1d2912cb1SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 2e9be9d5eSMiklos Szeredi /* 3e9be9d5eSMiklos Szeredi * 4e9be9d5eSMiklos Szeredi * Copyright (C) 2011 Novell Inc. 5e9be9d5eSMiklos Szeredi */ 6e9be9d5eSMiklos Szeredi 75b825c3aSIngo Molnar #include <uapi/linux/magic.h> 8e9be9d5eSMiklos Szeredi #include <linux/fs.h> 9e9be9d5eSMiklos Szeredi #include <linux/namei.h> 10e9be9d5eSMiklos Szeredi #include <linux/xattr.h> 11e9be9d5eSMiklos Szeredi #include <linux/mount.h> 12e9be9d5eSMiklos Szeredi #include <linux/parser.h> 13e9be9d5eSMiklos Szeredi #include <linux/module.h> 14cc259639SAndy Whitcroft #include <linux/statfs.h> 15f45827e8SErez Zadok #include <linux/seq_file.h> 16d837a49bSMiklos Szeredi #include <linux/posix_acl_xattr.h> 17e487d889SAmir Goldstein #include <linux/exportfs.h> 182b1a7746SMiklos Szeredi #include <linux/file.h> 19e9be9d5eSMiklos Szeredi #include "overlayfs.h" 20e9be9d5eSMiklos Szeredi 21e9be9d5eSMiklos Szeredi MODULE_AUTHOR("Miklos Szeredi <miklos@szeredi.hu>"); 22e9be9d5eSMiklos Szeredi MODULE_DESCRIPTION("Overlay filesystem"); 23e9be9d5eSMiklos Szeredi MODULE_LICENSE("GPL"); 24e9be9d5eSMiklos Szeredi 25e9be9d5eSMiklos Szeredi 26e9be9d5eSMiklos Szeredi struct ovl_dir_cache; 27e9be9d5eSMiklos Szeredi 28a78d9f0dSMiklos Szeredi #define OVL_MAX_STACK 500 29a78d9f0dSMiklos Szeredi 30688ea0e5SMiklos Szeredi static bool ovl_redirect_dir_def = IS_ENABLED(CONFIG_OVERLAY_FS_REDIRECT_DIR); 31688ea0e5SMiklos Szeredi module_param_named(redirect_dir, ovl_redirect_dir_def, bool, 0644); 32253e7483SNicolas Schier MODULE_PARM_DESC(redirect_dir, 33688ea0e5SMiklos Szeredi "Default to on or off for the redirect_dir feature"); 34e9be9d5eSMiklos Szeredi 35438c84c2SMiklos Szeredi static bool ovl_redirect_always_follow = 36438c84c2SMiklos Szeredi IS_ENABLED(CONFIG_OVERLAY_FS_REDIRECT_ALWAYS_FOLLOW); 37438c84c2SMiklos Szeredi module_param_named(redirect_always_follow, ovl_redirect_always_follow, 38438c84c2SMiklos Szeredi bool, 0644); 39253e7483SNicolas Schier MODULE_PARM_DESC(redirect_always_follow, 40438c84c2SMiklos Szeredi "Follow redirects even if redirect_dir feature is turned off"); 41438c84c2SMiklos Szeredi 4202bcd157SAmir Goldstein static bool ovl_index_def = IS_ENABLED(CONFIG_OVERLAY_FS_INDEX); 4302bcd157SAmir Goldstein module_param_named(index, ovl_index_def, bool, 0644); 44253e7483SNicolas Schier MODULE_PARM_DESC(index, 4502bcd157SAmir Goldstein "Default to on or off for the inodes index feature"); 4602bcd157SAmir Goldstein 47f168f109SAmir Goldstein static bool ovl_nfs_export_def = IS_ENABLED(CONFIG_OVERLAY_FS_NFS_EXPORT); 48f168f109SAmir Goldstein module_param_named(nfs_export, ovl_nfs_export_def, bool, 0644); 49253e7483SNicolas Schier MODULE_PARM_DESC(nfs_export, 50f168f109SAmir Goldstein "Default to on or off for the NFS export feature"); 51f168f109SAmir Goldstein 52795939a9SAmir Goldstein static bool ovl_xino_auto_def = IS_ENABLED(CONFIG_OVERLAY_FS_XINO_AUTO); 53795939a9SAmir Goldstein module_param_named(xino_auto, ovl_xino_auto_def, bool, 0644); 54253e7483SNicolas Schier MODULE_PARM_DESC(xino_auto, 55795939a9SAmir Goldstein "Auto enable xino feature"); 56795939a9SAmir Goldstein 57d5791044SVivek Goyal static bool ovl_metacopy_def = IS_ENABLED(CONFIG_OVERLAY_FS_METACOPY); 58d5791044SVivek Goyal module_param_named(metacopy, ovl_metacopy_def, bool, 0644); 59253e7483SNicolas Schier MODULE_PARM_DESC(metacopy, 60d5791044SVivek Goyal "Default to on or off for the metadata only copy up feature"); 61d5791044SVivek Goyal 62e9be9d5eSMiklos Szeredi static void ovl_dentry_release(struct dentry *dentry) 63e9be9d5eSMiklos Szeredi { 64e9be9d5eSMiklos Szeredi struct ovl_entry *oe = dentry->d_fsdata; 65e9be9d5eSMiklos Szeredi 66e9be9d5eSMiklos Szeredi if (oe) { 67*163db0daSAmir Goldstein ovl_stack_put(ovl_lowerstack(oe), ovl_numlower(oe)); 68e9be9d5eSMiklos Szeredi kfree_rcu(oe, rcu); 69e9be9d5eSMiklos Szeredi } 70e9be9d5eSMiklos Szeredi } 71e9be9d5eSMiklos Szeredi 722d902671SMiklos Szeredi static struct dentry *ovl_d_real(struct dentry *dentry, 73fb16043bSMiklos Szeredi const struct inode *inode) 74d101a125SMiklos Szeredi { 75cef4cbffSMiklos Szeredi struct dentry *real = NULL, *lower; 76d101a125SMiklos Szeredi 77e8c985baSMiklos Szeredi /* It's an overlay file */ 78e8c985baSMiklos Szeredi if (inode && d_inode(dentry) == inode) 79e8c985baSMiklos Szeredi return dentry; 80e8c985baSMiklos Szeredi 81ca4c8a3aSMiklos Szeredi if (!d_is_reg(dentry)) { 82d101a125SMiklos Szeredi if (!inode || inode == d_inode(dentry)) 83d101a125SMiklos Szeredi return dentry; 84d101a125SMiklos Szeredi goto bug; 85d101a125SMiklos Szeredi } 86d101a125SMiklos Szeredi 87d101a125SMiklos Szeredi real = ovl_dentry_upper(dentry); 882c3d7358SVivek Goyal if (real && (inode == d_inode(real))) 89d101a125SMiklos Szeredi return real; 90d101a125SMiklos Szeredi 912c3d7358SVivek Goyal if (real && !inode && ovl_has_upperdata(d_inode(dentry))) 922c3d7358SVivek Goyal return real; 932c3d7358SVivek Goyal 94cef4cbffSMiklos Szeredi lower = ovl_dentry_lowerdata(dentry); 95cef4cbffSMiklos Szeredi if (!lower) 96d101a125SMiklos Szeredi goto bug; 97cef4cbffSMiklos Szeredi real = lower; 98d101a125SMiklos Szeredi 99c4fcfc16SMiklos Szeredi /* Handle recursion */ 100fb16043bSMiklos Szeredi real = d_real(real, inode); 101c4fcfc16SMiklos Szeredi 102d101a125SMiklos Szeredi if (!inode || inode == d_inode(real)) 103d101a125SMiklos Szeredi return real; 104d101a125SMiklos Szeredi bug: 105cef4cbffSMiklos Szeredi WARN(1, "%s(%pd4, %s:%lu): real dentry (%p/%lu) not found\n", 106cef4cbffSMiklos Szeredi __func__, dentry, inode ? inode->i_sb->s_id : "NULL", 107cef4cbffSMiklos Szeredi inode ? inode->i_ino : 0, real, 108cef4cbffSMiklos Szeredi real && d_inode(real) ? d_inode(real)->i_ino : 0); 109d101a125SMiklos Szeredi return dentry; 110d101a125SMiklos Szeredi } 111d101a125SMiklos Szeredi 1123bb7df92SMiklos Szeredi static int ovl_revalidate_real(struct dentry *d, unsigned int flags, bool weak) 1133bb7df92SMiklos Szeredi { 1143bb7df92SMiklos Szeredi int ret = 1; 1153bb7df92SMiklos Szeredi 1163bb7df92SMiklos Szeredi if (weak) { 1173bb7df92SMiklos Szeredi if (d->d_flags & DCACHE_OP_WEAK_REVALIDATE) 1183bb7df92SMiklos Szeredi ret = d->d_op->d_weak_revalidate(d, flags); 1193bb7df92SMiklos Szeredi } else if (d->d_flags & DCACHE_OP_REVALIDATE) { 1203bb7df92SMiklos Szeredi ret = d->d_op->d_revalidate(d, flags); 1213bb7df92SMiklos Szeredi if (!ret) { 1223bb7df92SMiklos Szeredi if (!(flags & LOOKUP_RCU)) 1233bb7df92SMiklos Szeredi d_invalidate(d); 1243bb7df92SMiklos Szeredi ret = -ESTALE; 1253bb7df92SMiklos Szeredi } 1263bb7df92SMiklos Szeredi } 1273bb7df92SMiklos Szeredi return ret; 1283bb7df92SMiklos Szeredi } 1293bb7df92SMiklos Szeredi 1303bb7df92SMiklos Szeredi static int ovl_dentry_revalidate_common(struct dentry *dentry, 1313bb7df92SMiklos Szeredi unsigned int flags, bool weak) 1327c03b5d4SMiklos Szeredi { 133a6ff2bc0SAmir Goldstein struct ovl_entry *oe = OVL_E(dentry); 1345522c9c7SAmir Goldstein struct ovl_path *lowerstack = ovl_lowerstack(oe); 135672e4268SChen Zhongjin struct inode *inode = d_inode_rcu(dentry); 136bccece1eSMiklos Szeredi struct dentry *upper; 1377c03b5d4SMiklos Szeredi unsigned int i; 1387c03b5d4SMiklos Szeredi int ret = 1; 1397c03b5d4SMiklos Szeredi 140672e4268SChen Zhongjin /* Careful in RCU mode */ 141672e4268SChen Zhongjin if (!inode) 142672e4268SChen Zhongjin return -ECHILD; 143672e4268SChen Zhongjin 144672e4268SChen Zhongjin upper = ovl_i_dentry_upper(inode); 145bccece1eSMiklos Szeredi if (upper) 146bccece1eSMiklos Szeredi ret = ovl_revalidate_real(upper, flags, weak); 147bccece1eSMiklos Szeredi 1485522c9c7SAmir Goldstein for (i = 0; ret > 0 && i < ovl_numlower(oe); i++) 1495522c9c7SAmir Goldstein ret = ovl_revalidate_real(lowerstack[i].dentry, flags, weak); 1505522c9c7SAmir Goldstein 1517c03b5d4SMiklos Szeredi return ret; 1527c03b5d4SMiklos Szeredi } 1533bb7df92SMiklos Szeredi 1543bb7df92SMiklos Szeredi static int ovl_dentry_revalidate(struct dentry *dentry, unsigned int flags) 1553bb7df92SMiklos Szeredi { 1563bb7df92SMiklos Szeredi return ovl_dentry_revalidate_common(dentry, flags, false); 1577c03b5d4SMiklos Szeredi } 1587c03b5d4SMiklos Szeredi 1597c03b5d4SMiklos Szeredi static int ovl_dentry_weak_revalidate(struct dentry *dentry, unsigned int flags) 1607c03b5d4SMiklos Szeredi { 1613bb7df92SMiklos Szeredi return ovl_dentry_revalidate_common(dentry, flags, true); 1627c03b5d4SMiklos Szeredi } 1637c03b5d4SMiklos Szeredi 164e9be9d5eSMiklos Szeredi static const struct dentry_operations ovl_dentry_operations = { 165e9be9d5eSMiklos Szeredi .d_release = ovl_dentry_release, 166d101a125SMiklos Szeredi .d_real = ovl_d_real, 1677c03b5d4SMiklos Szeredi .d_revalidate = ovl_dentry_revalidate, 1687c03b5d4SMiklos Szeredi .d_weak_revalidate = ovl_dentry_weak_revalidate, 1697c03b5d4SMiklos Szeredi }; 1707c03b5d4SMiklos Szeredi 17113cf199dSAmir Goldstein static struct kmem_cache *ovl_inode_cachep; 17213cf199dSAmir Goldstein 17313cf199dSAmir Goldstein static struct inode *ovl_alloc_inode(struct super_block *sb) 17413cf199dSAmir Goldstein { 175fd60b288SMuchun Song struct ovl_inode *oi = alloc_inode_sb(sb, ovl_inode_cachep, GFP_KERNEL); 17613cf199dSAmir Goldstein 177b3885bd6SHirofumi Nakagawa if (!oi) 178b3885bd6SHirofumi Nakagawa return NULL; 179b3885bd6SHirofumi Nakagawa 18004a01ac7SMiklos Szeredi oi->cache = NULL; 181cf31c463SMiklos Szeredi oi->redirect = NULL; 18204a01ac7SMiklos Szeredi oi->version = 0; 18313c72075SMiklos Szeredi oi->flags = 0; 18409d8b586SMiklos Szeredi oi->__upperdentry = NULL; 185ffa5723cSAmir Goldstein oi->lowerpath.dentry = NULL; 186ffa5723cSAmir Goldstein oi->lowerpath.layer = NULL; 1872664bd08SVivek Goyal oi->lowerdata = NULL; 188a015dafcSAmir Goldstein mutex_init(&oi->lock); 18925b7713aSMiklos Szeredi 19013cf199dSAmir Goldstein return &oi->vfs_inode; 19113cf199dSAmir Goldstein } 19213cf199dSAmir Goldstein 1930b269dedSAl Viro static void ovl_free_inode(struct inode *inode) 19413cf199dSAmir Goldstein { 1950b269dedSAl Viro struct ovl_inode *oi = OVL_I(inode); 19613cf199dSAmir Goldstein 1970b269dedSAl Viro kfree(oi->redirect); 1980b269dedSAl Viro mutex_destroy(&oi->lock); 1990b269dedSAl Viro kmem_cache_free(ovl_inode_cachep, oi); 20013cf199dSAmir Goldstein } 20113cf199dSAmir Goldstein 20213cf199dSAmir Goldstein static void ovl_destroy_inode(struct inode *inode) 20313cf199dSAmir Goldstein { 20409d8b586SMiklos Szeredi struct ovl_inode *oi = OVL_I(inode); 20509d8b586SMiklos Szeredi 20609d8b586SMiklos Szeredi dput(oi->__upperdentry); 207ffa5723cSAmir Goldstein dput(oi->lowerpath.dentry); 2082664bd08SVivek Goyal if (S_ISDIR(inode->i_mode)) 2094edb83bbSMiklos Szeredi ovl_dir_cache_free(inode); 2102664bd08SVivek Goyal else 2112664bd08SVivek Goyal iput(oi->lowerdata); 21213cf199dSAmir Goldstein } 21313cf199dSAmir Goldstein 214ad204488SMiklos Szeredi static void ovl_free_fs(struct ovl_fs *ofs) 215e9be9d5eSMiklos Szeredi { 216df820f8dSMiklos Szeredi struct vfsmount **mounts; 217dd662667SMiklos Szeredi unsigned i; 218e9be9d5eSMiklos Szeredi 2190be0bfd2SAmir Goldstein iput(ofs->workbasedir_trap); 220146d62e5SAmir Goldstein iput(ofs->indexdir_trap); 221146d62e5SAmir Goldstein iput(ofs->workdir_trap); 222c21c839bSChengguang Xu dput(ofs->whiteout); 223ad204488SMiklos Szeredi dput(ofs->indexdir); 224ad204488SMiklos Szeredi dput(ofs->workdir); 225ad204488SMiklos Szeredi if (ofs->workdir_locked) 226ad204488SMiklos Szeredi ovl_inuse_unlock(ofs->workbasedir); 227ad204488SMiklos Szeredi dput(ofs->workbasedir); 228ad204488SMiklos Szeredi if (ofs->upperdir_locked) 22908f4c7c8SMiklos Szeredi ovl_inuse_unlock(ovl_upper_mnt(ofs)->mnt_root); 230df820f8dSMiklos Szeredi 231df820f8dSMiklos Szeredi /* Hack! Reuse ofs->layers as a vfsmount array before freeing it */ 232df820f8dSMiklos Szeredi mounts = (struct vfsmount **) ofs->layers; 233b8e42a65SMiklos Szeredi for (i = 0; i < ofs->numlayer; i++) { 23494375f9dSAmir Goldstein iput(ofs->layers[i].trap); 235df820f8dSMiklos Szeredi mounts[i] = ofs->layers[i].mnt; 236146d62e5SAmir Goldstein } 237df820f8dSMiklos Szeredi kern_unmount_array(mounts, ofs->numlayer); 23894375f9dSAmir Goldstein kfree(ofs->layers); 239b7bf9908SAmir Goldstein for (i = 0; i < ofs->numfs; i++) 24007f1e596SAmir Goldstein free_anon_bdev(ofs->fs[i].pseudo_dev); 24107f1e596SAmir Goldstein kfree(ofs->fs); 242e9be9d5eSMiklos Szeredi 243ad204488SMiklos Szeredi kfree(ofs->config.lowerdir); 244ad204488SMiklos Szeredi kfree(ofs->config.upperdir); 245ad204488SMiklos Szeredi kfree(ofs->config.workdir); 246438c84c2SMiklos Szeredi kfree(ofs->config.redirect_mode); 247ad204488SMiklos Szeredi if (ofs->creator_cred) 248ad204488SMiklos Szeredi put_cred(ofs->creator_cred); 249ad204488SMiklos Szeredi kfree(ofs); 250e9be9d5eSMiklos Szeredi } 251e9be9d5eSMiklos Szeredi 252a9075cdbSMiklos Szeredi static void ovl_put_super(struct super_block *sb) 253a9075cdbSMiklos Szeredi { 254a9075cdbSMiklos Szeredi struct ovl_fs *ofs = sb->s_fs_info; 255a9075cdbSMiklos Szeredi 256a9075cdbSMiklos Szeredi ovl_free_fs(ofs); 257a9075cdbSMiklos Szeredi } 258a9075cdbSMiklos Szeredi 259e8d4bfe3SChengguang Xu /* Sync real dirty inodes in upper filesystem (if it exists) */ 260e593b2bfSAmir Goldstein static int ovl_sync_fs(struct super_block *sb, int wait) 261e593b2bfSAmir Goldstein { 262ad204488SMiklos Szeredi struct ovl_fs *ofs = sb->s_fs_info; 263e593b2bfSAmir Goldstein struct super_block *upper_sb; 264e593b2bfSAmir Goldstein int ret; 265e593b2bfSAmir Goldstein 266335d3fc5SSargun Dhillon ret = ovl_sync_status(ofs); 267335d3fc5SSargun Dhillon /* 268335d3fc5SSargun Dhillon * We have to always set the err, because the return value isn't 269335d3fc5SSargun Dhillon * checked in syncfs, and instead indirectly return an error via 270335d3fc5SSargun Dhillon * the sb's writeback errseq, which VFS inspects after this call. 271335d3fc5SSargun Dhillon */ 272335d3fc5SSargun Dhillon if (ret < 0) { 273335d3fc5SSargun Dhillon errseq_set(&sb->s_wb_err, -EIO); 274335d3fc5SSargun Dhillon return -EIO; 275335d3fc5SSargun Dhillon } 276e8d4bfe3SChengguang Xu 277335d3fc5SSargun Dhillon if (!ret) 278335d3fc5SSargun Dhillon return ret; 279335d3fc5SSargun Dhillon 280e8d4bfe3SChengguang Xu /* 28132b1924bSKonstantin Khlebnikov * Not called for sync(2) call or an emergency sync (SB_I_SKIP_SYNC). 