!opts->nocase && c >= 'a' && c <= 'z') ? c - 32 : c; 70 } 71 if (space) 72 return -EINVAL; 73 if (opts->name_check == 's' && len && c != '.') { 74 c = *name++; 75 len--; 76 if (c != '.') 77 return -EINVAL; 78 } 79 while (c != '.' && len--) 80 c = *name++; 81 if (c == '.') { 82 while (walk - res < 8) 83 *walk++ = ' '; 84 while (len > 0 && walk - res < MSDOS_NAME) { 85 c = *name++; 86 len--; 87 if (opts->name_check != 'r' && strchr(bad_chars, c)) 88 return -EINVAL; 89 if (opts->name_check == 's' && 90 strchr(bad_if_strict, c)) 91 return -EINVAL; 92 if (c < ' ' || c == ':' || c == '\\') 93 return -EINVAL; 94 if (c == '.') { 95 if (opts->name_check == 's') 96 return -EINVAL; 97 break; 98 } 99 if (c >= 'A' && c <= 'Z' && opts->name_check == 's') 100 return -EINVAL; 101 space = c == ' '; 102 if (!opts->nocase && c >= 'a' && c <= 'z') 103 *walk++ = c - 32; 104 else 105 *walk++ = c; 106 } 107 if (space) 108 return -EINVAL; 109 if (opts->name_check == 's' && len) 110 return -EINVAL; 111 } 112 while (walk - res < MSDOS_NAME) 113 *walk++ = ' '; 114 115 return 0; 116 } 117 118 /***** Locates a directory entry. Uses unformatted name. */ 119 static int msdos_find(struct inode *dir, const unsigned char *name, int len, 120 struct fat_slot_info *sinfo) 121 { 122 struct msdos_sb_info *sbi = MSDOS_SB(dir->i_sb); 123 unsigned char msdos_name[MSDOS_NAME]; 124 int err; 125 126 err = msdos_format_name(name, len, msdos_name, &sbi->options); 127 if (err) 128 return -ENOENT; 129 130 err = fat_scan(dir, msdos_name, sinfo); 131 if (!err && sbi->options.dotsOK) { 132 if (name[0] == '.') { 133 if (!(sinfo->de->attr & ATTR_HIDDEN)) 134 err = -ENOENT; 135 } else { 136 if (sinfo->de->attr & ATTR_HIDDEN) 137 err = -ENOENT; 138 } 139 if (err) 140 brelse(sinfo->bh); 141 } 142 return err; 143 } 144 145 /* 146 * Compute the hash for the msdos name corresponding to the dentry. 147 * Note: if the name is invalid, we leave the hash code unchanged so 148 * that the existing dentry can be used. The msdos fs routines will 149 * return ENOENT or EINVAL as appropriate. 150 */ 151 static int msdos_hash(const struct dentry *dentry, struct qstr *qstr) 152 { 153 struct fat_mount_options *options = &MSDOS_SB(dentry->d_sb)->options; 154 unsigned char msdos_name[MSDOS_NAME]; 155 int error; 156 157 error = msdos_format_name(qstr->name, qstr->len, msdos_name, options); 158 if (!error) 159 qstr->hash = full_name_hash(dentry, msdos_name, MSDOS_NAME); 160 return 0; 161 } 162 163 /* 164 * Compare two msdos names. If either of the names are invalid, 165 * we fall back to doing the standard name comparison. 166 */ 167 static int msdos_cmp(const struct dentry *dentry, 168 unsigned int len, const char *str, const struct qstr *name) 169 { 170 struct fat_mount_options *options = &MSDOS_SB(dentry->d_sb)->options; 171 unsigned char a_msdos_name[MSDOS_NAME], b_msdos_name[MSDOS_NAME]; 172 int error; 173 174 error = msdos_format_name(name->name, name->len, a_msdos_name, options); 175 if (error) 176 goto old_compare; 177 error = msdos_format_name(str, len, b_msdos_name, options); 178 if (error) 179 goto old_compare; 180 error = memcmp(a_msdos_name, b_msdos_name, MSDOS_NAME); 181 out: 182 return error; 183 184 old_compare: 185 error = 1; 186 if (name->len == len) 187 error = memcmp(name->name, str, len); 188 goto out; 189 } 190 191 static const