xref: /openbmc/linux/fs/nfs/callback_xdr.c (revision 363e0df0)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds  * linux/fs/nfs/callback_xdr.c
31da177e4SLinus Torvalds  *
41da177e4SLinus Torvalds  * Copyright (C) 2004 Trond Myklebust
51da177e4SLinus Torvalds  *
61da177e4SLinus Torvalds  * NFSv4 callback encode/decode procedures
71da177e4SLinus Torvalds  */
81da177e4SLinus Torvalds #include <linux/kernel.h>
91da177e4SLinus Torvalds #include <linux/sunrpc/svc.h>
101da177e4SLinus Torvalds #include <linux/nfs4.h>
111da177e4SLinus Torvalds #include <linux/nfs_fs.h>
125a0e3ad6STejun Heo #include <linux/slab.h>
13c36fca52SAndy Adamson #include <linux/sunrpc/bc_xprt.h>
144ce79717STrond Myklebust #include "nfs4_fs.h"
151da177e4SLinus Torvalds #include "callback.h"
16c36fca52SAndy Adamson #include "internal.h"
171da177e4SLinus Torvalds 
181da177e4SLinus Torvalds #define CB_OP_TAGLEN_MAXSZ	(512)
191da177e4SLinus Torvalds #define CB_OP_HDR_RES_MAXSZ	(2 + CB_OP_TAGLEN_MAXSZ)
201da177e4SLinus Torvalds #define CB_OP_GETATTR_BITMAP_MAXSZ	(4)
211da177e4SLinus Torvalds #define CB_OP_GETATTR_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ + \
221da177e4SLinus Torvalds 				CB_OP_GETATTR_BITMAP_MAXSZ + \
231da177e4SLinus Torvalds 				2 + 2 + 3 + 3)
241da177e4SLinus Torvalds #define CB_OP_RECALL_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ)
251da177e4SLinus Torvalds 
264aece6a1SBenny Halevy #if defined(CONFIG_NFS_V4_1)
27f2a62561SFred Isaman #define CB_OP_LAYOUTRECALL_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ)
281be5683bSMarc Eshel #define CB_OP_DEVICENOTIFY_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ)
294aece6a1SBenny Halevy #define CB_OP_SEQUENCE_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ + \
304aece6a1SBenny Halevy 					4 + 1 + 3)
3131f09607SAlexandros Batsakis #define CB_OP_RECALLANY_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ)
32b9efa1b2SAndy Adamson #define CB_OP_RECALLSLOT_RES_MAXSZ	(CB_OP_HDR_RES_MAXSZ)
334aece6a1SBenny Halevy #endif /* CONFIG_NFS_V4_1 */
344aece6a1SBenny Halevy 
351da177e4SLinus Torvalds #define NFSDBG_FACILITY NFSDBG_CALLBACK
361da177e4SLinus Torvalds 
3731d2b435SAndy Adamson /* Internal error code */
3831d2b435SAndy Adamson #define NFS4ERR_RESOURCE_HDR	11050
3931d2b435SAndy Adamson 
40c36fca52SAndy Adamson typedef __be32 (*callback_process_op_t)(void *, void *,
41c36fca52SAndy Adamson 					struct cb_process_state *);
42e6f684f6SAl Viro typedef __be32 (*callback_decode_arg_t)(struct svc_rqst *, struct xdr_stream *, void *);
43e6f684f6SAl Viro typedef __be32 (*callback_encode_res_t)(struct svc_rqst *, struct xdr_stream *, void *);
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds 
461da177e4SLinus Torvalds struct callback_op {
471da177e4SLinus Torvalds 	callback_process_op_t process_op;
481da177e4SLinus Torvalds 	callback_decode_arg_t decode_args;
491da177e4SLinus Torvalds 	callback_encode_res_t encode_res;
501da177e4SLinus Torvalds 	long res_maxsize;
511da177e4SLinus Torvalds };
521da177e4SLinus Torvalds 
531da177e4SLinus Torvalds static struct callback_op callback_ops[];
541da177e4SLinus Torvalds 
557111c66eSAl Viro static __be32 nfs4_callback_null(struct svc_rqst *rqstp, void *argp, void *resp)
561da177e4SLinus Torvalds {
571da177e4SLinus Torvalds 	return htonl(NFS4_OK);
581da177e4SLinus Torvalds }
591da177e4SLinus Torvalds 
605704fdebSAl Viro static int nfs4_decode_void(struct svc_rqst *rqstp, __be32 *p, void *dummy)
611da177e4SLinus Torvalds {
621da177e4SLinus Torvalds 	return xdr_argsize_check(rqstp, p);
631da177e4SLinus Torvalds }
641da177e4SLinus Torvalds 
655704fdebSAl Viro static int nfs4_encode_void(struct svc_rqst *rqstp, __be32 *p, void *dummy)
661da177e4SLinus Torvalds {
671da177e4SLinus Torvalds 	return xdr_ressize_check(rqstp, p);
681da177e4SLinus Torvalds }
691da177e4SLinus Torvalds 
705704fdebSAl Viro static __be32 *read_buf(struct xdr_stream *xdr, int nbytes)
711da177e4SLinus Torvalds {
725704fdebSAl Viro 	__be32 *p;
731da177e4SLinus Torvalds 
741da177e4SLinus Torvalds 	p = xdr_inline_decode(xdr, nbytes);
751da177e4SLinus Torvalds 	if (unlikely(p == NULL))
761da177e4SLinus Torvalds 		printk(KERN_WARNING "NFSv4 callback reply buffer overflowed!\n");
771da177e4SLinus Torvalds 	return p;
781da177e4SLinus Torvalds }
791da177e4SLinus Torvalds 
80e6f684f6SAl Viro static __be32 decode_string(struct xdr_stream *xdr, unsigned int *len, const char **str)
811da177e4SLinus Torvalds {
825704fdebSAl Viro 	__be32 *p;
831da177e4SLinus Torvalds 
841da177e4SLinus Torvalds 	p = read_buf(xdr, 4);
851da177e4SLinus Torvalds 	if (unlikely(p == NULL))
861da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
871da177e4SLinus Torvalds 	*len = ntohl(*p);
881da177e4SLinus Torvalds 
891da177e4SLinus Torvalds 	if (*len != 0) {
901da177e4SLinus Torvalds 		p = read_buf(xdr, *len);
911da177e4SLinus Torvalds 		if (unlikely(p == NULL))
921da177e4SLinus Torvalds 			return htonl(NFS4ERR_RESOURCE);
931da177e4SLinus Torvalds 		*str = (const char *)p;
941da177e4SLinus Torvalds 	} else
951da177e4SLinus Torvalds 		*str = NULL;
961da177e4SLinus Torvalds 
971da177e4SLinus Torvalds 	return 0;
981da177e4SLinus Torvalds }
991da177e4SLinus Torvalds 
100e6f684f6SAl Viro static __be32 decode_fh(struct xdr_stream *xdr, struct nfs_fh *fh)
1011da177e4SLinus Torvalds {
1025704fdebSAl Viro 	__be32 *p;
1031da177e4SLinus Torvalds 
1041da177e4SLinus Torvalds 	p = read_buf(xdr, 4);
1051da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1061da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1071da177e4SLinus Torvalds 	fh->size = ntohl(*p);
1081da177e4SLinus Torvalds 	if (fh->size > NFS4_FHSIZE)
1091da177e4SLinus Torvalds 		return htonl(NFS4ERR_BADHANDLE);
1101da177e4SLinus Torvalds 	p = read_buf(xdr, fh->size);
1111da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1121da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1131da177e4SLinus Torvalds 	memcpy(&fh->data[0], p, fh->size);
1141da177e4SLinus Torvalds 	memset(&fh->data[fh->size], 0, sizeof(fh->data) - fh->size);
1151da177e4SLinus Torvalds 	return 0;
1161da177e4SLinus Torvalds }
1171da177e4SLinus Torvalds 
118e6f684f6SAl Viro static __be32 decode_bitmap(struct xdr_stream *xdr, uint32_t *bitmap)
1191da177e4SLinus Torvalds {
1205704fdebSAl Viro 	__be32 *p;
1211da177e4SLinus Torvalds 	unsigned int attrlen;
