Avoid beyond bounds copy while caching ACL
[zen-stable.git] / fs / ext4 / ioctl.c
blob6eee25591b8159bc96d35a16f94f94c0855a35b9
1 /*
2 * linux/fs/ext4/ioctl.c
4 * Copyright (C) 1993, 1994, 1995
5 * Remy Card (card@masi.ibp.fr)
6 * Laboratoire MASI - Institut Blaise Pascal
7 * Universite Pierre et Marie Curie (Paris VI)
8 */
10 #include <linux/fs.h>
11 #include <linux/jbd2.h>
12 #include <linux/capability.h>
13 #include <linux/time.h>
14 #include <linux/compat.h>
15 #include <linux/mount.h>
16 #include <linux/file.h>
17 #include <asm/uaccess.h>
18 #include "ext4_jbd2.h"
19 #include "ext4.h"
21 #define MAX_32_NUM ((((unsigned long long) 1) << 32) - 1)
23 long ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
25 struct inode *inode = filp->f_dentry->d_inode;
26 struct super_block *sb = inode->i_sb;
27 struct ext4_inode_info *ei = EXT4_I(inode);
28 unsigned int flags;
30 ext4_debug("cmd = %u, arg = %lu\n", cmd, arg);
32 switch (cmd) {
33 case EXT4_IOC_GETFLAGS:
34 ext4_get_inode_flags(ei);
35 flags = ei->i_flags & EXT4_FL_USER_VISIBLE;
36 return put_user(flags, (int __user *) arg);
37 case EXT4_IOC_SETFLAGS: {
38 handle_t *handle = NULL;
39 int err, migrate = 0;
40 struct ext4_iloc iloc;
41 unsigned int oldflags;
42 unsigned int jflag;
44 if (!inode_owner_or_capable(inode))
45 return -EACCES;
47 if (get_user(flags, (int __user *) arg))
48 return -EFAULT;
50 err = mnt_want_write_file(filp);
51 if (err)
52 return err;
54 flags = ext4_mask_flags(inode->i_mode, flags);
56 err = -EPERM;
57 mutex_lock(&inode->i_mutex);
58 /* Is it quota file? Do not allow user to mess with it */
59 if (IS_NOQUOTA(inode))
60 goto flags_out;
62 oldflags = ei->i_flags;
64 /* The JOURNAL_DATA flag is modifiable only by root */
65 jflag = flags & EXT4_JOURNAL_DATA_FL;
68 * The IMMUTABLE and APPEND_ONLY flags can only be changed by
69 * the relevant capability.
71 * This test looks nicer. Thanks to Pauline Middelink
73 if ((flags ^ oldflags) & (EXT4_APPEND_FL | EXT4_IMMUTABLE_FL)) {
74 if (!capable(CAP_LINUX_IMMUTABLE))
75 goto flags_out;
79 * The JOURNAL_DATA flag can only be changed by
80 * the relevant capability.
