1 // SPDX-License-Identifier: GPL-2.0-only
3 * Copyright (C) 2001, 2002 Sistina Software (UK) Limited.
4 * Copyright (C) 2004 - 2006 Red Hat, Inc. All rights reserved.
6 * This file is released under the GPL.
11 #include <linux/module.h>
12 #include <linux/vmalloc.h>
13 #include <linux/miscdevice.h>
14 #include <linux/sched/mm.h>
15 #include <linux/init.h>
16 #include <linux/wait.h>
17 #include <linux/slab.h>
18 #include <linux/rbtree.h>
19 #include <linux/dm-ioctl.h>
20 #include <linux/hdreg.h>
21 #include <linux/compat.h>
22 #include <linux/nospec.h>
24 #include <linux/uaccess.h>
25 #include <linux/ima.h>
27 #define DM_MSG_PREFIX "ioctl"
28 #define DM_DRIVER_EMAIL "dm-devel@lists.linux.dev"
32 * poll will wait until the global event number is greater than
35 volatile unsigned int global_event_nr
;
39 *---------------------------------------------------------------
40 * The ioctl interface needs to be able to look up devices by
42 *---------------------------------------------------------------
45 struct rb_node name_node
;
46 struct rb_node uuid_node
;
52 struct mapped_device
*md
;
53 struct dm_table
*new_map
;
58 struct dm_target_versions
*vers
, *old_vers
;
64 static struct rb_root name_rb_tree
= RB_ROOT
;
65 static struct rb_root uuid_rb_tree
= RB_ROOT
;
67 static void dm_hash_remove_all(bool keep_open_devices
, bool mark_deferred
, bool only_deferred
);
70 * Guards access to both hash tables.
72 static DECLARE_RWSEM(_hash_lock
);
75 * Protects use of mdptr to obtain hash cell name and uuid from mapped device.
77 static DEFINE_MUTEX(dm_hash_cells_mutex
);
79 static void dm_hash_exit(void)
81 dm_hash_remove_all(false, false, false);
85 *---------------------------------------------------------------
86 * Code for looking up a device by name
87 *---------------------------------------------------------------
89 static struct hash_cell
*__get_name_cell(const char *str
)
91 struct rb_node
*n
= name_rb_tree
.rb_node
;
94 struct hash_cell
*hc
= container_of(n
, struct hash_cell
, name_node
);
97 c
= strcmp(hc
->name
, str
);
102 n
= c
>= 0 ? n
->rb_left
: n
->rb_right
;
108 static struct hash_cell
*__get_uuid_cell(const char *str
)
110 struct rb_node
*n
= uuid_rb_tree
.rb_node
;
113 struct hash_cell
*hc
= container_of(n
, struct hash_cell
, uuid_node
);
116 c
= strcmp(hc
->uuid
, str
);
121 n
= c
>= 0 ? n
->rb_left
: n
->rb_right
;
127 static void __unlink_name(struct hash_cell
*hc
)
130 hc
->name_set
= false;
131 rb_erase(&hc
->name_node
, &name_rb_tree
);
135 static void __unlink_uuid(struct hash_cell
*hc
)
138 hc
->uuid_set
= false;
139 rb_erase(&hc
->uuid_node
, &uuid_rb_tree
);
143 static void __link_name(struct hash_cell
*new_hc
)
145 struct rb_node
**n
, *parent
;
147 __unlink_name(new_hc
);
149 new_hc
->name_set
= true;
151 n
= &name_rb_tree
.rb_node
;
155 struct hash_cell
*hc
= container_of(*n
, struct hash_cell
, name_node
);
158 c
= strcmp(hc
->name
, new_hc
->name
);
161 n
= c
>= 0 ? &hc
->name_node
.rb_left
: &hc
->name_node
.rb_right
;
164 rb_link_node(&new_hc
->name_node
, parent
, n
);
165 rb_insert_color(&new_hc
->name_node
, &name_rb_tree
);
168 static void __link_uuid(struct hash_cell
*new_hc
)
170 struct rb_node
**n
, *parent
;
172 __unlink_uuid(new_hc
);
174 new_hc
->uuid_set
= true;
176 n
= &uuid_rb_tree
.rb_node
;
180 struct hash_cell
*hc
= container_of(*n
, struct hash_cell
, uuid_node
);
183 c
= strcmp(hc
->uuid
, new_hc
->uuid
);
186 n
= c
> 0 ? &hc
->uuid_node
.rb_left
: &hc
->uuid_node
.rb_right
;
189 rb_link_node(&new_hc
->uuid_node
, parent
, n
);
190 rb_insert_color(&new_hc
->uuid_node
, &uuid_rb_tree
);
193 static struct hash_cell
*__get_dev_cell(uint64_t dev
)
195 struct mapped_device
*md
;
196 struct hash_cell
*hc
;
198 md
= dm_get_md(huge_decode_dev(dev
));
202 hc
= dm_get_mdptr(md
);
212 *---------------------------------------------------------------
213 * Inserting, removing and renaming a device.
214 *---------------------------------------------------------------
216 static struct hash_cell
*alloc_cell(const char *name
, const char *uuid
,
217 struct mapped_device
*md
)
219 struct hash_cell
*hc
;
221 hc
= kmalloc(sizeof(*hc
), GFP_KERNEL
);
225 hc
->name
= kstrdup(name
, GFP_KERNEL
);
235 hc
->uuid
= kstrdup(uuid
, GFP_KERNEL
);
243 hc
->name_set
= hc
->uuid_set
= false;
249 static void free_cell(struct hash_cell
*hc
)
259 * The kdev_t and uuid of a device can never change once it is
260 * initially inserted.
262 static int dm_hash_insert(const char *name
, const char *uuid
, struct mapped_device
*md
)
264 struct hash_cell
*cell
, *hc
;
267 * Allocate the new cells.
269 cell
= alloc_cell(name
, uuid
, md
);
274 * Insert the cell into both hash tables.
276 down_write(&_hash_lock
);
277 hc
= __get_name_cell(name
);
286 hc
= __get_uuid_cell(uuid
);
295 mutex_lock(&dm_hash_cells_mutex
);
296 dm_set_mdptr(md
, cell
);
297 mutex_unlock(&dm_hash_cells_mutex
);
298 up_write(&_hash_lock
);
303 up_write(&_hash_lock
);
308 static struct dm_table
*__hash_remove(struct hash_cell
*hc
)
310 struct dm_table
*table
;
313 lockdep_assert_held(&_hash_lock
);
315 /* remove from the dev trees */
318 mutex_lock(&dm_hash_cells_mutex
);
319 dm_set_mdptr(hc
->md
, NULL
);
320 mutex_unlock(&dm_hash_cells_mutex
);
322 table
= dm_get_live_table(hc
->md
, &srcu_idx
);
324 dm_table_event(table
);
325 dm_put_live_table(hc
->md
, srcu_idx
);
336 static void dm_hash_remove_all(bool keep_open_devices
, bool mark_deferred
, bool only_deferred
)
340 struct hash_cell
*hc
;
341 struct mapped_device
*md
;
347 down_write(&_hash_lock
);
349 for (n
= rb_first(&name_rb_tree
); n
; n
= rb_next(n
)) {
350 hc
= container_of(n
, struct hash_cell
, name_node
);
354 if (keep_open_devices
&&
355 dm_lock_for_deletion(md
, mark_deferred
, only_deferred
)) {
361 t
= __hash_remove(hc
);
363 up_write(&_hash_lock
);
369 dm_ima_measure_on_device_remove(md
, true);
371 if (likely(keep_open_devices
))
374 dm_destroy_immediate(md
);
377 * Some mapped devices may be using other mapped
378 * devices, so repeat until we make no further
379 * progress. If a new mapped device is created
380 * here it will also get removed.