1221da177e4SLinus Torvalds 
1231da177e4SLinus Torvalds 	p = read_buf(xdr, 4);
1241da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1251da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1261da177e4SLinus Torvalds 	attrlen = ntohl(*p);
1271da177e4SLinus Torvalds 	p = read_buf(xdr, attrlen << 2);
1281da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1291da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1301da177e4SLinus Torvalds 	if (likely(attrlen > 0))
1311da177e4SLinus Torvalds 		bitmap[0] = ntohl(*p++);
1321da177e4SLinus Torvalds 	if (attrlen > 1)
1331da177e4SLinus Torvalds 		bitmap[1] = ntohl(*p);
1341da177e4SLinus Torvalds 	return 0;
1351da177e4SLinus Torvalds }
1361da177e4SLinus Torvalds 
137e6f684f6SAl Viro static __be32 decode_stateid(struct xdr_stream *xdr, nfs4_stateid *stateid)
1381da177e4SLinus Torvalds {
1395704fdebSAl Viro 	__be32 *p;
1401da177e4SLinus Torvalds 
1411da177e4SLinus Torvalds 	p = read_buf(xdr, 16);
1421da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1431da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1441da177e4SLinus Torvalds 	memcpy(stateid->data, p, 16);
1451da177e4SLinus Torvalds 	return 0;
1461da177e4SLinus Torvalds }
1471da177e4SLinus Torvalds 
148e6f684f6SAl Viro static __be32 decode_compound_hdr_arg(struct xdr_stream *xdr, struct cb_compound_hdr_arg *hdr)
1491da177e4SLinus Torvalds {
1505704fdebSAl Viro 	__be32 *p;
151e6f684f6SAl Viro 	__be32 status;
1521da177e4SLinus Torvalds 
1531da177e4SLinus Torvalds 	status = decode_string(xdr, &hdr->taglen, &hdr->tag);
1541da177e4SLinus Torvalds 	if (unlikely(status != 0))
1551da177e4SLinus Torvalds 		return status;
1561da177e4SLinus Torvalds 	/* We do not like overly long tags! */
1575cce428dSChuck Lever 	if (hdr->taglen > CB_OP_TAGLEN_MAXSZ - 12) {
1581da177e4SLinus Torvalds 		printk("NFSv4 CALLBACK %s: client sent tag of length %u\n",
1593110ff80SHarvey Harrison 				__func__, hdr->taglen);
1601da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
1611da177e4SLinus Torvalds 	}
1621da177e4SLinus Torvalds 	p = read_buf(xdr, 12);
1631da177e4SLinus Torvalds 	if (unlikely(p == NULL))
1641da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
165b8f2ef84SBenny Halevy 	hdr->minorversion = ntohl(*p++);
16648a9e2d2SBenny Halevy 	/* Check minor version is zero or one. */
16748a9e2d2SBenny Halevy 	if (hdr->minorversion <= 1) {
168c36fca52SAndy Adamson 		hdr->cb_ident = ntohl(*p++); /* ignored by v4.1 */
16948a9e2d2SBenny Halevy 	} else {
170b8f2ef84SBenny Halevy 		printk(KERN_WARNING "%s: NFSv4 server callback with "
171b8f2ef84SBenny Halevy 			"illegal minor version %u!\n",
172b8f2ef84SBenny Halevy 			__func__, hdr->minorversion);
1731da177e4SLinus Torvalds 		return htonl(NFS4ERR_MINOR_VERS_MISMATCH);
1741da177e4SLinus Torvalds 	}
1751da177e4SLinus Torvalds 	hdr->nops = ntohl(*p);
176b8f2ef84SBenny Halevy 	dprintk("%s: minorversion %d nops %d\n", __func__,
177b8f2ef84SBenny Halevy 		hdr->minorversion, hdr->nops);
1781da177e4SLinus Torvalds 	return 0;
1791da177e4SLinus Torvalds }
1801da177e4SLinus Torvalds 
181e6f684f6SAl Viro static __be32 decode_op_hdr(struct xdr_stream *xdr, unsigned int *op)
1821da177e4SLinus Torvalds {
1835704fdebSAl Viro 	__be32 *p;
1841da177e4SLinus Torvalds 	p = read_buf(xdr, 4);
1851da177e4SLinus Torvalds 	if (unlikely(p == NULL))
18631d2b435SAndy Adamson 		return htonl(NFS4ERR_RESOURCE_HDR);
1871da177e4SLinus Torvalds 	*op = ntohl(*p);
1881da177e4SLinus Torvalds 	return 0;
1891da177e4SLinus Torvalds }
1901da177e4SLinus Torvalds 
191e6f684f6SAl Viro static __be32 decode_getattr_args(struct svc_rqst *rqstp, struct xdr_stream *xdr, struct cb_getattrargs *args)
1921da177e4SLinus Torvalds {
193e6f684f6SAl Viro 	__be32 status;
1941da177e4SLinus Torvalds 
1951da177e4SLinus Torvalds 	status = decode_fh(xdr, &args->fh);
1961da177e4SLinus Torvalds 	if (unlikely(status != 0))
1971da177e4SLinus Torvalds 		goto out;
198671beed7SChuck Lever 	args->addr = svc_addr(rqstp);
1991da177e4SLinus Torvalds 	status = decode_bitmap(xdr, args->bitmap);
2001da177e4SLinus Torvalds out:
2013110ff80SHarvey Harrison 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
2021da177e4SLinus Torvalds 	return status;
2031da177e4SLinus Torvalds }
2041da177e4SLinus Torvalds 
205e6f684f6SAl Viro static __be32 decode_recall_args(struct svc_rqst *rqstp, struct xdr_stream *xdr, struct cb_recallargs *args)
2061da177e4SLinus Torvalds {
2075704fdebSAl Viro 	__be32 *p;
208e6f684f6SAl Viro 	__be32 status;
2091da177e4SLinus Torvalds 
210c1d35866SChuck Lever 	args->addr = svc_addr(rqstp);
2111da177e4SLinus Torvalds 	status = decode_stateid(xdr, &args->stateid);
2121da177e4SLinus Torvalds 	if (unlikely(status != 0))
2131da177e4SLinus Torvalds 		goto out;
2141da177e4SLinus Torvalds 	p = read_buf(xdr, 4);
2151da177e4SLinus Torvalds 	if (unlikely(p == NULL)) {
2161da177e4SLinus Torvalds 		status = htonl(NFS4ERR_RESOURCE);
2171da177e4SLinus Torvalds 		goto out;
2181da177e4SLinus Torvalds 	}
2191da177e4SLinus Torvalds 	args->truncate = ntohl(*p);
2201da177e4SLinus Torvalds 	status = decode_fh(xdr, &args->fh);
2211da177e4SLinus Torvalds out:
2223110ff80SHarvey Harrison 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
2233873bc50SAlexey Dobriyan 	return status;
2241da177e4SLinus Torvalds }
2251da177e4SLinus Torvalds 
2264aece6a1SBenny Halevy #if defined(CONFIG_NFS_V4_1)
2274aece6a1SBenny Halevy 
228f2a62561SFred Isaman static __be32 decode_layoutrecall_args(struct svc_rqst *rqstp,
229f2a62561SFred Isaman 				       struct xdr_stream *xdr,
230f2a62561SFred Isaman 				       struct cb_layoutrecallargs *args)
231f2a62561SFred Isaman {
232f2a62561SFred Isaman 	__be32 *p;
233f2a62561SFred Isaman 	__be32 status = 0;
234f2a62561SFred Isaman 	uint32_t iomode;
235f2a62561SFred Isaman 
236f2a62561SFred Isaman 	args->cbl_addr = svc_addr(rqstp);
237f2a62561SFred Isaman 	p = read_buf(xdr, 4 * sizeof(uint32_t));
238f2a62561SFred Isaman 	if (unlikely(p == NULL)) {
239f2a62561SFred Isaman 		status = htonl(NFS4ERR_BADXDR);
240f2a62561SFred Isaman 		goto out;
241f2a62561SFred Isaman 	}
242f2a62561SFred Isaman 
243f2a62561SFred Isaman 	args->cbl_layout_type = ntohl(*p++);
244f2a62561SFred Isaman 	/* Depite the spec's xdr, iomode really belongs in the FILE switch,
24525985edcSLucas De Marchi 	 * as it is unusable and ignored with the other types.