28232b1924bSKonstantin Khlebnikov * All the super blocks will be iterated, including upper_sb. 283e8d4bfe3SChengguang Xu * 284e8d4bfe3SChengguang Xu * If this is a syncfs(2) call, then we do need to call 285e8d4bfe3SChengguang Xu * sync_filesystem() on upper_sb, but enough if we do it when being 286e8d4bfe3SChengguang Xu * called with wait == 1. 287e8d4bfe3SChengguang Xu */ 288e8d4bfe3SChengguang Xu if (!wait) 289e593b2bfSAmir Goldstein return 0; 290e593b2bfSAmir Goldstein 29108f4c7c8SMiklos Szeredi upper_sb = ovl_upper_mnt(ofs)->mnt_sb; 292e8d4bfe3SChengguang Xu 293e593b2bfSAmir Goldstein down_read(&upper_sb->s_umount); 294e8d4bfe3SChengguang Xu ret = sync_filesystem(upper_sb); 295e593b2bfSAmir Goldstein up_read(&upper_sb->s_umount); 296e8d4bfe3SChengguang Xu 297e593b2bfSAmir Goldstein return ret; 298e593b2bfSAmir Goldstein } 299e593b2bfSAmir Goldstein 300cc259639SAndy Whitcroft /** 301cc259639SAndy Whitcroft * ovl_statfs 3029c5dd803SYang Li * @dentry: The dentry to query 303cc259639SAndy Whitcroft * @buf: The struct kstatfs to fill in with stats 304cc259639SAndy Whitcroft * 305cc259639SAndy Whitcroft * Get the filesystem statistics. As writes always target the upper layer 3064ebc5818SMiklos Szeredi * filesystem pass the statfs to the upper filesystem (if it exists) 307cc259639SAndy Whitcroft */ 308cc259639SAndy Whitcroft static int ovl_statfs(struct dentry *dentry, struct kstatfs *buf) 309cc259639SAndy Whitcroft { 310cc259639SAndy Whitcroft struct ovl_fs *ofs = dentry->d_sb->s_fs_info; 311cc259639SAndy Whitcroft struct dentry *root_dentry = dentry->d_sb->s_root; 312cc259639SAndy Whitcroft struct path path; 313cc259639SAndy Whitcroft int err; 314cc259639SAndy Whitcroft 3154ebc5818SMiklos Szeredi ovl_path_real(root_dentry, &path); 316cc259639SAndy Whitcroft 317cc259639SAndy Whitcroft err = vfs_statfs(&path, buf); 318cc259639SAndy Whitcroft if (!err) { 3196b2d5fe4SMiklos Szeredi buf->f_namelen = ofs->namelen; 320cc259639SAndy Whitcroft buf->f_type = OVERLAYFS_SUPER_MAGIC; 321cc259639SAndy Whitcroft } 322cc259639SAndy Whitcroft 323cc259639SAndy Whitcroft return err; 324cc259639SAndy Whitcroft } 325cc259639SAndy Whitcroft 32602bcd157SAmir Goldstein /* Will this overlay be forced to mount/remount ro? */ 327ad204488SMiklos Szeredi static bool ovl_force_readonly(struct ovl_fs *ofs) 32802bcd157SAmir Goldstein { 32908f4c7c8SMiklos Szeredi return (!ovl_upper_mnt(ofs) || !ofs->workdir); 33002bcd157SAmir Goldstein } 33102bcd157SAmir Goldstein 332438c84c2SMiklos Szeredi static const char *ovl_redirect_mode_def(void) 333438c84c2SMiklos Szeredi { 334438c84c2SMiklos Szeredi return ovl_redirect_dir_def ? "on" : "off"; 335438c84c2SMiklos Szeredi } 336438c84c2SMiklos Szeredi 337795939a9SAmir Goldstein static const char * const ovl_xino_str[] = { 338795939a9SAmir Goldstein "off", 339795939a9SAmir Goldstein "auto", 340795939a9SAmir Goldstein "on", 341795939a9SAmir Goldstein }; 342795939a9SAmir Goldstein 343795939a9SAmir Goldstein static inline int ovl_xino_def(void) 344795939a9SAmir Goldstein { 345795939a9SAmir Goldstein return ovl_xino_auto_def ? OVL_XINO_AUTO : OVL_XINO_OFF; 346795939a9SAmir Goldstein } 347795939a9SAmir Goldstein 348f45827e8SErez Zadok /** 349f45827e8SErez Zadok * ovl_show_options 3509c5dd803SYang Li * @m: the seq_file handle 3519c5dd803SYang Li * @dentry: The dentry to query 352f45827e8SErez Zadok * 353f45827e8SErez Zadok * Prints the mount options for a given superblock. 354f45827e8SErez Zadok * Returns zero; does not fail. 355f45827e8SErez Zadok */ 356f45827e8SErez Zadok static int ovl_show_options(struct seq_file *m, struct dentry *dentry) 357f45827e8SErez Zadok { 358f45827e8SErez Zadok struct super_block *sb = dentry->d_sb; 359ad204488SMiklos Szeredi struct ovl_fs *ofs = sb->s_fs_info; 360f45827e8SErez Zadok 361ad204488SMiklos Szeredi seq_show_option(m, "lowerdir", ofs->config.lowerdir); 362ad204488SMiklos Szeredi if (ofs->config.upperdir) { 363ad204488SMiklos Szeredi seq_show_option(m, "upperdir", ofs->config.upperdir); 364ad204488SMiklos Szeredi seq_show_option(m, "workdir", ofs->config.workdir); 36553a08cb9SMiklos Szeredi } 366ad204488SMiklos Szeredi if (ofs->config.default_permissions) 3678d3095f4SMiklos Szeredi seq_puts(m, ",default_permissions"); 368438c84c2SMiklos Szeredi if (strcmp(ofs->config.redirect_mode, ovl_redirect_mode_def()) != 0) 369438c84c2SMiklos Szeredi seq_printf(m, ",redirect_dir=%s", ofs->config.redirect_mode); 370ad204488SMiklos Szeredi if (ofs->config.index != ovl_index_def) 371438c84c2SMiklos Szeredi seq_printf(m, ",index=%s", ofs->config.index ? "on" : "off"); 3725830fb6bSPavel Tikhomirov if (!ofs->config.uuid) 3735830fb6bSPavel Tikhomirov seq_puts(m, ",uuid=off"); 374f168f109SAmir Goldstein if (ofs->config.nfs_export != ovl_nfs_export_def) 375f168f109SAmir Goldstein seq_printf(m, ",nfs_export=%s", ofs->config.nfs_export ? 376f168f109SAmir Goldstein "on" : "off"); 3770f831ec8SAmir Goldstein if (ofs->config.xino != ovl_xino_def() && !ovl_same_fs(sb)) 378795939a9SAmir Goldstein seq_printf(m, ",xino=%s", ovl_xino_str[ofs->config.xino]); 379d5791044SVivek Goyal if (ofs->config.metacopy != ovl_metacopy_def) 380d5791044SVivek Goyal seq_printf(m, ",metacopy=%s", 381d5791044SVivek Goyal ofs->config.metacopy ? "on" : "off"); 382c86243b0SVivek Goyal if (ofs->config.ovl_volatile) 383c86243b0SVivek Goyal seq_puts(m, ",volatile"); 384321b46b9SGiuseppe Scrivano if (ofs->config.userxattr) 385321b46b9SGiuseppe Scrivano seq_puts(m, ",userxattr"); 386f45827e8SErez Zadok return 0; 387f45827e8SErez Zadok } 388f45827e8SErez Zadok 3893cdf6fe9SSeunghun Lee static int ovl_remount(struct super_block *sb, int *flags, char *data) 3903cdf6fe9SSeunghun Lee { 391ad204488SMiklos Szeredi struct ovl_fs *ofs = sb->s_fs_info; 392399c109dSChengguang Xu struct super_block *upper_sb; 393399c109dSChengguang Xu int ret = 0; 3943cdf6fe9SSeunghun Lee 3951751e8a6SLinus Torvalds if (!(*flags & SB_RDONLY) && ovl_force_readonly(ofs)) 3963cdf6fe9SSeunghun Lee return -EROFS; 3973cdf6fe9SSeunghun Lee 398399c109dSChengguang Xu if (*flags & SB_RDONLY && !sb_rdonly(sb)) { 39908f4c7c8SMiklos Szeredi upper_sb = ovl_upper_mnt(ofs)->mnt_sb; 400c86243b0SVivek Goyal if (ovl_should_sync(ofs)) { 401399c109dSChengguang Xu down_read(&upper_sb->s_umount); 402399c109dSChengguang Xu ret = sync_filesystem(upper_sb); 403399c109dSChengguang Xu up_read(&upper_sb->s_umount); 404399c109dSChengguang Xu } 405c86243b0SVivek Goyal } 406399c109dSChengguang Xu 407399c109dSChengguang Xu return ret; 4083cdf6fe9SSeunghun Lee } 4093cdf6fe9SSeunghun Lee 410e9be9d5eSMiklos Szeredi static const struct super_operations ovl_super_operations = { 41113cf199dSAmir Goldstein .alloc_inode = ovl_alloc_inode, 4120b269dedSAl Viro .free_inode = ovl_free_inode, 41313cf199dSAmir Goldstein .destroy_inode = ovl_destroy_inode, 41413cf199dSAmir Goldstein .drop_inode = generic_delete_inode, 415e9be9d5eSMiklos Szeredi .put_super = ovl_put_super, 416e593b2bfSAmir Goldstein .sync_fs = ovl_sync_fs, 417cc259639SAndy Whitcroft .statfs = ovl_statfs, 418f45827e8SErez Zadok .show_options = ovl_show_options, 4193cdf6fe9SSeunghun Lee .remount_fs = ovl_remount, 420e9be9d5eSMiklos Szeredi }; 421e9be9d5eSMiklos Szeredi 422e9be9d5eSMiklos Szeredi enum { 423e9be9d5eSMiklos Szeredi OPT_LOWERDIR, 424e9be9d5eSMiklos Szeredi OPT_UPPERDIR, 425e9be9d5eSMiklos Szeredi OPT_WORKDIR, 4268d3095f4SMiklos Szeredi OPT_DEFAULT_PERMISSIONS, 427438c84c2SMiklos Szeredi OPT_REDIRECT_DIR, 42802bcd157SAmir Goldstein OPT_INDEX_ON, 42902bcd157SAmir Goldstein OPT_INDEX_OFF, 4305830fb6bSPavel Tikhomirov OPT_UUID_ON, 4315830fb6bSPavel Tikhomirov OPT_UUID_OFF, 432f168f109SAmir Goldstein OPT_NFS_EXPORT_ON, 4332d2f2d73SMiklos Szeredi OPT_USERXATTR, 434f168f109SAmir Goldstein OPT_NFS_EXPORT_OFF, 435795939a9SAmir Goldstein OPT_XINO_ON, 436795939a9SAmir Goldstein OPT_XINO_OFF, 437795939a9SAmir Goldstein OPT_XINO_AUTO, 438d5791044SVivek Goyal OPT_METACOPY_ON, 439d5791044SVivek Goyal OPT_METACOPY_OFF, 440c86243b0SVivek Goyal OPT_VOLATILE, 441e9be9d5eSMiklos Szeredi OPT_ERR, 442e9be9d5eSMiklos Szeredi }; 443e9be9d5eSMiklos Szeredi 444e9be9d5eSMiklos Szeredi static const match_table_t ovl_tokens = { 445e9be9d5eSMiklos Szeredi {OPT_LOWERDIR, "lowerdir=%s"}, 446e9be9d5eSMiklos Szeredi {OPT_UPPERDIR, "upperdir=%s"}, 447e9be9d5eSMiklos Szeredi {OPT_WORKDIR, "workdir=%s"}, 4488d3095f4SMiklos Szeredi {OPT_DEFAULT_PERMISSIONS, "default_permissions"}, 449438c84c2SMiklos Szeredi {OPT_REDIRECT_DIR, "redirect_dir=%s"}, 45002bcd157SAmir Goldstein {OPT_INDEX_ON, "index=on"}, 45102bcd157SAmir Goldstein {OPT_INDEX_OFF, "index=off"}, 4522d2f2d73SMiklos Szeredi {OPT_USERXATTR, "userxattr"}, 4535830fb6bSPavel Tikhomirov {OPT_UUID_ON, "uuid=on"}, 4545830fb6bSPavel Tikhomirov {OPT_UUID_OFF, "uuid=off"}, 455f168f109SAmir Goldstein {OPT_NFS_EXPORT_ON, "nfs_export=on"}, 456f168f109SAmir Goldstein {OPT_NFS_EXPORT_OFF, "nfs_export=off"}, 457795939a9SAmir Goldstein {OPT_XINO_ON, "xino=on"}, 458795939a9SAmir Goldstein {OPT_XINO_OFF, "xino=off"}, 459795939a9SAmir Goldstein {OPT_XINO_AUTO, "xino=auto"}, 460d5791044SVivek Goyal {OPT_METACOPY_ON, "metacopy=on"}, 461d5791044SVivek Goyal {OPT_METACOPY_OFF, "metacopy=off"}, 462c86243b0SVivek Goyal {OPT_VOLATILE, "volatile"}, 463e9be9d5eSMiklos Szeredi {OPT_ERR, NULL} 464e9be9d5eSMiklos Szeredi }; 465e9be9d5eSMiklos Szeredi 46691c77947SMiklos Szeredi static char *ovl_next_opt(char **s) 46791c77947SMiklos Szeredi { 46891c77947SMiklos Szeredi char *sbegin = *s; 46991c77947SMiklos Szeredi char *p; 47091c77947SMiklos Szeredi 47191c77947SMiklos Szeredi if (sbegin == NULL) 47291c77947SMiklos Szeredi return NULL; 47391c77947SMiklos Szeredi 47491c77947SMiklos Szeredi for (p = sbegin; *p; p++) { 47591c77947SMiklos Szeredi if (*p == '\\') { 47691c77947SMiklos Szeredi p++; 47791c77947SMiklos Szeredi if (!*p) 47891c77947SMiklos Szeredi break; 47991c77947SMiklos Szeredi } else if (*p == ',') { 48091c77947SMiklos Szeredi *p = '\0'; 48191c77947SMiklos Szeredi *s = p + 1; 48291c77947SMiklos Szeredi return sbegin; 48391c77947SMiklos Szeredi } 48491c77947SMiklos Szeredi } 48591c77947SMiklos Szeredi *s = NULL; 48691c77947SMiklos Szeredi return sbegin; 48791c77947SMiklos Szeredi } 48891c77947SMiklos Szeredi 489438c84c2SMiklos Szeredi static int ovl_parse_redirect_mode(struct ovl_config *config, const char *mode) 490438c84c2SMiklos Szeredi { 491438c84c2SMiklos Szeredi if (strcmp(mode, "on") == 0) { 492438c84c2SMiklos Szeredi config->redirect_dir = true; 493438c84c2SMiklos Szeredi /* 494438c84c2SMiklos Szeredi * Does not make sense to have redirect creation without 495438c84c2SMiklos Szeredi * redirect following. 496438c84c2SMiklos Szeredi */ 497438c84c2SMiklos Szeredi config->redirect_follow = true; 498438c84c2SMiklos Szeredi } else if (strcmp(mode, "follow") == 0) { 499438c84c2SMiklos Szeredi config->redirect_follow = true; 500438c84c2SMiklos Szeredi } else if (strcmp(mode, "off") == 0) { 501438c84c2SMiklos Szeredi if (ovl_redirect_always_follow) 502438c84c2SMiklos Szeredi config->redirect_follow = true; 503438c84c2SMiklos Szeredi } else if (strcmp(mode, "nofollow") != 0) { 5041bd0a3aeSlijiazi pr_err("bad mount option \"redirect_dir=%s\"\n", 505438c84c2SMiklos Szeredi mode); 506438c84c2SMiklos Szeredi return -EINVAL; 507438c84c2SMiklos Szeredi } 508438c84c2SMiklos Szeredi 509438c84c2SMiklos Szeredi return 0; 510438c84c2SMiklos Szeredi } 511438c84c2SMiklos Szeredi 512e9be9d5eSMiklos Szeredi static int ovl_parse_opt(char *opt, struct ovl_config *config) 513e9be9d5eSMiklos Szeredi { 514e9be9d5eSMiklos Szeredi char *p; 515d5791044SVivek Goyal int err; 516d47748e5SMiklos Szeredi bool metacopy_opt = false, redirect_opt = false; 517b0def88dSAmir Goldstein bool nfs_export_opt = false, index_opt = false; 518e9be9d5eSMiklos Szeredi 519438c84c2SMiklos Szeredi config->redirect_mode = kstrdup(ovl_redirect_mode_def(), GFP_KERNEL); 520438c84c2SMiklos Szeredi if (!config->redirect_mode) 521438c84c2SMiklos Szeredi return -ENOMEM; 522438c84c2SMiklos Szeredi 52391c77947SMiklos Szeredi while ((p = ovl_next_opt(&opt)) != NULL) { 524e9be9d5eSMiklos Szeredi int token; 525e9be9d5eSMiklos Szeredi substring_t args[MAX_OPT_ARGS]; 526e9be9d5eSMiklos Szeredi 527e9be9d5eSMiklos Szeredi if (!