385 up_write(&_hash_lock
);
388 DMWARN("remove_all left %d open device(s)", dev_skipped
);
392 * Set the uuid of a hash_cell that isn't already set.
394 static void __set_cell_uuid(struct hash_cell
*hc
, char *new_uuid
)
396 mutex_lock(&dm_hash_cells_mutex
);
398 mutex_unlock(&dm_hash_cells_mutex
);
404 * Changes the name of a hash_cell and returns the old name for
405 * the caller to free.
407 static char *__change_cell_name(struct hash_cell
*hc
, char *new_name
)
412 * Rename and move the name cell.
417 mutex_lock(&dm_hash_cells_mutex
);
419 mutex_unlock(&dm_hash_cells_mutex
);
426 static struct mapped_device
*dm_hash_rename(struct dm_ioctl
*param
,
429 char *new_data
, *old_name
= NULL
;
430 struct hash_cell
*hc
;
431 struct dm_table
*table
;
432 struct mapped_device
*md
;
433 unsigned int change_uuid
= (param
->flags
& DM_UUID_FLAG
) ? 1 : 0;
439 new_data
= kstrdup(new, GFP_KERNEL
);
441 return ERR_PTR(-ENOMEM
);
443 down_write(&_hash_lock
);
449 hc
= __get_uuid_cell(new);
451 hc
= __get_name_cell(new);
454 DMERR("Unable to change %s on mapped device %s to one that already exists: %s",
455 change_uuid
? "uuid" : "name",
458 up_write(&_hash_lock
);
460 return ERR_PTR(-EBUSY
);
464 * Is there such a device as 'old' ?
466 hc
= __get_name_cell(param
->name
);
468 DMERR("Unable to rename non-existent device, %s to %s%s",
469 param
->name
, change_uuid
? "uuid " : "", new);
470 up_write(&_hash_lock
);
472 return ERR_PTR(-ENXIO
);
476 * Does this device already have a uuid?
478 if (change_uuid
&& hc
->uuid
) {
479 DMERR("Unable to change uuid of mapped device %s to %s "
480 "because uuid is already set to %s",
481 param
->name
, new, hc
->uuid
);
483 up_write(&_hash_lock
);
485 return ERR_PTR(-EINVAL
);
489 __set_cell_uuid(hc
, new_data
);
491 old_name
= __change_cell_name(hc
, new_data
);
494 * Wake up any dm event waiters.
496 table
= dm_get_live_table(hc
->md
, &srcu_idx
);
498 dm_table_event(table
);
499 dm_put_live_table(hc
->md
, srcu_idx
);
501 if (!dm_kobject_uevent(hc
->md
, KOBJ_CHANGE
, param
->event_nr
, false))
502 param
->flags
|= DM_UEVENT_GENERATED_FLAG
;
506 dm_ima_measure_on_device_rename(md
);
508 up_write(&_hash_lock
);
514 void dm_deferred_remove(void)
516 dm_hash_remove_all(true, false, true);
520 *---------------------------------------------------------------
521 * Implementation of the ioctl commands
522 *---------------------------------------------------------------
525 * All the ioctl commands get dispatched to functions with this
528 typedef int (*ioctl_fn
)(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
);
530 static int remove_all(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
532 dm_hash_remove_all(true, !!(param
->flags
& DM_DEFERRED_REMOVE
), false);
533 param
->data_size
= 0;
538 * Round up the ptr to an 8-byte boundary.
541 static inline size_t align_val(size_t val
)
543 return (val
+ ALIGN_MASK
) & ~ALIGN_MASK
;
545 static inline void *align_ptr(void *ptr
)
547 return (void *)align_val((size_t)ptr
);
551 * Retrieves the data payload buffer from an already allocated
554 static void *get_result_buffer(struct dm_ioctl
*param
, size_t param_size
,
557 param
->data_start
= align_ptr(param
+ 1) - (void *) param
;
559 if (param
->data_start
< param_size
)
560 *len
= param_size
- param
->data_start
;
564 return ((void *) param
) + param
->data_start
;
567 static bool filter_device(struct hash_cell
*hc
, const char *pfx_name
, const char *pfx_uuid
)
570 size_t val_len
, pfx_len
;
573 val_len
= strlen(val
);
574 pfx_len
= strnlen(pfx_name
, DM_NAME_LEN
);
575 if (pfx_len
> val_len
)
577 if (memcmp(val
, pfx_name
, pfx_len
))
580 val
= hc
->uuid
? hc
->uuid
: "";
581 val_len
= strlen(val
);
582 pfx_len
= strnlen(pfx_uuid
, DM_UUID_LEN
);
583 if (pfx_len
> val_len
)
585 if (memcmp(val
, pfx_uuid
, pfx_len
))
591 static int list_devices(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
594 struct hash_cell
*hc
;
595 size_t len
, needed
= 0;
596 struct gendisk
*disk
;
597 struct dm_name_list
*orig_nl
, *nl
, *old_nl
= NULL
;
600 down_write(&_hash_lock
);
603 * Loop through all the devices working out how much
606 for (n
= rb_first(&name_rb_tree
); n
; n
= rb_next(n
)) {
607 hc
= container_of(n
, struct hash_cell
, name_node
);
608 if (!filter_device(hc
, param
->name
, param
->uuid
))
610 needed
+= align_val(offsetof(struct dm_name_list
, name
) + strlen(hc
->name
) + 1);
611 needed
+= align_val(sizeof(uint32_t) * 2);
612 if (param
->flags
& DM_UUID_FLAG
&& hc
->uuid
)
613 needed
+= align_val(strlen(hc
->uuid
) + 1);
617 * Grab our output buffer.
619 nl
= orig_nl
= get_result_buffer(param
, param_size
, &len
);
620 if (len
< needed
|| len
< sizeof(nl
->dev
)) {
621 param
->flags
|= DM_BUFFER_FULL_FLAG
;
624 param
->data_size
= param
->data_start
+ needed
;
626 nl
->dev
= 0; /* Flags no data */
629 * Now loop through filling out the names.
631 for (n
= rb_first(&name_rb_tree
); n
; n
= rb_next(n
)) {
634 hc
= container_of(n
, struct hash_cell
, name_node
);
635 if (!filter_device(hc
, param
->name
, param
->uuid
))
638 old_nl
->next
= (uint32_t) ((void *) nl
-
640 disk
= dm_disk(hc
->md
);
641 nl
->dev
= huge_encode_dev(disk_devt(disk
));
643 strcpy(nl
->name
, hc
->name
);
646 event_nr
= align_ptr(nl
->name
+ strlen(hc
->name
) + 1);
647 event_nr
[0] = dm_get_event_nr(hc
->md
);
649 uuid_ptr
= align_ptr(event_nr
+ 2);
650 if (param
->flags
& DM_UUID_FLAG
) {
652 event_nr
[1] |= DM_NAME_LIST_FLAG_HAS_UUID
;
653 strcpy(uuid_ptr
, hc
->uuid
);
654 uuid_ptr
= align_ptr(uuid_ptr
+ strlen(hc
->uuid
) + 1);
656 event_nr
[1] |= DM_NAME_LIST_FLAG_DOESNT_HAVE_UUID
;
662 * If mismatch happens, security may be compromised due to buffer
663 * overflow, so it's better to crash.