246f2a62561SFred Isaman 	 */
247f2a62561SFred Isaman 	iomode = ntohl(*p++);
248f2a62561SFred Isaman 	args->cbl_layoutchanged = ntohl(*p++);
249f2a62561SFred Isaman 	args->cbl_recall_type = ntohl(*p++);
250f2a62561SFred Isaman 
251f2a62561SFred Isaman 	if (args->cbl_recall_type == RETURN_FILE) {
252f2a62561SFred Isaman 		args->cbl_range.iomode = iomode;
253f2a62561SFred Isaman 		status = decode_fh(xdr, &args->cbl_fh);
254f2a62561SFred Isaman 		if (unlikely(status != 0))
255f2a62561SFred Isaman 			goto out;
256f2a62561SFred Isaman 
257f2a62561SFred Isaman 		p = read_buf(xdr, 2 * sizeof(uint64_t));
258f2a62561SFred Isaman 		if (unlikely(p == NULL)) {
259f2a62561SFred Isaman 			status = htonl(NFS4ERR_BADXDR);
260f2a62561SFred Isaman 			goto out;
261f2a62561SFred Isaman 		}
262f2a62561SFred Isaman 		p = xdr_decode_hyper(p, &args->cbl_range.offset);
263f2a62561SFred Isaman 		p = xdr_decode_hyper(p, &args->cbl_range.length);
264f2a62561SFred Isaman 		status = decode_stateid(xdr, &args->cbl_stateid);
265f2a62561SFred Isaman 		if (unlikely(status != 0))
266f2a62561SFred Isaman 			goto out;
267f2a62561SFred Isaman 	} else if (args->cbl_recall_type == RETURN_FSID) {
268f2a62561SFred Isaman 		p = read_buf(xdr, 2 * sizeof(uint64_t));
269f2a62561SFred Isaman 		if (unlikely(p == NULL)) {
270f2a62561SFred Isaman 			status = htonl(NFS4ERR_BADXDR);
271f2a62561SFred Isaman 			goto out;
272f2a62561SFred Isaman 		}
273f2a62561SFred Isaman 		p = xdr_decode_hyper(p, &args->cbl_fsid.major);
274f2a62561SFred Isaman 		p = xdr_decode_hyper(p, &args->cbl_fsid.minor);
275f2a62561SFred Isaman 	} else if (args->cbl_recall_type != RETURN_ALL) {
276f2a62561SFred Isaman 		status = htonl(NFS4ERR_BADXDR);
277f2a62561SFred Isaman 		goto out;
278f2a62561SFred Isaman 	}
279f2a62561SFred Isaman 	dprintk("%s: ltype 0x%x iomode %d changed %d recall_type %d\n",
280f2a62561SFred Isaman 		__func__,
281f2a62561SFred Isaman 		args->cbl_layout_type, iomode,
282f2a62561SFred Isaman 		args->cbl_layoutchanged, args->cbl_recall_type);
283f2a62561SFred Isaman out:
284f2a62561SFred Isaman 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
285f2a62561SFred Isaman 	return status;
286f2a62561SFred Isaman }
287f2a62561SFred Isaman 
2881be5683bSMarc Eshel static
2891be5683bSMarc Eshel __be32 decode_devicenotify_args(struct svc_rqst *rqstp,
2901be5683bSMarc Eshel 				struct xdr_stream *xdr,
2911be5683bSMarc Eshel 				struct cb_devicenotifyargs *args)
2921be5683bSMarc Eshel {
2931be5683bSMarc Eshel 	__be32 *p;
2941be5683bSMarc Eshel 	__be32 status = 0;
2951be5683bSMarc Eshel 	u32 tmp;
2961be5683bSMarc Eshel 	int n, i;
2971be5683bSMarc Eshel 	args->ndevs = 0;
2981be5683bSMarc Eshel 
2991be5683bSMarc Eshel 	/* Num of device notifications */
3001be5683bSMarc Eshel 	p = read_buf(xdr, sizeof(uint32_t));
3011be5683bSMarc Eshel 	if (unlikely(p == NULL)) {
3021be5683bSMarc Eshel 		status = htonl(NFS4ERR_BADXDR);
3031be5683bSMarc Eshel 		goto out;
3041be5683bSMarc Eshel 	}
3051be5683bSMarc Eshel 	n = ntohl(*p++);
3061be5683bSMarc Eshel 	if (n <= 0)
3071be5683bSMarc Eshel 		goto out;
308363e0df0SDan Carpenter 	if (n > ULONG_MAX / sizeof(*args->devs)) {
309363e0df0SDan Carpenter 		status = htonl(NFS4ERR_BADXDR);
310363e0df0SDan Carpenter 		goto out;
311363e0df0SDan Carpenter 	}
3121be5683bSMarc Eshel 
3131be5683bSMarc Eshel 	args->devs = kmalloc(n * sizeof(*args->devs), GFP_KERNEL);
3141be5683bSMarc Eshel 	if (!args->devs) {
3151be5683bSMarc Eshel 		status = htonl(NFS4ERR_DELAY);
3161be5683bSMarc Eshel 		goto out;
3171be5683bSMarc Eshel 	}
3181be5683bSMarc Eshel 
3191be5683bSMarc Eshel 	/* Decode each dev notification */
3201be5683bSMarc Eshel 	for (i = 0; i < n; i++) {
3211be5683bSMarc Eshel 		struct cb_devicenotifyitem *dev = &args->devs[i];
3221be5683bSMarc Eshel 
3231be5683bSMarc Eshel 		p = read_buf(xdr, (4 * sizeof(uint32_t)) + NFS4_DEVICEID4_SIZE);
3241be5683bSMarc Eshel 		if (unlikely(p == NULL)) {
3251be5683bSMarc Eshel 			status = htonl(NFS4ERR_BADXDR);
3261be5683bSMarc Eshel 			goto err;
3271be5683bSMarc Eshel 		}
3281be5683bSMarc Eshel 
3291be5683bSMarc Eshel 		tmp = ntohl(*p++);	/* bitmap size */
3301be5683bSMarc Eshel 		if (tmp != 1) {
3311be5683bSMarc Eshel 			status = htonl(NFS4ERR_INVAL);
3321be5683bSMarc Eshel 			goto err;
3331be5683bSMarc Eshel 		}
3341be5683bSMarc Eshel 		dev->cbd_notify_type = ntohl(*p++);
3351be5683bSMarc Eshel 		if (dev->cbd_notify_type != NOTIFY_DEVICEID4_CHANGE &&
3361be5683bSMarc Eshel 		    dev->cbd_notify_type != NOTIFY_DEVICEID4_DELETE) {
3371be5683bSMarc Eshel 			status = htonl(NFS4ERR_INVAL);
3381be5683bSMarc Eshel 			goto err;
3391be5683bSMarc Eshel 		}
3401be5683bSMarc Eshel 
3411be5683bSMarc Eshel 		tmp = ntohl(*p++);	/* opaque size */
3421be5683bSMarc Eshel 		if (((dev->cbd_notify_type == NOTIFY_DEVICEID4_CHANGE) &&
3431be5683bSMarc Eshel 		     (tmp != NFS4_DEVICEID4_SIZE + 8)) ||
3441be5683bSMarc Eshel 		    ((dev->cbd_notify_type == NOTIFY_DEVICEID4_DELETE) &&
3451be5683bSMarc Eshel 		     (tmp != NFS4_DEVICEID4_SIZE + 4))) {
3461be5683bSMarc Eshel 			status = htonl(NFS4ERR_INVAL);
3471be5683bSMarc Eshel 			goto err;
3481be5683bSMarc Eshel 		}
3491be5683bSMarc Eshel 		dev->cbd_layout_type = ntohl(*p++);
3501be5683bSMarc Eshel 		memcpy(dev->cbd_dev_id.data, p, NFS4_DEVICEID4_SIZE);
3511be5683bSMarc Eshel 		p += XDR_QUADLEN(NFS4_DEVICEID4_SIZE);
3521be5683bSMarc Eshel 
3531be5683bSMarc Eshel 		if (dev->cbd_layout_type == NOTIFY_DEVICEID4_CHANGE) {
3541be5683bSMarc Eshel 			p = read_buf(xdr, sizeof(uint32_t));
3551be5683bSMarc Eshel 			if (unlikely(p == NULL)) {
3561be5683bSMarc Eshel 				status = htonl(NFS4ERR_BADXDR);
3571be5683bSMarc Eshel 				goto err;
3581be5683bSMarc Eshel 			}
3591be5683bSMarc Eshel 			dev->cbd_immediate = ntohl(*p++);
3601be5683bSMarc Eshel 		} else {
3611be5683bSMarc Eshel 			dev->cbd_immediate = 0;
3621be5683bSMarc Eshel 		}
3631be5683bSMarc Eshel 
3641be5683bSMarc Eshel 		args->ndevs++;
3651be5683bSMarc Eshel 
3661be5683bSMarc Eshel 		dprintk("%s: type %d layout 0x%x immediate %d\n",
3671be5683bSMarc Eshel 			__func__, dev->cbd_notify_type, dev->cbd_layout_type,
3681be5683bSMarc Eshel 			dev->cbd_immediate);
3691be5683bSMarc Eshel 	}
3701be5683bSMarc Eshel out:
3711be5683bSMarc Eshel 	dprintk("%s: status %d ndevs %d\n",
3721be5683bSMarc Eshel 		__func__, ntohl(status), args->ndevs);
3731be5683bSMarc Eshel 	return status;
3741be5683bSMarc Eshel err:
3751be5683bSMarc Eshel 	kfree(args->devs);
3761be5683bSMarc Eshel 	goto out;
3771be5683bSMarc Eshel }
3781be5683bSMarc Eshel 
3799733f0d9SAndy Adamson static __be32 decode_sessionid(struct xdr_stream *xdr,
3804aece6a1SBenny Halevy 				 struct nfs4_sessionid *sid)
3814aece6a1SBenny Halevy {
3829733f0d9SAndy Adamson 	__be32 *p;
3834aece6a1SBenny Halevy 	int len = NFS4_MAX_SESSIONID_LEN;
3844aece6a1SBenny Halevy 
3854aece6a1SBenny Halevy 	p = read_buf(xdr, len);
3864aece6a1SBenny Halevy 	if (unlikely(p == NULL))
387a419aef8SJoe Perches 		return htonl(NFS4ERR_RESOURCE);
3884aece6a1SBenny Halevy 
3894aece6a1SBenny Halevy 	memcpy(sid->data, p, len);
3904aece6a1SBenny Halevy 	return 0;
3914aece6a1SBenny Halevy }
3924aece6a1SBenny Halevy 
3939733f0d9SAndy Adamson static __be32 decode_rc_list(struct xdr_stream *xdr,
3944aece6a1SBenny Halevy 			       struct referring_call_list *rc_list)
3954aece6a1SBenny Halevy {
3969733f0d9SAndy Adamson 	__be32 *p;
3974aece6a1SBenny Halevy 	int i;
3989733f0d9SAndy Adamson 	__be32 status;
3994aece6a1SBenny Halevy 
4004aece6a1SBenny Halevy 	status = decode_sessionid(xdr, &rc_list->rcl_sessionid);
4014aece6a1SBenny Halevy 	if (status)
4024aece6a1SBenny Halevy 		goto out;
4034aece6a1SBenny Halevy 
4044aece6a1SBenny Halevy 	status = htonl(NFS4ERR_RESOURCE);
4054aece6a1SBenny Halevy 	p = read_buf(xdr, sizeof(uint32_t));
4064aece6a1SBenny Halevy 	if (unlikely(p == NULL))
4074aece6a1SBenny Halevy 		goto out;
4084aece6a1SBenny Halevy 
4094aece6a1SBenny Halevy 	rc_list->rcl_nrefcalls = ntohl(*p++);
4104aece6a1SBenny Halevy 	if (rc_list->rcl_nrefcalls) {
4114aece6a1SBenny Halevy 		p = read_buf(xdr,
4124aece6a1SBenny Halevy 			     rc_list->rcl_nrefcalls * 2 * sizeof(uint32_t));
4134aece6a1SBenny Halevy 		if (unlikely(p == NULL))
4144aece6a1SBenny Halevy 			goto out;
4154aece6a1SBenny Halevy 		rc_list->rcl_refcalls = kmalloc(rc_list->rcl_nrefcalls *
4164aece6a1SBenny Halevy 						sizeof(*rc_list->rcl_refcalls),
4174aece6a1SBenny Halevy 						GFP_KERNEL);
4184aece6a1SBenny Halevy 		if (unlikely(rc_list->rcl_refcalls == NULL))
4194aece6a1SBenny Halevy 			goto out;
4204aece6a1SBenny Halevy 		for (i = 0; i < rc_list->rcl_nrefcalls; i++) {
4214aece6a1SBenny Halevy 			rc_list->rcl_refcalls[i].rc_sequenceid = ntohl(*p++);
4224aece6a1SBenny Halevy 			rc_list->rcl_refcalls[i].rc_slotid = ntohl(*p++);
4234aece6a1SBenny Halevy 		}
4244aece6a1SBenny Halevy 	}
4254aece6a1SBenny Halevy 	status = 0;
4264aece6a1SBenny Halevy 
4274aece6a1SBenny Halevy out:
4284aece6a1SBenny Halevy 	return status;
4294aece6a1SBenny Halevy }
4304aece6a1SBenny Halevy 
4319733f0d9SAndy Adamson static __be32 decode_cb_sequence_args(struct svc_rqst *rqstp,
4324aece6a1SBenny Halevy 					struct xdr_stream *xdr,
4334aece6a1SBenny Halevy 					struct cb_sequenceargs *args)
4344aece6a1SBenny Halevy {
4359733f0d9SAndy Adamson 	__be32 *p;
4364aece6a1SBenny Halevy 	int i;
4379733f0d9SAndy Adamson 	__be32 status;
4384aece6a1SBenny Halevy 
4394aece6a1SBenny Halevy 	status = decode_sessionid(xdr, &args->csa_sessionid);
4404aece6a1SBenny Halevy 	if (status)
4414aece6a1SBenny Halevy 		goto out;
4424aece6a1SBenny Halevy 
4434aece6a1SBenny Halevy 	status = htonl(NFS4ERR_RESOURCE);
4444aece6a1SBenny Halevy 	p = read_buf(xdr, 5 * sizeof(uint32_t));
4454aece6a1SBenny Halevy 	if (unlikely(p == NULL))
4464aece6a1SBenny Halevy 		goto out;
4474aece6a1SBenny Halevy 
44865fc64e5SRicardo Labiaga 	args->csa_addr = svc_addr(rqstp);
4494aece6a1SBenny Halevy 	args->csa_sequenceid = ntohl(*p++);
4504aece6a1SBenny Halevy 	args->csa_slotid = ntohl(*p++);
4514aece6a1SBenny Halevy 	args->csa_highestslotid = ntohl(*p++);
4524aece6a1SBenny Halevy 	args->csa_cachethis = ntohl(*p++);
4534aece6a1SBenny Halevy 	args->csa_nrclists = ntohl(*p++);
4544aece6a1SBenny Halevy 	args->csa_rclists = NULL;
4554aece6a1SBenny Halevy 	if (args->csa_nrclists) {
4564aece6a1SBenny Halevy 		args->csa_rclists = kmalloc(args->csa_nrclists *
4574aece6a1SBenny Halevy 					    sizeof(*args->csa_rclists),
4584aece6a1SBenny Halevy 					    GFP_KERNEL);
4594aece6a1SBenny Halevy 		if (unlikely(args->csa_rclists == NULL))
4604aece6a1SBenny Halevy 			goto out;
4614aece6a1SBenny Halevy 
4624aece6a1SBenny Halevy 		for (i = 0; i < args->csa_nrclists; i++) {
4634aece6a1SBenny Halevy 			status = decode_rc_list(xdr, &args->csa_rclists[i]);
4644aece6a1SBenny Halevy 			if (status)
4654aece6a1SBenny Halevy 				goto out_free;
4664aece6a1SBenny Halevy 		}
4674aece6a1SBenny Halevy 	}
4684aece6a1SBenny Halevy 	status = 0;
4694aece6a1SBenny Halevy 
4704aece6a1SBenny Halevy 	dprintk("%s: sessionid %x:%x:%x:%x sequenceid %u slotid %u "
4714aece6a1SBenny Halevy 		"highestslotid %u cachethis %d nrclists %u\n",
4724aece6a1SBenny Halevy 		__func__,
4734aece6a1SBenny Halevy 		((u32 *)&args->csa_sessionid)[0],
4744aece6a1SBenny Halevy 		((u32 *)&args->csa_sessionid)[1],
4754aece6a1SBenny Halevy 		((u32 *)&args->csa_sessionid)[2],
4764aece6a1SBenny Halevy 		((u32 *)&args->csa_sessionid)[3],
4774aece6a1SBenny Halevy 		args->csa_sequenceid, args->csa_slotid,
4784aece6a1SBenny Halevy 		args->csa_highestslotid, args->csa_cachethis,
4794aece6a1SBenny Halevy 		args->csa_nrclists);
4804aece6a1SBenny Halevy out:
4814aece6a1SBenny Halevy 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
4824aece6a1SBenny Halevy 	return status;
4834aece6a1SBenny Halevy 
4844aece6a1SBenny Halevy out_free:
4854aece6a1SBenny Halevy 	for (i = 0; i < args->csa_nrclists; i++)
4864aece6a1SBenny Halevy 		kfree(args->csa_rclists[i].rcl_refcalls);
4874aece6a1SBenny Halevy 	kfree(args->csa_rclists);
4884aece6a1SBenny Halevy 	goto out;
4894aece6a1SBenny Halevy }
4904aece6a1SBenny Halevy 
4919733f0d9SAndy Adamson static __be32 decode_recallany_args(struct svc_rqst *rqstp,
49231f09607SAlexandros Batsakis 				      struct xdr_stream *xdr,
49331f09607SAlexandros Batsakis 				      struct cb_recallanyargs *args)
49431f09607SAlexandros Batsakis {
495d743c3c9SPeng Tao 	uint32_t bitmap[2];
496d743c3c9SPeng Tao 	__be32 *p, status;
49731f09607SAlexandros Batsakis 
49831f09607SAlexandros Batsakis 	args->craa_addr = svc_addr(rqstp);
49931f09607SAlexandros Batsakis 	p = read_buf(xdr, 4);
50031f09607SAlexandros Batsakis 	if (unlikely(p == NULL))
50131f09607SAlexandros Batsakis 		return htonl(NFS4ERR_BADXDR);
50231f09607SAlexandros Batsakis 	args->craa_objs_to_keep = ntohl(*p++);
503d743c3c9SPeng Tao 	status = decode_bitmap(xdr, bitmap);
