1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * Copyright (C) 2001, 2002 Sistina Software (UK) Limited. 4 * Copyright (C) 2004 - 2006 Red Hat, Inc. All rights reserved. 5 * 6 * This file is released under the GPL. 7 */ 8 9 #include "dm-core.h" 10 #include "dm-ima.h" 11 #include <linux/module.h> 12 #include <linux/vmalloc.h> 13 #include <linux/miscdevice.h> 14 #include <linux/sched/mm.h> 15 #include <linux/init.h> 16 #include <linux/wait.h> 17 #include <linux/slab.h> 18 #include <linux/rbtree.h> 19 #include <linux/dm-ioctl.h> 20 #include <linux/hdreg.h> 21 #include <linux/compat.h> 22 #include <linux/nospec.h> 23 24 #include <linux/uaccess.h> 25 #include <linux/ima.h> 26 27 #define DM_MSG_PREFIX "ioctl" 28 #define DM_DRIVER_EMAIL "dm-devel@lists.linux.dev" 29 30 struct dm_file { 31 /* 32 * poll will wait until the global event number is greater than 33 * this value. 34 */ 35 volatile unsigned int global_event_nr; 36 }; 37 38 /* 39 *--------------------------------------------------------------- 40 * The ioctl interface needs to be able to look up devices by 41 * name or uuid. 42 *--------------------------------------------------------------- 43 */ 44 struct hash_cell { 45 struct rb_node name_node; 46 struct rb_node uuid_node; 47 bool name_set; 48 bool uuid_set; 49 50 char *name; 51 char *uuid; 52 struct mapped_device *md; 53 struct dm_table *new_map; 54 }; 55 56 struct vers_iter { 57 struct dm_target_versions *vers, *old_vers; 58 char *end; 59 }; 60 61 62 static struct rb_root name_rb_tree = RB_ROOT; 63 static struct rb_root uuid_rb_tree = RB_ROOT; 64 65 #define DM_REMOVE_KEEP_OPEN_DEVICES 1 66 #define DM_REMOVE_MARK_DEFERRED 2 67 #define DM_REMOVE_ONLY_DEFERRED 4 68 #define DM_REMOVE_INTERRUPTIBLE 8 69 static int dm_hash_remove_all(unsigned flags); 70 71 /* 72 * Guards access to both hash tables. 73 */ 74 static DECLARE_RWSEM(_hash_lock); 75 76 /* 77 * Protects use of mdptr to obtain hash cell name and uuid from mapped device. 78 */ 79 static DEFINE_MUTEX(dm_hash_cells_mutex); 80 81 static void dm_hash_exit(void) 82 { 83 dm_hash_remove_all(0); 84 } 85 86 /* 87 *--------------------------------------------------------------- 88 * Code for looking up a device by name 89 *--------------------------------------------------------------- 90 */ 91 static struct hash_cell *__get_name_cell(const char *str) 92 { 93 struct rb_node *n = name_rb_tree.rb_node; 94 95 while (n) { 96 struct hash_cell *hc = container_of(n, struct hash_cell, name_node); 97 int c; 98 99 c = strcmp(hc->name, str); 100 if (!c) { 101 dm_get(hc->md); 102 return hc; 103 } 104 n = c >= 0 ? n->rb_left : n->rb_right; 105 } 106 107 return NULL; 108 } 109 110 static struct hash_cell *__get_uuid_cell(const char *str) 111 { 112 struct rb_node *n = uuid_rb_tree.rb_node; 113 114 while (n) { 115 struct hash_cell *hc = container_of(n, struct hash_cell, uuid_node); 116 int c; 117 118 c = strcmp(hc->uuid, str); 119 if (!c) { 120 dm_get(hc->md); 121 return hc; 122 } 123 n = c >= 0 ? n->rb_left : n->rb_right; 124 } 125 126 return NULL; 127 } 128 129 static void __unlink_name(struct hash_cell *hc) 130 { 131 if (hc->name_set) { 132 hc->name_set = false; 133 rb_erase(&hc->name_node, &name_rb_tree); 134 } 135 } 136 137 static void __unlink_uuid(struct hash_cell *hc) 138 { 139 if (hc->uuid_set) { 140 hc->uuid_set = false; 141 rb_erase(&hc->uuid_node, &uuid_rb_tree); 142 } 143 } 144 145 static void __link_name(struct hash_cell *new_hc) 146 { 147 struct rb_node **n, *parent; 148 149 __unlink_name(new_hc); 150 151 new_hc->name_set = true; 152 153 n = &name_rb_tree.rb_node; 154 parent = NULL; 155 156 while (*n) { 157 struct hash_cell *hc = container_of(*n, struct hash_cell, name_node); 158 int c; 159 160 c = strcmp(hc->name, new_hc->name); 161 BUG_ON(!c); 162 parent = *n; 163 n = c >= 0 ? &hc->name_node.rb_left : &hc->name_node.rb_right; 164 } 165 166 rb_link_node(&new_hc->name_node, parent, n); 167 rb_insert_color(&new_hc->name_node, &name_rb_tree); 168 } 169 170 static void __link_uuid(struct hash_cell *new_hc) 171 { 172 struct rb_node **n, *parent; 173 174 __unlink_uuid(new_hc); 175 176 new_hc->uuid_set = true; 177 178 n = &uuid_rb_tree.rb_node; 179 parent = NULL; 180 181 while (*n) { 182 struct hash_cell *hc = container_of(*n, struct hash_cell, uuid_node); 183 int c; 184 185 c = strcmp(hc->uuid, new_hc->uuid); 186 BUG_ON(!c); 187 parent = *n; 188 n = c > 0 ? &hc->uuid_node.rb_left : &hc->uuid_node.rb_right; 189 } 190 191 rb_link_node(&new_hc->uuid_node, parent, n); 192 rb_insert_color(&new_hc->uuid_node, &uuid_rb_tree); 193 } 194 195 static struct hash_cell *__get_dev_cell(uint64_t dev) 196 { 197 struct mapped_device *md; 198 struct hash_cell *hc; 199 200 md = dm_get_md(huge_decode_dev(dev)); 201 if (!md) 202 return NULL; 203 204 hc = dm_get_mdptr(md); 205 if (!hc) { 206 dm_put(md); 207 return NULL; 208 } 209 210 return hc; 211 } 212 213 /* 214 *--------------------------------------------------------------- 215 * Inserting, removing and renaming a device. 216 *--------------------------------------------------------------- 217 */ 218 static struct hash_cell *alloc_cell(const char *name, const char *uuid, 219 struct mapped_device *md) 220 { 221 struct hash_cell *hc; 222 223 hc = kmalloc_obj(*hc); 224 if (!hc) 225 return NULL; 226 227 hc->name = kstrdup(name, GFP_KERNEL); 228 if (!hc->name) { 229 kfree(hc); 230 return NULL; 231 } 232 233 if (!uuid) 234 hc->uuid = NULL; 235 236 else { 237 hc->uuid = kstrdup(uuid, GFP_KERNEL); 238 if (!hc->uuid) { 239 kfree(hc->name); 240 kfree(hc); 241 return NULL; 242 } 243 } 244 245 hc->name_set = hc->uuid_set = false; 246 hc->md = md; 247 hc->new_map = NULL; 248 return hc; 249 } 250 251 static void free_cell(struct hash_cell *hc) 252 { 253 if (hc) { 254 kfree(hc->name); 255 kfree(hc->uuid); 256 kfree(hc); 257 } 258 } 259 260 #ifdef CONFIG_IMA 261 262 /* 263 * Called while holding to _hash_lock, to guarantee the ordering of the 264 * following dm_ima_measure_on_* functions, which should be called 265 * right after dropping the _hash_lock 266 */ 267 static unsigned int dm_ima_init_context(struct hash_cell *hc, 268 struct dm_ima_context *context, 269 bool need_idx) 270 { 271 lockdep_assert_held(&_hash_lock); 272 273 if (unlikely(!context)) 274 return need_idx ? hc->md->ima.update_idx++ : 0; 275 276 context->update_idx = hc->md->ima.update_idx++; 277 strcpy(context->dev_name, hc->name); 278 strcpy(context->dev_uuid, hc->uuid ? : ""); 279 280 return context->update_idx; 281 } 282 283 /* 284 * Called by do_resume() to guarantee correct ordering, since do_resume() 285 * does not grab the _hash_lock when the table is not getting swapped or 286 * when actually swapping the active table 287 */ 288 static bool dm_ima_need_measure(struct mapped_device *md, 289 struct dm_table *table, 290 struct dm_ima_context *context) 291 { 292 int srcu_idx; 293 struct hash_cell *hc; 294 bool need_measure = false; 295 296 if (unlikely(!context)) 297 return false; 298 299 down_write(&_hash_lock); 300 /* Check if the device has been removed */ 301 hc = dm_get_mdptr(md); 302 if (hc) { 303 /* 304 * If we have a table, we need to make sure that it's the 305 * active table. Otherwise we raced with another process 306 * setting the active table and it will do the measurement 307 */ 308 if (!table || dm_get_live_table(md, &srcu_idx) == table) { 309 dm_ima_init_context(hc, context, false); 310 need_measure = true; 311 } 312 if (table) 313 dm_put_live_table(md, srcu_idx); 314 } 315 up_write(&_hash_lock); 316 317 return need_measure; 318 } 319 #else 320 static inline unsigned int dm_ima_init_context(struct hash_cell *hc, 321 struct dm_ima_context *context, 322 bool neex_idx) 323 { 324 return 0; 325 } 326 static inline bool dm_ima_need_measure(struct mapped_device *md, 327 struct dm_table *table, 328 struct dm_ima_context *context) 329 { 330 return false; 331 } 332 #endif 333 334 /* 335 * The kdev_t and uuid of a device can never change once it is 336 * initially inserted. 