*p) 528e9be9d5eSMiklos Szeredi continue; 529e9be9d5eSMiklos Szeredi 530e9be9d5eSMiklos Szeredi token = match_token(p, ovl_tokens, args); 531e9be9d5eSMiklos Szeredi switch (token) { 532e9be9d5eSMiklos Szeredi case OPT_UPPERDIR: 533e9be9d5eSMiklos Szeredi kfree(config->upperdir); 534e9be9d5eSMiklos Szeredi config->upperdir = match_strdup(&args[0]); 535e9be9d5eSMiklos Szeredi if (!config->upperdir) 536e9be9d5eSMiklos Szeredi return -ENOMEM; 537e9be9d5eSMiklos Szeredi break; 538e9be9d5eSMiklos Szeredi 539e9be9d5eSMiklos Szeredi case OPT_LOWERDIR: 540e9be9d5eSMiklos Szeredi kfree(config->lowerdir); 541e9be9d5eSMiklos Szeredi config->lowerdir = match_strdup(&args[0]); 542e9be9d5eSMiklos Szeredi if (!config->lowerdir) 543e9be9d5eSMiklos Szeredi return -ENOMEM; 544e9be9d5eSMiklos Szeredi break; 545e9be9d5eSMiklos Szeredi 546e9be9d5eSMiklos Szeredi case OPT_WORKDIR: 547e9be9d5eSMiklos Szeredi kfree(config->workdir); 548e9be9d5eSMiklos Szeredi config->workdir = match_strdup(&args[0]); 549e9be9d5eSMiklos Szeredi if (!config->workdir) 550e9be9d5eSMiklos Szeredi return -ENOMEM; 551e9be9d5eSMiklos Szeredi break; 552e9be9d5eSMiklos Szeredi 5538d3095f4SMiklos Szeredi case OPT_DEFAULT_PERMISSIONS: 5548d3095f4SMiklos Szeredi config->default_permissions = true; 5558d3095f4SMiklos Szeredi break; 5568d3095f4SMiklos Szeredi 557438c84c2SMiklos Szeredi case OPT_REDIRECT_DIR: 558438c84c2SMiklos Szeredi kfree(config->redirect_mode); 559438c84c2SMiklos Szeredi config->redirect_mode = match_strdup(&args[0]); 560438c84c2SMiklos Szeredi if (!config->redirect_mode) 561438c84c2SMiklos Szeredi return -ENOMEM; 562d47748e5SMiklos Szeredi redirect_opt = true; 563a6c60655SMiklos Szeredi break; 564a6c60655SMiklos Szeredi 56502bcd157SAmir Goldstein case OPT_INDEX_ON: 56602bcd157SAmir Goldstein config->index = true; 567b0def88dSAmir Goldstein index_opt = true; 56802bcd157SAmir Goldstein break; 56902bcd157SAmir Goldstein 57002bcd157SAmir Goldstein case OPT_INDEX_OFF: 57102bcd157SAmir Goldstein config->index = false; 572b0def88dSAmir Goldstein index_opt = true; 57302bcd157SAmir Goldstein break; 57402bcd157SAmir Goldstein 5755830fb6bSPavel Tikhomirov case OPT_UUID_ON: 5765830fb6bSPavel Tikhomirov config->uuid = true; 5775830fb6bSPavel Tikhomirov break; 5785830fb6bSPavel Tikhomirov 5795830fb6bSPavel Tikhomirov case OPT_UUID_OFF: 5805830fb6bSPavel Tikhomirov config->uuid = false; 5815830fb6bSPavel Tikhomirov break; 5825830fb6bSPavel Tikhomirov 583f168f109SAmir Goldstein case OPT_NFS_EXPORT_ON: 584f168f109SAmir Goldstein config->nfs_export = true; 585b0def88dSAmir Goldstein nfs_export_opt = true; 586f168f109SAmir Goldstein break; 587f168f109SAmir Goldstein 588f168f109SAmir Goldstein case OPT_NFS_EXPORT_OFF: 589f168f109SAmir Goldstein config->nfs_export = false; 590b0def88dSAmir Goldstein nfs_export_opt = true; 591f168f109SAmir Goldstein break; 592f168f109SAmir Goldstein 593795939a9SAmir Goldstein case OPT_XINO_ON: 594795939a9SAmir Goldstein config->xino = OVL_XINO_ON; 595795939a9SAmir Goldstein break; 596795939a9SAmir Goldstein 597795939a9SAmir Goldstein case OPT_XINO_OFF: 598795939a9SAmir Goldstein config->xino = OVL_XINO_OFF; 599795939a9SAmir Goldstein break; 600795939a9SAmir Goldstein 601795939a9SAmir Goldstein case OPT_XINO_AUTO: 602795939a9SAmir Goldstein config->xino = OVL_XINO_AUTO; 603795939a9SAmir Goldstein break; 604795939a9SAmir Goldstein 605d5791044SVivek Goyal case OPT_METACOPY_ON: 606d5791044SVivek Goyal config->metacopy = true; 607d47748e5SMiklos Szeredi metacopy_opt = true; 608d5791044SVivek Goyal break; 609d5791044SVivek Goyal 610d5791044SVivek Goyal case OPT_METACOPY_OFF: 611d5791044SVivek Goyal config->metacopy = false; 612b0def88dSAmir Goldstein metacopy_opt = true; 613d5791044SVivek Goyal break; 614d5791044SVivek Goyal 615c86243b0SVivek Goyal case OPT_VOLATILE: 616c86243b0SVivek Goyal config->ovl_volatile = true; 617c86243b0SVivek Goyal break; 618c86243b0SVivek Goyal 6192d2f2d73SMiklos Szeredi case OPT_USERXATTR: 6202d2f2d73SMiklos Szeredi config->userxattr = true; 6212d2f2d73SMiklos Szeredi break; 6222d2f2d73SMiklos Szeredi 623e9be9d5eSMiklos Szeredi default: 6241bd0a3aeSlijiazi pr_err("unrecognized mount option \"%s\" or missing value\n", 6251bd0a3aeSlijiazi p); 626e9be9d5eSMiklos Szeredi return -EINVAL; 627e9be9d5eSMiklos Szeredi } 628e9be9d5eSMiklos Szeredi } 62971cbad7eShujianyang 630f0e1266eSAmir Goldstein /* Workdir/index are useless in non-upper mount */ 631f0e1266eSAmir Goldstein if (!config->upperdir) { 632f0e1266eSAmir Goldstein if (config->workdir) { 6331bd0a3aeSlijiazi pr_info("option \"workdir=%s\" is useless in a non-upper mount, ignore\n", 63471cbad7eShujianyang config->workdir); 63571cbad7eShujianyang kfree(config->workdir); 63671cbad7eShujianyang config->workdir = NULL; 63771cbad7eShujianyang } 638f0e1266eSAmir Goldstein if (config->index && index_opt) { 639f0e1266eSAmir Goldstein pr_info("option \"index=on\" is useless in a non-upper mount, ignore\n"); 640f0e1266eSAmir Goldstein index_opt = false; 641f0e1266eSAmir Goldstein } 642f0e1266eSAmir Goldstein config->index = false; 643f0e1266eSAmir Goldstein } 64471cbad7eShujianyang 645c86243b0SVivek Goyal if (!config->upperdir && config->ovl_volatile) { 646c86243b0SVivek Goyal pr_info("option \"volatile\" is meaningless in a non-upper mount, ignoring it.\n"); 647c86243b0SVivek Goyal config->ovl_volatile = false; 648c86243b0SVivek Goyal } 649c86243b0SVivek Goyal 650d5791044SVivek Goyal err = ovl_parse_redirect_mode(config, config->redirect_mode); 651d5791044SVivek Goyal if (err) 652d5791044SVivek Goyal return err; 653d5791044SVivek Goyal 654d47748e5SMiklos Szeredi /* 655d47748e5SMiklos Szeredi * This is to make the logic below simpler. It doesn't make any other 656d47748e5SMiklos Szeredi * difference, since config->redirect_dir is only used for upper. 657d47748e5SMiklos Szeredi */ 658d47748e5SMiklos Szeredi if (!config->upperdir && config->redirect_follow) 659d47748e5SMiklos Szeredi config->redirect_dir = true; 660d47748e5SMiklos Szeredi 661d47748e5SMiklos Szeredi /* Resolve metacopy -> redirect_dir dependency */ 662d47748e5SMiklos Szeredi if (config->metacopy && !config->redirect_dir) { 663d47748e5SMiklos Szeredi if (metacopy_opt && redirect_opt) { 6641bd0a3aeSlijiazi pr_err("conflicting options: metacopy=on,redirect_dir=%s\n", 665d47748e5SMiklos Szeredi config->redirect_mode); 666d47748e5SMiklos Szeredi return -EINVAL; 667d47748e5SMiklos Szeredi } 668d47748e5SMiklos Szeredi if (redirect_opt) { 669d47748e5SMiklos Szeredi /* 670d47748e5SMiklos Szeredi * There was an explicit redirect_dir=... that resulted 671d47748e5SMiklos Szeredi * in this conflict. 672d47748e5SMiklos Szeredi */ 6731bd0a3aeSlijiazi pr_info("disabling metacopy due to redirect_dir=%s\n", 674d47748e5SMiklos Szeredi config->redirect_mode); 675d5791044SVivek Goyal config->metacopy = false; 676d47748e5SMiklos Szeredi } else { 677d47748e5SMiklos Szeredi /* Automatically enable redirect otherwise. */ 678d47748e5SMiklos Szeredi config->redirect_follow = config->redirect_dir = true; 679d47748e5SMiklos Szeredi } 680d5791044SVivek Goyal } 681d5791044SVivek Goyal 682b0def88dSAmir Goldstein /* Resolve nfs_export -> index dependency */ 683b0def88dSAmir Goldstein if (config->nfs_export && !config->index) { 684f0e1266eSAmir Goldstein if (!config->upperdir && config->redirect_follow) { 685f0e1266eSAmir Goldstein pr_info("NFS export requires \"redirect_dir=nofollow\" on non-upper mount, falling back to nfs_export=off.\n"); 686f0e1266eSAmir Goldstein config->nfs_export = false; 687f0e1266eSAmir Goldstein } else if (nfs_export_opt && index_opt) { 688b0def88dSAmir Goldstein pr_err("conflicting options: nfs_export=on,index=off\n"); 689b0def88dSAmir Goldstein return -EINVAL; 690f0e1266eSAmir Goldstein } else if (index_opt) { 691b0def88dSAmir Goldstein /* 692b0def88dSAmir Goldstein * There was an explicit index=off that resulted 693b0def88dSAmir Goldstein * in this conflict. 694b0def88dSAmir Goldstein */ 695b0def88dSAmir Goldstein pr_info("disabling nfs_export due to index=off\n"); 696b0def88dSAmir Goldstein config->nfs_export = false; 697b0def88dSAmir Goldstein } else { 698b0def88dSAmir Goldstein /* Automatically enable index otherwise. */ 699b0def88dSAmir Goldstein config->index = true; 700b0def88dSAmir Goldstein } 701b0def88dSAmir Goldstein } 702b0def88dSAmir Goldstein 703b0def88dSAmir Goldstein /* Resolve nfs_export -> !metacopy dependency */ 704b0def88dSAmir Goldstein if (config->nfs_export && config->metacopy) { 705b0def88dSAmir Goldstein if (nfs_export_opt && metacopy_opt) { 706b0def88dSAmir Goldstein pr_err("conflicting options: nfs_export=on,metacopy=on\n"); 707b0def88dSAmir Goldstein return -EINVAL; 708b0def88dSAmir Goldstein } 709b0def88dSAmir Goldstein if (metacopy_opt) { 710b0def88dSAmir Goldstein /* 711b0def88dSAmir Goldstein * There was an explicit metacopy=on that resulted 712b0def88dSAmir Goldstein * in this conflict. 713b0def88dSAmir Goldstein */ 714b0def88dSAmir Goldstein pr_info("disabling nfs_export due to metacopy=on\n"); 715b0def88dSAmir Goldstein config->nfs_export = false; 716b0def88dSAmir Goldstein } else { 717b0def88dSAmir Goldstein /* 718b0def88dSAmir Goldstein * There was an explicit nfs_export=on that resulted 719b0def88dSAmir Goldstein * in this conflict. 720b0def88dSAmir Goldstein */ 721b0def88dSAmir Goldstein pr_info("disabling metacopy due to nfs_export=on\n"); 722b0def88dSAmir Goldstein config->metacopy = false; 723b0def88dSAmir Goldstein } 724b0def88dSAmir Goldstein } 725b0def88dSAmir Goldstein 7262d2f2d73SMiklos Szeredi 7272d2f2d73SMiklos Szeredi /* Resolve userxattr -> !redirect && !metacopy dependency */ 7282d2f2d73SMiklos Szeredi if (config->userxattr) { 7292d2f2d73SMiklos Szeredi if (config->redirect_follow && redirect_opt) { 7302d2f2d73SMiklos Szeredi pr_err("conflicting options: userxattr,redirect_dir=%s\n", 7312d2f2d73SMiklos Szeredi config->redirect_mode); 7322d2f2d73SMiklos Szeredi return -EINVAL; 7332d2f2d73SMiklos Szeredi } 7342d2f2d73SMiklos Szeredi if (config->metacopy && metacopy_opt) { 7352d2f2d73SMiklos Szeredi pr_err("conflicting options: userxattr,metacopy=on\n"); 7362d2f2d73SMiklos Szeredi return -EINVAL; 7372d2f2d73SMiklos Szeredi } 7382d2f2d73SMiklos Szeredi /* 7392d2f2d73SMiklos Szeredi * Silently disable default setting of redirect and metacopy. 7402d2f2d73SMiklos Szeredi * This shall be the default in the future as well: these 7412d2f2d73SMiklos Szeredi * options must be explicitly enabled if used together with 7422d2f2d73SMiklos Szeredi * userxattr. 7432d2f2d73SMiklos Szeredi */ 7442d2f2d73SMiklos Szeredi config->redirect_dir = config->redirect_follow = false; 7452d2f2d73SMiklos Szeredi config->metacopy = false; 7462d2f2d73SMiklos Szeredi } 7472d2f2d73SMiklos Szeredi 748d5791044SVivek Goyal return 0; 749e9be9d5eSMiklos Szeredi } 750e9be9d5eSMiklos Szeredi 751e9be9d5eSMiklos Szeredi #define OVL_WORKDIR_NAME "work" 75202bcd157SAmir Goldstein #define OVL_INDEXDIR_NAME "index" 753e9be9d5eSMiklos Szeredi 754ad204488SMiklos Szeredi static struct dentry *ovl_workdir_create(struct ovl_fs *ofs, 7556b8aa129SAmir Goldstein const char *name, bool persist) 756e9be9d5eSMiklos Szeredi { 757ad204488SMiklos Szeredi struct inode *dir = ofs->workbasedir->d_inode; 75808f4c7c8SMiklos Szeredi struct vfsmount *mnt = ovl_upper_mnt(ofs); 759e9be9d5eSMiklos Szeredi struct dentry *work; 760e9be9d5eSMiklos Szeredi int err; 761e9be9d5eSMiklos Szeredi bool retried = false; 762e9be9d5eSMiklos Szeredi 7635955102cSAl Viro inode_lock_nested(dir, I_MUTEX_PARENT); 764e9be9d5eSMiklos Szeredi retry: 76522f289ceSChristian Brauner work = ovl_lookup_upper(ofs, name, ofs->workbasedir, strlen(name)); 766e9be9d5eSMiklos Szeredi 767e9be9d5eSMiklos Szeredi if (!IS_ERR(work)) { 768c11b9fddSMiklos Szeredi struct iattr attr = { 769c11b9fddSMiklos Szeredi .ia_valid = ATTR_MODE, 77032a3d848SAl Viro .ia_mode = S_IFDIR | 0, 771c11b9fddSMiklos Szeredi }; 772e9be9d5eSMiklos Szeredi 773e9be9d5eSMiklos Szeredi if (work->d_inode) { 774e9be9d5eSMiklos Szeredi err = -EEXIST; 775e9be9d5eSMiklos Szeredi if (retried) 776e9be9d5eSMiklos Szeredi goto out_dput; 777e9be9d5eSMiklos Szeredi 7786b8aa129SAmir Goldstein if (persist) 7796b8aa129SAmir Goldstein goto out_unlock; 7806b8aa129SAmir Goldstein 781e9be9d5eSMiklos Szeredi retried = true; 782576bb263SChristian Brauner err = ovl_workdir_cleanup(ofs, dir, mnt, work, 0); 783e9be9d5eSMiklos Szeredi dput(work); 784235ce9edSAmir Goldstein if (err == -EINVAL) { 785235ce9edSAmir Goldstein work = ERR_PTR(err); 786235ce9edSAmir Goldstein goto out_unlock; 787235ce9edSAmir Goldstein } 788e9be9d5eSMiklos Szeredi goto retry; 789e9be9d5eSMiklos Szeredi } 790e9be9d5eSMiklos Szeredi 791576bb263SChristian Brauner err = ovl_mkdir_real(ofs, dir, &work, attr.ia_mode); 7921f5573cfSMiklos Szeredi if (err) 7931f5573cfSMiklos Szeredi goto out_dput; 7941f5573cfSMiklos Szeredi 7951f5573cfSMiklos Szeredi /* Weird filesystem returning with hashed negative (kernfs)? */ 7961f5573cfSMiklos Szeredi err = -EINVAL; 7971f5573cfSMiklos Szeredi if (d_really_is_negative(work)) 7981f5573cfSMiklos Szeredi goto out_dput; 799c11b9fddSMiklos Szeredi 800cb348edbSMiklos Szeredi /* 801cb348edbSMiklos Szeredi * Try to remove POSIX ACL xattrs from workdir. We are good if: 802cb348edbSMiklos Szeredi * 803cb348edbSMiklos Szeredi * a) success (there was a POSIX ACL xattr and was removed) 804cb348edbSMiklos Szeredi * b) -ENODATA (there was no POSIX ACL xattr) 805cb348edbSMiklos Szeredi * c) -EOPNOTSUPP (POSIX ACL xattrs are not supported) 806cb348edbSMiklos Szeredi * 807cb348edbSMiklos Szeredi * There are various other error values that could effectively 808cb348edbSMiklos Szeredi * mean that the xattr doesn't exist (e.g. -ERANGE is returned 809cb348edbSMiklos Szeredi * if the xattr name is too long), but the set of filesystems 810cb348edbSMiklos Szeredi * allowed as upper are limited to "normal" ones, where checking 811cb348edbSMiklos Szeredi * for the above two errors is sufficient. 