504d743c3c9SPeng Tao 	if (unlikely(status))
505d743c3c9SPeng Tao 		return status;
506d743c3c9SPeng Tao 	args->craa_type_mask = bitmap[0];
50731f09607SAlexandros Batsakis 
50831f09607SAlexandros Batsakis 	return 0;
50931f09607SAlexandros Batsakis }
51031f09607SAlexandros Batsakis 
5119733f0d9SAndy Adamson static __be32 decode_recallslot_args(struct svc_rqst *rqstp,
512b9efa1b2SAndy Adamson 					struct xdr_stream *xdr,
513b9efa1b2SAndy Adamson 					struct cb_recallslotargs *args)
514b9efa1b2SAndy Adamson {
515b9efa1b2SAndy Adamson 	__be32 *p;
516b9efa1b2SAndy Adamson 
517b9efa1b2SAndy Adamson 	args->crsa_addr = svc_addr(rqstp);
518b9efa1b2SAndy Adamson 	p = read_buf(xdr, 4);
519b9efa1b2SAndy Adamson 	if (unlikely(p == NULL))
520b9efa1b2SAndy Adamson 		return htonl(NFS4ERR_BADXDR);
521b9efa1b2SAndy Adamson 	args->crsa_target_max_slots = ntohl(*p++);
522b9efa1b2SAndy Adamson 	return 0;
523b9efa1b2SAndy Adamson }
524b9efa1b2SAndy Adamson 
5254aece6a1SBenny Halevy #endif /* CONFIG_NFS_V4_1 */
5264aece6a1SBenny Halevy 
527e6f684f6SAl Viro static __be32 encode_string(struct xdr_stream *xdr, unsigned int len, const char *str)
5281da177e4SLinus Torvalds {
5295704fdebSAl Viro 	__be32 *p;
5301da177e4SLinus Torvalds 
5311da177e4SLinus Torvalds 	p = xdr_reserve_space(xdr, 4 + len);
5321da177e4SLinus Torvalds 	if (unlikely(p == NULL))
5331da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
5341da177e4SLinus Torvalds 	xdr_encode_opaque(p, str, len);
5351da177e4SLinus Torvalds 	return 0;
5361da177e4SLinus Torvalds }
5371da177e4SLinus Torvalds 
5381da177e4SLinus Torvalds #define CB_SUPPORTED_ATTR0 (FATTR4_WORD0_CHANGE|FATTR4_WORD0_SIZE)
5391da177e4SLinus Torvalds #define CB_SUPPORTED_ATTR1 (FATTR4_WORD1_TIME_METADATA|FATTR4_WORD1_TIME_MODIFY)
5405704fdebSAl Viro static __be32 encode_attr_bitmap(struct xdr_stream *xdr, const uint32_t *bitmap, __be32 **savep)
5411da177e4SLinus Torvalds {
5425704fdebSAl Viro 	__be32 bm[2];
5435704fdebSAl Viro 	__be32 *p;
5441da177e4SLinus Torvalds 
5451da177e4SLinus Torvalds 	bm[0] = htonl(bitmap[0] & CB_SUPPORTED_ATTR0);
5461da177e4SLinus Torvalds 	bm[1] = htonl(bitmap[1] & CB_SUPPORTED_ATTR1);
5471da177e4SLinus Torvalds 	if (bm[1] != 0) {
5481da177e4SLinus Torvalds 		p = xdr_reserve_space(xdr, 16);
5491da177e4SLinus Torvalds 		if (unlikely(p == NULL))
5501da177e4SLinus Torvalds 			return htonl(NFS4ERR_RESOURCE);
5511da177e4SLinus Torvalds 		*p++ = htonl(2);
5521da177e4SLinus Torvalds 		*p++ = bm[0];
5531da177e4SLinus Torvalds 		*p++ = bm[1];
5541da177e4SLinus Torvalds 	} else if (bm[0] != 0) {
5551da177e4SLinus Torvalds 		p = xdr_reserve_space(xdr, 12);
5561da177e4SLinus Torvalds 		if (unlikely(p == NULL))
5571da177e4SLinus Torvalds 			return htonl(NFS4ERR_RESOURCE);
5581da177e4SLinus Torvalds 		*p++ = htonl(1);
5591da177e4SLinus Torvalds 		*p++ = bm[0];
5601da177e4SLinus Torvalds 	} else {
5611da177e4SLinus Torvalds 		p = xdr_reserve_space(xdr, 8);
5621da177e4SLinus Torvalds 		if (unlikely(p == NULL))
5631da177e4SLinus Torvalds 			return htonl(NFS4ERR_RESOURCE);
5641da177e4SLinus Torvalds 		*p++ = htonl(0);
5651da177e4SLinus Torvalds 	}
5661da177e4SLinus Torvalds 	*savep = p;
5671da177e4SLinus Torvalds 	return 0;
5681da177e4SLinus Torvalds }
5691da177e4SLinus Torvalds 
570e6f684f6SAl Viro static __be32 encode_attr_change(struct xdr_stream *xdr, const uint32_t *bitmap, uint64_t change)
5711da177e4SLinus Torvalds {
5725704fdebSAl Viro 	__be32 *p;
5731da177e4SLinus Torvalds 
5741da177e4SLinus Torvalds 	if (!(bitmap[0] & FATTR4_WORD0_CHANGE))
5751da177e4SLinus Torvalds 		return 0;
5761da177e4SLinus Torvalds 	p = xdr_reserve_space(xdr, 8);
57790dc7d27SHarvey Harrison 	if (unlikely(!p))
5781da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
5791da177e4SLinus Torvalds 	p = xdr_encode_hyper(p, change);
5801da177e4SLinus Torvalds 	return 0;
5811da177e4SLinus Torvalds }
5821da177e4SLinus Torvalds 
583e6f684f6SAl Viro static __be32 encode_attr_size(struct xdr_stream *xdr, const uint32_t *bitmap, uint64_t size)
5841da177e4SLinus Torvalds {
5855704fdebSAl Viro 	__be32 *p;
5861da177e4SLinus Torvalds 
5871da177e4SLinus Torvalds 	if (!(bitmap[0] & FATTR4_WORD0_SIZE))
5881da177e4SLinus Torvalds 		return 0;
5891da177e4SLinus Torvalds 	p = xdr_reserve_space(xdr, 8);
59090dc7d27SHarvey Harrison 	if (unlikely(!p))
5911da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
5921da177e4SLinus Torvalds 	p = xdr_encode_hyper(p, size);
5931da177e4SLinus Torvalds 	return 0;
5941da177e4SLinus Torvalds }
5951da177e4SLinus Torvalds 
596e6f684f6SAl Viro static __be32 encode_attr_time(struct xdr_stream *xdr, const struct timespec *time)
5971da177e4SLinus Torvalds {
5985704fdebSAl Viro 	__be32 *p;
5991da177e4SLinus Torvalds 
6001da177e4SLinus Torvalds 	p = xdr_reserve_space(xdr, 12);
60190dc7d27SHarvey Harrison 	if (unlikely(!p))
6021da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
6031da177e4SLinus Torvalds 	p = xdr_encode_hyper(p, time->tv_sec);
6041da177e4SLinus Torvalds 	*p = htonl(time->tv_nsec);
6051da177e4SLinus Torvalds 	return 0;
6061da177e4SLinus Torvalds }
6071da177e4SLinus Torvalds 
608e6f684f6SAl Viro static __be32 encode_attr_ctime(struct xdr_stream *xdr, const uint32_t *bitmap, const struct timespec *time)
6091da177e4SLinus Torvalds {
6101da177e4SLinus Torvalds 	if (!(bitmap[1] & FATTR4_WORD1_TIME_METADATA))
6111da177e4SLinus Torvalds 		return 0;
6121da177e4SLinus Torvalds 	return encode_attr_time(xdr,time);
6131da177e4SLinus Torvalds }
6141da177e4SLinus Torvalds 
615e6f684f6SAl Viro static __be32 encode_attr_mtime(struct xdr_stream *xdr, const uint32_t *bitmap, const struct timespec *time)
6161da177e4SLinus Torvalds {
6171da177e4SLinus Torvalds 	if (!(bitmap[1] & FATTR4_WORD1_TIME_MODIFY))
6181da177e4SLinus Torvalds 		return 0;
6191da177e4SLinus Torvalds 	return encode_attr_time(xdr,time);
6201da177e4SLinus Torvalds }
6211da177e4SLinus Torvalds 
622e6f684f6SAl Viro static __be32 encode_compound_hdr_res(struct xdr_stream *xdr, struct cb_compound_hdr_res *hdr)
6231da177e4SLinus Torvalds {
624e6f684f6SAl Viro 	__be32 status;
6251da177e4SLinus Torvalds 
6261da177e4SLinus Torvalds 	hdr->status = xdr_reserve_space(xdr, 4);
6271da177e4SLinus Torvalds 	if (unlikely(hdr->status == NULL))
6281da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
6291da177e4SLinus Torvalds 	status = encode_string(xdr, hdr->taglen, hdr->tag);