337 */ 338 static int dm_hash_insert(const char *name, const char *uuid, struct mapped_device *md) 339 { 340 struct hash_cell *cell, *hc; 341 342 /* 343 * Allocate the new cells. 344 */ 345 cell = alloc_cell(name, uuid, md); 346 if (!cell) 347 return -ENOMEM; 348 349 /* 350 * Insert the cell into both hash tables. 351 */ 352 down_write(&_hash_lock); 353 hc = __get_name_cell(name); 354 if (hc) { 355 dm_put(hc->md); 356 goto bad; 357 } 358 359 __link_name(cell); 360 361 if (uuid) { 362 hc = __get_uuid_cell(uuid); 363 if (hc) { 364 __unlink_name(cell); 365 dm_put(hc->md); 366 goto bad; 367 } 368 __link_uuid(cell); 369 } 370 dm_get(md); 371 mutex_lock(&dm_hash_cells_mutex); 372 dm_set_mdptr(md, cell); 373 mutex_unlock(&dm_hash_cells_mutex); 374 up_write(&_hash_lock); 375 376 return 0; 377 378 bad: 379 up_write(&_hash_lock); 380 free_cell(cell); 381 return -EBUSY; 382 } 383 384 static struct dm_table *__hash_remove(struct hash_cell *hc) 385 { 386 struct dm_table *table; 387 int srcu_idx; 388 389 lockdep_assert_held(&_hash_lock); 390 391 /* remove from the dev trees */ 392 __unlink_name(hc); 393 __unlink_uuid(hc); 394 mutex_lock(&dm_hash_cells_mutex); 395 dm_set_mdptr(hc->md, NULL); 396 mutex_unlock(&dm_hash_cells_mutex); 397 398 table = dm_get_live_table(hc->md, &srcu_idx); 399 if (table) 400 dm_table_event(table); 401 dm_put_live_table(hc->md, srcu_idx); 402 403 table = NULL; 404 if (hc->new_map) 405 table = hc->new_map; 406 dm_put(hc->md); 407 free_cell(hc); 408 409 return table; 410 } 411 412 static int dm_hash_remove_all(unsigned flags) 413 { 414 int dev_skipped; 415 struct rb_node *n; 416 struct hash_cell *hc; 417 struct mapped_device *md; 418 struct dm_table *t; 419 struct dm_ima_context *ima_context = NULL; 420 unsigned int ima_idx; 421 422 dm_ima_alloc_context(&ima_context, true); 423 retry: 424 dev_skipped = 0; 425 426 down_write(&_hash_lock); 427 428 for (n = rb_first(&name_rb_tree); n; n = rb_next(n)) { 429 if (flags & DM_REMOVE_INTERRUPTIBLE && fatal_signal_pending(current)) { 430 up_write(&_hash_lock); 431 dm_ima_free_context(ima_context); 432 return -EINTR; 433 } 434 435 hc = container_of(n, struct hash_cell, name_node); 436 md = hc->md; 437 dm_get(md); 438 439 if (flags & DM_REMOVE_KEEP_OPEN_DEVICES && 440 dm_lock_for_deletion(md, !!(flags & DM_REMOVE_MARK_DEFERRED), !!(flags & DM_REMOVE_ONLY_DEFERRED))) { 441 dm_put(md); 442 dev_skipped++; 443 continue; 444 } 445 446 ima_idx = dm_ima_init_context(hc, ima_context, true); 447 t = __hash_remove(hc); 448 449 up_write(&_hash_lock); 450 451 if (t) { 452 dm_sync_table(md); 453 dm_table_destroy(t); 454 } 455 dm_ima_measure_on_device_remove(md, true, ima_context, ima_idx); 456 dm_put(md); 457 if (likely(flags & DM_REMOVE_KEEP_OPEN_DEVICES)) 458 dm_destroy(md); 459 else 460 dm_destroy_immediate(md); 461 462 /* 463 * Some mapped devices may be using other mapped 464 * devices, so repeat until we make no further 465 * progress. If a new mapped device is created 466 * here it will also get removed. 467 */ 468 goto retry; 469 } 470 471 up_write(&_hash_lock); 472 473 if (dev_skipped && !(flags & DM_REMOVE_ONLY_DEFERRED)) 474 DMWARN("remove_all left %d open device(s)", dev_skipped); 475 476 dm_ima_free_context(ima_context); 477 return 0; 478 } 479 480 /* 481 * Set the uuid of a hash_cell that isn't already set. 482 */ 483 static void __set_cell_uuid(struct hash_cell *hc, char *new_uuid) 484 { 485 mutex_lock(&dm_hash_cells_mutex); 486 hc->uuid = new_uuid; 487 mutex_unlock(&dm_hash_cells_mutex); 488 489 __link_uuid(hc); 490 } 491 492 /* 493 * Changes the name of a hash_cell and returns the old name for 494 * the caller to free. 495 */ 496 static char *__change_cell_name(struct hash_cell *hc, char *new_name) 497 { 498 char *old_name; 499 500 /* 501 * Rename and move the name cell. 502 */ 503 __unlink_name(hc); 504 old_name = hc->name; 505 506 mutex_lock(&dm_hash_cells_mutex); 507 hc->name = new_name; 508 mutex_unlock(&dm_hash_cells_mutex); 509 510 __link_name(hc); 511 512 return old_name; 513 } 514 515 static struct mapped_device *dm_hash_rename(struct dm_ioctl *param, 516 const char *new) 517 { 518 char *new_data, *old_name = NULL; 519 struct hash_cell *hc; 520 struct dm_table *table; 521 struct mapped_device *md; 522 unsigned int change_uuid = (param->flags & DM_UUID_FLAG) ? 1 : 0; 523 int srcu_idx; 524 struct dm_ima_context *ima_context = NULL; 525 526 /* 527 * duplicate new. 528 */ 529 new_data = kstrdup(new, GFP_KERNEL); 530 if (!new_data) 531 return ERR_PTR(-ENOMEM); 532 533 dm_ima_alloc_context(&ima_context, true); 534 down_write(&_hash_lock); 535 536 /* 537 * Is new free ? 538 */ 539 if (change_uuid) 540 hc = __get_uuid_cell(new); 541 else 542 hc = __get_name_cell(new); 543 544 if (hc) { 545 DMERR("Unable to change %s on mapped device %s to one that already exists: %s", 546 change_uuid ? "uuid" : "name", 547 param->name, new); 548 dm_put(hc->md); 549 up_write(&_hash_lock); 550 dm_ima_free_context(ima_context); 551 kfree(new_data); 552 return ERR_PTR(-EBUSY); 553 } 554 555 /* 556 * Is there such a device as 'old' ? 557 */ 558 hc = __get_name_cell(param->name); 559 if (!hc) { 560 DMERR("Unable to rename non-existent device, %s to %s%s", 561 param->name, change_uuid ? "uuid " : "", new); 562 up_write(&_hash_lock); 563 dm_ima_free_context(ima_context); 564 kfree(new_data); 565 return ERR_PTR(-ENXIO); 566 } 567 568 /* 569 * Does this device already have a uuid? 570 */ 571 if (change_uuid && hc->uuid) { 572 DMERR("Unable to change uuid of mapped device %s to %s " 573 "because uuid is already set to %s", 574 param->name, new, hc->uuid); 575 dm_put(hc->md); 576 up_write(&_hash_lock); 577 dm_ima_free_context(ima_context); 578 kfree(new_data); 579 return ERR_PTR(-EINVAL); 580 } 581 582 if (change_uuid) 583 __set_cell_uuid(hc, new_data); 584 else 585 old_name = __change_cell_name(hc, new_data); 586 587 /* 588 * Wake up any dm event waiters. 589 */ 590 table = dm_get_live_table(hc->md, &srcu_idx); 591 if (table) 592 dm_table_event(table); 593 dm_put_live_table(hc->md, srcu_idx); 594 595 if (!dm_kobject_uevent(hc->md, KOBJ_CHANGE, param->event_nr, false)) 596 param->flags |= DM_UEVENT_GENERATED_FLAG; 597 598 md = hc->md; 599 600 dm_ima_init_context(hc, ima_context, false); 601 602 up_write(&_hash_lock); 603 dm_ima_measure_on_device_rename(md, ima_context); 604 dm_ima_free_context(ima_context); 605 kfree(old_name); 606 607 return md; 608 } 609 610 void dm_deferred_remove(void) 611 { 612 dm_hash_remove_all(DM_REMOVE_KEEP_OPEN_DEVICES | DM_REMOVE_ONLY_DEFERRED); 613 } 614 615 /* 616 *--------------------------------------------------------------- 617 * Implementation of the ioctl commands 618 *--------------------------------------------------------------- 619 */ 620 /* 621 * All the ioctl commands get dispatched to functions with this 622 * prototype. 