665 BUG_ON((char *)nl
- (char *)orig_nl
!= needed
);
668 up_write(&_hash_lock
);
672 static void list_version_get_needed(struct target_type
*tt
, void *needed_param
)
674 size_t *needed
= needed_param
;
676 *needed
+= sizeof(struct dm_target_versions
);
677 *needed
+= strlen(tt
->name
) + 1;
678 *needed
+= ALIGN_MASK
;
681 static void list_version_get_info(struct target_type
*tt
, void *param
)
683 struct vers_iter
*info
= param
;
685 /* Check space - it might have changed since the first iteration */
686 if ((char *)info
->vers
+ sizeof(tt
->version
) + strlen(tt
->name
) + 1 > info
->end
) {
687 info
->flags
= DM_BUFFER_FULL_FLAG
;
692 info
->old_vers
->next
= (uint32_t) ((void *)info
->vers
- (void *)info
->old_vers
);
694 info
->vers
->version
[0] = tt
->version
[0];
695 info
->vers
->version
[1] = tt
->version
[1];
696 info
->vers
->version
[2] = tt
->version
[2];
697 info
->vers
->next
= 0;
698 strcpy(info
->vers
->name
, tt
->name
);
700 info
->old_vers
= info
->vers
;
701 info
->vers
= align_ptr((void *)(info
->vers
+ 1) + strlen(tt
->name
) + 1);
704 static int __list_versions(struct dm_ioctl
*param
, size_t param_size
, const char *name
)
706 size_t len
, needed
= 0;
707 struct dm_target_versions
*vers
;
708 struct vers_iter iter_info
;
709 struct target_type
*tt
= NULL
;
712 tt
= dm_get_target_type(name
);
718 * Loop through all the devices working out how much
722 dm_target_iterate(list_version_get_needed
, &needed
);
724 list_version_get_needed(tt
, &needed
);
727 * Grab our output buffer.
729 vers
= get_result_buffer(param
, param_size
, &len
);
731 param
->flags
|= DM_BUFFER_FULL_FLAG
;
734 param
->data_size
= param
->data_start
+ needed
;
736 iter_info
.param_size
= param_size
;
737 iter_info
.old_vers
= NULL
;
738 iter_info
.vers
= vers
;
740 iter_info
.end
= (char *)vers
+ needed
;
743 * Now loop through filling out the names & versions.
746 dm_target_iterate(list_version_get_info
, &iter_info
);
748 list_version_get_info(tt
, &iter_info
);
749 param
->flags
|= iter_info
.flags
;
753 dm_put_target_type(tt
);
757 static int list_versions(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
759 return __list_versions(param
, param_size
, NULL
);
762 static int get_target_version(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
764 return __list_versions(param
, param_size
, param
->name
);
767 static int check_name(const char *name
)
769 if (strchr(name
, '/')) {
770 DMERR("device name cannot contain '/'");
774 if (strcmp(name
, DM_CONTROL_NODE
) == 0 ||
775 strcmp(name
, ".") == 0 ||
776 strcmp(name
, "..") == 0) {
777 DMERR("device name cannot be \"%s\", \".\", or \"..\"", DM_CONTROL_NODE
);
785 * On successful return, the caller must not attempt to acquire
786 * _hash_lock without first calling dm_put_live_table, because dm_table_destroy
787 * waits for this dm_put_live_table and could be called under this lock.
789 static struct dm_table
*dm_get_inactive_table(struct mapped_device
*md
, int *srcu_idx
)
791 struct hash_cell
*hc
;
792 struct dm_table
*table
= NULL
;
794 /* increment rcu count, we don't care about the table pointer */
795 dm_get_live_table(md
, srcu_idx
);
797 down_read(&_hash_lock
);
798 hc
= dm_get_mdptr(md
);
800 DMERR("device has been removed from the dev hash table.");
807 up_read(&_hash_lock
);
812 static struct dm_table
*dm_get_live_or_inactive_table(struct mapped_device
*md
,
813 struct dm_ioctl
*param
,
816 return (param
->flags
& DM_QUERY_INACTIVE_TABLE_FLAG
) ?
817 dm_get_inactive_table(md
, srcu_idx
) : dm_get_live_table(md
, srcu_idx
);
821 * Fills in a dm_ioctl structure, ready for sending back to
824 static void __dev_status(struct mapped_device
*md
, struct dm_ioctl
*param
)
826 struct gendisk
*disk
= dm_disk(md
);
827 struct dm_table
*table
;
830 param
->flags
&= ~(DM_SUSPEND_FLAG
| DM_READONLY_FLAG
|
831 DM_ACTIVE_PRESENT_FLAG
| DM_INTERNAL_SUSPEND_FLAG
);
833 if (dm_suspended_md(md
))
834 param
->flags
|= DM_SUSPEND_FLAG
;
836 if (dm_suspended_internally_md(md
))
837 param
->flags
|= DM_INTERNAL_SUSPEND_FLAG
;
839 if (dm_test_deferred_remove_flag(md
))
840 param
->flags
|= DM_DEFERRED_REMOVE
;
842 param
->dev
= huge_encode_dev(disk_devt(disk
));
845 * Yes, this will be out of date by the time it gets back
846 * to userland, but it is still very useful for
849 param
->open_count
= dm_open_count(md
);
851 param
->event_nr
= dm_get_event_nr(md
);
852 param
->target_count
= 0;
854 table
= dm_get_live_table(md
, &srcu_idx
);
856 if (!(param
->flags
& DM_QUERY_INACTIVE_TABLE_FLAG
)) {
857 if (get_disk_ro(disk
))
858 param
->flags
|= DM_READONLY_FLAG
;
859 param
->target_count
= table
->num_targets
;
862 param
->flags
|= DM_ACTIVE_PRESENT_FLAG
;
864 dm_put_live_table(md
, srcu_idx
);
866 if (param
->flags
& DM_QUERY_INACTIVE_TABLE_FLAG
) {
869 table
= dm_get_inactive_table(md
, &srcu_idx
);
871 if (!(dm_table_get_mode(table
) & BLK_OPEN_WRITE
))
872 param
->flags
|= DM_READONLY_FLAG
;
873 param
->target_count
= table
->num_targets
;
875 dm_put_live_table(md
, srcu_idx
);
879 static int dev_create(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
881 int r
, m
= DM_ANY_MINOR
;
882 struct mapped_device
*md
;
884 r
= check_name(param
->name
);
888 if (param
->flags
& DM_PERSISTENT_DEV_FLAG
)
889 m
= MINOR(huge_decode_dev(param
->dev
));
891 r
= dm_create(m
, &md
);
895 r
= dm_hash_insert(param
->name
, *param
->uuid
? param
->uuid
: NULL
, md
);
902 param
->flags
&= ~DM_INACTIVE_PRESENT_FLAG
;
904 __dev_status(md
, param
);
912 * Always use UUID for lookups if it's present, otherwise use name or dev.
914 static struct hash_cell
*__find_device_hash_cell(struct dm_ioctl
*param
)
916 struct hash_cell
*hc
= NULL
;
919 if (*param
->name
|| param
->dev
) {
920 DMERR("Invalid ioctl structure: uuid %s, name %s, dev %llx",
921 param
->uuid
, param
->name
, (unsigned long long)param
->dev
);
925 hc
= __get_uuid_cell(param
->uuid
);
928 } else if (*param
->name
) {
930 DMERR("Invalid ioctl structure: name %s, dev %llx",
931 param
->name
, (unsigned long long)param
->dev
);
935 hc
= __get_name_cell(param
->name
);
938 } else if (param
->dev
) {
939 hc
= __get_dev_cell(param
->dev
);
946 * Sneakily write in both the name and the uuid
947 * while we have the cell.