812cb348edbSMiklos Szeredi */ 81331acceb9SChristian Brauner err = ovl_do_remove_acl(ofs, work, XATTR_NAME_POSIX_ACL_DEFAULT); 814e1ff3dd1SMiklos Szeredi if (err && err != -ENODATA && err != -EOPNOTSUPP) 815c11b9fddSMiklos Szeredi goto out_dput; 816c11b9fddSMiklos Szeredi 81731acceb9SChristian Brauner err = ovl_do_remove_acl(ofs, work, XATTR_NAME_POSIX_ACL_ACCESS); 818e1ff3dd1SMiklos Szeredi if (err && err != -ENODATA && err != -EOPNOTSUPP) 819c11b9fddSMiklos Szeredi goto out_dput; 820c11b9fddSMiklos Szeredi 821c11b9fddSMiklos Szeredi /* Clear any inherited mode bits */ 822c11b9fddSMiklos Szeredi inode_lock(work->d_inode); 823a15506eaSChristian Brauner err = ovl_do_notify_change(ofs, work, &attr); 824c11b9fddSMiklos Szeredi inode_unlock(work->d_inode); 825c11b9fddSMiklos Szeredi if (err) 826c11b9fddSMiklos Szeredi goto out_dput; 8276b8aa129SAmir Goldstein } else { 8286b8aa129SAmir Goldstein err = PTR_ERR(work); 8296b8aa129SAmir Goldstein goto out_err; 830e9be9d5eSMiklos Szeredi } 831e9be9d5eSMiklos Szeredi out_unlock: 8326b8aa129SAmir Goldstein inode_unlock(dir); 833e9be9d5eSMiklos Szeredi return work; 834e9be9d5eSMiklos Szeredi 835e9be9d5eSMiklos Szeredi out_dput: 836e9be9d5eSMiklos Szeredi dput(work); 8376b8aa129SAmir Goldstein out_err: 8381bd0a3aeSlijiazi pr_warn("failed to create directory %s/%s (errno: %i); mounting read-only\n", 839ad204488SMiklos Szeredi ofs->config.workdir, name, -err); 8406b8aa129SAmir Goldstein work = NULL; 841e9be9d5eSMiklos Szeredi goto out_unlock; 842e9be9d5eSMiklos Szeredi } 843e9be9d5eSMiklos Szeredi 84491c77947SMiklos Szeredi static void ovl_unescape(char *s) 84591c77947SMiklos Szeredi { 84691c77947SMiklos Szeredi char *d = s; 84791c77947SMiklos Szeredi 84891c77947SMiklos Szeredi for (;; s++, d++) { 84991c77947SMiklos Szeredi if (*s == '\\') 85091c77947SMiklos Szeredi s++; 85191c77947SMiklos Szeredi *d = *s; 85291c77947SMiklos Szeredi if (!*s) 85391c77947SMiklos Szeredi break; 85491c77947SMiklos Szeredi } 85591c77947SMiklos Szeredi } 85691c77947SMiklos Szeredi 857ab508822SMiklos Szeredi static int ovl_mount_dir_noesc(const char *name, struct path *path) 858ab508822SMiklos Szeredi { 859a78d9f0dSMiklos Szeredi int err = -EINVAL; 860ab508822SMiklos Szeredi 861a78d9f0dSMiklos Szeredi if (!*name) { 8621bd0a3aeSlijiazi pr_err("empty lowerdir\n"); 863a78d9f0dSMiklos Szeredi goto out; 864a78d9f0dSMiklos Szeredi } 865ab508822SMiklos Szeredi err = kern_path(name, LOOKUP_FOLLOW, path); 866ab508822SMiklos Szeredi if (err) { 8671bd0a3aeSlijiazi pr_err("failed to resolve '%s': %i\n", name, err); 868ab508822SMiklos Szeredi goto out; 869ab508822SMiklos Szeredi } 870ab508822SMiklos Szeredi err = -EINVAL; 8717c03b5d4SMiklos Szeredi if (ovl_dentry_weird(path->dentry)) { 8721bd0a3aeSlijiazi pr_err("filesystem on '%s' not supported\n", name); 873ab508822SMiklos Szeredi goto out_put; 874ab508822SMiklos Szeredi } 8752b8c30e9SMiklos Szeredi if (!d_is_dir(path->dentry)) { 8761bd0a3aeSlijiazi pr_err("'%s' not a directory\n", name); 877ab508822SMiklos Szeredi goto out_put; 878ab508822SMiklos Szeredi } 879ab508822SMiklos Szeredi return 0; 880ab508822SMiklos Szeredi 881ab508822SMiklos Szeredi out_put: 8828aafcb59SMiklos Szeredi path_put_init(path); 883ab508822SMiklos Szeredi out: 884ab508822SMiklos Szeredi return err; 885ab508822SMiklos Szeredi } 886ab508822SMiklos Szeredi 887ab508822SMiklos Szeredi static int ovl_mount_dir(const char *name, struct path *path) 888ab508822SMiklos Szeredi { 889ab508822SMiklos Szeredi int err = -ENOMEM; 890ab508822SMiklos Szeredi char *tmp = kstrdup(name, GFP_KERNEL); 891ab508822SMiklos Szeredi 892ab508822SMiklos Szeredi if (tmp) { 893ab508822SMiklos Szeredi ovl_unescape(tmp); 894ab508822SMiklos Szeredi err = ovl_mount_dir_noesc(tmp, path); 8957c03b5d4SMiklos Szeredi 896bccece1eSMiklos Szeredi if (!err && path->dentry->d_flags & DCACHE_OP_REAL) { 8971bd0a3aeSlijiazi pr_err("filesystem on '%s' not supported as upperdir\n", 8987c03b5d4SMiklos Szeredi tmp); 8998aafcb59SMiklos Szeredi path_put_init(path); 9007c03b5d4SMiklos Szeredi err = -EINVAL; 9017c03b5d4SMiklos Szeredi } 902ab508822SMiklos Szeredi kfree(tmp); 903ab508822SMiklos Szeredi } 904ab508822SMiklos Szeredi return err; 905ab508822SMiklos Szeredi } 906ab508822SMiklos Szeredi 9072d343087SAl Viro static int ovl_check_namelen(const struct path *path, struct ovl_fs *ofs, 9086b2d5fe4SMiklos Szeredi const char *name) 9096b2d5fe4SMiklos Szeredi { 9106b2d5fe4SMiklos Szeredi struct kstatfs statfs; 9116b2d5fe4SMiklos Szeredi int err = vfs_statfs(path, &statfs); 9126b2d5fe4SMiklos Szeredi 9136b2d5fe4SMiklos Szeredi if (err) 9141bd0a3aeSlijiazi pr_err("statfs failed on '%s'\n", name); 9156b2d5fe4SMiklos Szeredi else 9166b2d5fe4SMiklos Szeredi ofs->namelen = max(ofs->namelen, statfs.f_namelen); 9176b2d5fe4SMiklos Szeredi 9186b2d5fe4SMiklos Szeredi return err; 9196b2d5fe4SMiklos Szeredi } 9206b2d5fe4SMiklos Szeredi 9216b2d5fe4SMiklos Szeredi static int ovl_lower_dir(const char *name, struct path *path, 922f4288844SMiklos Szeredi struct ovl_fs *ofs, int *stack_depth) 923ab508822SMiklos Szeredi { 924e487d889SAmir Goldstein int fh_type; 925ab508822SMiklos Szeredi int err; 926ab508822SMiklos Szeredi 927a78d9f0dSMiklos Szeredi err = ovl_mount_dir_noesc(name, path); 928ab508822SMiklos Szeredi if (err) 929b8e42a65SMiklos Szeredi return err; 930ab508822SMiklos Szeredi 9316b2d5fe4SMiklos Szeredi err = ovl_check_namelen(path, ofs, name); 9326b2d5fe4SMiklos Szeredi if (err) 933b8e42a65SMiklos Szeredi return err; 9346b2d5fe4SMiklos Szeredi 935ab508822SMiklos Szeredi *stack_depth = max(*stack_depth, path->mnt->mnt_sb->s_stack_depth); 936ab508822SMiklos Szeredi 93702bcd157SAmir Goldstein /* 938f168f109SAmir Goldstein * The inodes index feature and NFS export need to encode and decode 939f168f109SAmir Goldstein * file handles, so they require that all layers support them. 94002bcd157SAmir Goldstein */ 941e487d889SAmir Goldstein fh_type = ovl_can_decode_fh(path->dentry->d_sb); 942f168f109SAmir Goldstein if ((ofs->config.nfs_export || 943e487d889SAmir Goldstein (ofs->config.index && ofs->config.upperdir)) && !fh_type) { 94402bcd157SAmir Goldstein ofs->config.index = false; 945f168f109SAmir Goldstein ofs->config.nfs_export = false; 9461bd0a3aeSlijiazi pr_warn("fs on '%s' does not support file handles, falling back to index=off,nfs_export=off.\n", 947f168f109SAmir Goldstein name); 94802bcd157SAmir Goldstein } 949b0e0f697SAmir Goldstein /* 950b0e0f697SAmir Goldstein * Decoding origin file handle is required for persistent st_ino. 951b0e0f697SAmir Goldstein * Without persistent st_ino, xino=auto falls back to xino=off. 952b0e0f697SAmir Goldstein */ 953b0e0f697SAmir Goldstein if (ofs->config.xino == OVL_XINO_AUTO && 954b0e0f697SAmir Goldstein ofs->config.upperdir && !fh_type) { 955b0e0f697SAmir Goldstein ofs->config.xino = OVL_XINO_OFF; 956b0e0f697SAmir Goldstein pr_warn("fs on '%s' does not support file handles, falling back to xino=off.\n", 957b0e0f697SAmir Goldstein name); 958b0e0f697SAmir Goldstein } 95902bcd157SAmir Goldstein 960e487d889SAmir Goldstein /* Check if lower fs has 32bit inode numbers */ 961e487d889SAmir Goldstein if (fh_type != FILEID_INO32_GEN) 9620f831ec8SAmir Goldstein ofs->xino_mode = -1; 963e487d889SAmir Goldstein 964ab508822SMiklos Szeredi return 0; 965ab508822SMiklos Szeredi } 966ab508822SMiklos Szeredi 967e9be9d5eSMiklos Szeredi /* Workdir should not be subdir of upperdir and vice versa */ 968e9be9d5eSMiklos Szeredi static bool ovl_workdir_ok(struct dentry *workdir, struct dentry *upperdir) 969e9be9d5eSMiklos Szeredi { 970e9be9d5eSMiklos Szeredi bool ok = false; 971e9be9d5eSMiklos Szeredi 972e9be9d5eSMiklos Szeredi if (workdir != upperdir) { 973e9be9d5eSMiklos Szeredi ok = (lock_rename(workdir, upperdir) == NULL); 974e9be9d5eSMiklos Szeredi unlock_rename(workdir, upperdir); 975e9be9d5eSMiklos Szeredi } 976e9be9d5eSMiklos Szeredi return ok; 977e9be9d5eSMiklos Szeredi } 978e9be9d5eSMiklos Szeredi 979a78d9f0dSMiklos Szeredi static unsigned int ovl_split_lowerdirs(char *str) 980a78d9f0dSMiklos Szeredi { 981a78d9f0dSMiklos Szeredi unsigned int ctr = 1; 982a78d9f0dSMiklos Szeredi char *s, *d; 983a78d9f0dSMiklos Szeredi 984a78d9f0dSMiklos Szeredi for (s = d = str;; s++, d++) { 985a78d9f0dSMiklos Szeredi if (*s == '\\') { 986a78d9f0dSMiklos Szeredi s++; 987a78d9f0dSMiklos Szeredi } else if (*s == ':') { 988a78d9f0dSMiklos Szeredi *d = '\0'; 989a78d9f0dSMiklos Szeredi ctr++; 990a78d9f0dSMiklos Szeredi continue; 991a78d9f0dSMiklos Szeredi } 992a78d9f0dSMiklos Szeredi *d = *s; 993a78d9f0dSMiklos Szeredi if (!*s) 994a78d9f0dSMiklos Szeredi break; 995a78d9f0dSMiklos Szeredi } 996a78d9f0dSMiklos Szeredi return ctr; 997a78d9f0dSMiklos Szeredi } 998a78d9f0dSMiklos Szeredi 9990eb45fc3SAndreas Gruenbacher static int ovl_own_xattr_get(const struct xattr_handler *handler, 10000eb45fc3SAndreas Gruenbacher struct dentry *dentry, struct inode *inode, 10010eb45fc3SAndreas Gruenbacher const char *name, void *buffer, size_t size) 10020eb45fc3SAndreas Gruenbacher { 100348fab5d7SAmir Goldstein return -EOPNOTSUPP; 10040eb45fc3SAndreas Gruenbacher } 10050eb45fc3SAndreas Gruenbacher 1006d837a49bSMiklos Szeredi static int ovl_own_xattr_set(const struct xattr_handler *handler, 100739f60c1cSChristian Brauner struct mnt_idmap *idmap, 1008d837a49bSMiklos Szeredi struct dentry *dentry, struct inode *inode, 1009d837a49bSMiklos Szeredi const char *name, const void *value, 1010d837a49bSMiklos Szeredi size_t size, int flags) 1011d837a49bSMiklos Szeredi { 101248fab5d7SAmir Goldstein return -EOPNOTSUPP; 1013d837a49bSMiklos Szeredi } 1014d837a49bSMiklos Szeredi 10150eb45fc3SAndreas Gruenbacher static int ovl_other_xattr_get(const struct xattr_handler *handler, 10160eb45fc3SAndreas Gruenbacher struct dentry *dentry, struct inode *inode, 10170eb45fc3SAndreas Gruenbacher const char *name, void *buffer, size_t size) 10180eb45fc3SAndreas Gruenbacher { 10191d88f183SMiklos Szeredi return ovl_xattr_get(dentry, inode, name, buffer, size); 10200eb45fc3SAndreas Gruenbacher } 10210eb45fc3SAndreas Gruenbacher 10220e585cccSAndreas Gruenbacher static int ovl_other_xattr_set(const struct xattr_handler *handler, 102339f60c1cSChristian Brauner struct mnt_idmap *idmap, 10240e585cccSAndreas Gruenbacher struct dentry *dentry, struct inode *inode, 10250e585cccSAndreas Gruenbacher const char *name, const void *value, 10260e585cccSAndreas Gruenbacher size_t size, int flags) 10270e585cccSAndreas Gruenbacher { 10281d88f183SMiklos Szeredi return ovl_xattr_set(dentry, inode, name, value, size, flags); 10290e585cccSAndreas Gruenbacher } 10300e585cccSAndreas Gruenbacher 10312d2f2d73SMiklos Szeredi static const struct xattr_handler ovl_own_trusted_xattr_handler = { 10322d2f2d73SMiklos Szeredi .prefix = OVL_XATTR_TRUSTED_PREFIX, 10332d2f2d73SMiklos Szeredi .get = ovl_own_xattr_get, 10342d2f2d73SMiklos Szeredi .set = ovl_own_xattr_set, 10352d2f2d73SMiklos Szeredi }; 10362d2f2d73SMiklos Szeredi 10372d2f2d73SMiklos Szeredi static const struct xattr_handler ovl_own_user_xattr_handler = { 10382d2f2d73SMiklos Szeredi .prefix = OVL_XATTR_USER_PREFIX, 10390eb45fc3SAndreas Gruenbacher .get = ovl_own_xattr_get, 1040d837a49bSMiklos Szeredi .set = ovl_own_xattr_set, 1041d837a49bSMiklos Szeredi }; 1042d837a49bSMiklos Szeredi 1043d837a49bSMiklos Szeredi static const struct xattr_handler ovl_other_xattr_handler = { 1044d837a49bSMiklos Szeredi .prefix = "", /* catch all */ 10450eb45fc3SAndreas Gruenbacher .get = ovl_other_xattr_get, 1046d837a49bSMiklos Szeredi .set = ovl_other_xattr_set, 1047d837a49bSMiklos Szeredi }; 1048d837a49bSMiklos Szeredi 10492d2f2d73SMiklos Szeredi static const struct xattr_handler *ovl_trusted_xattr_handlers[] = { 10502d2f2d73SMiklos Szeredi &ovl_own_trusted_xattr_handler, 10512d2f2d73SMiklos Szeredi &ovl_other_xattr_handler, 10522d2f2d73SMiklos Szeredi NULL 10532d2f2d73SMiklos Szeredi }; 10542d2f2d73SMiklos Szeredi 10552d2f2d73SMiklos Szeredi static const struct xattr_handler *ovl_user_xattr_handlers[] = { 10562d2f2d73SMiklos Szeredi &ovl_own_user_xattr_handler, 1057d837a49bSMiklos Szeredi &ovl_other_xattr_handler, 1058d837a49bSMiklos Szeredi NULL 1059d837a49bSMiklos Szeredi }; 1060d837a49bSMiklos Szeredi 1061146d62e5SAmir Goldstein static int ovl_setup_trap(struct super_block *sb, struct dentry *dir, 1062146d62e5SAmir Goldstein struct inode **ptrap, const char *name) 1063146d62e5SAmir Goldstein { 1064146d62e5SAmir Goldstein struct inode *trap; 1065146d62e5SAmir Goldstein int err; 1066146d62e5SAmir Goldstein 1067146d62e5SAmir Goldstein trap = ovl_get_trap_inode(sb, dir); 10681dac6f5bSArnd Bergmann err = PTR_ERR_OR_ZERO(trap); 10691dac6f5bSArnd Bergmann if (err) { 1070146d62e5SAmir Goldstein if (err == -ELOOP) 10711bd0a3aeSlijiazi pr_err("conflicting %s path\n", name); 1072146d62e5SAmir Goldstein return err; 1073146d62e5SAmir Goldstein } 1074146d62e5SAmir Goldstein 1075146d62e5SAmir Goldstein *ptrap = trap; 1076146d62e5SAmir Goldstein return 0; 1077146d62e5SAmir Goldstein } 1078146d62e5SAmir Goldstein 10790be0bfd2SAmir Goldstein /* 10800be0bfd2SAmir Goldstein * Determine how we treat concurrent use of upperdir/workdir based on the 10810be0bfd2SAmir Goldstein * index feature. This is papering over mount leaks of container runtimes, 10820be0bfd2SAmir Goldstein * for example, an old overlay mount is leaked and now its upperdir is 10830be0bfd2SAmir Goldstein * attempted to be used as a lower layer in a new overlay mount. 