623 */ 624 typedef int (*ioctl_fn)(struct file *filp, struct dm_ioctl *param, size_t param_size); 625 626 static int remove_all(struct file *filp, struct dm_ioctl *param, size_t param_size) 627 { 628 int r; 629 int flags = DM_REMOVE_KEEP_OPEN_DEVICES | DM_REMOVE_INTERRUPTIBLE; 630 if (param->flags & DM_DEFERRED_REMOVE) 631 flags |= DM_REMOVE_MARK_DEFERRED; 632 r = dm_hash_remove_all(flags); 633 param->data_size = 0; 634 return r; 635 } 636 637 /* 638 * Round up the ptr to an 8-byte boundary. 639 */ 640 #define ALIGN_MASK 7 641 static inline size_t align_val(size_t val) 642 { 643 return (val + ALIGN_MASK) & ~ALIGN_MASK; 644 } 645 static inline void *align_ptr(void *ptr) 646 { 647 return (void *)align_val((size_t)ptr); 648 } 649 650 /* 651 * Retrieves the data payload buffer from an already allocated 652 * struct dm_ioctl. 653 */ 654 static void *get_result_buffer(struct dm_ioctl *param, size_t param_size, 655 size_t *len) 656 { 657 param->data_start = align_ptr(param + 1) - (void *) param; 658 659 if (param->data_start < param_size) { 660 *len = param_size - param->data_start; 661 } else { 662 /* 663 * The buffer can be as small as offsetof(*param, data), which 664 * is less than sizeof(*param), so don't run off the end of it. 665 */ 666 *len = 0; 667 param->data_start = param_size; 668 } 669 670 return ((void *) param) + param->data_start; 671 } 672 673 static bool filter_device(struct hash_cell *hc, const char *pfx_name, const char *pfx_uuid) 674 { 675 const char *val; 676 size_t val_len, pfx_len; 677 678 val = hc->name; 679 val_len = strlen(val); 680 pfx_len = strnlen(pfx_name, DM_NAME_LEN); 681 if (pfx_len > val_len) 682 return false; 683 if (memcmp(val, pfx_name, pfx_len)) 684 return false; 685 686 val = hc->uuid ? hc->uuid : ""; 687 val_len = strlen(val); 688 pfx_len = strnlen(pfx_uuid, DM_UUID_LEN); 689 if (pfx_len > val_len) 690 return false; 691 if (memcmp(val, pfx_uuid, pfx_len)) 692 return false; 693 694 return true; 695 } 696 697 static int list_devices(struct file *filp, struct dm_ioctl *param, size_t param_size) 698 { 699 struct rb_node *n; 700 struct hash_cell *hc; 701 size_t len; 702 struct dm_name_list *nl, *old_nl = NULL; 703 void *result_start, *result_limit; 704 uint32_t *event_nr; 705 706 /* 707 * Grab our output buffer. 708 */ 709 nl = result_start = get_result_buffer(param, param_size, &len); 710 result_limit = result_start + len; 711 712 if (len >= sizeof(*nl)) 713 nl->dev = 0; /* Flags no data */ 714 715 down_write(&_hash_lock); 716 717 /* 718 * Loop through filling out the names. 719 */ 720 for (n = rb_first(&name_rb_tree); n; n = rb_next(n)) { 721 void *next_nl; 722 723 hc = container_of(n, struct hash_cell, name_node); 724 if (!filter_device(hc, param->name, param->uuid)) 725 continue; 726 727 len = strlen(hc->name); 728 event_nr = align_ptr(nl->name + len + 1); 729 next_nl = event_nr + 2; 730 if (next_nl > result_limit) 731 break; 732 733 ((u64 *)event_nr)[-1] = 0; 734 memcpy(nl->name, hc->name, len); 735 736 nl->dev = huge_encode_dev(disk_devt(dm_disk(hc->md))); 737 738 event_nr[0] = dm_get_event_nr(hc->md); 739 event_nr[1] = 0; 740 741 if (param->flags & DM_UUID_FLAG) { 742 if (hc->uuid) { 743 len = strlen(hc->uuid); 744 next_nl = align_ptr(next_nl + len + 1); 745 if (next_nl > result_limit) 746 break; 747 event_nr[1] |= DM_NAME_LIST_FLAG_HAS_UUID; 748 ((u64 *)next_nl)[-1] = 0; 749 memcpy(event_nr + 2, hc->uuid, len); 750 } else { 751 event_nr[1] |= DM_NAME_LIST_FLAG_DOESNT_HAVE_UUID; 752 } 753 } 754 nl->next = next_nl - (void *)nl; 755 old_nl = nl; 756 nl = next_nl; 757 } 758 759 if (old_nl) 760 old_nl->next = 0; 761 762 if (n) 763 param->flags |= DM_BUFFER_FULL_FLAG; 764 else 765 param->data_size = param->data_start + ((void *)nl - result_start); 766 767 up_write(&_hash_lock); 768 return 0; 769 } 770 771 static void list_version_get_info(struct target_type *tt, void *param) 772 { 773 struct vers_iter *info = param; 774 struct dm_target_versions *vers = info->vers; 775 size_t name_len = strlen(tt->name); 776 777 if (!vers) 778 return; 779 780 info->old_vers = vers; 781 info->vers = align_ptr((void *)(info->vers + 1) + name_len + 1); 782 783 /* Check space */ 784 if ((char *)info->vers > info->end) { 785 info->vers = NULL; 786 return; 787 } 788 789 /* Zero padding and terminate vers->name[] */ 790 ((u64 *)info->vers)[-1] = 0; 791 792 vers->next = (char *)info->vers - (char *)vers; 793 794 vers->version[0] = tt->version[0]; 795 vers->version[1] = tt->version[1]; 796 vers->version[2] = tt->version[2]; 797 memcpy(vers->name, tt->name, name_len); 798 } 799 800 static int __list_versions(struct dm_ioctl *param, size_t param_size, const char *name) 801 { 802 size_t len; 803 struct dm_target_versions *vers; 804 struct vers_iter iter_info; 805 struct target_type *tt = NULL; 806 807 if (name) { 808 tt = dm_get_target_type(name); 809 if (!tt) 810 return -EINVAL; 811 } 812 813 /* 814 * Grab our output buffer. 815 */ 816 vers = get_result_buffer(param, param_size, &len); 817 818 iter_info.old_vers = NULL; 819 iter_info.vers = vers; 820 iter_info.end = (char *)vers + len; 821 822 /* 823 * Loop through filling out the names & versions. 824 */ 825 if (!tt) 826 dm_target_iterate(list_version_get_info, &iter_info); 827 else 828 list_version_get_info(tt, &iter_info); 829 830 if (iter_info.vers) { 831 if (iter_info.old_vers) 832 iter_info.old_vers->next = 0; 833 param->data_size = param->data_start + ((char *)iter_info.vers - (char *)vers); 834 } else { 835 param->flags |= DM_BUFFER_FULL_FLAG; 836 } 837 838 if (tt) 839 dm_put_target_type(tt); 840 return 0; 841 } 842 843 static int list_versions(struct file *filp, struct dm_ioctl *param, size_t param_size) 844 { 845 return __list_versions(param, param_size, NULL); 846 } 847 848 static int get_target_version(struct file *filp, struct dm_ioctl *param, size_t param_size) 849 { 850 return __list_versions(param, param_size, param->name); 851 } 852 853 static int check_name(const char *name) 854 { 855 if (strchr(name, '/')) { 856 DMERR("device name cannot contain '/'"); 857 return -EINVAL; 858 } 859 860 if (strcmp(name, DM_CONTROL_NODE) == 0 || 861 strcmp(name, ".") == 0 || 862 strcmp(name, "..") == 0) { 863 DMERR("device name cannot be \"%s\", \".\", or \"..\"", DM_CONTROL_NODE); 864 return -EINVAL; 865 } 866 867 return 0; 868 } 869 870 /* 871 * On successful return, the caller must not attempt to acquire 872 * _hash_lock without first calling dm_put_live_table, because dm_table_destroy 873 * waits for this dm_put_live_table and could be called under this lock. 874 */ 875 static struct dm_table *dm_get_inactive_table(struct mapped_device *md, int *srcu_idx) 876 { 877 struct hash_cell *hc; 878 struct dm_table *table = NULL; 879 880 /* increment rcu count, we don't care about the table pointer */ 881 dm_get_live_table(md, srcu_idx); 882 883 down_read(&_hash_lock); 884 hc = dm_get_mdptr(md); 885 if (!hc) { 886 DMERR("device has been removed from the dev hash table."); 887 goto out; 888 } 889 890 table = hc->new_map; 891 892 out: 893 up_read(&_hash_lock); 894 895 return table; 896 } 897 898 static struct dm_table *dm_get_live_or_inactive_table(struct mapped_device *md, 899 struct dm_ioctl *param, 900 int *srcu_idx) 901 { 902 return (param->flags & DM_QUERY_INACTIVE_TABLE_FLAG) ? 903 dm_get_inactive_table(md, srcu_idx) : dm_get_live_table(md, srcu_idx); 904 } 905 906 /* 907 * Fills in a dm_ioctl structure, ready for sending back to 908 * userland. 