949 strscpy(param
->name
, hc
->name
, sizeof(param
->name
));
951 strscpy(param
->uuid
, hc
->uuid
, sizeof(param
->uuid
));
953 param
->uuid
[0] = '\0';
956 param
->flags
|= DM_INACTIVE_PRESENT_FLAG
;
958 param
->flags
&= ~DM_INACTIVE_PRESENT_FLAG
;
963 static struct mapped_device
*find_device(struct dm_ioctl
*param
)
965 struct hash_cell
*hc
;
966 struct mapped_device
*md
= NULL
;
968 down_read(&_hash_lock
);
969 hc
= __find_device_hash_cell(param
);
972 up_read(&_hash_lock
);
977 static int dev_remove(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
979 struct hash_cell
*hc
;
980 struct mapped_device
*md
;
984 down_write(&_hash_lock
);
985 hc
= __find_device_hash_cell(param
);
988 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table.");
989 up_write(&_hash_lock
);
996 * Ensure the device is not open and nothing further can open it.
998 r
= dm_lock_for_deletion(md
, !!(param
->flags
& DM_DEFERRED_REMOVE
), false);
1000 if (r
== -EBUSY
&& param
->flags
& DM_DEFERRED_REMOVE
) {
1001 up_write(&_hash_lock
);
1005 DMDEBUG_LIMIT("unable to remove open device %s", hc
->name
);
1006 up_write(&_hash_lock
);
1011 t
= __hash_remove(hc
);
1012 up_write(&_hash_lock
);
1016 dm_table_destroy(t
);
1019 param
->flags
&= ~DM_DEFERRED_REMOVE
;
1021 dm_ima_measure_on_device_remove(md
, false);
1023 if (!dm_kobject_uevent(md
, KOBJ_REMOVE
, param
->event_nr
, false))
1024 param
->flags
|= DM_UEVENT_GENERATED_FLAG
;
1032 * Check a string doesn't overrun the chunk of
1033 * memory we copied from userland.
1035 static int invalid_str(char *str
, void *end
)
1037 while ((void *) str
< end
)
1044 static int dev_rename(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1047 char *new_data
= (char *) param
+ param
->data_start
;
1048 struct mapped_device
*md
;
1049 unsigned int change_uuid
= (param
->flags
& DM_UUID_FLAG
) ? 1 : 0;
1051 if (new_data
< param
->data
||
1052 invalid_str(new_data
, (void *) param
+ param_size
) || !*new_data
||
1053 strlen(new_data
) > (change_uuid
? DM_UUID_LEN
- 1 : DM_NAME_LEN
- 1)) {
1054 DMERR("Invalid new mapped device name or uuid string supplied.");
1059 r
= check_name(new_data
);
1064 md
= dm_hash_rename(param
, new_data
);
1068 __dev_status(md
, param
);
1074 static int dev_set_geometry(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1077 struct mapped_device
*md
;
1078 struct hd_geometry geometry
;
1079 unsigned long indata
[4];
1080 char *geostr
= (char *) param
+ param
->data_start
;
1083 md
= find_device(param
);
1087 if (geostr
< param
->data
||
1088 invalid_str(geostr
, (void *) param
+ param_size
)) {
1089 DMERR("Invalid geometry supplied.");
1093 x
= sscanf(geostr
, "%lu %lu %lu %lu%c", indata
,
1094 indata
+ 1, indata
+ 2, indata
+ 3, &dummy
);
1097 DMERR("Unable to interpret geometry settings.");
1101 if (indata
[0] > 65535 || indata
[1] > 255 || indata
[2] > 255) {
1102 DMERR("Geometry exceeds range limits.");
1106 geometry
.cylinders
= indata
[0];
1107 geometry
.heads
= indata
[1];
1108 geometry
.sectors
= indata
[2];
1109 geometry
.start
= indata
[3];
1111 r
= dm_set_geometry(md
, &geometry
);
1113 param
->data_size
= 0;
1120 static int do_suspend(struct dm_ioctl
*param
)
1123 unsigned int suspend_flags
= DM_SUSPEND_LOCKFS_FLAG
;
1124 struct mapped_device
*md
;
1126 md
= find_device(param
);
1130 if (param
->flags
& DM_SKIP_LOCKFS_FLAG
)
1131 suspend_flags
&= ~DM_SUSPEND_LOCKFS_FLAG
;
1132 if (param
->flags
& DM_NOFLUSH_FLAG
)
1133 suspend_flags
|= DM_SUSPEND_NOFLUSH_FLAG
;
1135 if (!dm_suspended_md(md
)) {
1136 r
= dm_suspend(md
, suspend_flags
);
1141 __dev_status(md
, param
);
1149 static int do_resume(struct dm_ioctl
*param
)
1152 unsigned int suspend_flags
= DM_SUSPEND_LOCKFS_FLAG
;
1153 struct hash_cell
*hc
;
1154 struct mapped_device
*md
;
1155 struct dm_table
*new_map
, *old_map
= NULL
;
1156 bool need_resize_uevent
= false;
1158 down_write(&_hash_lock
);
1160 hc
= __find_device_hash_cell(param
);
1162 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table.");
1163 up_write(&_hash_lock
);
1169 new_map
= hc
->new_map
;
1171 param
->flags
&= ~DM_INACTIVE_PRESENT_FLAG
;
1173 up_write(&_hash_lock
);
1175 /* Do we need to load a new map ? */
1177 sector_t old_size
, new_size
;
1179 /* Suspend if it isn't already suspended */
1180 if (param
->flags
& DM_SKIP_LOCKFS_FLAG
)
1181 suspend_flags
&= ~DM_SUSPEND_LOCKFS_FLAG
;
1182 if (param
->flags
& DM_NOFLUSH_FLAG
)
1183 suspend_flags
|= DM_SUSPEND_NOFLUSH_FLAG
;
1184 if (!dm_suspended_md(md
)) {
1185 r
= dm_suspend(md
, suspend_flags
);
1187 down_write(&_hash_lock
);
1188 hc
= dm_get_mdptr(md
);
1189 if (hc
&& !hc
->new_map
) {
1190 hc
->new_map
= new_map
;
1195 up_write(&_hash_lock
);
1198 dm_table_destroy(new_map
);
1205 old_size
= dm_get_size(md
);
1206 old_map
= dm_swap_table(md
, new_map
);
1207 if (IS_ERR(old_map
)) {
1209 dm_table_destroy(new_map
);
1211 return PTR_ERR(old_map
);
1213 new_size
= dm_get_size(md
);
1214 if (old_size
&& new_size
&& old_size
!= new_size
)
1215 need_resize_uevent
= true;
1217 if (dm_table_get_mode(new_map
) & BLK_OPEN_WRITE
)
1218 set_disk_ro(dm_disk(md
), 0);
1220 set_disk_ro(dm_disk(md
), 1);
1223 if (dm_suspended_md(md
)) {
1226 dm_ima_measure_on_device_resume(md
, new_map
? true : false);
1228 if (!dm_kobject_uevent(md
, KOBJ_CHANGE
, param
->event_nr
, need_resize_uevent
))
1229 param
->flags
|= DM_UEVENT_GENERATED_FLAG
;
1234 * Since dm_swap_table synchronizes RCU, nobody should be in
1235 * read-side critical section already.
1238 dm_table_destroy(old_map
);
1241 __dev_status(md
, param
);
1248 * Set or unset the suspension state of a device.
1249 * If the device already is in the requested state we just return its status.
1251 static int dev_suspend(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1253 if (param
->flags
& DM_SUSPEND_FLAG
)
1254 return do_suspend(param
);
1256 return do_resume(param
);
1260 * Copies device info back to user space, used by
1261 * the create and info ioctls.