10840be0bfd2SAmir Goldstein */ 10850be0bfd2SAmir Goldstein static int ovl_report_in_use(struct ovl_fs *ofs, const char *name) 10860be0bfd2SAmir Goldstein { 10870be0bfd2SAmir Goldstein if (ofs->config.index) { 10881bd0a3aeSlijiazi pr_err("%s is in-use as upperdir/workdir of another mount, mount with '-o index=off' to override exclusive upperdir protection.\n", 10890be0bfd2SAmir Goldstein name); 10900be0bfd2SAmir Goldstein return -EBUSY; 10910be0bfd2SAmir Goldstein } else { 10921bd0a3aeSlijiazi pr_warn("%s is in-use as upperdir/workdir of another mount, accessing files from both mounts will result in undefined behavior.\n", 10930be0bfd2SAmir Goldstein name); 10940be0bfd2SAmir Goldstein return 0; 10950be0bfd2SAmir Goldstein } 10960be0bfd2SAmir Goldstein } 10970be0bfd2SAmir Goldstein 1098146d62e5SAmir Goldstein static int ovl_get_upper(struct super_block *sb, struct ovl_fs *ofs, 1099b8e42a65SMiklos Szeredi struct ovl_layer *upper_layer, struct path *upperpath) 11006ee8acf0SMiklos Szeredi { 11015064975eSMiklos Szeredi struct vfsmount *upper_mnt; 11026ee8acf0SMiklos Szeredi int err; 11036ee8acf0SMiklos Szeredi 1104ad204488SMiklos Szeredi err = ovl_mount_dir(ofs->config.upperdir, upperpath); 11056ee8acf0SMiklos Szeredi if (err) 11066ee8acf0SMiklos Szeredi goto out; 11076ee8acf0SMiklos Szeredi 1108e21a6c57SAmir Goldstein /* Upperdir path should not be r/o */ 1109e21a6c57SAmir Goldstein if (__mnt_is_readonly(upperpath->mnt)) { 11101bd0a3aeSlijiazi pr_err("upper fs is r/o, try multi-lower layers mount\n"); 11116ee8acf0SMiklos Szeredi err = -EINVAL; 11126ee8acf0SMiklos Szeredi goto out; 11136ee8acf0SMiklos Szeredi } 11146ee8acf0SMiklos Szeredi 1115ad204488SMiklos Szeredi err = ovl_check_namelen(upperpath, ofs, ofs->config.upperdir); 11166ee8acf0SMiklos Szeredi if (err) 11176ee8acf0SMiklos Szeredi goto out; 11186ee8acf0SMiklos Szeredi 1119b8e42a65SMiklos Szeredi err = ovl_setup_trap(sb, upperpath->dentry, &upper_layer->trap, 1120146d62e5SAmir Goldstein "upperdir"); 1121146d62e5SAmir Goldstein if (err) 1122146d62e5SAmir Goldstein goto out; 1123146d62e5SAmir Goldstein 11245064975eSMiklos Szeredi upper_mnt = clone_private_mount(upperpath); 11255064975eSMiklos Szeredi err = PTR_ERR(upper_mnt); 11265064975eSMiklos Szeredi if (IS_ERR(upper_mnt)) { 11271bd0a3aeSlijiazi pr_err("failed to clone upperpath\n"); 11285064975eSMiklos Szeredi goto out; 11295064975eSMiklos Szeredi } 11305064975eSMiklos Szeredi 11315064975eSMiklos Szeredi /* Don't inherit atime flags */ 11325064975eSMiklos Szeredi upper_mnt->mnt_flags &= ~(MNT_NOATIME | MNT_NODIRATIME | MNT_RELATIME); 1133b8e42a65SMiklos Szeredi upper_layer->mnt = upper_mnt; 1134b8e42a65SMiklos Szeredi upper_layer->idx = 0; 1135b8e42a65SMiklos Szeredi upper_layer->fsid = 0; 11368c25741aSMiklos Szeredi 1137654255faSJeffle Xu /* 1138654255faSJeffle Xu * Inherit SB_NOSEC flag from upperdir. 1139654255faSJeffle Xu * 1140654255faSJeffle Xu * This optimization changes behavior when a security related attribute 1141654255faSJeffle Xu * (suid/sgid/security.*) is changed on an underlying layer. This is 1142654255faSJeffle Xu * okay because we don't yet have guarantees in that case, but it will 1143654255faSJeffle Xu * need careful treatment once we want to honour changes to underlying 1144654255faSJeffle Xu * filesystems. 1145654255faSJeffle Xu */ 1146654255faSJeffle Xu if (upper_mnt->mnt_sb->s_flags & SB_NOSEC) 1147654255faSJeffle Xu sb->s_flags |= SB_NOSEC; 1148654255faSJeffle Xu 114908f4c7c8SMiklos Szeredi if (ovl_inuse_trylock(ovl_upper_mnt(ofs)->mnt_root)) { 11508c25741aSMiklos Szeredi ofs->upperdir_locked = true; 11518c25741aSMiklos Szeredi } else { 11520be0bfd2SAmir Goldstein err = ovl_report_in_use(ofs, "upperdir"); 11530be0bfd2SAmir Goldstein if (err) 11540be0bfd2SAmir Goldstein goto out; 11558c25741aSMiklos Szeredi } 11568c25741aSMiklos Szeredi 11576ee8acf0SMiklos Szeredi err = 0; 11586ee8acf0SMiklos Szeredi out: 11596ee8acf0SMiklos Szeredi return err; 11606ee8acf0SMiklos Szeredi } 11616ee8acf0SMiklos Szeredi 1162cad218abSAmir Goldstein /* 1163cad218abSAmir Goldstein * Returns 1 if RENAME_WHITEOUT is supported, 0 if not supported and 1164cad218abSAmir Goldstein * negative values if error is encountered. 1165cad218abSAmir Goldstein */ 1166576bb263SChristian Brauner static int ovl_check_rename_whiteout(struct ovl_fs *ofs) 1167cad218abSAmir Goldstein { 1168576bb263SChristian Brauner struct dentry *workdir = ofs->workdir; 1169cad218abSAmir Goldstein struct inode *dir = d_inode(workdir); 1170cad218abSAmir Goldstein struct dentry *temp; 1171cad218abSAmir Goldstein struct dentry *dest; 1172cad218abSAmir Goldstein struct dentry *whiteout; 1173cad218abSAmir Goldstein struct name_snapshot name; 1174cad218abSAmir Goldstein int err; 1175cad218abSAmir Goldstein 1176cad218abSAmir Goldstein inode_lock_nested(dir, I_MUTEX_PARENT); 1177cad218abSAmir Goldstein 1178576bb263SChristian Brauner temp = ovl_create_temp(ofs, workdir, OVL_CATTR(S_IFREG | 0)); 1179cad218abSAmir Goldstein err = PTR_ERR(temp); 1180cad218abSAmir Goldstein if (IS_ERR(temp)) 1181cad218abSAmir Goldstein goto out_unlock; 1182cad218abSAmir Goldstein 1183576bb263SChristian Brauner dest = ovl_lookup_temp(ofs, workdir); 1184cad218abSAmir Goldstein err = PTR_ERR(dest); 1185cad218abSAmir Goldstein if (IS_ERR(dest)) { 1186cad218abSAmir Goldstein dput(temp); 1187cad218abSAmir Goldstein goto out_unlock; 1188cad218abSAmir Goldstein } 1189cad218abSAmir Goldstein 1190cad218abSAmir Goldstein /* Name is inline and stable - using snapshot as a copy helper */ 1191cad218abSAmir Goldstein take_dentry_name_snapshot(&name, temp); 1192576bb263SChristian Brauner err = ovl_do_rename(ofs, dir, temp, dir, dest, RENAME_WHITEOUT); 1193cad218abSAmir Goldstein if (err) { 1194cad218abSAmir Goldstein if (err == -EINVAL) 1195cad218abSAmir Goldstein err = 0; 1196cad218abSAmir Goldstein goto cleanup_temp; 1197cad218abSAmir Goldstein } 1198cad218abSAmir Goldstein 119922f289ceSChristian Brauner whiteout = ovl_lookup_upper(ofs, name.name.name, workdir, name.name.len); 1200cad218abSAmir Goldstein err = PTR_ERR(whiteout); 1201cad218abSAmir Goldstein if (IS_ERR(whiteout)) 1202cad218abSAmir Goldstein goto cleanup_temp; 1203cad218abSAmir Goldstein 1204cad218abSAmir Goldstein err = ovl_is_whiteout(whiteout); 1205cad218abSAmir Goldstein 1206cad218abSAmir Goldstein /* Best effort cleanup of whiteout and temp file */ 1207cad218abSAmir Goldstein if (err) 1208576bb263SChristian Brauner ovl_cleanup(ofs, dir, whiteout); 1209cad218abSAmir Goldstein dput(whiteout); 1210cad218abSAmir Goldstein 1211cad218abSAmir Goldstein cleanup_temp: 1212576bb263SChristian Brauner ovl_cleanup(ofs, dir, temp); 1213cad218abSAmir Goldstein release_dentry_name_snapshot(&name); 1214cad218abSAmir Goldstein dput(temp); 1215cad218abSAmir Goldstein dput(dest); 1216cad218abSAmir Goldstein 1217cad218abSAmir Goldstein out_unlock: 1218cad218abSAmir Goldstein inode_unlock(dir); 1219cad218abSAmir Goldstein 1220cad218abSAmir Goldstein return err; 1221cad218abSAmir Goldstein } 1222cad218abSAmir Goldstein 1223576bb263SChristian Brauner static struct dentry *ovl_lookup_or_create(struct ovl_fs *ofs, 1224576bb263SChristian Brauner struct dentry *parent, 1225c86243b0SVivek Goyal const char *name, umode_t mode) 1226c86243b0SVivek Goyal { 1227c86243b0SVivek Goyal size_t len = strlen(name); 1228c86243b0SVivek Goyal struct dentry *child; 1229c86243b0SVivek Goyal 1230c86243b0SVivek Goyal inode_lock_nested(parent->d_inode, I_MUTEX_PARENT); 123122f289ceSChristian Brauner child = ovl_lookup_upper(ofs, name, parent, len); 1232c86243b0SVivek Goyal if (!IS_ERR(child) && !child->d_inode) 1233576bb263SChristian Brauner child = ovl_create_real(ofs, parent->d_inode, child, 1234c86243b0SVivek Goyal OVL_CATTR(mode)); 1235c86243b0SVivek Goyal inode_unlock(parent->d_inode); 1236c86243b0SVivek Goyal dput(parent); 1237c86243b0SVivek Goyal 1238c86243b0SVivek Goyal return child; 1239c86243b0SVivek Goyal } 1240c86243b0SVivek Goyal 1241c86243b0SVivek Goyal /* 1242c86243b0SVivek Goyal * Creates $workdir/work/incompat/volatile/dirty file if it is not already 1243c86243b0SVivek Goyal * present. 1244c86243b0SVivek Goyal */ 1245c86243b0SVivek Goyal static int ovl_create_volatile_dirty(struct ovl_fs *ofs) 1246c86243b0SVivek Goyal { 1247c86243b0SVivek Goyal unsigned int ctr; 1248c86243b0SVivek Goyal struct dentry *d = dget(ofs->workbasedir); 1249c86243b0SVivek Goyal static const char *const volatile_path[] = { 1250c86243b0SVivek Goyal OVL_WORKDIR_NAME, "incompat", "volatile", "dirty" 1251c86243b0SVivek Goyal }; 1252c86243b0SVivek Goyal const char *const *name = volatile_path; 1253c86243b0SVivek Goyal 1254c86243b0SVivek Goyal for (ctr = ARRAY_SIZE(volatile_path); ctr; ctr--, name++) { 1255576bb263SChristian Brauner d = ovl_lookup_or_create(ofs, d, *name, ctr > 1 ? S_IFDIR : S_IFREG); 1256c86243b0SVivek Goyal if (IS_ERR(d)) 1257c86243b0SVivek Goyal return PTR_ERR(d); 1258c86243b0SVivek Goyal } 1259c86243b0SVivek Goyal dput(d); 1260c86243b0SVivek Goyal return 0; 1261c86243b0SVivek Goyal } 1262c86243b0SVivek Goyal 1263146d62e5SAmir Goldstein static int ovl_make_workdir(struct super_block *sb, struct ovl_fs *ofs, 12642d343087SAl Viro const struct path *workpath) 12658ed61dc3SMiklos Szeredi { 126608f4c7c8SMiklos Szeredi struct vfsmount *mnt = ovl_upper_mnt(ofs); 12672b1a7746SMiklos Szeredi struct dentry *workdir; 12682b1a7746SMiklos Szeredi struct file *tmpfile; 1269d80172c2SAmir Goldstein bool rename_whiteout; 1270d80172c2SAmir Goldstein bool d_type; 1271e487d889SAmir Goldstein int fh_type; 12728ed61dc3SMiklos Szeredi int err; 12738ed61dc3SMiklos Szeredi 12742ba9d57eSAmir Goldstein err = mnt_want_write(mnt); 12752ba9d57eSAmir Goldstein if (err) 12762ba9d57eSAmir Goldstein return err; 12772ba9d57eSAmir Goldstein 1278235ce9edSAmir Goldstein workdir = ovl_workdir_create(ofs, OVL_WORKDIR_NAME, false); 1279235ce9edSAmir Goldstein err = PTR_ERR(workdir); 1280235ce9edSAmir Goldstein if (IS_ERR_OR_NULL(workdir)) 12812ba9d57eSAmir Goldstein goto out; 12828ed61dc3SMiklos Szeredi 1283235ce9edSAmir Goldstein ofs->workdir = workdir; 1284235ce9edSAmir Goldstein 1285146d62e5SAmir Goldstein err = ovl_setup_trap(sb, ofs->workdir, &ofs->workdir_trap, "workdir"); 1286146d62e5SAmir Goldstein if (err) 1287146d62e5SAmir Goldstein goto out; 1288146d62e5SAmir Goldstein 12898ed61dc3SMiklos Szeredi /* 12908ed61dc3SMiklos Szeredi * Upper should support d_type, else whiteouts are visible. Given 12918ed61dc3SMiklos Szeredi * workdir and upper are on same fs, we can do iterate_dir() on 12928ed61dc3SMiklos Szeredi * workdir. This check requires successful creation of workdir in 12938ed61dc3SMiklos Szeredi * previous step. 12948ed61dc3SMiklos Szeredi */ 12958ed61dc3SMiklos Szeredi err = ovl_check_d_type_supported(workpath); 12968ed61dc3SMiklos Szeredi if (err < 0) 12972ba9d57eSAmir Goldstein goto out; 12988ed61dc3SMiklos Szeredi 1299d80172c2SAmir Goldstein d_type = err; 1300d80172c2SAmir Goldstein if (!d_type) 13011bd0a3aeSlijiazi pr_warn("upper fs needs to support d_type.\n"); 13028ed61dc3SMiklos Szeredi 13038ed61dc3SMiklos Szeredi /* Check if upper/work fs supports O_TMPFILE */ 13042b1a7746SMiklos Szeredi tmpfile = ovl_do_tmpfile(ofs, ofs->workdir, S_IFREG | 0); 13052b1a7746SMiklos Szeredi ofs->tmpfile = !IS_ERR(tmpfile); 1306ad204488SMiklos Szeredi if (ofs->tmpfile) 13072b1a7746SMiklos Szeredi fput(tmpfile); 13088ed61dc3SMiklos Szeredi else 13091bd0a3aeSlijiazi pr_warn("upper fs does not support tmpfile.\n"); 13108ed61dc3SMiklos Szeredi 1311cad218abSAmir Goldstein 1312cad218abSAmir Goldstein /* Check if upper/work fs supports RENAME_WHITEOUT */ 1313576bb263SChristian Brauner err = ovl_check_rename_whiteout(ofs); 1314cad218abSAmir Goldstein if (err < 0) 1315cad218abSAmir Goldstein goto out; 1316cad218abSAmir Goldstein 1317d80172c2SAmir Goldstein rename_whiteout = err; 1318d80172c2SAmir Goldstein if (!rename_whiteout) 1319cad218abSAmir Goldstein pr_warn("upper fs does not support RENAME_WHITEOUT.\n"); 1320cad218abSAmir Goldstein 13218ed61dc3SMiklos Szeredi /* 13222d2f2d73SMiklos Szeredi * Check if upper/work fs supports (trusted|user).overlay.* xattr 13238ed61dc3SMiklos Szeredi */ 1324c914c0e2SAmir Goldstein err = ovl_setxattr(ofs, ofs->workdir, OVL_XATTR_OPAQUE, "0", 1); 13258ed61dc3SMiklos Szeredi if (err) { 1326b10b85feSMiklos Szeredi pr_warn("failed to set xattr on upper\n"); 1327ad204488SMiklos Szeredi ofs->noxattr = true; 1328b0e0f697SAmir Goldstein if (ofs->config.index || ofs->config.metacopy) { 1329a683737bSAmir Goldstein ofs->config.index = false; 1330d5791044SVivek Goyal ofs->config.metacopy = false; 1331b10b85feSMiklos Szeredi pr_warn("...falling back to index=off,metacopy=off.\n"); 1332b0e0f697SAmir Goldstein } 1333b0e0f697SAmir Goldstein /* 1334b0e0f697SAmir Goldstein * xattr support is required for persistent st_ino. 1335b0e0f697SAmir Goldstein * Without persistent st_ino, xino=auto falls back to xino=off. 1336b0e0f697SAmir Goldstein */ 1337b0e0f697SAmir Goldstein if (ofs->config.xino == OVL_XINO_AUTO) { 1338b0e0f697SAmir Goldstein ofs->config.xino = OVL_XINO_OFF; 1339b10b85feSMiklos Szeredi pr_warn("...falling back to xino=off.