909 */ 910 static void __dev_status(struct mapped_device *md, struct dm_ioctl *param) 911 { 912 struct gendisk *disk = dm_disk(md); 913 struct dm_table *table; 914 int srcu_idx; 915 916 param->flags &= ~(DM_SUSPEND_FLAG | DM_READONLY_FLAG | 917 DM_ACTIVE_PRESENT_FLAG | DM_INTERNAL_SUSPEND_FLAG); 918 919 if (dm_suspended_md(md)) 920 param->flags |= DM_SUSPEND_FLAG; 921 922 if (dm_suspended_internally_md(md)) 923 param->flags |= DM_INTERNAL_SUSPEND_FLAG; 924 925 if (dm_test_deferred_remove_flag(md)) 926 param->flags |= DM_DEFERRED_REMOVE; 927 928 param->dev = huge_encode_dev(disk_devt(disk)); 929 930 /* 931 * Yes, this will be out of date by the time it gets back 932 * to userland, but it is still very useful for 933 * debugging. 934 */ 935 param->open_count = dm_open_count(md); 936 937 param->event_nr = dm_get_event_nr(md); 938 param->target_count = 0; 939 940 table = dm_get_live_table(md, &srcu_idx); 941 if (table) { 942 if (!(param->flags & DM_QUERY_INACTIVE_TABLE_FLAG)) { 943 if (get_disk_ro(disk)) 944 param->flags |= DM_READONLY_FLAG; 945 param->target_count = table->num_targets; 946 } 947 948 param->flags |= DM_ACTIVE_PRESENT_FLAG; 949 } 950 dm_put_live_table(md, srcu_idx); 951 952 if (param->flags & DM_QUERY_INACTIVE_TABLE_FLAG) { 953 int srcu_idx; 954 955 table = dm_get_inactive_table(md, &srcu_idx); 956 if (table) { 957 if (!(dm_table_get_mode(table) & BLK_OPEN_WRITE)) 958 param->flags |= DM_READONLY_FLAG; 959 param->target_count = table->num_targets; 960 } 961 dm_put_live_table(md, srcu_idx); 962 } 963 } 964 965 static int dev_create(struct file *filp, struct dm_ioctl *param, size_t param_size) 966 { 967 int r, m = DM_ANY_MINOR; 968 struct mapped_device *md; 969 970 r = check_name(param->name); 971 if (r) 972 return r; 973 974 if (param->flags & DM_PERSISTENT_DEV_FLAG) 975 m = MINOR(huge_decode_dev(param->dev)); 976 977 r = dm_create(m, &md); 978 if (r) 979 return r; 980 981 r = dm_hash_insert(param->name, *param->uuid ? param->uuid : NULL, md); 982 if (r) { 983 dm_put(md); 984 dm_destroy(md); 985 return r; 986 } 987 988 param->flags &= ~DM_INACTIVE_PRESENT_FLAG; 989 990 __dev_status(md, param); 991 992 dm_put(md); 993 994 return 0; 995 } 996 997 /* 998 * Always use UUID for lookups if it's present, otherwise use name or dev. 999 */ 1000 static struct hash_cell *__find_device_hash_cell(struct dm_ioctl *param) 1001 { 1002 struct hash_cell *hc = NULL; 1003 1004 if (*param->uuid) { 1005 if (*param->name || param->dev) { 1006 DMERR("Invalid ioctl structure: uuid %s, name %s, dev %llx", 1007 param->uuid, param->name, (unsigned long long)param->dev); 1008 return NULL; 1009 } 1010 1011 hc = __get_uuid_cell(param->uuid); 1012 if (!hc) 1013 return NULL; 1014 } else if (*param->name) { 1015 if (param->dev) { 1016 DMERR("Invalid ioctl structure: name %s, dev %llx", 1017 param->name, (unsigned long long)param->dev); 1018 return NULL; 1019 } 1020 1021 hc = __get_name_cell(param->name); 1022 if (!hc) 1023 return NULL; 1024 } else if (param->dev) { 1025 hc = __get_dev_cell(param->dev); 1026 if (!hc) 1027 return NULL; 1028 } else 1029 return NULL; 1030 1031 /* 1032 * Sneakily write in both the name and the uuid 1033 * while we have the cell. 1034 */ 1035 strscpy(param->name, hc->name, sizeof(param->name)); 1036 if (hc->uuid) 1037 strscpy(param->uuid, hc->uuid, sizeof(param->uuid)); 1038 else 1039 param->uuid[0] = '\0'; 1040 1041 if (hc->new_map) 1042 param->flags |= DM_INACTIVE_PRESENT_FLAG; 1043 else 1044 param->flags &= ~DM_INACTIVE_PRESENT_FLAG; 1045 1046 return hc; 1047 } 1048 1049 static struct mapped_device *find_device(struct dm_ioctl *param) 1050 { 1051 struct hash_cell *hc; 1052 struct mapped_device *md = NULL; 1053 1054 down_read(&_hash_lock); 1055 hc = __find_device_hash_cell(param); 1056 if (hc) 1057 md = hc->md; 1058 up_read(&_hash_lock); 1059 1060 return md; 1061 } 1062 1063 static int dev_remove(struct file *filp, struct dm_ioctl *param, size_t param_size) 1064 { 1065 struct hash_cell *hc; 1066 struct mapped_device *md; 1067 int r; 1068 struct dm_table *t; 1069 struct dm_ima_context *ima_context = NULL; 1070 unsigned int ima_idx; 1071 1072 dm_ima_alloc_context(&ima_context, true); 1073 down_write(&_hash_lock); 1074 hc = __find_device_hash_cell(param); 1075 1076 if (!hc) { 1077 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table."); 1078 up_write(&_hash_lock); 1079 dm_ima_free_context(ima_context); 1080 return -ENXIO; 1081 } 1082 1083 md = hc->md; 1084 1085 /* 1086 * Ensure the device is not open and nothing further can open it. 1087 */ 1088 r = dm_lock_for_deletion(md, !!(param->flags & DM_DEFERRED_REMOVE), false); 1089 if (r) { 1090 if (r == -EBUSY && param->flags & DM_DEFERRED_REMOVE) { 1091 up_write(&_hash_lock); 1092 dm_put(md); 1093 dm_ima_free_context(ima_context); 1094 return 0; 1095 } 1096 DMDEBUG_LIMIT("unable to remove open device %s", hc->name); 1097 up_write(&_hash_lock); 1098 dm_put(md); 1099 dm_ima_free_context(ima_context); 1100 return r; 1101 } 1102 1103 ima_idx = dm_ima_init_context(hc, ima_context, true); 1104 t = __hash_remove(hc); 1105 up_write(&_hash_lock); 1106 1107 if (t) { 1108 dm_sync_table(md); 1109 dm_table_destroy(t); 1110 } 1111 1112 param->flags &= ~DM_DEFERRED_REMOVE; 1113 1114 dm_ima_measure_on_device_remove(md, false, ima_context, ima_idx); 1115 dm_ima_free_context(ima_context); 1116 1117 if (!dm_kobject_uevent(md, KOBJ_REMOVE, param->event_nr, false)) 1118 param->flags |= DM_UEVENT_GENERATED_FLAG; 1119 1120 dm_put(md); 1121 dm_destroy(md); 1122 return 0; 1123 } 1124 1125 /* 1126 * Check a string doesn't overrun the chunk of 1127 * memory we copied from userland. 1128 */ 1129 static int invalid_str(char *str, void *end) 1130 { 1131 while ((void *) str < end) 1132 if (!*str++) 1133 return 0; 1134 1135 return -EINVAL; 1136 } 1137 1138 static int dev_rename(struct file *filp, struct dm_ioctl *param, size_t param_size) 1139 { 1140 int r; 1141 char *new_data = (char *) param + param->data_start; 1142 struct mapped_device *md; 1143 unsigned int change_uuid = (param->flags & DM_UUID_FLAG) ? 1 : 0; 1144 1145 if (new_data < param->data || 1146 invalid_str(new_data, (void *) param + param_size) || !*new_data || 1147 strlen(new_data) > (change_uuid ? DM_UUID_LEN - 1 : DM_NAME_LEN - 1)) { 1148 DMERR("Invalid new mapped device name or uuid string supplied."); 1149 return -EINVAL; 1150 } 1151 1152 if (!change_uuid) { 1153 r = check_name(new_data); 1154 if (r) 1155 return r; 1156 } 1157 1158 md = dm_hash_rename(param, new_data); 1159 if (IS_ERR(md)) 1160 return PTR_ERR(md); 1161 1162 __dev_status(md, param); 1163 dm_put(md); 1164 1165 return 0; 1166 } 1167 1168 static int dev_set_geometry(struct file *filp, struct dm_ioctl *param, size_t param_size) 1169 { 1170 int r = -EINVAL, x; 1171 struct mapped_device *md; 1172 struct hd_geometry geometry; 1173 unsigned long indata[4]; 1174 char *geostr = (char *) param + param->data_start; 1175 char dummy; 1176 1177 md = find_device(param); 1178 if (!md) 1179 return -ENXIO; 1180 1181 if (geostr < param->data || 1182 invalid_str(geostr, (void *) param + param_size)) { 1183 DMERR("Invalid geometry supplied."); 1184 goto out; 1185 } 1186 1187 x = sscanf(geostr, "%lu %lu %lu %lu%c", indata, 1188 indata + 1, indata + 2, indata + 3, &dummy); 1189 1190 if (x != 4) { 1191 DMERR("Unable to interpret geometry