1263 static int dev_status(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1265 struct mapped_device
*md
;
1267 md
= find_device(param
);
1271 __dev_status(md
, param
);
1278 * Build up the status struct for each target
1280 static void retrieve_status(struct dm_table
*table
,
1281 struct dm_ioctl
*param
, size_t param_size
)
1283 unsigned int i
, num_targets
;
1284 struct dm_target_spec
*spec
;
1285 char *outbuf
, *outptr
;
1287 size_t remaining
, len
, used
= 0;
1288 unsigned int status_flags
= 0;
1290 outptr
= outbuf
= get_result_buffer(param
, param_size
, &len
);
1292 if (param
->flags
& DM_STATUS_TABLE_FLAG
)
1293 type
= STATUSTYPE_TABLE
;
1294 else if (param
->flags
& DM_IMA_MEASUREMENT_FLAG
)
1295 type
= STATUSTYPE_IMA
;
1297 type
= STATUSTYPE_INFO
;
1299 /* Get all the target info */
1300 num_targets
= table
->num_targets
;
1301 for (i
= 0; i
< num_targets
; i
++) {
1302 struct dm_target
*ti
= dm_table_get_target(table
, i
);
1305 remaining
= len
- (outptr
- outbuf
);
1306 if (remaining
<= sizeof(struct dm_target_spec
)) {
1307 param
->flags
|= DM_BUFFER_FULL_FLAG
;
1311 spec
= (struct dm_target_spec
*) outptr
;
1314 spec
->sector_start
= ti
->begin
;
1315 spec
->length
= ti
->len
;
1316 strscpy_pad(spec
->target_type
, ti
->type
->name
,
1317 sizeof(spec
->target_type
));
1319 outptr
+= sizeof(struct dm_target_spec
);
1320 remaining
= len
- (outptr
- outbuf
);
1321 if (remaining
<= 0) {
1322 param
->flags
|= DM_BUFFER_FULL_FLAG
;
1326 /* Get the status/table string from the target driver */
1327 if (ti
->type
->status
) {
1328 if (param
->flags
& DM_NOFLUSH_FLAG
)
1329 status_flags
|= DM_STATUS_NOFLUSH_FLAG
;
1330 ti
->type
->status(ti
, type
, status_flags
, outptr
, remaining
);
1334 l
= strlen(outptr
) + 1;
1335 if (l
== remaining
) {
1336 param
->flags
|= DM_BUFFER_FULL_FLAG
;
1341 used
= param
->data_start
+ (outptr
- outbuf
);
1343 outptr
= align_ptr(outptr
);
1344 spec
->next
= outptr
- outbuf
;
1348 param
->data_size
= used
;
1350 param
->target_count
= num_targets
;
1354 * Wait for a device to report an event
1356 static int dev_wait(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1359 struct mapped_device
*md
;
1360 struct dm_table
*table
;
1363 md
= find_device(param
);
1368 * Wait for a notification event
1370 if (dm_wait_event(md
, param
->event_nr
)) {
1376 * The userland program is going to want to know what
1377 * changed to trigger the event, so we may as well tell
1378 * him and save an ioctl.
1380 __dev_status(md
, param
);
1382 table
= dm_get_live_or_inactive_table(md
, param
, &srcu_idx
);
1384 retrieve_status(table
, param
, param_size
);
1385 dm_put_live_table(md
, srcu_idx
);
1394 * Remember the global event number and make it possible to poll
1395 * for further events.
1397 static int dev_arm_poll(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1399 struct dm_file
*priv
= filp
->private_data
;
1401 priv
->global_event_nr
= atomic_read(&dm_global_event_nr
);
1406 static inline blk_mode_t
get_mode(struct dm_ioctl
*param
)
1408 blk_mode_t mode
= BLK_OPEN_READ
| BLK_OPEN_WRITE
;
1410 if (param
->flags
& DM_READONLY_FLAG
)
1411 mode
= BLK_OPEN_READ
;
1416 static int next_target(struct dm_target_spec
*last
, uint32_t next
, const char *end
,
1417 struct dm_target_spec
**spec
, char **target_params
)
1419 static_assert(__alignof__(struct dm_target_spec
) <= 8,
1420 "struct dm_target_spec must not require more than 8-byte alignment");
1423 * Number of bytes remaining, starting with last. This is always
1424 * sizeof(struct dm_target_spec) or more, as otherwise *last was
1425 * out of bounds already.
1427 size_t remaining
= end
- (char *)last
;
1430 * There must be room for both the next target spec and the
1431 * NUL-terminator of the target itself.
1433 if (remaining
- sizeof(struct dm_target_spec
) <= next
) {
1434 DMERR("Target spec extends beyond end of parameters");
1438 if (next
% __alignof__(struct dm_target_spec
)) {
1439 DMERR("Next dm_target_spec (offset %u) is not %zu-byte aligned",
1440 next
, __alignof__(struct dm_target_spec
));
1444 *spec
= (struct dm_target_spec
*) ((unsigned char *) last
+ next
);
1445 *target_params
= (char *) (*spec
+ 1);
1450 static int populate_table(struct dm_table
*table
,
1451 struct dm_ioctl
*param
, size_t param_size
)
1455 struct dm_target_spec
*spec
= (struct dm_target_spec
*) param
;
1456 uint32_t next
= param
->data_start
;
1457 const char *const end
= (const char *) param
+ param_size
;
1458 char *target_params
;
1459 size_t min_size
= sizeof(struct dm_ioctl
);
1461 if (!param
->target_count
) {
1462 DMERR("%s: no targets specified", __func__
);
1466 for (i
= 0; i
< param
->target_count
; i
++) {
1467 const char *nul_terminator
;
1469 if (next
< min_size
) {
1470 DMERR("%s: next target spec (offset %u) overlaps %s",
1471 __func__
, next
, i
? "previous target" : "'struct dm_ioctl'");
1475 r
= next_target(spec
, next
, end
, &spec
, &target_params
);
1477 DMERR("unable to find target");
1481 nul_terminator
= memchr(target_params
, 0, (size_t)(end
- target_params
));
1482 if (nul_terminator
== NULL
) {
1483 DMERR("%s: target parameters not NUL-terminated", __func__
);
1487 /* Add 1 for NUL terminator */
1488 min_size
= (size_t)(nul_terminator
- (const char *)spec
) + 1;
1490 r
= dm_table_add_target(table
, spec
->target_type
,
1491 (sector_t
) spec
->sector_start
,
1492 (sector_t
) spec
->length
,
1495 DMERR("error adding target to table");
1502 return dm_table_complete(table
);
1505 static bool is_valid_type(enum dm_queue_mode cur
, enum dm_queue_mode
new)
1508 (cur
== DM_TYPE_BIO_BASED
&& new == DM_TYPE_DAX_BIO_BASED
))
1514 static int table_load(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1517 struct hash_cell
*hc
;
1518 struct dm_table
*t
, *old_map
= NULL
;
1519 struct mapped_device
*md
;
1520 struct target_type
*immutable_target_type
;
1522 md
= find_device(param
);
1526 r
= dm_table_create(&t
, get_mode(param
), param
->target_count
, md
);
1530 /* Protect md->type and md->queue against concurrent table loads. */
1531 dm_lock_md_type(md
);
1532 r
= populate_table(t
, param
, param_size
);
1534 goto err_unlock_md_type
;
1536 dm_ima_measure_on_table_load(t
, STATUSTYPE_IMA
);
1538 immutable_target_type
= dm_get_immutable_target_type(md
);
1539 if (immutable_target_type
&&
1540 (immutable_target_type
!= dm_table_get_immutable_target_type(t
)) &&
1541 !dm_table_get_wildcard_target(t
)) {
1542 DMERR("can't replace immutable target type %s",
1543 immutable_target_type
->name
);
1545 goto err_unlock_md_type
;
1548 if (dm_get_md_type(md
) == DM_TYPE_NONE
) {
1549 /* setup md->queue to reflect md's type (may block) */
1550 r
= dm_setup_md_queue(md
, t
);
1552 DMERR("unable to set up device queue for new table.");
1553 goto err_unlock_md_type
;
1555 } else if (!is_valid_type(dm_get_md_type(md
), dm_table_get_type(t
))) {
1556 DMERR("can't change device type (old=%u vs new=%u) after initial table load.",
1557 dm_get_md_type(md
), dm_table_get_type(t
));
1559 goto err_unlock_md_type
;
1562 dm_unlock_md_type(md
);
1564 /* stage inactive table */
1565 down_write(&_hash_lock
);
1566 hc
= dm_get_mdptr(md
);
1568 DMERR("device has been removed from the dev hash table.");
1569 up_write(&_hash_lock
);
1571 goto err_destroy_table
;
1575 old_map
= hc
->new_map
;
1577 up_write(&_hash_lock
);
1579 param
->flags
|= DM_INACTIVE_PRESENT_FLAG
;
1580 __dev_status(md
, param
);
1584 dm_table_destroy(old_map
);
1592 dm_unlock_md_type(md
);
1594 dm_table_destroy(t
);
1601 static int table_clear(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1603 struct hash_cell
*hc
;
1604 struct mapped_device
*md
;
1605 struct dm_table
*old_map
= NULL
;
1606 bool has_new_map
= false;
1608 down_write(&_hash_lock
);
1610 hc
= __find_device_hash_cell(param
);
1612 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table.");
1613 up_write(&_hash_lock
);
1618 old_map
= hc
->new_map
;
1624 up_write(&_hash_lock
);
1626 param
->flags
&= ~DM_INACTIVE_PRESENT_FLAG
;
1627 __dev_status(md
, param
);
1631 dm_table_destroy(old_map
);
1633 dm_ima_measure_on_table_clear(md
, has_new_map
);
1640 * Retrieves a list of devices used by a particular dm device.