\n"); 1340b0e0f697SAmir Goldstein } 1341b10b85feSMiklos Szeredi if (err == -EPERM && !ofs->config.userxattr) 1342b10b85feSMiklos Szeredi pr_info("try mounting with 'userxattr' option\n"); 13432ba9d57eSAmir Goldstein err = 0; 13448ed61dc3SMiklos Szeredi } else { 1345c914c0e2SAmir Goldstein ovl_removexattr(ofs, ofs->workdir, OVL_XATTR_OPAQUE); 13468ed61dc3SMiklos Szeredi } 13478ed61dc3SMiklos Szeredi 1348d80172c2SAmir Goldstein /* 1349d80172c2SAmir Goldstein * We allowed sub-optimal upper fs configuration and don't want to break 1350d80172c2SAmir Goldstein * users over kernel upgrade, but we never allowed remote upper fs, so 1351d80172c2SAmir Goldstein * we can enforce strict requirements for remote upper fs. 1352d80172c2SAmir Goldstein */ 1353d80172c2SAmir Goldstein if (ovl_dentry_remote(ofs->workdir) && 1354d80172c2SAmir Goldstein (!d_type || !rename_whiteout || ofs->noxattr)) { 1355d80172c2SAmir Goldstein pr_err("upper fs missing required features.\n"); 1356d80172c2SAmir Goldstein err = -EINVAL; 1357d80172c2SAmir Goldstein goto out; 1358d80172c2SAmir Goldstein } 1359d80172c2SAmir Goldstein 1360c86243b0SVivek Goyal /* 1361c86243b0SVivek Goyal * For volatile mount, create a incompat/volatile/dirty file to keep 1362c86243b0SVivek Goyal * track of it. 1363c86243b0SVivek Goyal */ 1364c86243b0SVivek Goyal if (ofs->config.ovl_volatile) { 1365c86243b0SVivek Goyal err = ovl_create_volatile_dirty(ofs); 1366c86243b0SVivek Goyal if (err < 0) { 1367c86243b0SVivek Goyal pr_err("Failed to create volatile/dirty file.\n"); 1368c86243b0SVivek Goyal goto out; 1369c86243b0SVivek Goyal } 1370c86243b0SVivek Goyal } 1371c86243b0SVivek Goyal 13728ed61dc3SMiklos Szeredi /* Check if upper/work fs supports file handles */ 1373e487d889SAmir Goldstein fh_type = ovl_can_decode_fh(ofs->workdir->d_sb); 1374e487d889SAmir Goldstein if (ofs->config.index && !fh_type) { 1375ad204488SMiklos Szeredi ofs->config.index = false; 13761bd0a3aeSlijiazi pr_warn("upper fs does not support file handles, falling back to index=off.\n"); 13778ed61dc3SMiklos Szeredi } 13788ed61dc3SMiklos Szeredi 1379e487d889SAmir Goldstein /* Check if upper fs has 32bit inode numbers */ 1380e487d889SAmir Goldstein if (fh_type != FILEID_INO32_GEN) 13810f831ec8SAmir Goldstein ofs->xino_mode = -1; 1382e487d889SAmir Goldstein 1383f168f109SAmir Goldstein /* NFS export of r/w mount depends on index */ 1384f168f109SAmir Goldstein if (ofs->config.nfs_export && !ofs->config.index) { 13851bd0a3aeSlijiazi pr_warn("NFS export requires \"index=on\", falling back to nfs_export=off.\n"); 1386f168f109SAmir Goldstein ofs->config.nfs_export = false; 1387f168f109SAmir Goldstein } 13882ba9d57eSAmir Goldstein out: 13892ba9d57eSAmir Goldstein mnt_drop_write(mnt); 13902ba9d57eSAmir Goldstein return err; 13918ed61dc3SMiklos Szeredi } 13928ed61dc3SMiklos Szeredi 1393146d62e5SAmir Goldstein static int ovl_get_workdir(struct super_block *sb, struct ovl_fs *ofs, 13942d343087SAl Viro const struct path *upperpath) 1395520d7c86SMiklos Szeredi { 1396520d7c86SMiklos Szeredi int err; 1397bca44b52SMiklos Szeredi struct path workpath = { }; 1398520d7c86SMiklos Szeredi 1399ad204488SMiklos Szeredi err = ovl_mount_dir(ofs->config.workdir, &workpath); 1400520d7c86SMiklos Szeredi if (err) 1401520d7c86SMiklos Szeredi goto out; 1402520d7c86SMiklos Szeredi 1403520d7c86SMiklos Szeredi err = -EINVAL; 1404bca44b52SMiklos Szeredi if (upperpath->mnt != workpath.mnt) { 14051bd0a3aeSlijiazi pr_err("workdir and upperdir must reside under the same mount\n"); 1406520d7c86SMiklos Szeredi goto out; 1407520d7c86SMiklos Szeredi } 1408bca44b52SMiklos Szeredi if (!ovl_workdir_ok(workpath.dentry, upperpath->dentry)) { 14091bd0a3aeSlijiazi pr_err("workdir and upperdir must be separate subtrees\n"); 1410520d7c86SMiklos Szeredi goto out; 1411520d7c86SMiklos Szeredi } 1412520d7c86SMiklos Szeredi 14138c25741aSMiklos Szeredi ofs->workbasedir = dget(workpath.dentry); 14148c25741aSMiklos Szeredi 14158c25741aSMiklos Szeredi if (ovl_inuse_trylock(ofs->workbasedir)) { 1416ad204488SMiklos Szeredi ofs->workdir_locked = true; 1417520d7c86SMiklos Szeredi } else { 14180be0bfd2SAmir Goldstein err = ovl_report_in_use(ofs, "workdir"); 14190be0bfd2SAmir Goldstein if (err) 14200be0bfd2SAmir Goldstein goto out; 1421520d7c86SMiklos Szeredi } 1422520d7c86SMiklos Szeredi 14230be0bfd2SAmir Goldstein err = ovl_setup_trap(sb, ofs->workbasedir, &ofs->workbasedir_trap, 14240be0bfd2SAmir Goldstein "workdir"); 14250be0bfd2SAmir Goldstein if (err) 14260be0bfd2SAmir Goldstein goto out; 14270be0bfd2SAmir Goldstein 1428146d62e5SAmir Goldstein err = ovl_make_workdir(sb, ofs, &workpath); 1429bca44b52SMiklos Szeredi 1430520d7c86SMiklos Szeredi out: 1431bca44b52SMiklos Szeredi path_put(&workpath); 1432bca44b52SMiklos Szeredi 1433520d7c86SMiklos Szeredi return err; 1434520d7c86SMiklos Szeredi } 1435520d7c86SMiklos Szeredi 1436146d62e5SAmir Goldstein static int ovl_get_indexdir(struct super_block *sb, struct ovl_fs *ofs, 14372d343087SAl Viro struct ovl_entry *oe, const struct path *upperpath) 1438f7e3a7d9SMiklos Szeredi { 143908f4c7c8SMiklos Szeredi struct vfsmount *mnt = ovl_upper_mnt(ofs); 1440235ce9edSAmir Goldstein struct dentry *indexdir; 1441f7e3a7d9SMiklos Szeredi int err; 1442f7e3a7d9SMiklos Szeredi 14432ba9d57eSAmir Goldstein err = mnt_want_write(mnt); 14442ba9d57eSAmir Goldstein if (err) 14452ba9d57eSAmir Goldstein return err; 14462ba9d57eSAmir Goldstein 1447f7e3a7d9SMiklos Szeredi /* Verify lower root is upper root origin */ 1448610afc0bSMiklos Szeredi err = ovl_verify_origin(ofs, upperpath->dentry, 14495522c9c7SAmir Goldstein ovl_lowerstack(oe)->dentry, true); 1450f7e3a7d9SMiklos Szeredi if (err) { 14511bd0a3aeSlijiazi pr_err("failed to verify upper root origin\n"); 1452f7e3a7d9SMiklos Szeredi goto out; 1453f7e3a7d9SMiklos Szeredi } 1454f7e3a7d9SMiklos Szeredi 145520396365SAmir Goldstein /* index dir will act also as workdir */ 145620396365SAmir Goldstein iput(ofs->workdir_trap); 145720396365SAmir Goldstein ofs->workdir_trap = NULL; 145820396365SAmir Goldstein dput(ofs->workdir); 1459470c1563SAmir Goldstein ofs->workdir = NULL; 1460235ce9edSAmir Goldstein indexdir = ovl_workdir_create(ofs, OVL_INDEXDIR_NAME, true); 1461235ce9edSAmir Goldstein if (IS_ERR(indexdir)) { 1462235ce9edSAmir Goldstein err = PTR_ERR(indexdir); 1463235ce9edSAmir Goldstein } else if (indexdir) { 1464235ce9edSAmir Goldstein ofs->indexdir = indexdir; 1465235ce9edSAmir Goldstein ofs->workdir = dget(indexdir); 146620396365SAmir Goldstein 1467146d62e5SAmir Goldstein err = ovl_setup_trap(sb, ofs->indexdir, &ofs->indexdir_trap, 1468146d62e5SAmir Goldstein "indexdir"); 1469146d62e5SAmir Goldstein if (err) 1470146d62e5SAmir Goldstein goto out; 1471146d62e5SAmir Goldstein 1472ad1d615cSAmir Goldstein /* 1473ad1d615cSAmir Goldstein * Verify upper root is exclusively associated with index dir. 14742d2f2d73SMiklos Szeredi * Older kernels stored upper fh in ".overlay.origin" 1475ad1d615cSAmir Goldstein * xattr. If that xattr exists, verify that it is a match to 1476ad1d615cSAmir Goldstein * upper dir file handle. In any case, verify or set xattr 14772d2f2d73SMiklos Szeredi * ".overlay.upper" to indicate that index may have 1478ad1d615cSAmir Goldstein * directory entries. 1479ad1d615cSAmir Goldstein */ 1480610afc0bSMiklos Szeredi if (ovl_check_origin_xattr(ofs, ofs->indexdir)) { 1481610afc0bSMiklos Szeredi err = ovl_verify_set_fh(ofs, ofs->indexdir, 1482610afc0bSMiklos Szeredi OVL_XATTR_ORIGIN, 1483ad1d615cSAmir Goldstein upperpath->dentry, true, false); 1484f7e3a7d9SMiklos Szeredi if (err) 14851bd0a3aeSlijiazi pr_err("failed to verify index dir 'origin' xattr\n"); 1486ad1d615cSAmir Goldstein } 1487610afc0bSMiklos Szeredi err = ovl_verify_upper(ofs, ofs->indexdir, upperpath->dentry, 1488610afc0bSMiklos Szeredi true); 1489ad1d615cSAmir Goldstein if (err) 14901bd0a3aeSlijiazi pr_err("failed to verify index dir 'upper' xattr\n"); 1491f7e3a7d9SMiklos Szeredi 1492f7e3a7d9SMiklos Szeredi /* Cleanup bad/stale/orphan index entries */ 1493f7e3a7d9SMiklos Szeredi if (!err) 14941eff1a1dSAmir Goldstein err = ovl_indexdir_cleanup(ofs); 1495f7e3a7d9SMiklos Szeredi } 1496ad204488SMiklos Szeredi if (err || !ofs->indexdir) 14971bd0a3aeSlijiazi pr_warn("try deleting index dir or mounting with '-o index=off' to disable inodes index.\n"); 1498f7e3a7d9SMiklos Szeredi 1499f7e3a7d9SMiklos Szeredi out: 15002ba9d57eSAmir Goldstein mnt_drop_write(mnt); 1501f7e3a7d9SMiklos Szeredi return err; 1502f7e3a7d9SMiklos Szeredi } 1503f7e3a7d9SMiklos Szeredi 15049df085f3SAmir Goldstein static bool ovl_lower_uuid_ok(struct ovl_fs *ofs, const uuid_t *uuid) 15055148626bSAmir Goldstein { 15065148626bSAmir Goldstein unsigned int i; 15079df085f3SAmir Goldstein 150808f4c7c8SMiklos Szeredi if (!ofs->config.nfs_export && !ovl_upper_mnt(ofs)) 15099df085f3SAmir Goldstein return true; 15109df085f3SAmir Goldstein 1511a888db31SAmir Goldstein /* 1512a888db31SAmir Goldstein * We allow using single lower with null uuid for index and nfs_export 1513a888db31SAmir Goldstein * for example to support those features with single lower squashfs. 1514a888db31SAmir Goldstein * To avoid regressions in setups of overlay with re-formatted lower 1515a888db31SAmir Goldstein * squashfs, do not allow decoding origin with lower null uuid unless 1516a888db31SAmir Goldstein * user opted-in to one of the new features that require following the 1517a888db31SAmir Goldstein * lower inode of non-dir upper. 1518a888db31SAmir Goldstein */ 1519ca45275cSVyacheslav Yurkov if (ovl_allow_offline_changes(ofs) && uuid_is_null(uuid)) 1520a888db31SAmir Goldstein return false; 1521a888db31SAmir Goldstein 15221b81ddddSAmir Goldstein for (i = 0; i < ofs->numfs; i++) { 15239df085f3SAmir Goldstein /* 15249df085f3SAmir Goldstein * We use uuid to associate an overlay lower file handle with a 15259df085f3SAmir Goldstein * lower layer, so we can accept lower fs with null uuid as long 15269df085f3SAmir Goldstein * as all lower layers with null uuid are on the same fs. 15277e63c87fSAmir Goldstein * if we detect multiple lower fs with the same uuid, we 15287e63c87fSAmir Goldstein * disable lower file handle decoding on all of them. 15299df085f3SAmir Goldstein */ 15301b81ddddSAmir Goldstein if (ofs->fs[i].is_lower && 15311b81ddddSAmir Goldstein uuid_equal(&ofs->fs[i].sb->s_uuid, uuid)) { 153207f1e596SAmir Goldstein ofs->fs[i].bad_uuid = true; 15339df085f3SAmir Goldstein return false; 15349df085f3SAmir Goldstein } 15357e63c87fSAmir Goldstein } 15369df085f3SAmir Goldstein return true; 15379df085f3SAmir Goldstein } 15389df085f3SAmir Goldstein 15399df085f3SAmir Goldstein /* Get a unique fsid for the layer */ 15409df085f3SAmir Goldstein static int ovl_get_fsid(struct ovl_fs *ofs, const struct path *path) 15419df085f3SAmir Goldstein { 15429df085f3SAmir Goldstein struct super_block *sb = path->mnt->mnt_sb; 15439df085f3SAmir Goldstein unsigned int i; 15445148626bSAmir Goldstein dev_t dev; 15455148626bSAmir Goldstein int err; 15467e63c87fSAmir Goldstein bool bad_uuid = false; 1547b0e0f697SAmir Goldstein bool warn = false; 15485148626bSAmir Goldstein 154907f1e596SAmir Goldstein for (i = 0; i < ofs->numfs; i++) { 155007f1e596SAmir Goldstein if (ofs->fs[i].sb == sb) 155107f1e596SAmir Goldstein return i; 15525148626bSAmir Goldstein } 15535148626bSAmir Goldstein 15549df085f3SAmir Goldstein if (!ovl_lower_uuid_ok(ofs, &sb->s_uuid)) { 15557e63c87fSAmir Goldstein bad_uuid = true; 1556b0e0f697SAmir Goldstein if (ofs->config.xino == OVL_XINO_AUTO) { 1557b0e0f697SAmir Goldstein ofs->config.xino = OVL_XINO_OFF; 1558b0e0f697SAmir Goldstein warn = true; 1559b0e0f697SAmir Goldstein } 15607e63c87fSAmir Goldstein if (ofs->config.index || ofs->config.nfs_export) { 15619df085f3SAmir Goldstein ofs->config.index = false; 15629df085f3SAmir Goldstein ofs->config.nfs_export = false; 1563b0e0f697SAmir Goldstein warn = true; 1564b0e0f697SAmir Goldstein } 1565b0e0f697SAmir Goldstein if (warn) { 1566b0e0f697SAmir Goldstein pr_warn("%s uuid detected in lower fs '%pd2', falling back to xino=%s,index=off,nfs_export=off.\n", 15677e63c87fSAmir Goldstein uuid_is_null(&sb->s_uuid) ? "null" : 15687e63c87fSAmir Goldstein "conflicting", 1569b0e0f697SAmir Goldstein path->dentry, ovl_xino_str[ofs->config.xino]); 15709df085f3SAmir Goldstein } 15717e63c87fSAmir Goldstein } 15729df085f3SAmir Goldstein 15735148626bSAmir Goldstein err = get_anon_bdev(&dev); 15745148626bSAmir Goldstein if (err) { 15751bd0a3aeSlijiazi pr_err("failed to get anonymous bdev for lowerpath\n"); 15765148626bSAmir Goldstein return err; 15775148626bSAmir Goldstein } 15785148626bSAmir Goldstein 157907f1e596SAmir Goldstein ofs->fs[ofs->numfs].sb = sb; 158007f1e596SAmir Goldstein ofs->fs[ofs->numfs].pseudo_dev = dev; 158107f1e596SAmir Goldstein ofs->fs[ofs->numfs].bad_uuid = bad_uuid; 15825148626bSAmir Goldstein 158307f1e596SAmir Goldstein return ofs->numfs++; 15845148626bSAmir Goldstein } 15855148626bSAmir Goldstein 158694375f9dSAmir Goldstein static int ovl_get_layers(struct super_block *sb, struct ovl_fs *ofs, 1587b8e42a65SMiklos Szeredi struct path *stack, unsigned int numlower, 1588b8e42a65SMiklos Szeredi struct ovl_layer *layers) 1589520d7c86SMiklos Szeredi { 1590520d7c86SMiklos Szeredi int err; 1591520d7c86SMiklos Szeredi unsigned int i; 1592520d7c86SMiklos Szeredi 1593520d7c86SMiklos Szeredi err = -ENOMEM; 159407f1e596SAmir Goldstein ofs->fs = kcalloc(numlower + 1, sizeof(struct ovl_sb), GFP_KERNEL); 159507f1e596SAmir Goldstein if (ofs->fs == NULL) 15965148626bSAmir Goldstein goto out; 15975148626bSAmir Goldstein 159807f1e596SAmir Goldstein /* idx/fsid 0 are reserved for upper fs even with lower only overlay */ 159907f1e596SAmir Goldstein ofs->numfs++; 160007f1e596SAmir Goldstein 160107f1e596SAmir Goldstein /* 1602b7bf9908SAmir Goldstein * All lower layers that share the same fs as upper layer, use the same 1603b7bf9908SAmir Goldstein * pseudo_dev as upper layer. Allocate fs[0].pseudo_dev even for lower 1604b7bf9908SAmir Goldstein * only overlay to simplify ovl_fs_free(). 