settings."); 1192 goto out; 1193 } 1194 1195 if (indata[0] > 65535 || indata[1] > 255 || indata[2] > 255) { 1196 DMERR("Geometry exceeds range limits."); 1197 goto out; 1198 } 1199 1200 geometry.cylinders = indata[0]; 1201 geometry.heads = indata[1]; 1202 geometry.sectors = indata[2]; 1203 geometry.start = indata[3]; 1204 1205 r = dm_set_geometry(md, &geometry); 1206 1207 param->data_size = 0; 1208 1209 out: 1210 dm_put(md); 1211 return r; 1212 } 1213 1214 static int do_suspend(struct dm_ioctl *param) 1215 { 1216 int r = 0; 1217 unsigned int suspend_flags = DM_SUSPEND_LOCKFS_FLAG; 1218 struct mapped_device *md; 1219 1220 md = find_device(param); 1221 if (!md) 1222 return -ENXIO; 1223 1224 if (param->flags & DM_SKIP_LOCKFS_FLAG) 1225 suspend_flags &= ~DM_SUSPEND_LOCKFS_FLAG; 1226 if (param->flags & DM_NOFLUSH_FLAG) 1227 suspend_flags |= DM_SUSPEND_NOFLUSH_FLAG; 1228 1229 if (!dm_suspended_md(md)) { 1230 r = dm_suspend(md, suspend_flags); 1231 if (r) 1232 goto out; 1233 } 1234 1235 __dev_status(md, param); 1236 1237 out: 1238 dm_put(md); 1239 1240 return r; 1241 } 1242 1243 static int do_resume(struct dm_ioctl *param) 1244 { 1245 int r = 0; 1246 unsigned int suspend_flags = DM_SUSPEND_LOCKFS_FLAG; 1247 struct hash_cell *hc; 1248 struct mapped_device *md; 1249 struct dm_table *new_map, *old_map = NULL; 1250 bool need_resize_uevent = false; 1251 struct dm_ima_context *ima_context = NULL; 1252 1253 dm_ima_alloc_context(&ima_context, true); 1254 down_write(&_hash_lock); 1255 1256 hc = __find_device_hash_cell(param); 1257 if (!hc) { 1258 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table."); 1259 up_write(&_hash_lock); 1260 dm_ima_free_context(ima_context); 1261 return -ENXIO; 1262 } 1263 1264 md = hc->md; 1265 1266 new_map = hc->new_map; 1267 hc->new_map = NULL; 1268 param->flags &= ~DM_INACTIVE_PRESENT_FLAG; 1269 if (new_map) 1270 dm_ima_init_context(hc, ima_context, false); 1271 up_write(&_hash_lock); 1272 1273 /* Do we need to load a new map ? */ 1274 if (new_map) { 1275 sector_t old_size, new_size; 1276 blk_mode_t new_map_mode; 1277 1278 dm_ima_context_table_op(md, ima_context, DM_IMA_TABLE_SAVE); 1279 /* Suspend if it isn't already suspended */ 1280 if (param->flags & DM_SKIP_LOCKFS_FLAG) 1281 suspend_flags &= ~DM_SUSPEND_LOCKFS_FLAG; 1282 if (param->flags & DM_NOFLUSH_FLAG) 1283 suspend_flags |= DM_SUSPEND_NOFLUSH_FLAG; 1284 if (!dm_suspended_md(md)) { 1285 r = dm_suspend(md, suspend_flags); 1286 if (r) { 1287 down_write(&_hash_lock); 1288 hc = dm_get_mdptr(md); 1289 if (hc && !hc->new_map) { 1290 hc->new_map = new_map; 1291 new_map = NULL; 1292 dm_ima_init_context(hc, ima_context, 1293 false); 1294 } else { 1295 r = -ENXIO; 1296 } 1297 up_write(&_hash_lock); 1298 if (new_map) { 1299 dm_sync_table(md); 1300 dm_table_destroy(new_map); 1301 } else 1302 dm_ima_context_table_op(md, ima_context, DM_IMA_TABLE_RESTORE); 1303 dm_ima_free_context(ima_context); 1304 dm_put(md); 1305 return r; 1306 } 1307 } 1308 1309 new_map_mode = dm_table_get_mode(new_map); 1310 old_size = dm_get_size(md); 1311 old_map = dm_swap_table(md, new_map); 1312 if (IS_ERR(old_map)) { 1313 dm_sync_table(md); 1314 dm_table_destroy(new_map); 1315 dm_ima_free_context(ima_context); 1316 dm_put(md); 1317 return PTR_ERR(old_map); 1318 } 1319 if (dm_ima_need_measure(md, new_map, ima_context)) 1320 dm_ima_measure_on_device_resume(md, true, ima_context); 1321 new_size = dm_get_size(md); 1322 if (old_size && new_size && old_size != new_size) 1323 need_resize_uevent = true; 1324 1325 if (new_map_mode & BLK_OPEN_WRITE) 1326 set_disk_ro(dm_disk(md), 0); 1327 else 1328 set_disk_ro(dm_disk(md), 1); 1329 } 1330 1331 if (dm_suspended_md(md)) { 1332 r = dm_resume(md); 1333 if (!r) { 1334 if (!new_map && dm_ima_need_measure(md, NULL, 1335 ima_context)) 1336 dm_ima_measure_on_device_resume(md, false, 1337 ima_context); 1338 1339 if (!dm_kobject_uevent(md, KOBJ_CHANGE, param->event_nr, need_resize_uevent)) 1340 param->flags |= DM_UEVENT_GENERATED_FLAG; 1341 } 1342 } 1343 1344 /* 1345 * Since dm_swap_table synchronizes RCU, nobody should be in 1346 * read-side critical section already. 1347 */ 1348 if (old_map) 1349 dm_table_destroy(old_map); 1350 1351 if (!r) 1352 __dev_status(md, param); 1353 1354 dm_ima_free_context(ima_context); 1355 dm_put(md); 1356 return r; 1357 } 1358 1359 /* 1360 * Set or unset the suspension state of a device. 1361 * If the device already is in the requested state we just return its status. 1362 */ 1363 static int dev_suspend(struct file *filp, struct dm_ioctl *param, size_t param_size) 1364 { 1365 if (param->flags & DM_SUSPEND_FLAG) 1366 return do_suspend(param); 1367 1368 return do_resume(param); 1369 } 1370 1371 /* 1372 * Copies device info back to user space, used by 1373 * the create and info ioctls. 1374 */ 1375 static int dev_status(struct file *filp, struct dm_ioctl *param, size_t param_size) 1376 { 1377 struct mapped_device *md; 1378 1379 md = find_device(param); 1380 if (!md) 1381 return -ENXIO; 1382 1383 __dev_status(md, param); 1384 dm_put(md); 1385 1386 return 0; 1387 } 1388 1389 /* 1390 * Build up the status struct for each target 1391 */ 1392 static void retrieve_status(struct dm_table *table, 1393 struct dm_ioctl *param, size_t param_size) 1394 { 1395 unsigned int i, num_targets; 1396 struct dm_target_spec *spec; 1397 char *outbuf, *outptr; 1398 status_type_t type; 1399 size_t remaining, len, used = 0; 1400 unsigned int status_flags = 0; 1401 1402 outptr = outbuf = get_result_buffer(param, param_size, &len); 1403 1404 if (param->flags & DM_STATUS_TABLE_FLAG) 1405 type = STATUSTYPE_TABLE; 1406 else if (param->flags & DM_IMA_MEASUREMENT_FLAG) 1407 type = STATUSTYPE_IMA; 1408 else 1409 type = STATUSTYPE_INFO; 1410 1411 /* Get all the target info */ 1412 num_targets = table->num_targets; 1413 for (i = 0; i < num_targets; i++) { 1414 struct dm_target *ti = dm_table_get_target(table, i); 1415 size_t l; 1416 1417 remaining = len - (outptr - outbuf); 1418 if (remaining <= sizeof(struct dm_target_spec)) { 1419 param->flags |= DM_BUFFER_FULL_FLAG; 1420 break; 1421 } 1422 1423 spec = (struct dm_target_spec *) outptr; 1424 1425 spec->status = 0; 1426 spec->sector_start = ti->begin; 1427 spec->length = ti->len; 1428 strscpy_pad(spec->target_type, ti->type->name, 1429 sizeof(spec->target_type)); 1430 1431 outptr += sizeof(struct dm_target_spec); 1432 remaining = len - (outptr - outbuf); 1433 1434 /* Get the status/table string from the target driver */ 1435 if (ti->type->status) { 1436 if (param->flags & DM_NOFLUSH_FLAG) 1437 status_flags |= DM_STATUS_NOFLUSH_FLAG; 1438 ti->type->status(ti, type, status_flags, outptr, remaining); 1439 } else 1440 outptr[0] = '\0'; 1441 1442 l = strlen(outptr) + 1; 1443 if (l == remaining) { 1444 param->flags |= DM_BUFFER_FULL_FLAG; 1445 break; 1446 } 1447 1448 outptr += l; 1449 used = param->data_start + (outptr - outbuf); 1450 1451 outptr = align_ptr(outptr); 1452 if (!outptr || outptr > outbuf + len) { 1453 param->flags |= DM_BUFFER_FULL_FLAG; 1454 break; 1455 } 1456 spec->next = outptr - outbuf; 1457 } 1458 1459 if (used) 1460 param->data_size = used; 1461 1462 param->target_count = num_targets; 1463 } 1464 1465 /* 1466 * Wait for a device to report an event 1467 */ 1468 static int dev_wait(struct file *filp, struct dm_ioctl *param, size_t param_size) 1469 { 1470 int r = 0; 1471 struct mapped_device *md; 1472 struct dm_table *table; 1473 int srcu_idx; 1474 1475 md = find_device(param); 1476 if (!md) 1477 return -ENXIO; 1478 1479 /* 1480 * Wait for a notification event 1481 */ 1482 if (dm_wait_event(md, param->event_nr)) { 1483 r = -ERESTARTSYS; 1484 goto out; 1485 } 1486 1487 /* 1488 * The userland program is going to want to know what 1489 * changed to trigger the event, so we may as well tell 1490 * him and save an ioctl. 