1642 static void retrieve_deps(struct dm_table
*table
,
1643 struct dm_ioctl
*param
, size_t param_size
)
1645 unsigned int count
= 0;
1646 struct list_head
*tmp
;
1648 struct dm_dev_internal
*dd
;
1649 struct dm_target_deps
*deps
;
1651 down_read(&table
->devices_lock
);
1653 deps
= get_result_buffer(param
, param_size
, &len
);
1656 * Count the devices.
1658 list_for_each(tmp
, dm_table_get_devices(table
))
1662 * Check we have enough space.
1664 needed
= struct_size(deps
, dev
, count
);
1666 param
->flags
|= DM_BUFFER_FULL_FLAG
;
1671 * Fill in the devices.
1673 deps
->count
= count
;
1675 list_for_each_entry(dd
, dm_table_get_devices(table
), list
)
1676 deps
->dev
[count
++] = huge_encode_dev(dd
->dm_dev
->bdev
->bd_dev
);
1678 param
->data_size
= param
->data_start
+ needed
;
1681 up_read(&table
->devices_lock
);
1684 static int table_deps(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1686 struct mapped_device
*md
;
1687 struct dm_table
*table
;
1690 md
= find_device(param
);
1694 __dev_status(md
, param
);
1696 table
= dm_get_live_or_inactive_table(md
, param
, &srcu_idx
);
1698 retrieve_deps(table
, param
, param_size
);
1699 dm_put_live_table(md
, srcu_idx
);
1707 * Return the status of a device as a text string for each
1710 static int table_status(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1712 struct mapped_device
*md
;
1713 struct dm_table
*table
;
1716 md
= find_device(param
);
1720 __dev_status(md
, param
);
1722 table
= dm_get_live_or_inactive_table(md
, param
, &srcu_idx
);
1724 retrieve_status(table
, param
, param_size
);
1725 dm_put_live_table(md
, srcu_idx
);
1733 * Process device-mapper dependent messages. Messages prefixed with '@'
1734 * are processed by the DM core. All others are delivered to the target.
1735 * Returns a number <= 1 if message was processed by device mapper.
1736 * Returns 2 if message should be delivered to the target.
1738 static int message_for_md(struct mapped_device
*md
, unsigned int argc
, char **argv
,
1739 char *result
, unsigned int maxlen
)
1744 return 2; /* no '@' prefix, deliver to target */
1746 if (!strcasecmp(argv
[0], "@cancel_deferred_remove")) {
1748 DMERR("Invalid arguments for @cancel_deferred_remove");
1751 return dm_cancel_deferred_remove(md
);
1754 r
= dm_stats_message(md
, argc
, argv
, result
, maxlen
);
1758 DMERR("Unsupported message sent to DM core: %s", argv
[0]);
1763 * Pass a message to the target that's at the supplied device offset.
1765 static int target_message(struct file
*filp
, struct dm_ioctl
*param
, size_t param_size
)
1769 struct mapped_device
*md
;
1770 struct dm_table
*table
;
1771 struct dm_target
*ti
;
1772 struct dm_target_msg
*tmsg
= (void *) param
+ param
->data_start
;
1774 char *result
= get_result_buffer(param
, param_size
, &maxlen
);
1777 md
= find_device(param
);
1781 if (tmsg
< (struct dm_target_msg
*) param
->data
||
1782 invalid_str(tmsg
->message
, (void *) param
+ param_size
)) {
1783 DMERR("Invalid target message parameters.");
1788 r
= dm_split_args(&argc
, &argv
, tmsg
->message
);
1790 DMERR("Failed to split target message parameters");
1795 DMERR("Empty message received.");
1800 r
= message_for_md(md
, argc
, argv
, result
, maxlen
);
1804 table
= dm_get_live_table(md
, &srcu_idx
);
1808 if (dm_deleting_md(md
)) {
1813 ti
= dm_table_find_target(table
, tmsg
->sector
);
1815 DMERR("Target message sector outside device.");
1817 } else if (ti
->type
->message
)
1818 r
= ti
->type
->message(ti
, argc
, argv
, result
, maxlen
);
1820 DMERR("Target type does not support messages");
1825 dm_put_live_table(md
, srcu_idx
);
1830 __dev_status(md
, param
);
1833 param
->flags
|= DM_DATA_OUT_FLAG
;
1834 if (dm_message_test_buffer_overflow(result
, maxlen
))
1835 param
->flags
|= DM_BUFFER_FULL_FLAG
;
1837 param
->data_size
= param
->data_start
+ strlen(result
) + 1;
1846 * The ioctl parameter block consists of two parts, a dm_ioctl struct
1847 * followed by a data buffer. This flag is set if the second part,
1848 * which has a variable size, is not used by the function processing
1851 #define IOCTL_FLAGS_NO_PARAMS 1
1852 #define IOCTL_FLAGS_ISSUE_GLOBAL_EVENT 2
1855 *---------------------------------------------------------------
1856 * Implementation of open/close/ioctl on the special char device.
