1 // SPDX-License-Identifier: GPL-2.0 2 /* 3 * XDR support for nfsd 4 * 5 * Copyright (C) 1995, 1996 Olaf Kirch <okir@monad.swb.de> 6 */ 7 8 #include "vfs.h" 9 #include "xdr.h" 10 #include "auth.h" 11 12 #define NFSDDBG_FACILITY NFSDDBG_XDR 13 14 /* 15 * Mapping of S_IF* types to NFS file types 16 */ 17 static u32 nfs_ftypes[] = { 18 NFNON, NFCHR, NFCHR, NFBAD, 19 NFDIR, NFBAD, NFBLK, NFBAD, 20 NFREG, NFBAD, NFLNK, NFBAD, 21 NFSOCK, NFBAD, NFLNK, NFBAD, 22 }; 23 24 25 /* 26 * XDR functions for basic NFS types 27 */ 28 static __be32 * 29 decode_fh(__be32 *p, struct svc_fh *fhp) 30 { 31 fh_init(fhp, NFS_FHSIZE); 32 memcpy(&fhp->fh_handle.fh_base, p, NFS_FHSIZE); 33 fhp->fh_handle.fh_size = NFS_FHSIZE; 34 35 /* FIXME: Look up export pointer here and verify 36 * Sun Secure RPC if requested */ 37 return p + (NFS_FHSIZE >> 2); 38 } 39 40 /* Helper function for NFSv2 ACL code */ 41 __be32 *nfs2svc_decode_fh(__be32 *p, struct svc_fh *fhp) 42 { 43 return decode_fh(p, fhp); 44 } 45 46 static __be32 * 47 encode_fh(__be32 *p, struct svc_fh *fhp) 48 { 49 memcpy(p, &fhp->fh_handle.fh_base, NFS_FHSIZE); 50 return p + (NFS_FHSIZE>> 2); 51 } 52 53 /* 54 * Decode a file name and make sure that the path contains 55 * no slashes or null bytes. 56 */ 57 static __be32 * 58 decode_filename(__be32 *p, char **namp, unsigned int *lenp) 59 { 60 char *name; 61 unsigned int i; 62 63 if ((p = xdr_decode_string_inplace(p, namp, lenp, NFS_MAXNAMLEN)) != NULL) { 64 for (i = 0, name = *namp; i < *lenp; i++, name++) { 65 if (*name == '\0' || *name == '/') 66 return NULL; 67 } 68 } 69 70 return p; 71 } 72 73 static __be32 * 74 decode_pathname(__be32 *p, char **namp, unsigned int *lenp) 75 { 76 char *name; 77 unsigned int i; 78 79 if ((p = xdr_decode_string_inplace(p, namp, lenp, NFS_MAXPATHLEN)) != NULL) { 80 for (i = 0, name = *namp; i < *lenp; i++, name++) { 81 if (*name == '\0') 82 return NULL; 83 } 84 } 85 86 return p; 87 } 88 89 static __be32 * 90 decode_sattr(__be32 *p, struct iattr *iap) 91 { 92 u32 tmp, tmp1; 93 94 iap->ia_valid = 0; 95 96 /* Sun client bug compatibility check: some sun clients seem to 97 * put 0xffff in the mode field when they mean 0xffffffff. 98 * Quoting the 4.4BSD nfs server code: Nah nah nah nah na nah. 99 */ 100 if ((tmp = ntohl(*p++)) != (u32)-1 && tmp != 0xffff) { 101 iap->ia_valid |= ATTR_MODE; 102 iap->ia_mode = tmp; 103 } 104 if ((tmp = ntohl(*p++)) != (u32)-1) { 105 iap->ia_uid = make_kuid(&init_user_ns, tmp); 106 if (uid_valid(iap->ia_uid)) 107 iap->ia_valid |= ATTR_UID; 108 } 109 if ((tmp = ntohl(*p++)) != (u32)-1) { 110 iap->ia_gid = make_kgid(&init_user_ns, tmp); 111 if (gid_valid(iap->ia_gid)) 112 iap->ia_valid |= ATTR_GID; 113 } 114 if ((tmp = ntohl(*p++)) != (u32)-1) { 115 iap->ia_valid |= ATTR_SIZE; 116 iap->ia_size = tmp; 117 } 118 tmp = ntohl(*p++); tmp1 = ntohl(*p++); 119 if (tmp != (u32)-1 && tmp1 != (u32)-1) { 120 iap->ia_valid |= ATTR_ATIME | ATTR_ATIME_SET; 121 iap->ia_atime.tv_sec = tmp; 122 iap->ia_atime.tv_nsec = tmp1 * 1000; 123 } 124 tmp = ntohl(*p++); tmp1 = ntohl(*p++); 125 if (tmp != (u32)-1 && tmp1 != (u32)-1) { 126 iap->ia_valid |= ATTR_MTIME | ATTR_MTIME_SET; 127 iap->ia_mtime.tv_sec = tmp; 128 iap->ia_mtime.tv_nsec = tmp1 * 1000; 129 /* 130 * Passing the invalid value useconds=1000000 for mtime 131 * is a Sun convention for "set both mtime and atime to 132 * current server time". It's needed to make permissions 133 * checks for the "touch" program across v2 mounts to 134 * Solaris and Irix boxes work correctly. See description of 135 * sattr in section 6.1 of "NFS Illustrated" by 136 * Brent Callaghan, Addison-Wesley, ISBN 0-201-32750-5 137 */ 138 if (tmp1 == 1000000) 139 iap->ia_valid &= ~(ATTR_ATIME_SET|ATTR_MTIME_SET); 140 } 141 return p; 142 } 143 144 static __be32 * 145 encode_fattr(struct svc_rqst *rqstp, __be32 *p, struct svc_fh *fhp, 146 struct kstat *stat) 147 { 148 struct dentry *dentry = fhp->fh_dentry; 149 int type; 150 struct timespec time; 151 u32 f; 152 153 type = (stat->mode & S_IFMT); 154 155 *p++ = htonl(nfs_ftypes[type >> 12]); 156 *p++ = htonl((u32) stat->mode); 157 *p++ = htonl((u32) stat->nlink); 158 *p++ = htonl((u32) from_kuid(&init_user_ns, stat->uid)); 159 *p++ = htonl((u32) from_kgid(&init_user_ns, stat->gid)); 160 161 if (S_ISLNK(type) && stat->size > NFS_MAXPATHLEN) { 162 *p++ = htonl(NFS_MAXPATHLEN); 163 } else { 164 *p++ = htonl((u32) stat->size); 165 } 166 *p++ = htonl((u32) stat->blksize); 167 if (S_ISCHR(type) || S_ISBLK(type)) 168 *p++ = htonl(new_encode_dev(stat->rdev)); 169 else 170 *p++ = htonl(0xffffffff); 171 *p++ = htonl((u32) stat->blocks); 172 switch (fsid_source(fhp)) { 173 default: 174 case FSIDSOURCE_DEV: 175 *p++ = htonl(new_encode_dev(stat->dev)); 176 break; 177 case FSIDSOURCE_FSID: 178 *p++ = htonl((u32) fhp->fh_export->ex_fsid); 179 break; 180 case FSIDSOURCE_UUID: 181 f = ((u32*)fhp->fh_export->ex_uuid)[0]; 182 f ^= ((u32*)fhp->fh_export->ex_uuid)[1]; 183 f ^= ((u32*)fhp->fh_export->ex_uuid)[2]; 184 f ^= ((u32*)fhp->fh_export->ex_uuid)[3]; 185 *p++ = htonl(f); 186 break; 187 } 188 *p++ = htonl((u32) stat->ino); 189 *p++ = htonl((u32) stat->atime.tv_sec); 190 *p++ = htonl(stat->atime.tv_nsec ? stat->atime.tv_nsec / 1000 : 0); 191 time = stat->mtime; 192 lease_get_mtime(d_inode(dentry), &time); 193 *p++ = htonl((u32) time.tv_sec); 194 *p++ = htonl(time.tv_nsec ? time.tv_nsec / 1000 : 0); 195 *p++ = htonl((u32) stat->ctime.tv_sec); 196 *p++ = htonl(stat->ctime.tv_nsec ? stat->ctime.tv_nsec / 1000 : 0); 197 198 return p; 199 } 200 201 /* Helper function for NFSv2 ACL code */ 202 __be32 *nfs2svc_encode_fattr(struct svc_rqst *rqstp, __be32 *p, struct svc_fh *fhp, struct kstat *stat) 203 { 204 return encode_fattr(rqstp, p, fhp, stat); 205 } 206 207 /* 208 * XDR decode functions 209 */ 210 int 211 nfssvc_decode_void(struct svc_rqst *rqstp, __be32 *p) 212 { 213 return xdr_argsize_check(rqstp, p); 214 } 215 216 int 217 nfssvc_decode_fhandle(struct svc_rqst *rqstp, __be32 *p) 218 { 219 struct nfsd_fhandle *args = rqstp->rq_argp; 220 221 p = decode_fh(p, &args->fh); 222 if (!p) 223 return 0; 224 return xdr_argsize_check(rqstp, p); 225 } 226 227 int 228 nfssvc_decode_sattrargs(struct svc_rqst *rqstp, __be32 *p) 229 { 230 struct nfsd_sattrargs *args = rqstp->rq_argp; 231 232 p = decode_fh(p, &args->fh); 233 if (!p) 234 return 0; 235 p = decode_sattr(p, &args->attrs); 236 237 return xdr_argsize_check(rqstp, p); 238 } 239 240 int 241 nfssvc_decode_diropargs(struct svc_rqst *rqstp, __be32 *p) 242 { 243 struct nfsd_diropargs *args = rqstp->rq_argp; 244 245 if (!(p = decode_fh(p, &args->fh)) 246 || !(p = decode_filename(p, &args->name, &args->len))) 247 return 0; 248 249 return xdr_argsize_check(rqstp, p); 250 } 251 252 int 253 nfssvc_decode_readargs(struct svc_rqst *rqstp, __be32 *p) 254 { 255 struct nfsd_readargs *args = rqstp->rq_argp; 256 unsigned int len; 257 int v; 258 p = decode_fh(p, &args->fh); 259 if (!p) 260 return 0; 261 262 args->offset = ntohl(*p++); 263 len = args->count = ntohl(*p++); 264 p++; /* totalcount - unused */ 265 266 len = min_t(unsigned int, len, NFSSVC_MAXBLKSIZE_V2); 267 268 /* set up somewhere to store response. 269 * We take pages, put them on reslist and include in iovec 270 */ 271 v=0; 272 while (len > 0) { 273 struct page *p = *(rqstp->rq_next_page++); 274 275 rqstp->rq_vec[v].iov_base = page_address(p); 276 rqstp->rq_vec[v].iov_len = min_t(unsigned int, len, PAGE_SIZE); 277 len -= rqstp->rq_vec[v].iov_len; 278 v++; 279 } 280 args->vlen = v; 281 return xdr_argsize_check(rqstp, p); 282 } 283 284 int 285 nfssvc_decode_writeargs(struct svc_rqst *rqstp, __be32 *p) 286 { 287 struct nfsd_writeargs *args = rqstp->rq_argp; 288 unsigned int len, hdr, dlen; 289 struct kvec *head = rqstp->rq_arg.head; 290 int v; 291 292 p = decode_fh(p, &args->fh); 293 if (!p) 294 return 0; 295 296 p++; /* beginoffset */ 297 args->offset = ntohl(*p++); /* offset */ 298 p++; /* totalcount */ 299 len = args->len = ntohl(*p++); 300 /* 301 * The protocol specifies a maximum of 8192 bytes. 302 */ 303 if (len > NFSSVC_MAXBLKSIZE_V2) 304 return 0; 305 306 /* 307 * Check to make sure that we got the right number of 308 * bytes. 309 */ 310 hdr = (void*)p - head->iov_base; 311 if (hdr > head->iov_len) 312 return 0; 313 dlen = head->iov_len + rqstp->rq_arg.page_len - hdr; 314 315 /* 316 * Round the length of the data which was specified up to 317 * the next multiple of XDR units and then compare that 318 * against the length which was actually received. 319 * Note that when RPCSEC/GSS (for example) is used, the 320 * data buffer can be padded so dlen might be larger 321 * than required. It must never be smaller. 322 */ 323 if (dlen < XDR_QUADLEN(len)*4) 324 return 0; 325 326 rqstp->rq_vec[0].iov_base = (void*)p; 327 rqstp->rq_vec[0].iov_len = head->iov_len - hdr; 328 v = 0; 329 while (len > rqstp->rq_vec[v].iov_len) { 330 len -= rqstp->rq_vec[v].iov_len; 331 v++; 332 rqstp->rq_vec[v].iov_base = page_address(rqstp->rq_pages[v]); 333 rqstp->rq_vec[v].iov_len = PAGE_SIZE; 334 } 335 rqstp->rq_vec[v].iov_len = len; 336 args->vlen = v + 1; 337 return 1; 338 } 339 340 int 341 nfssvc_decode_createargs(struct svc_rqst *rqstp, __be32 *p) 342 { 343 struct nfsd_createargs *args = rqstp->rq_argp; 344 345 if ( !