nfs3acl.c 6.27 KB
Newer Older
1
2
3
4
5
6
/*
 * Process version 3 NFSACL requests.
 *
 * Copyright (C) 2002-2003 Andreas Gruenbacher <agruen@suse.de>
 */

7
8
#include "nfsd.h"
/* FIXME: nfsacl.h is a broken header */
9
#include <linux/nfsacl.h>
10
#include <linux/gfp.h>
11
12
#include "cache.h"
#include "xdr3.h"
13
#include "vfs.h"
14
15
16
17
18
19

#define RETURN_STATUS(st)	{ resp->status = (st); return (st); }

/*
 * NULL call.
 */
Al Viro's avatar
Al Viro committed
20
static __be32
21
22
23
24
25
26
27
28
nfsd3_proc_null(struct svc_rqst *rqstp, void *argp, void *resp)
{
	return nfs_ok;
}

/*
 * Get the Access and/or Default ACL of a file.
 */
Al Viro's avatar
Al Viro committed
29
static __be32 nfsd3_proc_getacl(struct svc_rqst * rqstp,
30
31
32
		struct nfsd3_getaclargs *argp, struct nfsd3_getaclres *resp)
{
	struct posix_acl *acl;
33
34
	struct inode *inode;
	svc_fh *fh;
35
	__be32 nfserr = 0;
36
37

	fh = fh_copy(&resp->fh, &argp->fh);
Miklos Szeredi's avatar
Miklos Szeredi committed
38
39
	nfserr = fh_verify(rqstp, &resp->fh, 0, NFSD_MAY_NOP);
	if (nfserr)
40
		RETURN_STATUS(nfserr);
41

42
	inode = d_inode(fh->fh_dentry);
43

44
	if (argp->mask & ~NFS_ACL_MASK)
45
46
47
48
		RETURN_STATUS(nfserr_inval);
	resp->mask = argp->mask;

	if (resp->mask & (NFS_ACL|NFS_ACLCNT)) {
49
		acl = get_acl(inode, ACL_TYPE_ACCESS);
50
51
52
53
		if (acl == NULL) {
			/* Solaris returns the inode's minimum ACL. */
			acl = posix_acl_from_mode(inode->i_mode, GFP_KERNEL);
		}
54
55
56
57
		if (IS_ERR(acl)) {
			nfserr = nfserrno(PTR_ERR(acl));
			goto fail;
		}
58
59
60
61
62
		resp->acl_access = acl;
	}
	if (resp->mask & (NFS_DFACL|NFS_DFACLCNT)) {
		/* Check how Solaris handles requests for the Default ACL
		   of a non-directory! */
63
		acl = get_acl(inode, ACL_TYPE_DEFAULT);
64
		if (IS_ERR(acl)) {
65
66
			nfserr = nfserrno(PTR_ERR(acl));
			goto fail;
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
		}
		resp->acl_default = acl;
	}

	/* resp->acl_{access,default} are released in nfs3svc_release_getacl. */
	RETURN_STATUS(0);

fail:
	posix_acl_release(resp->acl_access);
	posix_acl_release(resp->acl_default);
	RETURN_STATUS(nfserr);
}

/*
 * Set the Access and/or Default ACL of a file.
 */
Al Viro's avatar
Al Viro committed
83
static __be32 nfsd3_proc_setacl(struct svc_rqst * rqstp,
84
85
86
		struct nfsd3_setaclargs *argp,
		struct nfsd3_attrstat *resp)
{
87
	struct inode *inode;
88
	svc_fh *fh;
89
	__be32 nfserr = 0;
90
	int error;
91
92

	fh = fh_copy(&resp->fh, &argp->fh);
Miklos Szeredi's avatar
Miklos Szeredi committed
93
	nfserr = fh_verify(rqstp, &resp->fh, 0, NFSD_MAY_SATTR);
94
95
	if (nfserr)
		goto out;
96

97
	inode = d_inode(fh->fh_dentry);
98

99
100
101
102
	error = fh_want_write(fh);
	if (error)
		goto out_errno;

103
104
105
	fh_lock(fh);

	error = set_posix_acl(inode, ACL_TYPE_ACCESS, argp->acl_access);
106
	if (error)
107
108
		goto out_drop_lock;
	error = set_posix_acl(inode, ACL_TYPE_DEFAULT, argp->acl_default);
109

110
111
out_drop_lock:
	fh_unlock(fh);
112
113
114
115
	fh_drop_write(fh);
out_errno:
	nfserr = nfserrno(error);
out:
116
117
118
119
120
121
122
123
124
125
	/* argp->acl_{access,default} may have been allocated in
	   nfs3svc_decode_setaclargs. */
	posix_acl_release(argp->acl_access);
	posix_acl_release(argp->acl_default);
	RETURN_STATUS(nfserr);
}

/*
 * XDR decode functions
 */
126
static int nfs3svc_decode_getaclargs(struct svc_rqst *rqstp, __be32 *p,
127
128
		struct nfsd3_getaclargs *args)
{
129
130
	p = nfs3svc_decode_fh(p, &args->fh);
	if (!p)
131
132
133
134
135
136
137
		return 0;
	args->mask = ntohl(*p); p++;

	return xdr_argsize_check(rqstp, p);
}


138
static int nfs3svc_decode_setaclargs(struct svc_rqst *rqstp, __be32 *p,
139
140
141
142
143
144
		struct nfsd3_setaclargs *args)
{
	struct kvec *head = rqstp->rq_arg.head;
	unsigned int base;
	int n;