struct dentry_operations msdos_dentry_operations = { 192 .d_hash = msdos_hash, 193 .d_compare = msdos_cmp, 194 }; 195 196 /* 197 * AV. Wrappers for FAT sb operations. Is it wise? 198 */ 199 200 /***** Get inode using directory and name */ 201 static struct dentry *msdos_lookup(struct inode *dir, struct dentry *dentry, 202 unsigned int flags) 203 { 204 struct super_block *sb = dir->i_sb; 205 struct fat_slot_info sinfo; 206 struct inode *inode; 207 int err; 208 209 mutex_lock(&MSDOS_SB(sb)->s_lock); 210 err = msdos_find(dir, dentry->d_name.name, dentry->d_name.len, &sinfo); 211 switch (err) { 212 case -ENOENT: 213 inode = NULL; 214 break; 215 case 0: 216 inode = fat_build_inode(sb, sinfo.de, sinfo.i_pos); 217 brelse(sinfo.bh); 218 break; 219 default: 220 inode = ERR_PTR(err); 221 } 222 mutex_unlock(&MSDOS_SB(sb)->s_lock); 223 return d_splice_alias(inode, dentry); 224 } 225 226 /***** Creates a directory entry (name is already formatted). */ 227 static int msdos_add_entry(struct inode *dir, const unsigned char *name, 228 int is_dir, int is_hid, int cluster, 229 struct timespec64 *ts, struct fat_slot_info *sinfo) 230 { 231 struct msdos_sb_info *sbi = MSDOS_SB(dir->i_sb); 232 struct msdos_dir_entry de; 233 __le16 time, date; 234 int err; 235 236 memcpy(de.name, name, MSDOS_NAME); 237 de.attr = is_dir ? ATTR_DIR : ATTR_ARCH; 238 if (is_hid) 239 de.attr |= ATTR_HIDDEN; 240 de.lcase = 0; 241 fat_time_unix2fat(sbi, ts, &time, &date, NULL); 242 de.cdate = de.adate = 0; 243 de.ctime = 0; 244 de.ctime_cs = 0; 245 de.time = time; 246 de.date = date; 247 fat_set_start(&de, cluster); 248 de.size = 0; 249 250 err = fat_add_entries(dir, &de, 1, sinfo); 251 if (err) 252 return err; 253 254 fat_truncate_time(dir, ts, S_CTIME|S_MTIME); 255 if (IS_DIRSYNC(dir)) 256 (void)fat_sync_inode(dir); 257 else 258 mark_inode_dirty(dir); 259 260 return 0; 261 } 262 263 /***** Create a file */ 264 static int msdos_create(struct inode *dir, struct dentry *dentry, umode_t mode, 265 bool excl) 266 { 267 struct super_block *sb = dir->i_sb; 268 struct inode *inode = NULL; 269 struct fat_slot_info sinfo; 270 struct timespec64 ts; 271 unsigned char msdos_name[MSDOS_NAME]; 272 int err, is_hid; 273 274 mutex_lock(&MSDOS_SB(sb)->s_lock); 275 276 err = msdos_format_name(dentry->d_name.name, dentry->d_name.len, 277 msdos_name, &MSDOS_SB(sb)->options); 278 if (err) 279 goto out; 280 is_hid = (dentry->d_name.name[0] == '.') && (msdos_name[0] != '.'); 281 /* Have to do it due to foo vs. .foo conflicts */ 282 if (!fat_scan(dir, msdos_name, &sinfo)) { 283 brelse(sinfo.bh); 284 err = -EINVAL; 285 goto out; 286 } 287 288 ts = current_time(dir); 289 err = msdos_add_entry(dir, msdos_name, 0, is_hid, 0, &ts, &sinfo); 290 if (err) 291 goto out; 292 inode = fat_build_inode(sb, sinfo.de, sinfo.i_pos); 293 brelse(sinfo.bh); 294 if (IS_ERR(inode)) { 295 err = PTR_ERR(inode); 296 goto out; 297 } 298 fat_truncate_time(inode, &ts, S_ATIME|S_CTIME|S_MTIME); 299 /* timestamp is already written, so mark_inode_dirty() is unneeded. */ 300 301 d_instantiate(dentry, inode); 302 out: 303 mutex_unlock(&MSDOS_SB(sb)->s_lock); 304 if (!err) 305 err = fat_flush_inodes(sb, dir, inode); 306 return err; 307 } 308 309 /***** Remove a directory */ 310 static int msdos_rmdir(struct inode *dir, struct dentry *dentry) 311 { 312 struct super_block *sb = dir->i_sb; 313 struct inode *inode = d_inode(dentry); 314 struct fat_slot_info sinfo; 315 int err; 316 317 mutex_lock(&MSDOS_SB(sb)->s_lock); 318 err = fat_dir_empty(inode); 319 if (err) 320 goto out; 321 err = msdos_find(dir, dentry->d_name.name, dentry->d_name.len, &sinfo); 322 if (err) 323 goto out; 324 325 err = fat_remove_entries(dir, &sinfo); /* and releases bh */ 326 if (err) 327 goto out; 328 drop_nlink(dir); 329 330 clear_nlink(inode); 331 fat_truncate_time(inode, NULL, S_CTIME); 332 fat_detach(inode); 333 out: 334 mutex_unlock(&MSDOS_SB(sb)->s_lock); 335 if (!err) 336 err = fat_flush_inodes(sb, dir, inode); 337 338 return err; 339 } 340 341 /***** Make a directory */ 342 static int msdos_mkdir(struct inode *dir, struct dentry *dentry, umode_t mode) 343 { 344 struct super_block *sb = dir->i_sb; 345 struct fat_slot_info sinfo; 346 struct inode *inode; 347 unsigned char msdos_name[MSDOS_NAME]; 348 struct timespec64 ts; 349 int err, is_hid, cluster; 350 351 mutex_lock(&MSDOS_SB(sb)->s_lock); 352 353 err = msdos_format_name(dentry->d_name.name, dentry->d_name.len, 354 msdos_name, &MSDOS_SB(sb)->options); 355 if (err) 356 goto out; 357 is_hid = (dentry->d_name.name[0] == '.') && (msdos_name[0] != '.'); 358 /* foo vs .foo situation */ 359 if (!fat_scan(dir, msdos_name, &sinfo)) { 360 brelse(sinfo.bh); 361 err = -EINVAL; 362 goto out; 363 } 364 365 ts = current_time(dir); 366 cluster = fat_alloc_new_dir(dir, &ts); 367 if (cluster < 0) { 368 err = cluster; 369 goto out; 370 } 371 err = msdos_add_entry(dir, msdos_name, 1, is_hid, cluster, &ts, &sinfo); 372 if (err) 373 goto out_free; 374 inc_nlink(dir); 375 376 inode = fat_build_inode(sb, sinfo.de, sinfo.i_pos); 377 brelse(sinfo.bh); 378 if (IS_ERR(inode)) { 379 err = PTR_ERR(inode); 380 /* the directory was completed, just return a error */ 381 goto out; 382 } 383 set_nlink(inode, 2); 384 fat_truncate_time(inode, &ts, S_ATIME|S_CTIME|S_MTIME); 385 /* timestamp is already written, so mark_inode_dirty() is unneeded. */ 386 387 d_instantiate(dentry, inode); 388 389 mutex_unlock(&MSDOS_SB(sb)->s_lock); 390 fat_flush_inodes(sb, dir, inode); 391 return 0; 392 393 out_free: 394 fat_free_clusters(dir, cluster); 395 out: 396 mutex_unlock(&MSDOS_SB(sb)->s_lock); 397 return err; 398 } 399 400 /***** Unlink a file */ 401 static int msdos_unlink(struct inode *dir, struct dentry *dentry) 402 { 403 struct inode *inode = d_inode(dentry); 404 struct super_block *sb = inode->i_sb; 405 struct fat_slot_info sinfo; 406 int err; 407 408 mutex_lock(&MSDOS_SB(sb)->s_lock); 409 err = msdos_find(dir, dentry->d_name.name, dentry->d_name.len, &sinfo); 410 if (err) 411 goto out; 412 413 err = fat_remove_entries(dir, &sinfo); /* and releases bh */ 414 if (err) 415 goto out; 416 clear_nlink(inode); 417 fat_truncate_time(inode, NULL, S_CTIME); 418 fat_detach(inode); 419 out: 420 mutex_unlock(&MSDOS_SB(sb)->s_lock); 421 if (!err) 422 err = fat_flush_inodes(sb, dir, inode); 423 424 return err; 425 } 426 427 static int do_msdos_rename(struct inode *old_dir, unsigned char *old_name, 428 struct dentry *old_dentry, 429 struct inode *new_dir, unsigned char *new_name, 430 struct dentry *new_dentry, int is_hid) 431 { 432 struct buffer_head *dotdot_bh; 433 struct msdos_dir_entry *dotdot_de; 434 struct inode *old_inode, *new_inode; 435 struct fat_slot_info