6301da177e4SLinus Torvalds 	if (unlikely(status != 0))
6311da177e4SLinus Torvalds 		return status;
6321da177e4SLinus Torvalds 	hdr->nops = xdr_reserve_space(xdr, 4);
6331da177e4SLinus Torvalds 	if (unlikely(hdr->nops == NULL))
6341da177e4SLinus Torvalds 		return htonl(NFS4ERR_RESOURCE);
6351da177e4SLinus Torvalds 	return 0;
6361da177e4SLinus Torvalds }
6371da177e4SLinus Torvalds 
638e6f684f6SAl Viro static __be32 encode_op_hdr(struct xdr_stream *xdr, uint32_t op, __be32 res)
6391da177e4SLinus Torvalds {
6405704fdebSAl Viro 	__be32 *p;
6411da177e4SLinus Torvalds 
6421da177e4SLinus Torvalds 	p = xdr_reserve_space(xdr, 8);
6431da177e4SLinus Torvalds 	if (unlikely(p == NULL))
64431d2b435SAndy Adamson 		return htonl(NFS4ERR_RESOURCE_HDR);
6451da177e4SLinus Torvalds 	*p++ = htonl(op);
6461da177e4SLinus Torvalds 	*p = res;
6471da177e4SLinus Torvalds 	return 0;
6481da177e4SLinus Torvalds }
6491da177e4SLinus Torvalds 
650e6f684f6SAl Viro static __be32 encode_getattr_res(struct svc_rqst *rqstp, struct xdr_stream *xdr, const struct cb_getattrres *res)
6511da177e4SLinus Torvalds {
6525704fdebSAl Viro 	__be32 *savep = NULL;
653e6f684f6SAl Viro 	__be32 status = res->status;
6541da177e4SLinus Torvalds 
6551da177e4SLinus Torvalds 	if (unlikely(status != 0))
6561da177e4SLinus Torvalds 		goto out;
6571da177e4SLinus Torvalds 	status = encode_attr_bitmap(xdr, res->bitmap, &savep);
6581da177e4SLinus Torvalds 	if (unlikely(status != 0))
6591da177e4SLinus Torvalds 		goto out;
6601da177e4SLinus Torvalds 	status = encode_attr_change(xdr, res->bitmap, res->change_attr);
6611da177e4SLinus Torvalds 	if (unlikely(status != 0))
6621da177e4SLinus Torvalds 		goto out;
6631da177e4SLinus Torvalds 	status = encode_attr_size(xdr, res->bitmap, res->size);
6641da177e4SLinus Torvalds 	if (unlikely(status != 0))
6651da177e4SLinus Torvalds 		goto out;
6661da177e4SLinus Torvalds 	status = encode_attr_ctime(xdr, res->bitmap, &res->ctime);
6671da177e4SLinus Torvalds 	if (unlikely(status != 0))
6681da177e4SLinus Torvalds 		goto out;
6691da177e4SLinus Torvalds 	status = encode_attr_mtime(xdr, res->bitmap, &res->mtime);
6701da177e4SLinus Torvalds 	*savep = htonl((unsigned int)((char *)xdr->p - (char *)(savep+1)));
6711da177e4SLinus Torvalds out:
6723110ff80SHarvey Harrison 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
6731da177e4SLinus Torvalds 	return status;
6741da177e4SLinus Torvalds }
6751da177e4SLinus Torvalds 
67634bc47c9SBenny Halevy #if defined(CONFIG_NFS_V4_1)
67734bc47c9SBenny Halevy 
6789733f0d9SAndy Adamson static __be32 encode_sessionid(struct xdr_stream *xdr,
6794aece6a1SBenny Halevy 				 const struct nfs4_sessionid *sid)
6804aece6a1SBenny Halevy {
6819733f0d9SAndy Adamson 	__be32 *p;
6824aece6a1SBenny Halevy 	int len = NFS4_MAX_SESSIONID_LEN;
6834aece6a1SBenny Halevy 
6844aece6a1SBenny Halevy 	p = xdr_reserve_space(xdr, len);
6854aece6a1SBenny Halevy 	if (unlikely(p == NULL))
6864aece6a1SBenny Halevy 		return htonl(NFS4ERR_RESOURCE);
6874aece6a1SBenny Halevy 
6884aece6a1SBenny Halevy 	memcpy(p, sid, len);
6894aece6a1SBenny Halevy 	return 0;
6904aece6a1SBenny Halevy }
6914aece6a1SBenny Halevy 
6929733f0d9SAndy Adamson static __be32 encode_cb_sequence_res(struct svc_rqst *rqstp,
6934aece6a1SBenny Halevy 				       struct xdr_stream *xdr,
6944aece6a1SBenny Halevy 				       const struct cb_sequenceres *res)
6954aece6a1SBenny Halevy {
6969733f0d9SAndy Adamson 	__be32 *p;
6974aece6a1SBenny Halevy 	unsigned status = res->csr_status;
6984aece6a1SBenny Halevy 
6994aece6a1SBenny Halevy 	if (unlikely(status != 0))
7004aece6a1SBenny Halevy 		goto out;
7014aece6a1SBenny Halevy 
7024aece6a1SBenny Halevy 	encode_sessionid(xdr, &res->csr_sessionid);
7034aece6a1SBenny Halevy 
7044aece6a1SBenny Halevy 	p = xdr_reserve_space(xdr, 4 * sizeof(uint32_t));
7054aece6a1SBenny Halevy 	if (unlikely(p == NULL))
7064aece6a1SBenny Halevy 		return htonl(NFS4ERR_RESOURCE);
7074aece6a1SBenny Halevy 
7084aece6a1SBenny Halevy 	*p++ = htonl(res->csr_sequenceid);
7094aece6a1SBenny Halevy 	*p++ = htonl(res->csr_slotid);
7104aece6a1SBenny Halevy 	*p++ = htonl(res->csr_highestslotid);
7114aece6a1SBenny Halevy 	*p++ = htonl(res->csr_target_highestslotid);
7124aece6a1SBenny Halevy out:
7134aece6a1SBenny Halevy 	dprintk("%s: exit with status = %d\n", __func__, ntohl(status));
7144aece6a1SBenny Halevy 	return status;
7154aece6a1SBenny Halevy }
7164aece6a1SBenny Halevy 
71734bc47c9SBenny Halevy static __be32
71834bc47c9SBenny Halevy preprocess_nfs41_op(int nop, unsigned int op_nr, struct callback_op **op)
71934bc47c9SBenny Halevy {
720281fe15dSBenny Halevy 	if (op_nr == OP_CB_SEQUENCE) {
721281fe15dSBenny Halevy 		if (nop != 0)
722281fe15dSBenny Halevy 			return htonl(NFS4ERR_SEQUENCE_POS);
723281fe15dSBenny Halevy 	} else {
724281fe15dSBenny Halevy 		if (nop == 0)
725281fe15dSBenny Halevy 			return htonl(NFS4ERR_OP_NOT_IN_SESSION);
726281fe15dSBenny Halevy 	}
727281fe15dSBenny Halevy 
72834bc47c9SBenny Halevy 	switch (op_nr) {
72934bc47c9SBenny Halevy 	case OP_CB_GETATTR:
73034bc47c9SBenny Halevy 	case OP_CB_RECALL:
7314aece6a1SBenny Halevy 	case OP_CB_SEQUENCE:
73231f09607SAlexandros Batsakis 	case OP_CB_RECALL_ANY:
733b9efa1b2SAndy Adamson 	case OP_CB_RECALL_SLOT:
734f2a62561SFred Isaman 	case OP_CB_LAYOUTRECALL:
7351be5683bSMarc Eshel 	case OP_CB_NOTIFY_DEVICEID:
73634bc47c9SBenny Halevy 		*op = &callback_ops[op_nr];
73734bc47c9SBenny Halevy 		break;
73834bc47c9SBenny Halevy 
73934bc47c9SBenny Halevy 	case OP_CB_NOTIFY:
74034bc47c9SBenny Halevy 	case OP_CB_PUSH_DELEG:
74134bc47c9SBenny Halevy 	case OP_CB_RECALLABLE_OBJ_AVAIL:
74234bc47c9SBenny Halevy 	case OP_CB_WANTS_CANCELLED:
74334bc47c9SBenny Halevy 	case OP_CB_NOTIFY_LOCK:
74434bc47c9SBenny Halevy 		return htonl(NFS4ERR_NOTSUPP);
74534bc47c9SBenny Halevy 
74634bc47c9SBenny Halevy 	default:
74734bc47c9SBenny Halevy 		return htonl(NFS4ERR_OP_ILLEGAL);
74834bc47c9SBenny Halevy 	}
74934bc47c9SBenny Halevy 
75034bc47c9SBenny Halevy 	return htonl(NFS_OK);
75134bc47c9SBenny Halevy }
75234bc47c9SBenny Halevy 
75342acd021SAndy Adamson static void nfs4_callback_free_slot(struct nfs4_session *session)
75442acd021SAndy Adamson {
75542acd021SAndy Adamson 	struct nfs4_slot_table *tbl = &session->bc_slot_table;
75642acd021SAndy Adamson 
75742acd021SAndy Adamson 	spin_lock(&tbl->slot_tbl_lock);
75842acd021SAndy Adamson 	/*
75942acd021SAndy Adamson 	 * Let the state manager know callback processing done.