1491 */ 1492 __dev_status(md, param); 1493 1494 table = dm_get_live_or_inactive_table(md, param, &srcu_idx); 1495 if (table) 1496 retrieve_status(table, param, param_size); 1497 dm_put_live_table(md, srcu_idx); 1498 1499 out: 1500 dm_put(md); 1501 1502 return r; 1503 } 1504 1505 /* 1506 * Remember the global event number and make it possible to poll 1507 * for further events. 1508 */ 1509 static int dev_arm_poll(struct file *filp, struct dm_ioctl *param, size_t param_size) 1510 { 1511 struct dm_file *priv = filp->private_data; 1512 1513 priv->global_event_nr = atomic_read(&dm_global_event_nr); 1514 1515 return 0; 1516 } 1517 1518 static inline blk_mode_t get_mode(struct dm_ioctl *param) 1519 { 1520 blk_mode_t mode = BLK_OPEN_READ | BLK_OPEN_WRITE; 1521 1522 if (param->flags & DM_READONLY_FLAG) 1523 mode = BLK_OPEN_READ; 1524 1525 return mode; 1526 } 1527 1528 static int next_target(struct dm_target_spec *last, uint32_t next, const char *end, 1529 struct dm_target_spec **spec, char **target_params) 1530 { 1531 static_assert(__alignof__(struct dm_target_spec) <= 8, 1532 "struct dm_target_spec must not require more than 8-byte alignment"); 1533 1534 /* 1535 * Number of bytes remaining, starting with last. This is always 1536 * sizeof(struct dm_target_spec) or more, as otherwise *last was 1537 * out of bounds already. 1538 */ 1539 size_t remaining = end - (char *)last; 1540 1541 /* 1542 * There must be room for both the next target spec and the 1543 * NUL-terminator of the target itself. 1544 */ 1545 if (remaining - sizeof(struct dm_target_spec) <= next) { 1546 DMERR("Target spec extends beyond end of parameters"); 1547 return -EINVAL; 1548 } 1549 1550 if (next % __alignof__(struct dm_target_spec)) { 1551 DMERR("Next dm_target_spec (offset %u) is not %zu-byte aligned", 1552 next, __alignof__(struct dm_target_spec)); 1553 return -EINVAL; 1554 } 1555 1556 *spec = (struct dm_target_spec *) ((unsigned char *) last + next); 1557 *target_params = (char *) (*spec + 1); 1558 1559 return 0; 1560 } 1561 1562 static int populate_table(struct dm_table *table, 1563 struct dm_ioctl *param, size_t param_size) 1564 { 1565 int r; 1566 unsigned int i = 0; 1567 struct dm_target_spec *spec = (struct dm_target_spec *) param; 1568 uint32_t next = param->data_start; 1569 const char *const end = (const char *) param + param_size; 1570 char *target_params; 1571 size_t min_size = sizeof(struct dm_ioctl); 1572 1573 if (!param->target_count) { 1574 DMERR("%s: no targets specified", __func__); 1575 return -EINVAL; 1576 } 1577 1578 for (i = 0; i < param->target_count; i++) { 1579 const char *nul_terminator; 1580 1581 if (next < min_size) { 1582 DMERR("%s: next target spec (offset %u) overlaps %s", 1583 __func__, next, i ? "previous target" : "'struct dm_ioctl'"); 1584 return -EINVAL; 1585 } 1586 1587 r = next_target(spec, next, end, &spec, &target_params); 1588 if (r) { 1589 DMERR("unable to find target"); 1590 return r; 1591 } 1592 1593 nul_terminator = memchr(target_params, 0, (size_t)(end - target_params)); 1594 if (nul_terminator == NULL) { 1595 DMERR("%s: target parameters not NUL-terminated", __func__); 1596 return -EINVAL; 1597 } 1598 1599 /* Add 1 for NUL terminator */ 1600 min_size = (size_t)(nul_terminator - (const char *)spec) + 1; 1601 1602 r = dm_table_add_target(table, spec->target_type, 1603 (sector_t) spec->sector_start, 1604 (sector_t) spec->length, 1605 target_params); 1606 if (r) { 1607 DMERR("error adding target to table"); 1608 return r; 1609 } 1610 1611 next = spec->next; 1612 } 1613 1614 return dm_table_complete(table); 1615 } 1616 1617 static bool is_valid_type(enum dm_queue_mode cur, enum dm_queue_mode new) 1618 { 1619 if (cur == new || 1620 (cur == DM_TYPE_BIO_BASED && new == DM_TYPE_DAX_BIO_BASED)) 1621 return true; 1622 1623 return false; 1624 } 1625 1626 static int table_load(struct file *filp, struct dm_ioctl *param, size_t param_size) 1627 { 1628 int r, srcu_idx; 1629 struct hash_cell *hc; 1630 struct dm_table *t, *old_map = NULL; 1631 struct mapped_device *md; 1632 struct target_type *immutable_target_type; 1633 struct dm_ima_context *ima_context = NULL; 1634 1635 md = find_device(param); 1636 if (!md) 1637 return -ENXIO; 1638 1639 r = dm_table_create(&t, get_mode(param), param->target_count, md); 1640 if (r) 1641 goto err; 1642 1643 /* Protect md->type and md->queue against concurrent table loads. */ 1644 dm_lock_md_type(md); 1645 r = populate_table(t, param, param_size); 1646 if (r) 1647 goto err_unlock_md_type; 1648 1649 immutable_target_type = dm_get_immutable_target_type(md); 1650 if (immutable_target_type && 1651 (immutable_target_type != dm_table_get_immutable_target_type(t)) && 1652 !dm_table_get_wildcard_target(t)) { 1653 DMERR("can't replace immutable target type %s", 1654 immutable_target_type->name); 1655 r = -EINVAL; 1656 goto err_unlock_md_type; 1657 } 1658 1659 if (dm_get_md_type(md) == DM_TYPE_NONE) { 1660 /* setup md->queue to reflect md's type (may block) */ 1661 r = dm_setup_md_queue(md, t); 1662 if (r) { 1663 DMERR("unable to set up device queue for new table."); 1664 goto err_unlock_md_type; 1665 } 1666 } else if (!is_valid_type(dm_get_md_type(md), dm_table_get_type(t))) { 1667 DMERR("can't change device type (old=%u vs new=%u) after initial table load.", 1668 dm_get_md_type(md), dm_table_get_type(t)); 1669 r = -EINVAL; 1670 goto err_unlock_md_type; 1671 } 1672 1673 dm_unlock_md_type(md); 1674 1675 dm_ima_alloc_context(&ima_context, false); 1676 /* stage inactive table */ 1677 down_write(&_hash_lock); 1678 hc = dm_get_mdptr(md); 1679 if (!hc) { 1680 DMERR("device has been removed from the dev hash table."); 1681 up_write(&_hash_lock); 1682 dm_ima_free_context(ima_context); 1683 r = -ENXIO; 1684 goto err_destroy_table; 1685 } 1686 1687 if (hc->new_map) 1688 old_map = hc->new_map; 1689 hc->new_map = t; 1690 dm_ima_init_context(hc, ima_context, false); 1691 /* Make sure new_map doesn't get freed before we measure it*/ 1692 dm_get_live_table(md, &srcu_idx); 1693 up_write(&_hash_lock); 1694 1695 dm_ima_measure_on_table_load(t, ima_context); 1696 dm_ima_free_context(ima_context); 1697 dm_put_live_table(md, srcu_idx); 1698 1699 param->flags |= DM_INACTIVE_PRESENT_FLAG; 1700 __dev_status(md, param); 1701 1702 if (old_map) { 1703 dm_sync_table(md); 1704 dm_table_destroy(old_map); 1705 } 1706 1707 dm_put(md); 1708 1709 return 0; 1710 1711 err_unlock_md_type: 1712 dm_unlock_md_type(md); 1713 err_destroy_table: 1714 dm_table_destroy(t); 1715 err: 1716 dm_put(md); 1717 1718 return r; 1719 } 1720 1721 static int table_clear(struct file *filp, struct dm_ioctl *param, size_t param_size) 1722 { 1723 struct hash_cell *hc; 1724 struct mapped_device *md; 1725 struct dm_table *old_map = NULL; 1726 struct dm_ima_context *ima_context = NULL; 1727 1728 dm_ima_alloc_context(&ima_context, true); 1729 down_write(&_hash_lock); 1730 1731 hc = __find_device_hash_cell(param); 1732 if (!hc) { 1733 DMDEBUG_LIMIT("device doesn't appear to be in the dev hash table."); 1734 up_write(&_hash_lock); 1735 dm_ima_free_context(ima_context); 1736 return -ENXIO; 1737 } 1738 1739 if (hc->new_map) { 1740 old_map = hc->new_map; 1741 hc->new_map = NULL; 1742 } 1743 1744 dm_ima_init_context(hc, ima_context, false); 1745 md = hc->md; 1746 up_write(&_hash_lock); 1747 dm_ima_measure_on_table_clear(md, ima_context); 1748 dm_ima_free_context(ima_context); 1749 1750 param->flags &= ~DM_INACTIVE_PRESENT_FLAG; 1751 __dev_status(md, param); 1752 1753 if (old_map) { 1754 dm_sync_table(md); 1755 dm_table_destroy(old_map); 1756 } 1757 dm_put(md); 1758 1759 return 0; 1760 } 1761 1762 /* 1763 * Retrieves a list of devices used by a particular dm device. 