old_sinfo, sinfo; 436 struct timespec64 ts; 437 loff_t new_i_pos; 438 int err, old_attrs, is_dir, update_dotdot, corrupt = 0; 439 440 old_sinfo.bh = sinfo.bh = dotdot_bh = NULL; 441 old_inode = d_inode(old_dentry); 442 new_inode = d_inode(new_dentry); 443 444 err = fat_scan(old_dir, old_name, &old_sinfo); 445 if (err) { 446 err = -EIO; 447 goto out; 448 } 449 450 is_dir = S_ISDIR(old_inode->i_mode); 451 update_dotdot = (is_dir && old_dir != new_dir); 452 if (update_dotdot) { 453 if (fat_get_dotdot_entry(old_inode, &dotdot_bh, &dotdot_de)) { 454 err = -EIO; 455 goto out; 456 } 457 } 458 459 old_attrs = MSDOS_I(old_inode)->i_attrs; 460 err = fat_scan(new_dir, new_name, &sinfo); 461 if (!err) { 462 if (!new_inode) { 463 /* "foo" -> ".foo" case. just change the ATTR_HIDDEN */ 464 if (sinfo.de != old_sinfo.de) { 465 err = -EINVAL; 466 goto out; 467 } 468 if (is_hid) 469 MSDOS_I(old_inode)->i_attrs |= ATTR_HIDDEN; 470 else 471 MSDOS_I(old_inode)->i_attrs &= ~ATTR_HIDDEN; 472 if (IS_DIRSYNC(old_dir)) { 473 err = fat_sync_inode(old_inode); 474 if (err) { 475 MSDOS_I(old_inode)->i_attrs = old_attrs; 476 goto out; 477 } 478 } else 479 mark_inode_dirty(old_inode); 480 481 inode_inc_iversion(old_dir); 482 fat_truncate_time(old_dir, NULL, S_CTIME|S_MTIME); 483 if (IS_DIRSYNC(old_dir)) 484 (void)fat_sync_inode(old_dir); 485 else 486 mark_inode_dirty(old_dir); 487 goto out; 488 } 489 } 490 491 ts = current_time(old_inode); 492 if (new_inode) { 493 if (err) 494 goto out; 495 if (is_dir) { 496 err = fat_dir_empty(new_inode); 497 if (err) 498 goto out; 499 } 500 new_i_pos = MSDOS_I(new_inode)->i_pos; 501 fat_detach(new_inode); 502 } else { 503 err = msdos_add_entry(new_dir, new_name, is_dir, is_hid, 0, 504 &ts, &sinfo); 505 if (err) 506 goto out; 507 new_i_pos = sinfo.i_pos; 508 } 509 inode_inc_iversion(new_dir); 510 511 fat_detach(old_inode); 512 fat_attach(old_inode, new_i_pos); 513 if (is_hid) 514 MSDOS_I(old_inode)->i_attrs |= ATTR_HIDDEN; 515 else 516 MSDOS_I(old_inode)->i_attrs &= ~ATTR_HIDDEN; 517 if (IS_DIRSYNC(new_dir)) { 518 err = fat_sync_inode(old_inode); 519 if (err) 520 goto error_inode; 521 } else 522 mark_inode_dirty(old_inode); 523 524 if (update_dotdot) { 525 fat_set_start(dotdot_de, MSDOS_I(new_dir)->i_logstart); 526 mark_buffer_dirty_inode(dotdot_bh, old_inode); 527 if (IS_DIRSYNC(new_dir)) { 528 err = sync_dirty_buffer(dotdot_bh); 529 if (err) 530 goto error_dotdot; 531 } 532 drop_nlink(old_dir); 533 if (!new_inode) 534 inc_nlink(new_dir); 535 } 536 537 err = fat_remove_entries(old_dir, &old_sinfo); /* and releases bh */ 538 old_sinfo.bh = NULL; 539 if (err) 540 goto error_dotdot; 541 inode_inc_iversion(old_dir); 542 fat_truncate_time(old_dir, &ts, S_CTIME|S_MTIME); 543 if (IS_DIRSYNC(old_dir)) 544 (void)fat_sync_inode(old_dir); 545 else 546 mark_inode_dirty(old_dir); 547 548 if (new_inode) { 549 drop_nlink(new_inode); 550 if (is_dir) 551 drop_nlink(new_inode); 552 fat_truncate_time(new_inode, &ts, S_CTIME); 553 } 554 out: 555 brelse(sinfo.bh); 556 brelse(dotdot_bh); 557 brelse(old_sinfo.bh); 558 return err; 559 560 error_dotdot: 561 /* data cluster is shared, serious corruption */ 562 corrupt = 1; 563 564 if (update_dotdot) { 565 fat_set_start(dotdot_de, MSDOS_I(old_dir)->i_logstart); 566 mark_buffer_dirty_inode(dotdot_bh, old_inode); 567 corrupt |= sync_dirty_buffer(dotdot_bh); 568 } 569 error_inode: 570 fat_detach(old_inode); 571 fat_attach(old_inode, old_sinfo.i_pos); 572 MSDOS_I(old_inode)->i_attrs = old_attrs; 573 if (new_inode) { 574 fat_attach(new_inode, new_i_pos); 575 if (corrupt) 576 corrupt |= fat_sync_inode(new_inode); 577 } else { 578 /* 579 * If new entry was not sharing the data cluster, it 580 * shouldn't be serious corruption. 