145
146
	p = nfs3svc_decode_fh(p, &args->fh);
	if (!p)
147
148
		return 0;
	args->mask = ntohl(*p++);
149
	if (args->mask & ~NFS_ACL_MASK ||
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
	    !xdr_argsize_check(rqstp, p))
		return 0;

	base = (char *)p - (char *)head->iov_base;
	n = nfsacl_decode(&rqstp->rq_arg, base, NULL,
			  (args->mask & NFS_ACL) ?
			  &args->acl_access : NULL);
	if (n > 0)
		n = nfsacl_decode(&rqstp->rq_arg, base + n, NULL,
				  (args->mask & NFS_DFACL) ?
				  &args->acl_default : NULL);
	return (n > 0);
}

/*
 * XDR encode functions
 */

/* GETACL */
169
static int nfs3svc_encode_getaclres(struct svc_rqst *rqstp, __be32 *p,
170
171
172
173
174
		struct nfsd3_getaclres *resp)
{
	struct dentry *dentry = resp->fh.fh_dentry;

	p = nfs3svc_encode_post_op_attr(rqstp, p, &resp->fh);
175
176
	if (resp->status == 0 && dentry && d_really_is_positive(dentry)) {
		struct inode *inode = d_inode(dentry);
177
178
179
		struct kvec *head = rqstp->rq_res.head;
		unsigned int base;
		int n;
180
		int w;
181
182
183
184
185
186

		*p++ = htonl(resp->mask);
		if (!xdr_ressize_check(rqstp, p))
			return 0;
		base = (char *)p - (char *)head->iov_base;

187
188
189
		rqstp->rq_res.page_len = w = nfsacl_size(
			(resp->mask & NFS_ACL)   ? resp->acl_access  : NULL,
			(resp->mask & NFS_DFACL) ? resp->acl_default : NULL);
190
		while (w > 0) {
191
			if (!*(rqstp->rq_next_page++))
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
				return 0;
			w -= PAGE_SIZE;
		}

		n = nfsacl_encode(&rqstp->rq_res, base, inode,
				  resp->acl_access,
				  resp->mask & NFS_ACL, 0);
		if (n > 0)
			n = nfsacl_encode(&rqstp->rq_res, base + n, inode,
					  resp->acl_default,
					  resp->mask & NFS_DFACL,
					  NFS_ACL_DEFAULT);
		if (n <= 0)
			return 0;
	} else
		if (!xdr_ressize_check(rqstp, p))
			return 0;

	return 1;
}

/* SETACL */
214
static int nfs3svc_encode_setaclres(struct svc_rqst *rqstp, __be32 *p,
215
216
217
218
219
220
221
222
223
224
		struct nfsd3_attrstat *resp)
{
	p = nfs3svc_encode_post_op_attr(rqstp, p, &resp->fh);

	return xdr_ressize_check(rqstp, p);
}

/*
 * XDR release functions
 */
225
static int nfs3svc_release_getacl(struct svc_rqst *rqstp, __be32 *p,
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
		struct nfsd3_getaclres *resp)
{
	fh_put(&resp->fh);
	posix_acl_release(resp->acl_access);
	posix_acl_release(resp->acl_default);
	return 1;
}

#define nfs3svc_decode_voidargs		NULL
#define nfs3svc_release_void		NULL
#define nfsd3_setaclres			nfsd3_attrstat
#define nfsd3_voidres			nfsd3_voidargs
struct nfsd3_voidargs { int dummy; };

#define PROC(name, argt, rest, relt, cache, respsize)	\
 { (svc_procfunc) nfsd3_proc_##name,		\
   (kxdrproc_t) nfs3svc_decode_##argt##args,	\
   (kxdrproc_t) nfs3svc_encode_##rest##res,	\
   (kxdrproc_t) nfs3svc_release_##relt,		\
   sizeof(struct nfsd3_##argt##args),		\
   sizeof(struct nfsd3_##rest##res),		\
   0,						\
   cache,					\
   respsize,					\
 }

#define ST 1		/* status*/
#define AT 21		/* attributes */
#define pAT (1+AT)	/* post attributes - conditional */
#define ACL (1+NFS_ACL_MAX_ENTRIES*3)  /* Access Control List */

static struct svc_procedure		nfsd_acl_procedures3[] = {
  PROC(null,	void,		void,		void,	  RC_NOCACHE, ST),
  PROC(getacl,	getacl,		getacl,		getacl,	  RC_NOCACHE, ST+1+2*(1+ACL)),
  PROC(setacl,	setacl,		setacl,		fhandle,  RC_NOCACHE, ST+pAT),
};

struct svc_version	nfsd_acl_version3 = {
		.vs_vers	= 3,
		.vs_nproc	= 3,
		.vs_proc	= nfsd_acl_procedures3,
		.vs_dispatch	= nfsd_dispatch,
		.vs_xdrsize	= NFS3_SVC_XDRSIZE,
};