16051b81ddddSAmir Goldstein * is_lower will be set if upper fs is shared with a lower layer. 160607f1e596SAmir Goldstein */ 1607b7bf9908SAmir Goldstein err = get_anon_bdev(&ofs->fs[0].pseudo_dev); 1608b7bf9908SAmir Goldstein if (err) { 1609b7bf9908SAmir Goldstein pr_err("failed to get anonymous bdev for upper fs\n"); 1610b7bf9908SAmir Goldstein goto out; 1611b7bf9908SAmir Goldstein } 1612b7bf9908SAmir Goldstein 161308f4c7c8SMiklos Szeredi if (ovl_upper_mnt(ofs)) { 161408f4c7c8SMiklos Szeredi ofs->fs[0].sb = ovl_upper_mnt(ofs)->mnt_sb; 16151b81ddddSAmir Goldstein ofs->fs[0].is_lower = false; 161607f1e596SAmir Goldstein } 161707f1e596SAmir Goldstein 1618520d7c86SMiklos Szeredi for (i = 0; i < numlower; i++) { 1619520d7c86SMiklos Szeredi struct vfsmount *mnt; 1620146d62e5SAmir Goldstein struct inode *trap; 16215148626bSAmir Goldstein int fsid; 1622520d7c86SMiklos Szeredi 16239df085f3SAmir Goldstein err = fsid = ovl_get_fsid(ofs, &stack[i]); 16245148626bSAmir Goldstein if (err < 0) 1625520d7c86SMiklos Szeredi goto out; 1626520d7c86SMiklos Szeredi 162724f14009Syoungjun /* 162824f14009Syoungjun * Check if lower root conflicts with this overlay layers before 162924f14009Syoungjun * checking if it is in-use as upperdir/workdir of "another" 163024f14009Syoungjun * mount, because we do not bother to check in ovl_is_inuse() if 163124f14009Syoungjun * the upperdir/workdir is in fact in-use by our 163224f14009Syoungjun * upperdir/workdir. 163324f14009Syoungjun */ 1634146d62e5SAmir Goldstein err = ovl_setup_trap(sb, stack[i].dentry, &trap, "lowerdir"); 1635146d62e5SAmir Goldstein if (err) 1636146d62e5SAmir Goldstein goto out; 1637146d62e5SAmir Goldstein 16380be0bfd2SAmir Goldstein if (ovl_is_inuse(stack[i].dentry)) { 16390be0bfd2SAmir Goldstein err = ovl_report_in_use(ofs, "lowerdir"); 164024f14009Syoungjun if (err) { 164124f14009Syoungjun iput(trap); 16420be0bfd2SAmir Goldstein goto out; 16430be0bfd2SAmir Goldstein } 164424f14009Syoungjun } 16450be0bfd2SAmir Goldstein 1646520d7c86SMiklos Szeredi mnt = clone_private_mount(&stack[i]); 1647520d7c86SMiklos Szeredi err = PTR_ERR(mnt); 1648520d7c86SMiklos Szeredi if (IS_ERR(mnt)) { 16491bd0a3aeSlijiazi pr_err("failed to clone lowerpath\n"); 1650146d62e5SAmir Goldstein iput(trap); 1651520d7c86SMiklos Szeredi goto out; 1652520d7c86SMiklos Szeredi } 16535148626bSAmir Goldstein 1654520d7c86SMiklos Szeredi /* 1655520d7c86SMiklos Szeredi * Make lower layers R/O. That way fchmod/fchown on lower file 1656520d7c86SMiklos Szeredi * will fail instead of modifying lower fs. 1657520d7c86SMiklos Szeredi */ 1658520d7c86SMiklos Szeredi mnt->mnt_flags |= MNT_READONLY | MNT_NOATIME; 1659520d7c86SMiklos Szeredi 166013464165SMiklos Szeredi layers[ofs->numlayer].trap = trap; 166113464165SMiklos Szeredi layers[ofs->numlayer].mnt = mnt; 166213464165SMiklos Szeredi layers[ofs->numlayer].idx = ofs->numlayer; 166313464165SMiklos Szeredi layers[ofs->numlayer].fsid = fsid; 166413464165SMiklos Szeredi layers[ofs->numlayer].fs = &ofs->fs[fsid]; 166594375f9dSAmir Goldstein ofs->numlayer++; 16661b81ddddSAmir Goldstein ofs->fs[fsid].is_lower = true; 1667520d7c86SMiklos Szeredi } 1668e487d889SAmir Goldstein 1669795939a9SAmir Goldstein /* 1670795939a9SAmir Goldstein * When all layers on same fs, overlay can use real inode numbers. 1671926e94d7SAmir Goldstein * With mount option "xino=<on|auto>", mounter declares that there are 1672926e94d7SAmir Goldstein * enough free high bits in underlying fs to hold the unique fsid. 1673795939a9SAmir Goldstein * If overlayfs does encounter underlying inodes using the high xino 1674795939a9SAmir Goldstein * bits reserved for fsid, it emits a warning and uses the original 1675dfe51d47SAmir Goldstein * inode number or a non persistent inode number allocated from a 1676dfe51d47SAmir Goldstein * dedicated range. 1677795939a9SAmir Goldstein */ 167808f4c7c8SMiklos Szeredi if (ofs->numfs - !ovl_upper_mnt(ofs) == 1) { 16790f831ec8SAmir Goldstein if (ofs->config.xino == OVL_XINO_ON) 16800f831ec8SAmir Goldstein pr_info("\"xino=on\" is useless with all layers on same fs, ignore.\n"); 16810f831ec8SAmir Goldstein ofs->xino_mode = 0; 168253afcd31SAmir Goldstein } else if (ofs->config.xino == OVL_XINO_OFF) { 168353afcd31SAmir Goldstein ofs->xino_mode = -1; 1684926e94d7SAmir Goldstein } else if (ofs->xino_mode < 0) { 1685795939a9SAmir Goldstein /* 168607f1e596SAmir Goldstein * This is a roundup of number of bits needed for encoding 1687dfe51d47SAmir Goldstein * fsid, where fsid 0 is reserved for upper fs (even with 1688dfe51d47SAmir Goldstein * lower only overlay) +1 extra bit is reserved for the non 1689dfe51d47SAmir Goldstein * persistent inode number range that is used for resolving 1690dfe51d47SAmir Goldstein * xino lower bits overflow. 1691795939a9SAmir Goldstein */ 1692dfe51d47SAmir Goldstein BUILD_BUG_ON(ilog2(OVL_MAX_STACK) > 30); 1693dfe51d47SAmir Goldstein ofs->xino_mode = ilog2(ofs->numfs - 1) + 2; 1694795939a9SAmir Goldstein } 1695795939a9SAmir Goldstein 16960f831ec8SAmir Goldstein if (ofs->xino_mode > 0) { 16971bd0a3aeSlijiazi pr_info("\"xino\" feature enabled using %d upper inode bits.\n", 16980f831ec8SAmir Goldstein ofs->xino_mode); 1699795939a9SAmir Goldstein } 1700e487d889SAmir Goldstein 1701520d7c86SMiklos Szeredi err = 0; 1702520d7c86SMiklos Szeredi out: 1703520d7c86SMiklos Szeredi return err; 1704520d7c86SMiklos Szeredi } 1705520d7c86SMiklos Szeredi 17064155c10aSMiklos Szeredi static struct ovl_entry *ovl_get_lowerstack(struct super_block *sb, 1707b8e42a65SMiklos Szeredi const char *lower, unsigned int numlower, 1708b8e42a65SMiklos Szeredi struct ovl_fs *ofs, struct ovl_layer *layers) 170953dbb0b4SMiklos Szeredi { 171053dbb0b4SMiklos Szeredi int err; 17114155c10aSMiklos Szeredi struct path *stack = NULL; 17125522c9c7SAmir Goldstein struct ovl_path *lowerstack; 1713b8e42a65SMiklos Szeredi unsigned int i; 17144155c10aSMiklos Szeredi struct ovl_entry *oe; 171553dbb0b4SMiklos Szeredi 1716b8e42a65SMiklos Szeredi if (!ofs->config.upperdir && numlower == 1) { 17171bd0a3aeSlijiazi pr_err("at least 2 lowerdir are needed while upperdir nonexistent\n"); 1718b8e42a65SMiklos Szeredi return ERR_PTR(-EINVAL); 171953dbb0b4SMiklos Szeredi } 172053dbb0b4SMiklos Szeredi 1721b8e42a65SMiklos Szeredi stack = kcalloc(numlower, sizeof(struct path), GFP_KERNEL); 172253dbb0b4SMiklos Szeredi if (!stack) 1723b8e42a65SMiklos Szeredi return ERR_PTR(-ENOMEM); 172453dbb0b4SMiklos Szeredi 172553dbb0b4SMiklos Szeredi err = -EINVAL; 1726b8e42a65SMiklos Szeredi for (i = 0; i < numlower; i++) { 1727b8e42a65SMiklos Szeredi err = ovl_lower_dir(lower, &stack[i], ofs, &sb->s_stack_depth); 172853dbb0b4SMiklos Szeredi if (err) 17294155c10aSMiklos Szeredi goto out_err; 173053dbb0b4SMiklos Szeredi 173153dbb0b4SMiklos Szeredi lower = strchr(lower, '\0') + 1; 173253dbb0b4SMiklos Szeredi } 173353dbb0b4SMiklos Szeredi 173453dbb0b4SMiklos Szeredi err = -EINVAL; 173553dbb0b4SMiklos Szeredi sb->s_stack_depth++; 173653dbb0b4SMiklos Szeredi if (sb->s_stack_depth > FILESYSTEM_MAX_STACK_DEPTH) { 17371bd0a3aeSlijiazi pr_err("maximum fs stacking depth exceeded\n"); 17384155c10aSMiklos Szeredi goto out_err; 173953dbb0b4SMiklos Szeredi } 174053dbb0b4SMiklos Szeredi 1741b8e42a65SMiklos Szeredi err = ovl_get_layers(sb, ofs, stack, numlower, layers); 17424155c10aSMiklos Szeredi if (err) 17434155c10aSMiklos Szeredi goto out_err; 17444155c10aSMiklos Szeredi 17454155c10aSMiklos Szeredi err = -ENOMEM; 17464155c10aSMiklos Szeredi oe = ovl_alloc_entry(numlower); 17474155c10aSMiklos Szeredi if (!oe) 17484155c10aSMiklos Szeredi goto out_err; 17494155c10aSMiklos Szeredi 17505522c9c7SAmir Goldstein lowerstack = ovl_lowerstack(oe); 17514155c10aSMiklos Szeredi for (i = 0; i < numlower; i++) { 17525522c9c7SAmir Goldstein lowerstack[i].dentry = dget(stack[i].dentry); 17535522c9c7SAmir Goldstein lowerstack[i].layer = &ofs->layers[i+1]; 17544155c10aSMiklos Szeredi } 175553dbb0b4SMiklos Szeredi 175653dbb0b4SMiklos Szeredi out: 175753dbb0b4SMiklos Szeredi for (i = 0; i < numlower; i++) 175853dbb0b4SMiklos Szeredi path_put(&stack[i]); 175953dbb0b4SMiklos Szeredi kfree(stack); 17604155c10aSMiklos Szeredi 17614155c10aSMiklos Szeredi return oe; 17624155c10aSMiklos Szeredi 17634155c10aSMiklos Szeredi out_err: 17644155c10aSMiklos Szeredi oe = ERR_PTR(err); 176553dbb0b4SMiklos Szeredi goto out; 176653dbb0b4SMiklos Szeredi } 176753dbb0b4SMiklos Szeredi 1768146d62e5SAmir Goldstein /* 1769146d62e5SAmir Goldstein * Check if this layer root is a descendant of: 1770146d62e5SAmir Goldstein * - another layer of this overlayfs instance 1771146d62e5SAmir Goldstein * - upper/work dir of any overlayfs instance 1772146d62e5SAmir Goldstein */ 17730be0bfd2SAmir Goldstein static int ovl_check_layer(struct super_block *sb, struct ovl_fs *ofs, 1774708fa015SMiklos Szeredi struct dentry *dentry, const char *name, 1775708fa015SMiklos Szeredi bool is_lower) 1776146d62e5SAmir Goldstein { 17779179c21dSMiklos Szeredi struct dentry *next = dentry, *parent; 1778146d62e5SAmir Goldstein int err = 0; 1779146d62e5SAmir Goldstein 17809179c21dSMiklos Szeredi if (!dentry) 1781146d62e5SAmir Goldstein return 0; 1782146d62e5SAmir Goldstein 1783146d62e5SAmir Goldstein parent = dget_parent(next); 17849179c21dSMiklos Szeredi 17859179c21dSMiklos Szeredi /* Walk back ancestors to root (inclusive) looking for traps */ 17869179c21dSMiklos Szeredi while (!err && parent != next) { 1787708fa015SMiklos Szeredi if (is_lower && ovl_lookup_trap_inode(sb, parent)) { 1788146d62e5SAmir Goldstein err = -ELOOP; 17891bd0a3aeSlijiazi pr_err("overlapping %s path\n", name); 17900be0bfd2SAmir Goldstein } else if (ovl_is_inuse(parent)) { 17910be0bfd2SAmir Goldstein err = ovl_report_in_use(ofs, name); 1792146d62e5SAmir Goldstein } 1793146d62e5SAmir Goldstein next = parent; 17949179c21dSMiklos Szeredi parent = dget_parent(next); 17959179c21dSMiklos Szeredi dput(next); 1796146d62e5SAmir Goldstein } 1797146d62e5SAmir Goldstein 17989179c21dSMiklos Szeredi dput(parent); 1799146d62e5SAmir Goldstein 1800146d62e5SAmir Goldstein return err; 1801146d62e5SAmir Goldstein } 1802146d62e5SAmir Goldstein 1803146d62e5SAmir Goldstein /* 1804146d62e5SAmir Goldstein * Check if any of the layers or work dirs overlap. 1805146d62e5SAmir Goldstein */ 1806146d62e5SAmir Goldstein static int ovl_check_overlapping_layers(struct super_block *sb, 1807146d62e5SAmir Goldstein struct ovl_fs *ofs) 1808146d62e5SAmir Goldstein { 1809146d62e5SAmir Goldstein int i, err; 1810146d62e5SAmir Goldstein 181108f4c7c8SMiklos Szeredi if (ovl_upper_mnt(ofs)) { 181208f4c7c8SMiklos Szeredi err = ovl_check_layer(sb, ofs, ovl_upper_mnt(ofs)->mnt_root, 1813708fa015SMiklos Szeredi "upperdir", false); 1814146d62e5SAmir Goldstein if (err) 1815146d62e5SAmir Goldstein return err; 1816146d62e5SAmir Goldstein 1817146d62e5SAmir Goldstein /* 1818146d62e5SAmir Goldstein * Checking workbasedir avoids hitting ovl_is_inuse(parent) of 1819146d62e5SAmir Goldstein * this instance and covers overlapping work and index dirs, 1820146d62e5SAmir Goldstein * unless work or index dir have been moved since created inside 1821146d62e5SAmir Goldstein * workbasedir. In that case, we already have their traps in 1822146d62e5SAmir Goldstein * inode cache and we will catch that case on lookup. 1823146d62e5SAmir Goldstein */ 1824708fa015SMiklos Szeredi err = ovl_check_layer(sb, ofs, ofs->workbasedir, "workdir", 1825708fa015SMiklos Szeredi false); 1826146d62e5SAmir Goldstein if (err) 1827146d62e5SAmir Goldstein return err; 1828146d62e5SAmir Goldstein } 1829146d62e5SAmir Goldstein 183094375f9dSAmir Goldstein for (i = 1; i < ofs->numlayer; i++) { 18310be0bfd2SAmir Goldstein err = ovl_check_layer(sb, ofs, 183294375f9dSAmir Goldstein ofs->layers[i].mnt->mnt_root, 1833708fa015SMiklos Szeredi "lowerdir", true); 1834146d62e5SAmir Goldstein if (err) 1835146d62e5SAmir Goldstein return err; 1836146d62e5SAmir Goldstein } 1837146d62e5SAmir Goldstein 1838146d62e5SAmir Goldstein return 0; 1839146d62e5SAmir Goldstein } 1840146d62e5SAmir Goldstein 18412effc5c2SAmir Goldstein static struct dentry *ovl_get_root(struct super_block *sb, 18422effc5c2SAmir Goldstein struct dentry *upperdentry, 18432effc5c2SAmir Goldstein struct ovl_entry *oe) 18442effc5c2SAmir Goldstein { 18452effc5c2SAmir Goldstein struct dentry *root; 18465522c9c7SAmir Goldstein struct ovl_path *lowerpath = ovl_lowerstack(oe); 184762c832edSAmir Goldstein unsigned long ino = d_inode(lowerpath->dentry)->i_ino; 184862c832edSAmir Goldstein int fsid = lowerpath->layer->fsid; 184962c832edSAmir Goldstein struct ovl_inode_params oip = { 185062c832edSAmir Goldstein .upperdentry = upperdentry, 185162c832edSAmir Goldstein .lowerpath = lowerpath, 185262c832edSAmir Goldstein }; 18532effc5c2SAmir Goldstein 18542effc5c2SAmir Goldstein root = d_make_root(ovl_new_inode(sb, S_IFDIR, 0)); 18552effc5c2SAmir Goldstein if (!root) 18562effc5c2SAmir Goldstein return NULL; 18572effc5c2SAmir Goldstein 18582effc5c2SAmir Goldstein root->d_fsdata = oe; 18592effc5c2SAmir Goldstein 18602effc5c2SAmir Goldstein if (upperdentry) { 186162c832edSAmir Goldstein /* Root inode uses upper st_ino/i_ino */ 186262c832edSAmir Goldstein ino = d_inode(upperdentry)->i_ino; 186362c832edSAmir Goldstein fsid = 0; 18642effc5c2SAmir Goldstein ovl_dentry_set_upper_alias(root); 1865610afc0bSMiklos Szeredi if (ovl_is_impuredir(sb, upperdentry)) 18662effc5c2SAmir Goldstein ovl_set_flag(OVL_IMPURE, d_inode(root)); 18672effc5c2SAmir Goldstein } 18682effc5c2SAmir Goldstein 