82 if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL)) {
83 if (!capable(CAP_SYS_RESOURCE))
84 goto flags_out;
86 if (oldflags & EXT4_EXTENTS_FL) {
87 /* We don't support clearning extent flags */
88 if (!(flags & EXT4_EXTENTS_FL)) {
89 err = -EOPNOTSUPP;
90 goto flags_out;
92 } else if (flags & EXT4_EXTENTS_FL) {
93 /* migrate the file */
94 migrate = 1;
95 flags &= ~EXT4_EXTENTS_FL;
98 if (flags & EXT4_EOFBLOCKS_FL) {
99 /* we don't support adding EOFBLOCKS flag */
100 if (!(oldflags & EXT4_EOFBLOCKS_FL)) {
101 err = -EOPNOTSUPP;
102 goto flags_out;
104 } else if (oldflags & EXT4_EOFBLOCKS_FL)
105 ext4_truncate(inode);
107 handle = ext4_journal_start(inode, 1);
108 if (IS_ERR(handle)) {
109 err = PTR_ERR(handle);
110 goto flags_out;
112 if (IS_SYNC(inode))
113 ext4_handle_sync(handle);
114 err = ext4_reserve_inode_write(handle, inode, &iloc);
115 if (err)
116 goto flags_err;
118 flags = flags & EXT4_FL_USER_MODIFIABLE;
119 flags |= oldflags & ~EXT4_FL_USER_MODIFIABLE;
120 ei->i_flags = flags;
122 ext4_set_inode_flags(inode);
123 inode->i_ctime = ext4_current_time(inode);
125 err = ext4_mark_iloc_dirty(handle, inode, &iloc);
126 flags_err:
127 ext4_journal_stop(handle);
128 if (err)
129 goto flags_out;
131 if ((jflag ^ oldflags) & (EXT4_JOURNAL_DATA_FL))
132 err = ext4_change_inode_journal_flag(inode, jflag);
133 if (err)
134 goto flags_out;
135 if (migrate)
136 err = ext4_ext_migrate(inode);
137 flags_out:
138 mutex_unlock(&inode->i_mutex);
139 mnt_drop_write_file(filp);
140 return err;
142 case EXT4_IOC_GETVERSION:
143 case EXT4_IOC_GETVERSION_OLD:
144 return put_user(inode->i_generation, (int __user *) arg);
145 case EXT4_IOC_SETVERSION:
146 case EXT4_IOC_SETVERSION_OLD: {
147 handle_t *handle;
148 struct ext4_iloc iloc;
149 __u32 generation;
150 int err;
152 if (!inode_owner_or_capable(inode))
153 return -EPERM;
155 err = mnt_want_write_file(filp);
156 if (err)
157 return err;
158 if (get_user(generation, (int __user *) arg)) {
159 err = -EFAULT;
160 goto setversion_out;
163 mutex_lock(&inode->i_mutex);
164 handle = ext4_journal_start(inode, 1);
165 if (IS_ERR(handle)) {
166 err = PTR_ERR(handle);
167 goto unlock_out;
169 err = ext4_reserve_inode_write(handle, inode, &iloc);
170 if (err == 0) {
171 inode->i_ctime = ext4_current_time(inode);
172 inode->i_generation = generation;
173 err = ext4_mark_iloc_dirty(handle, inode, &iloc);
175 ext4_journal_stop(handle);
177 unlock_out:
178 mutex_unlock(&inode->i_mutex);
179 setversion_out:
180 mnt_drop_write_file(filp);
181 return err;
183 case EXT4_IOC_GROUP_EXTEND: {
184 ext4_fsblk_t n_blocks_count;
185 int err, err2=0;
187 err = ext4_resize_begin(sb);
188 if (err)
189 return err;
191 if (get_user(n_blocks_count, (__u32 __user *)arg)) {
192 err = -EFAULT;
193 goto group_extend_out;
196 if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
197 EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
198 ext4_msg(sb, KERN_ERR,
199 "Online resizing not supported with bigalloc");
200 err = -EOPNOTSUPP;
201 goto group_extend_out;
204 err = mnt_want_write_file(filp);
205 if (err)
206 goto group_extend_out;
208 err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
209 if (EXT4_SB(sb)->s_journal) {
210 jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
211 err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
212 jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
214 if (err == 0)
215 err = err2;
216 mnt_drop_write_file(filp);
217 group_extend_out:
218 ext4_resize_end(sb);
219 return err;
222 case EXT4_IOC_MOVE_EXT: {
223 struct move_extent me;
224 struct file *donor_filp;
225 int err;
227 if (!(filp->f_mode & FMODE_READ) ||
228 !(filp->f_mode & FMODE_WRITE))
229 return -EBADF;
231 if (copy_from_user(&me,
232 (struct move_extent __user *)arg, sizeof(me)))
233 return -EFAULT;
234 me.moved_len = 0;
236 donor_filp = fget(me.donor_fd);
237 if (!donor_filp)
238 return -EBADF;
240 if (!(donor_filp->f_mode & FMODE_WRITE)) {
241 err = -EBADF;
242 goto mext_out;
245 if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
246 EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
247 ext4_msg(sb, KERN_ERR,
248 "Online defrag not supported with bigalloc");
249 return -EOPNOTSUPP;
252 err = mnt_want_write_file(filp);
253 if (err)
254 goto mext_out;
256 err = ext4_move_extents(filp, donor_filp, me.orig_start,
257 me.donor_start, me.len, &me.moved_len);
258 mnt_drop_write_file(filp);
259 mnt_drop_write(filp->f_path.mnt);
261 if (copy_to_user((struct move_extent __user *)arg,
262 &me, sizeof(me)))
263 err = -EFAULT;
264 mext_out:
265 fput(donor_filp);
266 return err;
269 case EXT4_IOC_GROUP_ADD: {
270 struct ext4_new_group_data input;
271 int err, err2=0;
273 err = ext4_resize_begin(sb);
274 if (err)
275 return err;
277 if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
278 sizeof(input))) {
279 err = -EFAULT;
280 goto group_add_out;
283 if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
284 EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
285 ext4_msg(sb, KERN_ERR,
286 "Online resizing not supported with bigalloc");
287 err = -EOPNOTSUPP;
288 goto group_add_out;
291 err = mnt_want_write_file(filp);
292 if (err)
293 goto group_add_out;
295 err = ext4_group_add(sb, &input);
296 if (EXT4_SB(sb)->s_journal) {
297 jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
298 err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
299 jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
301 if (err == 0)
302 err = err2;
303 mnt_drop_write_file(filp);
304 group_add_out:
305 ext4_resize_end(sb);
306 return err;
309 case EXT4_IOC_MIGRATE:
311 int err;
312 if (!inode_owner_or_capable(inode))
313 return -EACCES;
315 err = mnt_want_write_file(filp);
316 if (err)
317 return err;
319 * inode_mutex prevent write and truncate on the file.
320 * Read still goes through. We take i_data_sem in
321 * ext4_ext_swap_inode_data before we switch the
322 * inode format to prevent read.
324 mutex_lock(&(inode->i_mutex));
325 err = ext4_ext_migrate(inode);
326 mutex_unlock(&(inode->i_mutex));
327 mnt_drop_write_file(filp);
328 return err;
331 case EXT4_IOC_ALLOC_DA_BLKS:
333 int err;
334 if (!inode_owner_or_capable(inode))
335 return -EACCES;
337 err = mnt_want_write_file(filp);
338 if (err)
339 return err;
340 err = ext4_alloc_da_blocks(inode);
341 mnt_drop_write_file(filp);
342 return err;
345 case EXT4_IOC_RESIZE_FS: {
346 ext4_fsblk_t n_blocks_count;
347 struct super_block *sb = inode->i_sb;
348 int err = 0, err2 = 0;
350 if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
351 EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
352 ext4_msg(sb, KERN_ERR,
353 "Online resizing not (yet) supported with bigalloc");
354 return -EOPNOTSUPP;
357 if (EXT4_HAS_INCOMPAT_FEATURE(sb,
358 EXT4_FEATURE_INCOMPAT_META_BG)) {
359 ext4_msg(sb, KERN_ERR,
360 "Online resizing not (yet) supported with meta_bg");
361 return -EOPNOTSUPP;
364 if (copy_from_user(&n_blocks_count, (__u64 __user *)arg,
