1 #include <linux/reiserfs_fs.h> 2 #include <linux/errno.h> 3 #include <linux/fs.h> 4 #include <linux/pagemap.h> 5 #include <linux/xattr.h> 6 #include <linux/slab.h> 7 #include <linux/reiserfs_xattr.h> 8 #include <linux/security.h> 9 #include <asm/uaccess.h> 10 11 static int 12 security_get(struct dentry *dentry, const char *name, void *buffer, size_t size, 13 int handler_flags) 14 { 15 if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX)) 16 return -EINVAL; 17 18 if (IS_PRIVATE(dentry->d_inode)) 19 return -EPERM; 20 21 return reiserfs_xattr_get(dentry->d_inode, name, buffer, size); 22 } 23 24 static int 25 security_set(struct dentry *dentry, const char *name, const void *buffer, 26 size_t size, int flags, int handler_flags) 27 { 28 if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX)) 29 return -EINVAL; 30 31 if (IS_PRIVATE(dentry->d_inode)) 32 return -EPERM; 33 34 return reiserfs_xattr_set(dentry->d_inode, name, buffer, size, flags); 35 } 36 37 static size_t security_list(struct dentry *dentry, char *list, size_t list_len, 38 const char *name, size_t namelen, int handler_flags) 39 { 40 const size_t len = namelen + 1; 41 42 if (IS_PRIVATE(dentry->d_inode)) 43 return 0; 44 45 if (list && len <= list_len) { 46 memcpy(list, name, namelen); 47 list[namelen] = '\0'; 48 } 49 50 return len; 51 } 52 53 /* Initializes the security context for a new inode and returns the number 54 * of blocks needed for the transaction. If successful, reiserfs_security 55 * must be released using reiserfs_security_free when the caller is done. */ 56 int reiserfs_security_init(struct inode *dir, struct inode *inode, 57 struct reiserfs_security_handle *sec) 58 { 59 int blocks = 0; 60 int error; 61 62 sec->name = NULL; 63 64 /* Don't add selinux attributes on xattrs - they'll never get used */ 65 if (IS_PRIVATE(dir)) 66 return 0; 67 68 error = security_inode_init_security(inode, dir, &sec->name, 69 &sec->value, &sec->length); 70 if (error) { 71 if (error == -EOPNOTSUPP) 72 error = 0; 73 74 sec->name = NULL; 75 sec->value = NULL; 76 sec->length = 0; 77 return error; 78 } 79 80 if (sec->length && reiserfs_xattrs_initialized(inode->i_sb)) { 81 blocks = reiserfs_xattr_jcreate_nblocks(inode) + 82 reiserfs_xattr_nblocks(inode, sec->length); 83 /* We don't want to count the directories twice if we have 84 * a default ACL. */ 85 REISERFS_I(inode)->i_flags |= i_has_xattr_dir; 86 } 87 return blocks; 88 } 89 90 int reiserfs_security_write(struct reiserfs_transaction_handle *th, 91 struct inode *inode, 92 struct reiserfs_security_handle *sec) 93 { 94 int error; 95 if (strlen(sec->name) < sizeof(XATTR_SECURITY_PREFIX)) 96 return -EINVAL; 97 98 error = reiserfs_xattr_set_handle(th, inode, sec->name, sec->value, 99 sec->length, XATTR_CREATE); 100 if (error == -ENODATA || error == -EOPNOTSUPP) 101 error = 0; 102 103 return error; 104 } 105 106 void reiserfs_security_free(struct reiserfs_security_handle *sec) 107 { 108 kfree(sec->name); 109 kfree(sec->value); 110 sec->name = NULL; 111 sec->value = NULL; 112 } 113 114 const struct xattr_handler reiserfs_xattr_security_handler = { 115 .prefix = XATTR_SECURITY_PREFIX, 116 .get = security_get, 117 .set = security_set, 118 .list = security_list, 119 }; 120