1857 *---------------------------------------------------------------
1859 static ioctl_fn
lookup_ioctl(unsigned int cmd
, int *ioctl_flags
)
1861 static const struct {
1866 {DM_VERSION_CMD
, 0, NULL
}, /* version is dealt with elsewhere */
1867 {DM_REMOVE_ALL_CMD
, IOCTL_FLAGS_NO_PARAMS
| IOCTL_FLAGS_ISSUE_GLOBAL_EVENT
, remove_all
},
1868 {DM_LIST_DEVICES_CMD
, 0, list_devices
},
1870 {DM_DEV_CREATE_CMD
, IOCTL_FLAGS_NO_PARAMS
| IOCTL_FLAGS_ISSUE_GLOBAL_EVENT
, dev_create
},
1871 {DM_DEV_REMOVE_CMD
, IOCTL_FLAGS_NO_PARAMS
| IOCTL_FLAGS_ISSUE_GLOBAL_EVENT
, dev_remove
},
1872 {DM_DEV_RENAME_CMD
, IOCTL_FLAGS_ISSUE_GLOBAL_EVENT
, dev_rename
},
1873 {DM_DEV_SUSPEND_CMD
, IOCTL_FLAGS_NO_PARAMS
, dev_suspend
},
1874 {DM_DEV_STATUS_CMD
, IOCTL_FLAGS_NO_PARAMS
, dev_status
},
1875 {DM_DEV_WAIT_CMD
, 0, dev_wait
},
1877 {DM_TABLE_LOAD_CMD
, 0, table_load
},
1878 {DM_TABLE_CLEAR_CMD
, IOCTL_FLAGS_NO_PARAMS
, table_clear
},
1879 {DM_TABLE_DEPS_CMD
, 0, table_deps
},
1880 {DM_TABLE_STATUS_CMD
, 0, table_status
},
1882 {DM_LIST_VERSIONS_CMD
, 0, list_versions
},
1884 {DM_TARGET_MSG_CMD
, 0, target_message
},
1885 {DM_DEV_SET_GEOMETRY_CMD
, 0, dev_set_geometry
},
1886 {DM_DEV_ARM_POLL_CMD
, IOCTL_FLAGS_NO_PARAMS
, dev_arm_poll
},
1887 {DM_GET_TARGET_VERSION_CMD
, 0, get_target_version
},
1890 if (unlikely(cmd
>= ARRAY_SIZE(_ioctls
)))
1893 cmd
= array_index_nospec(cmd
, ARRAY_SIZE(_ioctls
));
1894 *ioctl_flags
= _ioctls
[cmd
].flags
;
1895 return _ioctls
[cmd
].fn
;
1899 * As well as checking the version compatibility this always
1900 * copies the kernel interface version out.
1902 static int check_version(unsigned int cmd
, struct dm_ioctl __user
*user
,
1903 struct dm_ioctl
*kernel_params
)
1907 /* Make certain version is first member of dm_ioctl struct */
1908 BUILD_BUG_ON(offsetof(struct dm_ioctl
, version
) != 0);
1910 if (copy_from_user(kernel_params
->version
, user
->version
, sizeof(kernel_params
->version
)))
1913 if ((kernel_params
->version
[0] != DM_VERSION_MAJOR
) ||
1914 (kernel_params
->version
[1] > DM_VERSION_MINOR
)) {
1915 DMERR_LIMIT("ioctl interface mismatch: kernel(%u.%u.%u), user(%u.%u.%u), cmd(%d)",
1916 DM_VERSION_MAJOR
, DM_VERSION_MINOR
,
1917 DM_VERSION_PATCHLEVEL
,
1918 kernel_params
->version
[0],
1919 kernel_params
->version
[1],
1920 kernel_params
->version
[2],
1926 * Fill in the kernel version.
1928 kernel_params
->version
[0] = DM_VERSION_MAJOR
;
1929 kernel_params
->version
[1] = DM_VERSION_MINOR
;
1930 kernel_params
->version
[2] = DM_VERSION_PATCHLEVEL
;
1931 if (copy_to_user(user
->version
, kernel_params
->version
, sizeof(kernel_params
->version
)))
1937 #define DM_PARAMS_MALLOC 0x0001 /* Params allocated with kvmalloc() */
1938 #define DM_WIPE_BUFFER 0x0010 /* Wipe input buffer before returning from ioctl */
1940 static void free_params(struct dm_ioctl
*param
, size_t param_size
, int param_flags
)
1942 if (param_flags
& DM_WIPE_BUFFER
)
1943 memset(param
, 0, param_size
);
1945 if (param_flags
& DM_PARAMS_MALLOC
)
1949 static int copy_params(struct dm_ioctl __user
*user
, struct dm_ioctl
*param_kernel
,
1950 int ioctl_flags
, struct dm_ioctl
**param
, int *param_flags
)
1952 struct dm_ioctl
*dmi
;
1954 const size_t minimum_data_size
= offsetof(struct dm_ioctl
, data
);
1956 /* check_version() already copied version from userspace, avoid TOCTOU */
1957 if (copy_from_user((char *)param_kernel
+ sizeof(param_kernel
->version
),
1958 (char __user
*)user
+ sizeof(param_kernel
->version
),
1959 minimum_data_size
- sizeof(param_kernel
->version
)))
1962 if (unlikely(param_kernel
->data_size
< minimum_data_size
) ||
1963 unlikely(param_kernel
->data_size
> DM_MAX_TARGETS
* DM_MAX_TARGET_PARAMS
)) {
1964 DMERR_LIMIT("Invalid data size in the ioctl structure: %u",
1965 param_kernel
->data_size
);
1969 secure_data
= param_kernel
->flags
& DM_SECURE_DATA_FLAG
;
1971 *param_flags
= secure_data
? DM_WIPE_BUFFER
: 0;
1973 if (ioctl_flags
& IOCTL_FLAGS_NO_PARAMS
) {
1975 dmi
->data_size
= minimum_data_size
;
1980 * Use __GFP_HIGH to avoid low memory issues when a device is
1981 * suspended and the ioctl is needed to resume it.
1982 * Use kmalloc() rather than vmalloc() when we can.
1985 dmi
= kvmalloc(param_kernel
->data_size
, GFP_NOIO
| __GFP_HIGH
);
1988 if (secure_data
&& clear_user(user
, param_kernel
->data_size
))
1993 *param_flags
|= DM_PARAMS_MALLOC
;
1995 /* Copy from param_kernel (which was already copied from user) */
1996 memcpy(dmi
, param_kernel
, minimum_data_size
);
1998 if (copy_from_user(&dmi
->data
, (char __user
*)user
+ minimum_data_size
,
1999 param_kernel
->data_size
- minimum_data_size
))
2002 /* Wipe the user buffer so we do not return it to userspace */
2003 if (secure_data
&& clear_user(user
, param_kernel
->data_size
))
2010 free_params(dmi
, param_kernel
->data_size
, *param_flags
);
2015 static int validate_params(uint cmd
, struct dm_ioctl
*param
)
2017 /* Always clear this flag */
2018 param
->flags
&= ~DM_BUFFER_FULL_FLAG
;
2019 param
->flags
&= ~DM_UEVENT_GENERATED_FLAG
;
2020 param
->flags
&= ~DM_SECURE_DATA_FLAG
;
2021 param
->flags
&= ~DM_DATA_OUT_FLAG
;
2023 /* Ignores parameters */
2024 if (cmd
== DM_REMOVE_ALL_CMD
||
2025 cmd
== DM_LIST_DEVICES_CMD
||
2026 cmd
== DM_LIST_VERSIONS_CMD
)
2029 if (cmd
== DM_DEV_CREATE_CMD
) {
2030 if (!*param
->name
) {
2031 DMERR("name not supplied when creating device");
2034 } else if (*param
->uuid
&& *param
->name
) {
2035 DMERR("only supply one of name or uuid, cmd(%u)", cmd
);
2039 /* Ensure strings are terminated */
2040 param
->name
[DM_NAME_LEN
- 1] = '\0';
2041 param
->uuid
[DM_UUID_LEN
- 1] = '\0';
2046 static int ctl_ioctl(struct file
*file
, uint command
, struct dm_ioctl __user
*user
)
2052 struct dm_ioctl
*param
;
2054 size_t input_param_size
;
2055 struct dm_ioctl param_kernel
;
2057 /* only root can play with this */
2058 if (!capable(CAP_SYS_ADMIN
))
2061 if (_IOC_TYPE(command
) != DM_IOCTL
)
2064 cmd
= _IOC_NR(command
);
2067 * Check the interface version passed in. This also
2068 * writes out the kernel's interface version.
2070 r
= check_version(cmd
, user
, ¶m_kernel
);
2075 * Nothing more to do for the version command.