76042acd021SAndy Adamson 	 * A single slot, so highest used slotid is either 0 or -1
76142acd021SAndy Adamson 	 */
76255a67399STrond Myklebust 	tbl->highest_used_slotid = -1;
76342acd021SAndy Adamson 	nfs4_check_drain_bc_complete(session);
76442acd021SAndy Adamson 	spin_unlock(&tbl->slot_tbl_lock);
76542acd021SAndy Adamson }
76642acd021SAndy Adamson 
76755a67399STrond Myklebust static void nfs4_cb_free_slot(struct cb_process_state *cps)
76842acd021SAndy Adamson {
76955a67399STrond Myklebust 	if (cps->slotid != -1)
77055a67399STrond Myklebust 		nfs4_callback_free_slot(cps->clp->cl_session);
77142acd021SAndy Adamson }
77242acd021SAndy Adamson 
77334bc47c9SBenny Halevy #else /* CONFIG_NFS_V4_1 */
77434bc47c9SBenny Halevy 
77534bc47c9SBenny Halevy static __be32
77634bc47c9SBenny Halevy preprocess_nfs41_op(int nop, unsigned int op_nr, struct callback_op **op)
77734bc47c9SBenny Halevy {
77834bc47c9SBenny Halevy 	return htonl(NFS4ERR_MINOR_VERS_MISMATCH);
77934bc47c9SBenny Halevy }
78034bc47c9SBenny Halevy 
78155a67399STrond Myklebust static void nfs4_cb_free_slot(struct cb_process_state *cps)
78242acd021SAndy Adamson {
78342acd021SAndy Adamson }
78434bc47c9SBenny Halevy #endif /* CONFIG_NFS_V4_1 */
78534bc47c9SBenny Halevy 
78634bc47c9SBenny Halevy static __be32
78734bc47c9SBenny Halevy preprocess_nfs4_op(unsigned int op_nr, struct callback_op **op)
78834bc47c9SBenny Halevy {
78934bc47c9SBenny Halevy 	switch (op_nr) {
79034bc47c9SBenny Halevy 	case OP_CB_GETATTR:
79134bc47c9SBenny Halevy 	case OP_CB_RECALL:
79234bc47c9SBenny Halevy 		*op = &callback_ops[op_nr];
79334bc47c9SBenny Halevy 		break;
79434bc47c9SBenny Halevy 	default:
79534bc47c9SBenny Halevy 		return htonl(NFS4ERR_OP_ILLEGAL);
79634bc47c9SBenny Halevy 	}
79734bc47c9SBenny Halevy 
79834bc47c9SBenny Halevy 	return htonl(NFS_OK);
79934bc47c9SBenny Halevy }
80034bc47c9SBenny Halevy 
80134bc47c9SBenny Halevy static __be32 process_op(uint32_t minorversion, int nop,
80234bc47c9SBenny Halevy 		struct svc_rqst *rqstp,
8031da177e4SLinus Torvalds 		struct xdr_stream *xdr_in, void *argp,
804c36fca52SAndy Adamson 		struct xdr_stream *xdr_out, void *resp,
805c36fca52SAndy Adamson 		struct cb_process_state *cps)
8061da177e4SLinus Torvalds {
807a162a6b8STrond Myklebust 	struct callback_op *op = &callback_ops[0];
80831d2b435SAndy Adamson 	unsigned int op_nr;
80934bc47c9SBenny Halevy 	__be32 status;
8101da177e4SLinus Torvalds 	long maxlen;
811e6f684f6SAl Viro 	__be32 res;
8121da177e4SLinus Torvalds 
8133110ff80SHarvey Harrison 	dprintk("%s: start\n", __func__);
8141da177e4SLinus Torvalds 	status = decode_op_hdr(xdr_in, &op_nr);
81531d2b435SAndy Adamson 	if (unlikely(status))
81631d2b435SAndy Adamson 		return status;
8171da177e4SLinus Torvalds 
81834bc47c9SBenny Halevy 	dprintk("%s: minorversion=%d nop=%d op_nr=%u\n",
81934bc47c9SBenny Halevy 		__func__, minorversion, nop, op_nr);
82034bc47c9SBenny Halevy 
82134bc47c9SBenny Halevy 	status = minorversion ? preprocess_nfs41_op(nop, op_nr, &op) :
82234bc47c9SBenny Halevy 				preprocess_nfs4_op(op_nr, &op);
82334bc47c9SBenny Halevy 	if (status == htonl(NFS4ERR_OP_ILLEGAL))
82434bc47c9SBenny Halevy 		op_nr = OP_CB_ILLEGAL;
825b92b3019SAndy Adamson 	if (status)
826b92b3019SAndy Adamson 		goto encode_hdr;
82731d2b435SAndy Adamson 
828c36fca52SAndy Adamson 	if (cps->drc_status) {
829c36fca52SAndy Adamson 		status = cps->drc_status;
8304911096fSAndy Adamson 		goto encode_hdr;
8314911096fSAndy Adamson 	}
8324911096fSAndy Adamson 
8331da177e4SLinus Torvalds 	maxlen = xdr_out->end - xdr_out->p;
8341da177e4SLinus Torvalds 	if (maxlen > 0 && maxlen < PAGE_SIZE) {
8351da177e4SLinus Torvalds 		status = op->decode_args(rqstp, xdr_in, argp);
836e95e60daSAndy Adamson 		if (likely(status == 0))
837c36fca52SAndy Adamson 			status = op->process_op(argp, resp, cps);
8381da177e4SLinus Torvalds 	} else
8391da177e4SLinus Torvalds 		status = htonl(NFS4ERR_RESOURCE);
8401da177e4SLinus Torvalds 
841b92b3019SAndy Adamson encode_hdr:
8421da177e4SLinus Torvalds 	res = encode_op_hdr(xdr_out, op_nr, status);
84331d2b435SAndy Adamson 	if (unlikely(res))
84431d2b435SAndy Adamson 		return res;
8451da177e4SLinus Torvalds 	if (op->encode_res != NULL && status == 0)
8461da177e4SLinus Torvalds 		status = op->encode_res(rqstp, xdr_out, resp);
8473110ff80SHarvey Harrison 	dprintk("%s: done, status = %d\n", __func__, ntohl(status));
8481da177e4SLinus Torvalds 	return status;
8491da177e4SLinus Torvalds }
8501da177e4SLinus Torvalds 
8511da177e4SLinus Torvalds /*
8521da177e4SLinus Torvalds  * Decode, process and encode a COMPOUND
8531da177e4SLinus Torvalds  */
8547111c66eSAl Viro static __be32 nfs4_callback_compound(struct svc_rqst *rqstp, void *argp, void *resp)
8551da177e4SLinus Torvalds {
8563a6258e1STrond Myklebust 	struct cb_compound_hdr_arg hdr_arg = { 0 };
8573a6258e1STrond Myklebust 	struct cb_compound_hdr_res hdr_res = { NULL };
8581da177e4SLinus Torvalds 	struct xdr_stream xdr_in, xdr_out;
859c36fca52SAndy Adamson 	__be32 *p, status;
860c36fca52SAndy Adamson 	struct cb_process_state cps = {
861c36fca52SAndy Adamson 		.drc_status = 0,
862c36fca52SAndy Adamson 		.clp = NULL,
86355a67399STrond Myklebust 		.slotid = -1,
864c36fca52SAndy Adamson 	};
8653a6258e1STrond Myklebust 	unsigned int nops = 0;
8661da177e4SLinus Torvalds 
8673110ff80SHarvey Harrison 	dprintk("%s: start\n", __func__);
8681da177e4SLinus Torvalds 
8691da177e4SLinus Torvalds 	xdr_init_decode(&xdr_in, &rqstp->rq_arg, rqstp->rq_arg.head[0].iov_base);
8701da177e4SLinus Torvalds 
8715704fdebSAl Viro 	p = (__be32*)((char *)rqstp->rq_res.head[0].iov_base + rqstp->rq_res.head[0].iov_len);
8721da177e4SLinus Torvalds 	xdr_init_encode(&xdr_out, &rqstp->rq_res, p);
8731da177e4SLinus Torvalds 
8743a6258e1STrond Myklebust 	status = decode_compound_hdr_arg(&xdr_in, &hdr_arg);
8753a6258e1STrond Myklebust 	if (status == __constant_htonl(NFS4ERR_RESOURCE))
8763a6258e1STrond Myklebust 		return rpc_garbage_args;
8773a6258e1STrond Myklebust 
878c36fca52SAndy Adamson 	if (hdr_arg.minorversion == 0) {
879c36fca52SAndy Adamson 		cps.clp = nfs4_find_client_ident(hdr_arg.cb_ident);
880778be232SAndy Adamson 		if (!cps.clp || !check_gss_callback_principal(cps.clp, rqstp))
881c36fca52SAndy Adamson 			return rpc_drop_reply;
882778be232SAndy Adamson 	}
883c36fca52SAndy Adamson 
8841da177e4SLinus Torvalds 	hdr_res.taglen = hdr_arg.taglen;
8851da177e4SLinus Torvalds 	hdr_res.tag = hdr_arg.tag;
8863a6258e1STrond Myklebust 	if (encode_compound_hdr_res(&xdr_out, &hdr_res) != 0)
8873a6258e1STrond Myklebust 		return rpc_system_err;
8881da177e4SLinus Torvalds 
8893a6258e1STrond Myklebust 	while (status == 0 && nops != hdr_arg.nops) {
8904911096fSAndy Adamson 		status = process_op(hdr_arg.minorversion, nops, rqstp,
891c36fca52SAndy Adamson 				    &xdr_in, argp, &xdr_out, resp, &cps);
8921da177e4SLinus Torvalds 		nops++;
8931da177e4SLinus Torvalds 	}
8943a6258e1STrond Myklebust 
89531d2b435SAndy Adamson 	/* Buffer overflow in decode_ops_hdr or encode_ops_hdr. Return
89631d2b435SAndy Adamson 	* resource error in cb_compound status without returning op */
89731d2b435SAndy Adamson 	if (unlikely(status == htonl(NFS4ERR_RESOURCE_HDR))) {
89831d2b435SAndy Adamson 		status = htonl(NFS4ERR_RESOURCE);
89931d2b435SAndy Adamson 		nops--;
90031d2b435SAndy Adamson 	}
90131d2b435SAndy Adamson 
9021da177e4SLinus Torvalds 	*hdr_res.status = status;
9031da177e4SLinus Torvalds 	*hdr_res.nops = htonl(nops);
90455a67399STrond Myklebust 	nfs4_cb_free_slot(&cps);
905c36fca52SAndy Adamson 	nfs_put_client(cps.clp);
9063110ff80SHarvey Harrison 	dprintk("%s: done, status = %u\n", __func__, ntohl(status));
9071da177e4SLinus Torvalds 	return rpc_success;
9081da177e4SLinus Torvalds }
9091da177e4SLinus Torvalds 
9101da177e4SLinus Torvalds /*
9111da177e4SLinus Torvalds  * Define NFS4 callback COMPOUND ops.