365 sizeof(__u64))) {
366 return -EFAULT;
369 if (n_blocks_count > MAX_32_NUM &&
370 !EXT4_HAS_INCOMPAT_FEATURE(sb,
371 EXT4_FEATURE_INCOMPAT_64BIT)) {
372 ext4_msg(sb, KERN_ERR,
373 "File system only supports 32-bit block numbers");
374 return -EOPNOTSUPP;
377 err = ext4_resize_begin(sb);
378 if (err)
379 return err;
381 err = mnt_want_write(filp->f_path.mnt);
382 if (err)
383 goto resizefs_out;
385 err = ext4_resize_fs(sb, n_blocks_count);
386 if (EXT4_SB(sb)->s_journal) {
387 jbd2_journal_lock_updates(EXT4_SB(sb)->s_journal);
388 err2 = jbd2_journal_flush(EXT4_SB(sb)->s_journal);
389 jbd2_journal_unlock_updates(EXT4_SB(sb)->s_journal);
391 if (err == 0)
392 err = err2;
393 mnt_drop_write(filp->f_path.mnt);
394 resizefs_out:
395 ext4_resize_end(sb);
396 return err;
399 case FITRIM:
401 struct request_queue *q = bdev_get_queue(sb->s_bdev);
402 struct fstrim_range range;
403 int ret = 0;
405 if (!capable(CAP_SYS_ADMIN))
406 return -EPERM;
408 if (!blk_queue_discard(q))
409 return -EOPNOTSUPP;
411 if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
412 EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
413 ext4_msg(sb, KERN_ERR,
414 "FITRIM not supported with bigalloc");
415 return -EOPNOTSUPP;
418 if (copy_from_user(&range, (struct fstrim_range __user *)arg,
419 sizeof(range)))
420 return -EFAULT;
422 range.minlen = max((unsigned int)range.minlen,
423 q->limits.discard_granularity);
424 ret = ext4_trim_fs(sb, &range);
425 if (ret < 0)
426 return ret;
428 if (copy_to_user((struct fstrim_range __user *)arg, &range,
429 sizeof(range)))
430 return -EFAULT;
432 return 0;
435 default:
436 return -ENOTTY;
440 #ifdef CONFIG_COMPAT
441 long ext4_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
443 /* These are just misnamed, they actually get/put from/to user an int */
444 switch (cmd) {
445 case EXT4_IOC32_GETFLAGS:
446 cmd = EXT4_IOC_GETFLAGS;
447 break;
448 case EXT4_IOC32_SETFLAGS:
449 cmd = EXT4_IOC_SETFLAGS;
450 break;
451 case EXT4_IOC32_GETVERSION:
452 cmd = EXT4_IOC_GETVERSION;
453 break;
454 case EXT4_IOC32_SETVERSION:
455 cmd = EXT4_IOC_SETVERSION;
456 break;
457 case EXT4_IOC32_GROUP_EXTEND:
458 cmd = EXT4_IOC_GROUP_EXTEND;
459 break;
460 case EXT4_IOC32_GETVERSION_OLD:
461 cmd = EXT4_IOC_GETVERSION_OLD;
462 break;
463 case EXT4_IOC32_SETVERSION_OLD:
464 cmd = EXT4_IOC_SETVERSION_OLD;
465 break;
466 case EXT4_IOC32_GETRSVSZ:
467 cmd = EXT4_IOC_GETRSVSZ;
468 break;
469 case EXT4_IOC32_SETRSVSZ:
470 cmd = EXT4_IOC_SETRSVSZ;
471 break;
472 case EXT4_IOC32_GROUP_ADD: {
473 struct compat_ext4_new_group_input __user *uinput;
474 struct ext4_new_group_input input;
475 mm_segment_t old_fs;
476 int err;
478 uinput = compat_ptr(arg);
479 err = get_user(input.group, &uinput->group);
480 err |= get_user(input.block_bitmap, &uinput->block_bitmap);
481 err |= get_user(input.inode_bitmap, &uinput->inode_bitmap);
482 err |= get_user(input.inode_table, &uinput->inode_table);
483 err |= get_user(input.blocks_count, &uinput->blocks_count);
484 err |= get_user(input.reserved_blocks,
485 &uinput->reserved_blocks);
486 if (err)
487 return -EFAULT;
488 old_fs = get_fs();
489 set_fs(KERNEL_DS);
490 err = ext4_ioctl(file, EXT4_IOC_GROUP_ADD,
491 (unsigned long) &input);
492 set_fs(old_fs);
493 return err;
495 case EXT4_IOC_MOVE_EXT:
496 case FITRIM:
497 case EXT4_IOC_RESIZE_FS:
498 break;
499 default:
500 return -ENOIOCTLCMD;
502 return ext4_ioctl(file, cmd, (unsigned long) compat_ptr(arg));
504 #endif