(p = decode_fh(p, &args->fh)) 346 || !(p = decode_filename(p, &args->name, &args->len))) 347 return 0; 348 p = decode_sattr(p, &args->attrs); 349 350 return xdr_argsize_check(rqstp, p); 351 } 352 353 int 354 nfssvc_decode_renameargs(struct svc_rqst *rqstp, __be32 *p) 355 { 356 struct nfsd_renameargs *args = rqstp->rq_argp; 357 358 if (!(p = decode_fh(p, &args->ffh)) 359 || !(p = decode_filename(p, &args->fname, &args->flen)) 360 || !(p = decode_fh(p, &args->tfh)) 361 || !(p = decode_filename(p, &args->tname, &args->tlen))) 362 return 0; 363 364 return xdr_argsize_check(rqstp, p); 365 } 366 367 int 368 nfssvc_decode_readlinkargs(struct svc_rqst *rqstp, __be32 *p) 369 { 370 struct nfsd_readlinkargs *args = rqstp->rq_argp; 371 372 p = decode_fh(p, &args->fh); 373 if (!p) 374 return 0; 375 args->buffer = page_address(*(rqstp->rq_next_page++)); 376 377 return xdr_argsize_check(rqstp, p); 378 } 379 380 int 381 nfssvc_decode_linkargs(struct svc_rqst *rqstp, __be32 *p) 382 { 383 struct nfsd_linkargs *args = rqstp->rq_argp; 384 385 if (!(p = decode_fh(p, &args->ffh)) 386 || !(p = decode_fh(p, &args->tfh)) 387 || !(p = decode_filename(p, &args->tname, &args->tlen))) 388 return 0; 389 390 return xdr_argsize_check(rqstp, p); 391 } 392 393 int 394 nfssvc_decode_symlinkargs(struct svc_rqst *rqstp, __be32 *p) 395 { 396 struct nfsd_symlinkargs *args = rqstp->rq_argp; 397 398 if ( !(p = decode_fh(p, &args->ffh)) 399 || !(p = decode_filename(p, &args->fname, &args->flen)) 400 || !(p = decode_pathname(p, &args->tname, &args->tlen))) 401 return 0; 402 p = decode_sattr(p, &args->attrs); 403 404 return xdr_argsize_check(rqstp, p); 405 } 406 407 int 408 nfssvc_decode_readdirargs(struct svc_rqst *rqstp, __be32 *p) 409 { 410 struct nfsd_readdirargs *args = rqstp->rq_argp; 411 412 p = decode_fh(p, &args->fh); 413 if (!p) 414 return 0; 415 args->cookie = ntohl(*p++); 416 args->count = ntohl(*p++); 417 args->count = min_t(u32, args->count, PAGE_SIZE); 418 args->buffer = page_address(*(rqstp->rq_next_page++)); 419 420 return xdr_argsize_check(rqstp, p); 421 } 422 423 /* 424 * XDR encode functions 425 */ 426 int 427 nfssvc_encode_void(struct svc_rqst *rqstp, __be32 *p) 428 { 429 return xdr_ressize_check(rqstp, p); 430 } 431 432 int 433 nfssvc_encode_attrstat(struct svc_rqst *rqstp, __be32 *p) 434 { 435 struct nfsd_attrstat *resp = rqstp->rq_resp; 436 437 p = encode_fattr(rqstp, p, &resp->fh, &resp->stat); 438 return xdr_ressize_check(rqstp, p); 439 } 440 441 int 442 nfssvc_encode_diropres(struct svc_rqst *rqstp, __be32 *p) 443 { 444 struct nfsd_diropres *resp = rqstp->rq_resp; 445 446 p = encode_fh(p, &resp->fh); 447 p = encode_fattr(rqstp, p, &resp->fh, &resp->stat); 448 return xdr_ressize_check(rqstp, p); 449 } 450 451 int 452 nfssvc_encode_readlinkres(struct svc_rqst *rqstp, __be32 *p) 453 { 454 struct nfsd_readlinkres *resp = rqstp->rq_resp; 455 456 *p++ = htonl(resp->len); 457 xdr_ressize_check(rqstp, p); 458 rqstp->rq_res.page_len = resp->len; 459 if (resp->len & 3) { 460 /* need to pad the tail */ 461 rqstp->rq_res.tail[0].iov_base = p; 462 *p = 0; 463 rqstp->rq_res.tail[0].iov_len = 4 - (resp->len&3); 464 } 465 return 1; 466 } 467 468 int 469 nfssvc_encode_readres(struct svc_rqst *rqstp, __be32 *p) 470 { 471 struct nfsd_readres *resp = rqstp->rq_resp; 472 473 p = encode_fattr(rqstp, p, &resp->fh, &resp->stat); 474 *p++ = htonl(resp->count); 475 xdr_ressize_check(rqstp, p); 476 477 /* now update rqstp->rq_res to reflect data as well */ 478 rqstp->rq_res.page_len = resp->count; 479 if (resp->count & 3) { 480 /* need to pad the tail */ 481 rqstp->rq_res.tail[0].iov_base = p; 482 *p = 0; 483 rqstp->rq_res.tail[0].iov_len = 4 - (resp->count&3); 484 } 485 return 1; 486 } 487 488 int 489 nfssvc_encode_readdirres(struct svc_rqst *rqstp, __be32 *p) 490 { 491 struct nfsd_readdirres *resp = rqstp->rq_resp; 492 493 xdr_ressize_check(rqstp, p); 494 p = resp->buffer; 495 *p++ = 0; /* no more entries */ 496 *p++ = htonl((resp->common.err == nfserr_eof)); 497 rqstp->rq_res.page_len = (((unsigned long)p-1) & ~PAGE_MASK)+1; 498 499 return 1; 500 } 501 502 int 503 nfssvc_encode_statfsres(struct svc_rqst *rqstp, __be32 *p) 504 { 505 struct nfsd_statfsres *resp = rqstp->rq_resp; 506 struct kstatfs *stat = &resp->stats; 507 508 *p++ = htonl(NFSSVC_MAXBLKSIZE_V2); /* max transfer size */ 509 *p++ = htonl(stat->f_bsize); 510 *p++ = htonl(stat->f_blocks); 511 *p++ = htonl(stat->f_bfree); 512 *p++ = htonl(stat->f_bavail); 513 return xdr_ressize_check(rqstp, p); 514 } 515 516 int 517 nfssvc_encode_entry(void *ccdv, const char *name, 518 int namlen, loff_t offset, u64 ino, unsigned int d_type) 519 { 520 struct readdir_cd *ccd = ccdv; 521 struct nfsd_readdirres *cd = container_of(ccd, struct nfsd_readdirres, common); 522 __be32 *p = cd->buffer; 523 int buflen, slen; 524 525 /* 526 dprintk("nfsd: entry(%.*s off %ld ino %ld)\n", 527 namlen, name, offset, ino); 528 */ 529 530 if (offset > ~((u32) 0)) { 531 cd->common.err = nfserr_fbig; 532 return -EINVAL; 533 } 534 if (cd->offset) 535 *cd->offset = htonl(offset); 536 537 /* truncate filename */ 538 namlen = min(namlen, NFS2_MAXNAMLEN); 539 slen = XDR_QUADLEN(namlen); 540 541 if ((buflen = cd->buflen - slen - 4) < 0) { 542 cd->common.err = nfserr_toosmall; 543 return -EINVAL; 544 } 545 if (ino > ~((u32) 0)) { 546 cd->common.err = nfserr_fbig; 547 return -EINVAL; 548 } 549 *p++ = xdr_one; /* mark entry present */ 550 *p++ = htonl((u32) ino); /* file id */ 551 p = xdr_encode_array(p, name, namlen);/* name length & name */ 552 cd->offset = p; /* remember pointer */ 553 *p++ = htonl(~0U); /* offset of next entry */ 554 555 cd->buflen = buflen; 556 cd->buffer = p; 557 cd->common.err = nfs_ok; 558 return 0; 559 } 560 561 /* 562 * XDR release functions 563 */ 564 void 565 nfssvc_release_fhandle(struct svc_rqst *rqstp) 566 { 567 struct nfsd_fhandle *resp = rqstp->rq_resp; 568 569 fh_put(&resp->fh); 570 } 571