2077 if (cmd
== DM_VERSION_CMD
)
2080 fn
= lookup_ioctl(cmd
, &ioctl_flags
);
2082 DMERR("dm_ctl_ioctl: unknown command 0x%x", command
);
2087 * Copy the parameters into kernel space.
2089 r
= copy_params(user
, ¶m_kernel
, ioctl_flags
, ¶m
, ¶m_flags
);
2094 input_param_size
= param
->data_size
;
2095 r
= validate_params(cmd
, param
);
2099 param
->data_size
= offsetof(struct dm_ioctl
, data
);
2100 r
= fn(file
, param
, input_param_size
);
2102 if (unlikely(param
->flags
& DM_BUFFER_FULL_FLAG
) &&
2103 unlikely(ioctl_flags
& IOCTL_FLAGS_NO_PARAMS
))
2104 DMERR("ioctl %d tried to output some data but has IOCTL_FLAGS_NO_PARAMS set", cmd
);
2106 if (!r
&& ioctl_flags
& IOCTL_FLAGS_ISSUE_GLOBAL_EVENT
)
2107 dm_issue_global_event();
2110 * Copy the results back to userland.
2112 if (!r
&& copy_to_user(user
, param
, param
->data_size
))
2116 free_params(param
, input_param_size
, param_flags
);
2120 static long dm_ctl_ioctl(struct file
*file
, uint command
, ulong u
)
2122 return (long)ctl_ioctl(file
, command
, (struct dm_ioctl __user
*)u
);
2125 #ifdef CONFIG_COMPAT
2126 static long dm_compat_ctl_ioctl(struct file
*file
, uint command
, ulong u
)
2128 return (long)dm_ctl_ioctl(file
, command
, (ulong
) compat_ptr(u
));
2131 #define dm_compat_ctl_ioctl NULL
2134 static int dm_open(struct inode
*inode
, struct file
*filp
)
2137 struct dm_file
*priv
;
2139 r
= nonseekable_open(inode
, filp
);
2143 priv
= filp
->private_data
= kmalloc(sizeof(struct dm_file
), GFP_KERNEL
);
2147 priv
->global_event_nr
= atomic_read(&dm_global_event_nr
);
2152 static int dm_release(struct inode
*inode
, struct file
*filp
)
2154 kfree(filp
->private_data
);
2158 static __poll_t
dm_poll(struct file
*filp
, poll_table
*wait
)
2160 struct dm_file
*priv
= filp
->private_data
;
2163 poll_wait(filp
, &dm_global_eventq
, wait
);
2165 if ((int)(atomic_read(&dm_global_event_nr
) - priv
->global_event_nr
) > 0)
2171 static const struct file_operations _ctl_fops
= {
2173 .release
= dm_release
,
2175 .unlocked_ioctl
= dm_ctl_ioctl
,
2176 .compat_ioctl
= dm_compat_ctl_ioctl
,
2177 .owner
= THIS_MODULE
,
2178 .llseek
= noop_llseek
,
2181 static struct miscdevice _dm_misc
= {
2182 .minor
= MAPPER_CTRL_MINOR
,
2184 .nodename
= DM_DIR
"/" DM_CONTROL_NODE
,
2188 MODULE_ALIAS_MISCDEV(MAPPER_CTRL_MINOR
);
2189 MODULE_ALIAS("devname:" DM_DIR
"/" DM_CONTROL_NODE
);
2192 * Create misc character device and link to DM_DIR/control.
2194 int __init
dm_interface_init(void)
2198 r
= misc_register(&_dm_misc
);
2200 DMERR("misc_register failed for control device");
2204 DMINFO("%d.%d.%d%s initialised: %s", DM_VERSION_MAJOR
,
2205 DM_VERSION_MINOR
, DM_VERSION_PATCHLEVEL
, DM_VERSION_EXTRA
,
2210 void dm_interface_exit(void)
2212 misc_deregister(&_dm_misc
);
2217 * dm_copy_name_and_uuid - Copy mapped device name & uuid into supplied buffers
2218 * @md: Pointer to mapped_device
2219 * @name: Buffer (size DM_NAME_LEN) for name
2220 * @uuid: Buffer (size DM_UUID_LEN) for uuid or empty string if uuid not defined
2222 int dm_copy_name_and_uuid(struct mapped_device
*md
, char *name
, char *uuid
)
2225 struct hash_cell
*hc
;
2230 mutex_lock(&dm_hash_cells_mutex
);
2231 hc
= dm_get_mdptr(md
);
2238 strcpy(name
, hc
->name
);
2240 strcpy(uuid
, hc
->uuid
? : "");
2243 mutex_unlock(&dm_hash_cells_mutex
);
2247 EXPORT_SYMBOL_GPL(dm_copy_name_and_uuid
);
2250 * dm_early_create - create a mapped device in early boot.
2252 * @dmi: Contains main information of the device mapping to be created.
2253 * @spec_array: array of pointers to struct dm_target_spec. Describes the
2254 * mapping table of the device.
2255 * @target_params_array: array of strings with the parameters to a specific
2258 * Instead of having the struct dm_target_spec and the parameters for every
2259 * target embedded at the end of struct dm_ioctl (as performed in a normal
2260 * ioctl), pass them as arguments, so the caller doesn't need to serialize them.
2261 * The size of the spec_array and target_params_array is given by
2262 * @dmi->target_count.
2263 * This function is supposed to be called in early boot, so locking mechanisms
2264 * to protect against concurrent loads are not required.
2266 int __init
dm_early_create(struct dm_ioctl
*dmi
,
2267 struct dm_target_spec
**spec_array
,
2268 char **target_params_array
)
2270 int r
, m
= DM_ANY_MINOR
;
2271 struct dm_table
*t
, *old_map
;
2272 struct mapped_device
*md
;
2275 if (!dmi
->target_count
)
2278 r
= check_name(dmi
->name
);
2282 if (dmi
->flags
& DM_PERSISTENT_DEV_FLAG
)
2283 m
= MINOR(huge_decode_dev(dmi
->dev
));
2285 /* alloc dm device */
2286 r
= dm_create(m
, &md
);
2291 r
= dm_hash_insert(dmi
->name
, *dmi
->uuid
? dmi
->uuid
: NULL
, md
);
2293 goto err_destroy_dm
;
2296 r
= dm_table_create(&t
, get_mode(dmi
), dmi
->target_count
, md
);
2298 goto err_hash_remove
;
2301 for (i
= 0; i
< dmi
->target_count
; i
++) {
2302 r
= dm_table_add_target(t
, spec_array
[i
]->target_type
,
2303 (sector_t
) spec_array
[i
]->sector_start
,
2304 (sector_t
) spec_array
[i
]->length
,
2305 target_params_array
[i
]);
2307 DMERR("error adding target to table");
2308 goto err_destroy_table
;
2313 r
= dm_table_complete(t
);
2315 goto err_destroy_table
;
2317 /* setup md->queue to reflect md's type (may block) */
2318 r
= dm_setup_md_queue(md
, t
);
2320 DMERR("unable to set up device queue for new table.");
2321 goto err_destroy_table
;
2326 old_map
= dm_swap_table(md
, t
);
2327 if (IS_ERR(old_map
)) {
2328 r
= PTR_ERR(old_map
);
2329 goto err_destroy_table
;
2331 set_disk_ro(dm_disk(md
), !!(dmi
->flags
& DM_READONLY_FLAG
));
2336 goto err_destroy_table
;
2338 DMINFO("%s (%s) is ready", md
->disk
->disk_name
, dmi
->name
);
2343 dm_table_destroy(t
);
2345 down_write(&_hash_lock
);
2346 (void) __hash_remove(__get_name_cell(dmi
->name
));
2347 up_write(&_hash_lock
);
2348 /* release reference from __get_name_cell */