18692effc5c2SAmir Goldstein /* Root is always merge -> can have whiteouts */ 18702effc5c2SAmir Goldstein ovl_set_flag(OVL_WHITEOUTS, d_inode(root)); 18712effc5c2SAmir Goldstein ovl_dentry_set_flag(OVL_E_CONNECTED, root); 18722effc5c2SAmir Goldstein ovl_set_upperdata(d_inode(root)); 187362c832edSAmir Goldstein ovl_inode_init(d_inode(root), &oip, ino, fsid); 1874b07d5cc9SAmir Goldstein ovl_dentry_init_flags(root, upperdentry, DCACHE_OP_WEAK_REVALIDATE); 18752effc5c2SAmir Goldstein 18762effc5c2SAmir Goldstein return root; 18772effc5c2SAmir Goldstein } 18782effc5c2SAmir Goldstein 1879e9be9d5eSMiklos Szeredi static int ovl_fill_super(struct super_block *sb, void *data, int silent) 1880e9be9d5eSMiklos Szeredi { 188133006cdfSKees Cook struct path upperpath = { }; 1882e9be9d5eSMiklos Szeredi struct dentry *root_dentry; 18834155c10aSMiklos Szeredi struct ovl_entry *oe; 1884ad204488SMiklos Szeredi struct ovl_fs *ofs; 1885b8e42a65SMiklos Szeredi struct ovl_layer *layers; 188651f8f3c4SKonstantin Khlebnikov struct cred *cred; 1887b8e42a65SMiklos Szeredi char *splitlower = NULL; 1888b8e42a65SMiklos Szeredi unsigned int numlower; 1889e9be9d5eSMiklos Szeredi int err; 1890e9be9d5eSMiklos Szeredi 18919efb069dSMiklos Szeredi err = -EIO; 18929efb069dSMiklos Szeredi if (WARN_ON(sb->s_user_ns != current_user_ns())) 18939efb069dSMiklos Szeredi goto out; 18949efb069dSMiklos Szeredi 1895f4288844SMiklos Szeredi sb->s_d_op = &ovl_dentry_operations; 1896f4288844SMiklos Szeredi 1897f45827e8SErez Zadok err = -ENOMEM; 1898ad204488SMiklos Szeredi ofs = kzalloc(sizeof(struct ovl_fs), GFP_KERNEL); 1899ad204488SMiklos Szeredi if (!ofs) 1900e9be9d5eSMiklos Szeredi goto out; 1901e9be9d5eSMiklos Szeredi 1902d7b49b10SChengguang Xu err = -ENOMEM; 1903ad204488SMiklos Szeredi ofs->creator_cred = cred = prepare_creds(); 1904c6fe6254SMiklos Szeredi if (!cred) 1905c6fe6254SMiklos Szeredi goto out_err; 1906c6fe6254SMiklos Szeredi 1907c21c839bSChengguang Xu /* Is there a reason anyone would want not to share whiteouts? */ 1908c21c839bSChengguang Xu ofs->share_whiteout = true; 1909c21c839bSChengguang Xu 1910ad204488SMiklos Szeredi ofs->config.index = ovl_index_def; 19115830fb6bSPavel Tikhomirov ofs->config.uuid = true; 1912f168f109SAmir Goldstein ofs->config.nfs_export = ovl_nfs_export_def; 1913795939a9SAmir Goldstein ofs->config.xino = ovl_xino_def(); 1914d5791044SVivek Goyal ofs->config.metacopy = ovl_metacopy_def; 1915ad204488SMiklos Szeredi err = ovl_parse_opt((char *) data, &ofs->config); 1916f45827e8SErez Zadok if (err) 1917a9075cdbSMiklos Szeredi goto out_err; 1918f45827e8SErez Zadok 1919e9be9d5eSMiklos Szeredi err = -EINVAL; 1920ad204488SMiklos Szeredi if (!ofs->config.lowerdir) { 192107f2af7bSKonstantin Khlebnikov if (!silent) 19221bd0a3aeSlijiazi pr_err("missing 'lowerdir'\n"); 1923a9075cdbSMiklos Szeredi goto out_err; 192453a08cb9SMiklos Szeredi } 192553a08cb9SMiklos Szeredi 1926b8e42a65SMiklos Szeredi err = -ENOMEM; 1927b8e42a65SMiklos Szeredi splitlower = kstrdup(ofs->config.lowerdir, GFP_KERNEL); 1928b8e42a65SMiklos Szeredi if (!splitlower) 1929b8e42a65SMiklos Szeredi goto out_err; 1930b8e42a65SMiklos Szeredi 1931d7b49b10SChengguang Xu err = -EINVAL; 1932b8e42a65SMiklos Szeredi numlower = ovl_split_lowerdirs(splitlower); 1933b8e42a65SMiklos Szeredi if (numlower > OVL_MAX_STACK) { 1934b8e42a65SMiklos Szeredi pr_err("too many lower directories, limit is %d\n", 1935b8e42a65SMiklos Szeredi OVL_MAX_STACK); 1936b8e42a65SMiklos Szeredi goto out_err; 1937b8e42a65SMiklos Szeredi } 1938b8e42a65SMiklos Szeredi 1939d7b49b10SChengguang Xu err = -ENOMEM; 1940b8e42a65SMiklos Szeredi layers = kcalloc(numlower + 1, sizeof(struct ovl_layer), GFP_KERNEL); 1941b8e42a65SMiklos Szeredi if (!layers) 1942b8e42a65SMiklos Szeredi goto out_err; 1943b8e42a65SMiklos Szeredi 1944b8e42a65SMiklos Szeredi ofs->layers = layers; 1945b8e42a65SMiklos Szeredi /* Layer 0 is reserved for upper even if there's no upper */ 1946b8e42a65SMiklos Szeredi ofs->numlayer = 1; 1947b8e42a65SMiklos Szeredi 194853a08cb9SMiklos Szeredi sb->s_stack_depth = 0; 1949cf9a6784SMiklos Szeredi sb->s_maxbytes = MAX_LFS_FILESIZE; 19504d314f78SAmir Goldstein atomic_long_set(&ofs->last_ino, 1); 19514f119628SWilliam Dean /* Assume underlying fs uses 32bit inodes unless proven otherwise */ 195253afcd31SAmir Goldstein if (ofs->config.xino != OVL_XINO_OFF) { 19530f831ec8SAmir Goldstein ofs->xino_mode = BITS_PER_LONG - 32; 195453afcd31SAmir Goldstein if (!ofs->xino_mode) { 195553afcd31SAmir Goldstein pr_warn("xino not supported on 32bit kernel, falling back to xino=off.\n"); 195653afcd31SAmir Goldstein ofs->config.xino = OVL_XINO_OFF; 195753afcd31SAmir Goldstein } 195853afcd31SAmir Goldstein } 1959795939a9SAmir Goldstein 1960146d62e5SAmir Goldstein /* alloc/destroy_inode needed for setting up traps in inode cache */ 1961146d62e5SAmir Goldstein sb->s_op = &ovl_super_operations; 1962146d62e5SAmir Goldstein 1963ad204488SMiklos Szeredi if (ofs->config.upperdir) { 1964335d3fc5SSargun Dhillon struct super_block *upper_sb; 1965335d3fc5SSargun Dhillon 1966d7b49b10SChengguang Xu err = -EINVAL; 1967ad204488SMiklos Szeredi if (!ofs->config.workdir) { 19681bd0a3aeSlijiazi pr_err("missing 'workdir'\n"); 1969a9075cdbSMiklos Szeredi goto out_err; 1970e9be9d5eSMiklos Szeredi } 1971e9be9d5eSMiklos Szeredi 1972b8e42a65SMiklos Szeredi err = ovl_get_upper(sb, ofs, &layers[0], &upperpath); 197321a3b317SMiklos Szeredi if (err) 1974a9075cdbSMiklos Szeredi goto out_err; 1975d719e8f2SMiklos Szeredi 1976335d3fc5SSargun Dhillon upper_sb = ovl_upper_mnt(ofs)->mnt_sb; 1977335d3fc5SSargun Dhillon if (!ovl_should_sync(ofs)) { 1978335d3fc5SSargun Dhillon ofs->errseq = errseq_sample(&upper_sb->s_wb_err); 1979335d3fc5SSargun Dhillon if (errseq_check(&upper_sb->s_wb_err, ofs->errseq)) { 1980335d3fc5SSargun Dhillon err = -EIO; 1981335d3fc5SSargun Dhillon pr_err("Cannot mount volatile when upperdir has an unseen error. Sync upperdir fs to clear state.\n"); 1982335d3fc5SSargun Dhillon goto out_err; 1983335d3fc5SSargun Dhillon } 1984335d3fc5SSargun Dhillon } 1985335d3fc5SSargun Dhillon 1986146d62e5SAmir Goldstein err = ovl_get_workdir(sb, ofs, &upperpath); 19878ed61dc3SMiklos Szeredi if (err) 1988a9075cdbSMiklos Szeredi goto out_err; 1989c6fe6254SMiklos Szeredi 1990ad204488SMiklos Szeredi if (!ofs->workdir) 19911751e8a6SLinus Torvalds sb->s_flags |= SB_RDONLY; 19926e88256eSMiklos Szeredi 1993335d3fc5SSargun Dhillon sb->s_stack_depth = upper_sb->s_stack_depth; 1994335d3fc5SSargun Dhillon sb->s_time_gran = upper_sb->s_time_gran; 199521765194SVivek Goyal } 1996b8e42a65SMiklos Szeredi oe = ovl_get_lowerstack(sb, splitlower, numlower, ofs, layers); 19974155c10aSMiklos Szeredi err = PTR_ERR(oe); 19984155c10aSMiklos Szeredi if (IS_ERR(oe)) 1999a9075cdbSMiklos Szeredi goto out_err; 2000e9be9d5eSMiklos Szeredi 200171cbad7eShujianyang /* If the upper fs is nonexistent, we mark overlayfs r/o too */ 200208f4c7c8SMiklos Szeredi if (!ovl_upper_mnt(ofs)) 20031751e8a6SLinus Torvalds sb->s_flags |= SB_RDONLY; 2004e9be9d5eSMiklos Szeredi 20055830fb6bSPavel Tikhomirov if (!ofs->config.uuid && ofs->numfs > 1) { 20065830fb6bSPavel Tikhomirov pr_warn("The uuid=off requires a single fs for lower and upper, falling back to uuid=on.\n"); 20075830fb6bSPavel Tikhomirov ofs->config.uuid = true; 20085830fb6bSPavel Tikhomirov } 20095830fb6bSPavel Tikhomirov 2010470c1563SAmir Goldstein if (!ovl_force_readonly(ofs) && ofs->config.index) { 2011146d62e5SAmir Goldstein err = ovl_get_indexdir(sb, ofs, oe, &upperpath); 201254fb347eSAmir Goldstein if (err) 20134155c10aSMiklos Szeredi goto out_free_oe; 20146e88256eSMiklos Szeredi 2015972d0093SAmir Goldstein /* Force r/o mount with no index dir */ 201620396365SAmir Goldstein if (!ofs->indexdir) 20171751e8a6SLinus Torvalds sb->s_flags |= SB_RDONLY; 201802bcd157SAmir Goldstein } 201902bcd157SAmir Goldstein 2020146d62e5SAmir Goldstein err = ovl_check_overlapping_layers(sb, ofs); 2021146d62e5SAmir Goldstein if (err) 2022146d62e5SAmir Goldstein goto out_free_oe; 2023146d62e5SAmir Goldstein 2024972d0093SAmir Goldstein /* Show index=off in /proc/mounts for forced r/o mount */ 2025f168f109SAmir Goldstein if (!ofs->indexdir) { 2026ad204488SMiklos Szeredi ofs->config.index = false; 202708f4c7c8SMiklos Szeredi if (ovl_upper_mnt(ofs) && ofs->config.nfs_export) { 20281bd0a3aeSlijiazi pr_warn("NFS export requires an index dir, falling back to nfs_export=off.\n"); 2029f168f109SAmir Goldstein ofs->config.nfs_export = false; 2030f168f109SAmir Goldstein } 2031f168f109SAmir Goldstein } 203202bcd157SAmir Goldstein 2033d5791044SVivek Goyal if (ofs->config.metacopy && ofs->config.nfs_export) { 20341bd0a3aeSlijiazi pr_warn("NFS export is not supported with metadata only copy up, falling back to nfs_export=off.\n"); 2035d5791044SVivek Goyal ofs->config.nfs_export = false; 2036d5791044SVivek Goyal } 2037d5791044SVivek Goyal 20388383f174SAmir Goldstein if (ofs->config.nfs_export) 20398383f174SAmir Goldstein sb->s_export_op = &ovl_export_operations; 20408383f174SAmir Goldstein 204151f8f3c4SKonstantin Khlebnikov /* Never override disk quota limits or use reserved space */ 204251f8f3c4SKonstantin Khlebnikov cap_lower(cred->cap_effective, CAP_SYS_RESOURCE); 204351f8f3c4SKonstantin Khlebnikov 2044655042ccSVivek Goyal sb->s_magic = OVERLAYFS_SUPER_MAGIC; 20452d2f2d73SMiklos Szeredi sb->s_xattr = ofs->config.userxattr ? ovl_user_xattr_handlers : 20462d2f2d73SMiklos Szeredi ovl_trusted_xattr_handlers; 2047ad204488SMiklos Szeredi sb->s_fs_info = ofs; 2048de2a4a50SMiklos Szeredi sb->s_flags |= SB_POSIXACL; 204932b1924bSKonstantin Khlebnikov sb->s_iflags |= SB_I_SKIP_SYNC; 2050655042ccSVivek Goyal 2051c6fe6254SMiklos Szeredi err = -ENOMEM; 20522effc5c2SAmir Goldstein root_dentry = ovl_get_root(sb, upperpath.dentry, oe); 2053e9be9d5eSMiklos Szeredi if (!root_dentry) 20544155c10aSMiklos Szeredi goto out_free_oe; 2055e9be9d5eSMiklos Szeredi 2056e9be9d5eSMiklos Szeredi mntput(upperpath.mnt); 2057b8e42a65SMiklos Szeredi kfree(splitlower); 2058ed06e069SMiklos Szeredi 2059e9be9d5eSMiklos Szeredi sb->s_root = root_dentry; 2060e9be9d5eSMiklos Szeredi 2061e9be9d5eSMiklos Szeredi return 0; 2062e9be9d5eSMiklos Szeredi 20634155c10aSMiklos Szeredi out_free_oe: 2064*163db0daSAmir Goldstein ovl_free_entry(oe); 20654155c10aSMiklos Szeredi out_err: 2066b8e42a65SMiklos Szeredi kfree(splitlower); 2067e9be9d5eSMiklos Szeredi path_put(&upperpath); 2068ad204488SMiklos Szeredi ovl_free_fs(ofs); 2069e9be9d5eSMiklos Szeredi out: 2070e9be9d5eSMiklos Szeredi return err; 2071e9be9d5eSMiklos Szeredi } 2072e9be9d5eSMiklos Szeredi 2073e9be9d5eSMiklos Szeredi static struct dentry *ovl_mount(struct file_system_type *fs_type, int flags, 2074e9be9d5eSMiklos Szeredi const char *dev_name, void *raw_data) 2075e9be9d5eSMiklos Szeredi { 2076e9be9d5eSMiklos Szeredi return mount_nodev(fs_type, flags, raw_data, ovl_fill_super); 2077e9be9d5eSMiklos Szeredi } 2078e9be9d5eSMiklos Szeredi 2079e9be9d5eSMiklos Szeredi static struct file_system_type ovl_fs_type = { 2080e9be9d5eSMiklos Szeredi .owner = THIS_MODULE, 2081ef94b186SMiklos Szeredi .name = "overlay", 2082459c7c56SMiklos Szeredi .fs_flags = FS_USERNS_MOUNT, 2083e9be9d5eSMiklos Szeredi .mount = ovl_mount, 2084e9be9d5eSMiklos Szeredi .kill_sb = kill_anon_super, 2085e9be9d5eSMiklos Szeredi }; 2086ef94b186SMiklos Szeredi MODULE_ALIAS_FS("overlay"); 2087e9be9d5eSMiklos Szeredi 208813cf199dSAmir Goldstein static void ovl_inode_init_once(void *foo) 208913cf199dSAmir Goldstein { 209013cf199dSAmir Goldstein struct ovl_inode *oi = foo; 209113cf199dSAmir Goldstein 209213cf199dSAmir Goldstein inode_init_once(&oi->vfs_inode); 209313cf199dSAmir Goldstein } 209413cf199dSAmir Goldstein 2095e9be9d5eSMiklos Szeredi static int __init ovl_init(void) 2096e9be9d5eSMiklos Szeredi { 209713cf199dSAmir Goldstein int err; 209813cf199dSAmir Goldstein 209913cf199dSAmir Goldstein ovl_inode_cachep = kmem_cache_create("ovl_inode", 210013cf199dSAmir Goldstein sizeof(struct ovl_inode), 0, 210113cf199dSAmir Goldstein (SLAB_RECLAIM_ACCOUNT| 210213cf199dSAmir Goldstein SLAB_MEM_SPREAD|SLAB_ACCOUNT), 210313cf199dSAmir Goldstein ovl_inode_init_once); 210413cf199dSAmir Goldstein if (ovl_inode_cachep == NULL) 210513cf199dSAmir Goldstein return -ENOMEM; 210613cf199dSAmir Goldstein 21072406a307SJiufei Xue err = ovl_aio_request_cache_init(); 21082406a307SJiufei Xue if (!err) { 210913cf199dSAmir Goldstein err = register_filesystem(&ovl_fs_type); 21102406a307SJiufei Xue if (!err) 21112406a307SJiufei Xue return 0; 21122406a307SJiufei Xue 21132406a307SJiufei Xue ovl_aio_request_cache_destroy(); 21142406a307SJiufei Xue } 211513cf199dSAmir Goldstein kmem_cache_destroy(ovl_inode_cachep); 211613cf199dSAmir Goldstein 211713cf199dSAmir Goldstein return err; 2118e9be9d5eSMiklos Szeredi } 2119e9be9d5eSMiklos Szeredi 2120e9be9d5eSMiklos Szeredi static void __exit ovl_exit(void) 2121e9be9d5eSMiklos Szeredi { 2122e9be9d5eSMiklos Szeredi unregister_filesystem(&ovl_fs_type); 212313cf199dSAmir Goldstein 212413cf199dSAmir Goldstein /* 212513cf199dSAmir Goldstein * Make sure all delayed rcu free inodes are flushed before we 212613cf199dSAmir Goldstein * destroy cache. 212713cf199dSAmir Goldstein */ 212813cf199dSAmir Goldstein rcu_barrier(); 212913cf199dSAmir Goldstein kmem_cache_destroy(ovl_inode_cachep); 21302406a307SJiufei Xue ovl_aio_request_cache_destroy(); 2131e9be9d5eSMiklos Szeredi } 2132e9be9d5eSMiklos Szeredi 2133e9be9d5eSMiklos Szeredi module_init(ovl_init); 2134e9be9d5eSMiklos Szeredi module_exit(ovl_exit); 2135