1764 */ 1765 static void retrieve_deps(struct dm_table *table, 1766 struct dm_ioctl *param, size_t param_size) 1767 { 1768 unsigned int count = 0; 1769 struct list_head *tmp; 1770 size_t len, needed; 1771 struct dm_dev_internal *dd; 1772 struct dm_target_deps *deps; 1773 1774 deps = get_result_buffer(param, param_size, &len); 1775 1776 /* 1777 * Count the devices. 1778 */ 1779 list_for_each(tmp, dm_table_get_devices(table)) 1780 count++; 1781 1782 /* 1783 * Check we have enough space. 1784 */ 1785 needed = struct_size(deps, dev, count); 1786 if (len < needed) { 1787 param->flags |= DM_BUFFER_FULL_FLAG; 1788 return; 1789 } 1790 1791 /* 1792 * Fill in the devices. 1793 */ 1794 deps->count = count; 1795 count = 0; 1796 list_for_each_entry(dd, dm_table_get_devices(table), list) 1797 deps->dev[count++] = huge_encode_dev(dd->dm_dev->bdev->bd_dev); 1798 1799 param->data_size = param->data_start + needed; 1800 } 1801 1802 static int table_deps(struct file *filp, struct dm_ioctl *param, size_t param_size) 1803 { 1804 struct mapped_device *md; 1805 struct dm_table *table; 1806 int srcu_idx; 1807 1808 md = find_device(param); 1809 if (!md) 1810 return -ENXIO; 1811 1812 __dev_status(md, param); 1813 1814 table = dm_get_live_or_inactive_table(md, param, &srcu_idx); 1815 if (table) 1816 retrieve_deps(table, param, param_size); 1817 dm_put_live_table(md, srcu_idx); 1818 1819 dm_put(md); 1820 1821 return 0; 1822 } 1823 1824 /* 1825 * Return the status of a device as a text string for each 1826 * target. 1827 */ 1828 static int table_status(struct file *filp, struct dm_ioctl *param, size_t param_size) 1829 { 1830 struct mapped_device *md; 1831 struct dm_table *table; 1832 int srcu_idx; 1833 1834 md = find_device(param); 1835 if (!md) 1836 return -ENXIO; 1837 1838 __dev_status(md, param); 1839 1840 table = dm_get_live_or_inactive_table(md, param, &srcu_idx); 1841 if (table) 1842 retrieve_status(table, param, param_size); 1843 dm_put_live_table(md, srcu_idx); 1844 1845 dm_put(md); 1846 1847 return 0; 1848 } 1849 1850 /* 1851 * Process device-mapper dependent messages. Messages prefixed with '@' 1852 * are processed by the DM core. All others are delivered to the target. 1853 * Returns a number <= 1 if message was processed by device mapper. 1854 * Returns 2 if message should be delivered to the target. 1855 */ 1856 static int message_for_md(struct mapped_device *md, unsigned int argc, char **argv, 1857 char *result, unsigned int maxlen) 1858 { 1859 int r; 1860 1861 if (**argv != '@') 1862 return 2; /* no '@' prefix, deliver to target */ 1863 1864 if (!strcasecmp(argv[0], "@cancel_deferred_remove")) { 1865 if (argc != 1) { 1866 DMERR("Invalid arguments for @cancel_deferred_remove"); 1867 return -EINVAL; 1868 } 1869 return dm_cancel_deferred_remove(md); 1870 } 1871 1872 r = dm_stats_message(md, argc, argv, result, maxlen); 1873 if (r < 2) 1874 return r; 1875 1876 DMERR("Unsupported message sent to DM core: %s", argv[0]); 1877 return -EINVAL; 1878 } 1879 1880 /* 1881 * Pass a message to the target that's at the supplied device offset. 1882 */ 1883 static int target_message(struct file *filp, struct dm_ioctl *param, size_t param_size) 1884 { 1885 int r, argc; 1886 char **argv; 1887 struct mapped_device *md; 1888 struct dm_table *table; 1889 struct dm_target *ti; 1890 struct dm_target_msg *tmsg = (void *) param + param->data_start; 1891 size_t maxlen; 1892 char *result = get_result_buffer(param, param_size, &maxlen); 1893 int srcu_idx; 1894 1895 md = find_device(param); 1896 if (!md) 1897 return -ENXIO; 1898 1899 if (tmsg < (struct dm_target_msg *) param->data || 1900 invalid_str(tmsg->message, (void *) param + param_size)) { 1901 DMERR("Invalid target message parameters."); 1902 r = -EINVAL; 1903 goto out; 1904 } 1905 1906 r = dm_split_args(&argc, &argv, tmsg->message); 1907 if (r) { 1908 DMERR("Failed to split target message parameters"); 1909 goto out; 1910 } 1911 1912 if (!argc) { 1913 DMERR("Empty message received."); 1914 r = -EINVAL; 1915 goto out_argv; 1916 } 1917 1918 r = message_for_md(md, argc, argv, result, maxlen); 1919 if (r <= 1) 1920 goto out_argv; 1921 1922 table = dm_get_live_table(md, &srcu_idx); 1923 if (!table) { 1924 DMERR("The device has no table."); 1925 r = -EINVAL; 1926 goto out_table; 1927 } 1928 1929 if (dm_deleting_md(md)) { 1930 r = -ENXIO; 1931 goto out_table; 1932 } 1933 1934 ti = dm_table_find_target(table, tmsg->sector); 1935 if (!ti) { 1936 DMERR("Target message sector outside device."); 1937 r = -EINVAL; 1938 } else if (ti->type->message) 1939 r = ti->type->message(ti, argc, argv, result, maxlen); 1940 else { 1941 DMERR("Target type does not support messages"); 1942 r = -EINVAL; 1943 } 1944 1945 out_table: 1946 dm_put_live_table(md, srcu_idx); 1947 out_argv: 1948 kfree(argv); 1949 out: 1950 if (r >= 0) 1951 __dev_status(md, param); 1952 1953 if (r == 1) { 1954 param->flags |= DM_DATA_OUT_FLAG; 1955 if (dm_message_test_buffer_overflow(result, maxlen)) 1956 param->flags |= DM_BUFFER_FULL_FLAG; 1957 else 1958 param->data_size = param->data_start + strlen(result) + 1; 1959 r = 0; 1960 } 1961 1962 dm_put(md); 1963 return r; 1964 } 1965 1966 /* 1967 * The ioctl parameter block consists of two parts, a dm_ioctl struct 1968 * followed by a data buffer. This flag is set if the second part, 1969 * which has a variable size, is not used by the function processing 1970 * the ioctl. 1971 */ 1972 #define IOCTL_FLAGS_NO_PARAMS 1 1973 #define IOCTL_FLAGS_ISSUE_GLOBAL_EVENT 2 1974 1975 /* 1976 *--------------------------------------------------------------- 1977 * Implementation of open/close/ioctl on the special char device. 