9121da177e4SLinus Torvalds  */
9131da177e4SLinus Torvalds static struct callback_op callback_ops[] = {
9141da177e4SLinus Torvalds 	[0] = {
9151da177e4SLinus Torvalds 		.res_maxsize = CB_OP_HDR_RES_MAXSZ,
9161da177e4SLinus Torvalds 	},
9171da177e4SLinus Torvalds 	[OP_CB_GETATTR] = {
9181da177e4SLinus Torvalds 		.process_op = (callback_process_op_t)nfs4_callback_getattr,
9191da177e4SLinus Torvalds 		.decode_args = (callback_decode_arg_t)decode_getattr_args,
9201da177e4SLinus Torvalds 		.encode_res = (callback_encode_res_t)encode_getattr_res,
9211da177e4SLinus Torvalds 		.res_maxsize = CB_OP_GETATTR_RES_MAXSZ,
9221da177e4SLinus Torvalds 	},
9231da177e4SLinus Torvalds 	[OP_CB_RECALL] = {
9241da177e4SLinus Torvalds 		.process_op = (callback_process_op_t)nfs4_callback_recall,
9251da177e4SLinus Torvalds 		.decode_args = (callback_decode_arg_t)decode_recall_args,
9261da177e4SLinus Torvalds 		.res_maxsize = CB_OP_RECALL_RES_MAXSZ,
9274aece6a1SBenny Halevy 	},
9284aece6a1SBenny Halevy #if defined(CONFIG_NFS_V4_1)
929f2a62561SFred Isaman 	[OP_CB_LAYOUTRECALL] = {
930f2a62561SFred Isaman 		.process_op = (callback_process_op_t)nfs4_callback_layoutrecall,
931f2a62561SFred Isaman 		.decode_args =
932f2a62561SFred Isaman 			(callback_decode_arg_t)decode_layoutrecall_args,
933f2a62561SFred Isaman 		.res_maxsize = CB_OP_LAYOUTRECALL_RES_MAXSZ,
934f2a62561SFred Isaman 	},
9351be5683bSMarc Eshel 	[OP_CB_NOTIFY_DEVICEID] = {
9361be5683bSMarc Eshel 		.process_op = (callback_process_op_t)nfs4_callback_devicenotify,
9371be5683bSMarc Eshel 		.decode_args =
9381be5683bSMarc Eshel 			(callback_decode_arg_t)decode_devicenotify_args,
9391be5683bSMarc Eshel 		.res_maxsize = CB_OP_DEVICENOTIFY_RES_MAXSZ,
9401be5683bSMarc Eshel 	},
9414aece6a1SBenny Halevy 	[OP_CB_SEQUENCE] = {
9424aece6a1SBenny Halevy 		.process_op = (callback_process_op_t)nfs4_callback_sequence,
9434aece6a1SBenny Halevy 		.decode_args = (callback_decode_arg_t)decode_cb_sequence_args,
9444aece6a1SBenny Halevy 		.encode_res = (callback_encode_res_t)encode_cb_sequence_res,
9454aece6a1SBenny Halevy 		.res_maxsize = CB_OP_SEQUENCE_RES_MAXSZ,
9464aece6a1SBenny Halevy 	},
94731f09607SAlexandros Batsakis 	[OP_CB_RECALL_ANY] = {
94831f09607SAlexandros Batsakis 		.process_op = (callback_process_op_t)nfs4_callback_recallany,
94931f09607SAlexandros Batsakis 		.decode_args = (callback_decode_arg_t)decode_recallany_args,
95031f09607SAlexandros Batsakis 		.res_maxsize = CB_OP_RECALLANY_RES_MAXSZ,
95131f09607SAlexandros Batsakis 	},
952b9efa1b2SAndy Adamson 	[OP_CB_RECALL_SLOT] = {
953b9efa1b2SAndy Adamson 		.process_op = (callback_process_op_t)nfs4_callback_recallslot,
954b9efa1b2SAndy Adamson 		.decode_args = (callback_decode_arg_t)decode_recallslot_args,
955b9efa1b2SAndy Adamson 		.res_maxsize = CB_OP_RECALLSLOT_RES_MAXSZ,
956b9efa1b2SAndy Adamson 	},
9574aece6a1SBenny Halevy #endif /* CONFIG_NFS_V4_1 */
9581da177e4SLinus Torvalds };
9591da177e4SLinus Torvalds 
9601da177e4SLinus Torvalds /*
9611da177e4SLinus Torvalds  * Define NFS4 callback procedures
9621da177e4SLinus Torvalds  */
9631da177e4SLinus Torvalds static struct svc_procedure nfs4_callback_procedures1[] = {
9641da177e4SLinus Torvalds 	[CB_NULL] = {
9651da177e4SLinus Torvalds 		.pc_func = nfs4_callback_null,
9661da177e4SLinus Torvalds 		.pc_decode = (kxdrproc_t)nfs4_decode_void,
9671da177e4SLinus Torvalds 		.pc_encode = (kxdrproc_t)nfs4_encode_void,
9681da177e4SLinus Torvalds 		.pc_xdrressize = 1,
9691da177e4SLinus Torvalds 	},
9701da177e4SLinus Torvalds 	[CB_COMPOUND] = {
9711da177e4SLinus Torvalds 		.pc_func = nfs4_callback_compound,
9721da177e4SLinus Torvalds 		.pc_encode = (kxdrproc_t)nfs4_encode_void,
9731da177e4SLinus Torvalds 		.pc_argsize = 256,
9741da177e4SLinus Torvalds 		.pc_ressize = 256,
9751da177e4SLinus Torvalds 		.pc_xdrressize = NFS4_CALLBACK_BUFSIZE,
9761da177e4SLinus Torvalds 	}
9771da177e4SLinus Torvalds };
9781da177e4SLinus Torvalds 
9791da177e4SLinus Torvalds struct svc_version nfs4_callback_version1 = {
9801da177e4SLinus Torvalds 	.vs_vers = 1,
9811da177e4SLinus Torvalds 	.vs_nproc = ARRAY_SIZE(nfs4_callback_procedures1),
9821da177e4SLinus Torvalds 	.vs_proc = nfs4_callback_procedures1,
9831da177e4SLinus Torvalds 	.vs_xdrsize = NFS4_CALLBACK_XDRSIZE,
9841da177e4SLinus Torvalds 	.vs_dispatch = NULL,
98549697ee7SSteve Dickson 	.vs_hidden = 1,
9861da177e4SLinus Torvalds };
9871da177e4SLinus Torvalds 
98807bccc2dSAlexandros Batsakis struct svc_version nfs4_callback_version4 = {
98907bccc2dSAlexandros Batsakis 	.vs_vers = 4,
99007bccc2dSAlexandros Batsakis 	.vs_nproc = ARRAY_SIZE(nfs4_callback_procedures1),
99107bccc2dSAlexandros Batsakis 	.vs_proc = nfs4_callback_procedures1,
99207bccc2dSAlexandros Batsakis 	.vs_xdrsize = NFS4_CALLBACK_XDRSIZE,
99307bccc2dSAlexandros Batsakis 	.vs_dispatch = NULL,
9946070295eSJeff Layton 	.vs_hidden = 1,
99507bccc2dSAlexandros Batsakis };
996