581 */ 582 int err2 = fat_remove_entries(new_dir, &sinfo); 583 if (corrupt) 584 corrupt |= err2; 585 sinfo.bh = NULL; 586 } 587 if (corrupt < 0) { 588 fat_fs_error(new_dir->i_sb, 589 "%s: Filesystem corrupted (i_pos %lld)", 590 __func__, sinfo.i_pos); 591 } 592 goto out; 593 } 594 595 /***** Rename, a wrapper for rename_same_dir & rename_diff_dir */ 596 static int msdos_rename(struct inode *old_dir, struct dentry *old_dentry, 597 struct inode *new_dir, struct dentry *new_dentry, 598 unsigned int flags) 599 { 600 struct super_block *sb = old_dir->i_sb; 601 unsigned char old_msdos_name[MSDOS_NAME], new_msdos_name[MSDOS_NAME]; 602 int err, is_hid; 603 604 if (flags & ~RENAME_NOREPLACE) 605 return -EINVAL; 606 607 mutex_lock(&MSDOS_SB(sb)->s_lock); 608 609 err = msdos_format_name(old_dentry->d_name.name, 610 old_dentry->d_name.len, old_msdos_name, 611 &MSDOS_SB(old_dir->i_sb)->options); 612 if (err) 613 goto out; 614 err = msdos_format_name(new_dentry->d_name.name, 615 new_dentry->d_name.len, new_msdos_name, 616 &MSDOS_SB(new_dir->i_sb)->options); 617 if (err) 618 goto out; 619 620 is_hid = 621 (new_dentry->d_name.name[0] == '.') && (new_msdos_name[0] != '.'); 622 623 err = do_msdos_rename(old_dir, old_msdos_name, old_dentry, 624 new_dir, new_msdos_name, new_dentry, is_hid); 625 out: 626 mutex_unlock(&MSDOS_SB(sb)->s_lock); 627 if (!err) 628 err = fat_flush_inodes(sb, old_dir, new_dir); 629 return err; 630 } 631 632 static const struct inode_operations msdos_dir_inode_operations = { 633 .create = msdos_create, 634 .lookup = msdos_lookup, 635 .unlink = msdos_unlink, 636 .mkdir = msdos_mkdir, 637 .rmdir = msdos_rmdir, 638 .rename = msdos_rename, 639 .setattr = fat_setattr, 640 .getattr = fat_getattr, 641 .update_time = fat_update_time, 642 }; 643 644 static void setup(struct super_block *sb) 645 { 646 MSDOS_SB(sb)->dir_ops = &msdos_dir_inode_operations; 647 sb->s_d_op = &msdos_dentry_operations; 648 sb->s_flags |= SB_NOATIME; 649 } 650 651 static int msdos_fill_super(struct super_block *sb, void *data, int silent) 652 { 653 return fat_fill_super(sb, data, silent, 0, setup); 654 } 655 656 static struct dentry *msdos_mount(struct file_system_type *fs_type, 657 int flags, const char *dev_name, 658 void *data) 659 { 660 return mount_bdev(fs_type, flags, dev_name, data, msdos_fill_super); 661 } 662 663 static struct file_system_type msdos_fs_type = { 664 .owner = THIS_MODULE, 665 .name = "msdos", 666 .mount = msdos_mount, 667 .kill_sb = kill_block_super, 668 .fs_flags = FS_REQUIRES_DEV, 669 }; 670 MODULE_ALIAS_FS("msdos"); 671 672 static int __init init_msdos_fs(void) 673 { 674 return register_filesystem(&msdos_fs_type); 675 } 676 677 static void __exit exit_msdos_fs(void) 678 { 679 unregister_filesystem(&msdos_fs_type); 680 } 681 682 MODULE_LICENSE("GPL"); 683 MODULE_AUTHOR("Werner Almesberger"); 684 MODULE_DESCRIPTION("MS-DOS filesystem support"); 685 686 module_init(init_msdos_fs) 687 module_exit(exit_msdos_fs) 688