1978 *--------------------------------------------------------------- 1979 */ 1980 static ioctl_fn lookup_ioctl(unsigned int cmd, int *ioctl_flags) 1981 { 1982 static const struct { 1983 int flags; 1984 ioctl_fn fn; 1985 } _ioctls[] = { 1986 [DM_VERSION_CMD] = {0, NULL}, /* version is dealt with elsewhere */ 1987 [DM_REMOVE_ALL_CMD] = {IOCTL_FLAGS_NO_PARAMS | IOCTL_FLAGS_ISSUE_GLOBAL_EVENT, remove_all}, 1988 [DM_LIST_DEVICES_CMD] = {0, list_devices}, 1989 1990 [DM_DEV_CREATE_CMD] = {IOCTL_FLAGS_NO_PARAMS | IOCTL_FLAGS_ISSUE_GLOBAL_EVENT, dev_create}, 1991 [DM_DEV_REMOVE_CMD] = {IOCTL_FLAGS_NO_PARAMS | IOCTL_FLAGS_ISSUE_GLOBAL_EVENT, dev_remove}, 1992 [DM_DEV_RENAME_CMD] = {IOCTL_FLAGS_ISSUE_GLOBAL_EVENT, dev_rename}, 1993 [DM_DEV_SUSPEND_CMD] = {IOCTL_FLAGS_NO_PARAMS, dev_suspend}, 1994 [DM_DEV_STATUS_CMD] = {IOCTL_FLAGS_NO_PARAMS, dev_status}, 1995 [DM_DEV_WAIT_CMD] = {0, dev_wait}, 1996 1997 [DM_TABLE_LOAD_CMD] = {0, table_load}, 1998 [DM_TABLE_CLEAR_CMD] = {IOCTL_FLAGS_NO_PARAMS, table_clear}, 1999 [DM_TABLE_DEPS_CMD] = {0, table_deps}, 2000 [DM_TABLE_STATUS_CMD] = {0, table_status}, 2001 2002 [DM_LIST_VERSIONS_CMD] = {0, list_versions}, 2003 2004 [DM_TARGET_MSG_CMD] = {0, target_message}, 2005 [DM_DEV_SET_GEOMETRY_CMD] = {0, dev_set_geometry}, 2006 [DM_DEV_ARM_POLL_CMD] = {IOCTL_FLAGS_NO_PARAMS, dev_arm_poll}, 2007 [DM_GET_TARGET_VERSION_CMD] = {0, get_target_version}, 2008 [DM_MPATH_PROBE_PATHS_CMD] = {0, NULL}, /* block device ioctl */ 2009 }; 2010 2011 if (unlikely(cmd >= ARRAY_SIZE(_ioctls))) 2012 return NULL; 2013 2014 cmd = array_index_nospec(cmd, ARRAY_SIZE(_ioctls)); 2015 *ioctl_flags = _ioctls[cmd].flags; 2016 return _ioctls[cmd].fn; 2017 } 2018 2019 /* 2020 * As well as checking the version compatibility this always 2021 * copies the kernel interface version out. 2022 */ 2023 static int check_version(unsigned int cmd, struct dm_ioctl __user *user, 2024 struct dm_ioctl *kernel_params) 2025 { 2026 int r = 0; 2027 2028 /* Make certain version is first member of dm_ioctl struct */ 2029 BUILD_BUG_ON(offsetof(struct dm_ioctl, version) != 0); 2030 2031 if (copy_from_user(kernel_params->version, user->version, sizeof(kernel_params->version))) 2032 return -EFAULT; 2033 2034 if ((kernel_params->version[0] != DM_VERSION_MAJOR) || 2035 (kernel_params->version[1] > DM_VERSION_MINOR)) { 2036 DMERR_LIMIT("ioctl interface mismatch: kernel(%u.%u.%u), user(%u.%u.%u), cmd(%d)", 2037 DM_VERSION_MAJOR, DM_VERSION_MINOR, 2038 DM_VERSION_PATCHLEVEL, 2039 kernel_params->version[0], 2040 kernel_params->version[1], 2041 kernel_params->version[2], 2042 cmd); 2043 r = -EINVAL; 2044 } 2045 2046 /* 2047 * Fill in the kernel version. 2048 */ 2049 kernel_params->version[0] = DM_VERSION_MAJOR; 2050 kernel_params->version[1] = DM_VERSION_MINOR; 2051 kernel_params->version[2] = DM_VERSION_PATCHLEVEL; 2052 if (copy_to_user(user->version, kernel_params->version, sizeof(kernel_params->version))) 2053 return -EFAULT; 2054 2055 return r; 2056 } 2057 2058 #define DM_PARAMS_MALLOC 0x0001 /* Params allocated with kvmalloc() */ 2059 #define DM_WIPE_BUFFER 0x0010 /* Wipe input buffer before returning from ioctl */ 2060 2061 static void free_params(struct dm_ioctl *param, size_t param_size, int param_flags) 2062 { 2063 if (param_flags & DM_WIPE_BUFFER) 2064 memset(param, 0, param_size); 2065 2066 if (param_flags & DM_PARAMS_MALLOC) 2067 kvfree(param); 2068 } 2069 2070 static int copy_params(struct dm_ioctl __user *user, struct dm_ioctl *param_kernel, 2071 int ioctl_flags, struct dm_ioctl **param, int *param_flags) 2072 { 2073 struct dm_ioctl *dmi; 2074 int secure_data; 2075 const size_t minimum_data_size = offsetof(struct dm_ioctl, data); 2076 2077 /* check_version() already copied version from userspace, avoid TOCTOU */ 2078 if (copy_from_user((char *)param_kernel + sizeof(param_kernel->version), 2079 (char __user *)user + sizeof(param_kernel->version), 2080 minimum_data_size - sizeof(param_kernel->version))) 2081 return -EFAULT; 2082 2083 if (unlikely(param_kernel->data_size < minimum_data_size) || 2084 unlikely(param_kernel->data_size > DM_MAX_TARGETS * DM_MAX_TARGET_PARAMS)) { 2085 DMERR_LIMIT("Invalid data size in the ioctl structure: %u", 2086 param_kernel->data_size); 2087 return -EINVAL; 2088 } 2089 2090 secure_data = param_kernel->flags & DM_SECURE_DATA_FLAG; 2091 2092 *param_flags = secure_data ? DM_WIPE_BUFFER : 0; 2093 2094 if (ioctl_flags & IOCTL_FLAGS_NO_PARAMS) { 2095 dmi = param_kernel; 2096 dmi->data_size = minimum_data_size; 2097 goto data_copied; 2098 } 2099 2100 /* 2101 * Use __GFP_HIGH to avoid low memory issues when a device is 2102 * suspended and the ioctl is needed to resume it. 2103 * Use kmalloc() rather than vmalloc() when we can. 2104 */ 2105 dmi = NULL; 2106 dmi = kvmalloc(param_kernel->data_size, GFP_NOIO | __GFP_HIGH); 2107 2108 if (!dmi) { 2109 if (secure_data && clear_user(user, param_kernel->data_size)) 2110 return -EFAULT; 2111 return -ENOMEM; 2112 } 2113 2114 *param_flags |= DM_PARAMS_MALLOC; 2115 2116 /* Copy from param_kernel (which was already copied from user) */ 2117 memcpy(dmi, param_kernel, minimum_data_size); 2118 2119 if (copy_from_user(&dmi->data, (char __user *)user + minimum_data_size, 2120 param_kernel->data_size - minimum_data_size)) 2121 goto bad; 2122 data_copied: 2123 /* Wipe the user buffer so we do not return it to userspace */ 2124 if (secure_data && clear_user(user, param_kernel->data_size)) 2125 goto bad; 2126 2127 *param = dmi; 2128 return 0; 2129 2130 bad: 2131 free_params(dmi, param_kernel->data_size, *param_flags); 2132 2133 return -EFAULT; 2134 } 2135 2136 static int validate_params(uint cmd, struct dm_ioctl *param) 2137 { 2138 /* Always clear this flag */ 2139 param->flags &= ~DM_BUFFER_FULL_FLAG; 2140 param->flags &= ~DM_UEVENT_GENERATED_FLAG; 2141 param->flags &= ~DM_SECURE_DATA_FLAG; 2142 param->flags &= ~DM_DATA_OUT_FLAG; 2143 2144 /* Ignores parameters */ 2145 if (cmd == DM_REMOVE_ALL_CMD || 2146 cmd == DM_LIST_DEVICES_CMD || 2147 cmd == DM_LIST_VERSIONS_CMD) 2148 return 0; 2149 2150 if (cmd == DM_DEV_CREATE_CMD) { 2151 if (!*param->name) { 2152 DMERR("name not supplied when creating device"); 2153 return -EINVAL; 2154 } 2155 } else if (*param->uuid && *param->name) { 2156 DMERR("only supply one of name or uuid, cmd(%u)", cmd); 2157 return -EINVAL; 2158 } 2159 2160 /* Ensure strings are terminated */ 2161 param->name[DM_NAME_LEN - 1] = '\0'; 2162 param->uuid[DM_UUID_LEN - 1] = '\0'; 2163 2164 return 0; 2165 } 2166 2167 static int ctl_ioctl(struct file *file, uint command, struct dm_ioctl __user *user) 2168 { 2169 int r = 0; 2170 int ioctl_flags; 2171 int param_flags; 2172 unsigned int cmd; 2173 struct dm_ioctl *param; 2174 ioctl_fn fn = NULL; 2175 size_t input_param_size; 2176 struct dm_ioctl param_kernel; 2177 2178 /* only root can play with this */ 2179 if (!capable(CAP_SYS_ADMIN)) 2180 return -EACCES; 2181 2182 if (_IOC_TYPE(command) != DM_IOCTL) 2183 return -ENOTTY; 2184 2185 cmd = _IOC_NR(command); 2186 2187 /* 2188 * Check the interface version passed in. This also 2189 * writes out the kernel's interface version. 2190 */ 2191 r = check_version(cmd, user, ¶m_kernel); 2192 if (r) 2193 return r; 2194 2195 /* 2196 * Nothing more to do for the version command. 2197 */ 2198 if (cmd == DM_VERSION_CMD) 2199 return 0; 2200 2201 fn = lookup_ioctl(cmd, &ioctl_flags); 2202 if (!fn) { 2203 DMERR("dm_ctl_ioctl: unknown command 0x%x", command); 2204 return -ENOTTY; 2205 } 2206 2207 /* 2208 * Copy the parameters into kernel space. 2209 */ 2210 r = copy_params(user, ¶m_kernel, ioctl_flags, ¶m, ¶m_flags); 2211 2212 if (r) 2213 return r; 2214 2215 input_param_size = param->data_size; 2216 r = validate_params(cmd, param); 2217 if (r) 2218 goto out; 2219 2220 param->data_size = offsetof(struct dm_ioctl, data); 2221 r = fn(file, param, input_param_size); 2222 2223 if (unlikely(param->flags & DM_BUFFER_FULL_FLAG) && 2224 unlikely(ioctl_flags & IOCTL_FLAGS_NO_PARAMS)) 2225 DMERR("ioctl %d tried to output some data but has IOCTL_FLAGS_NO_PARAMS set", cmd); 2226 2227 if (!r && ioctl_flags & IOCTL_FLAGS_ISSUE_GLOBAL_EVENT) 2228 dm_issue_global_event(); 2229 2230 /* 2231 * Copy the results back to userland. 2232 */ 2233 if (!r && copy_to_user(user, param, param->data_size)) 2234 r = -EFAULT; 2235 2236 out: 2237 free_params(param, input_param_size, param_flags); 2238 return r; 2239 } 2240 2241 static long dm_ctl_ioctl(struct file *file, uint command, ulong u) 2242 { 2243 return (long)ctl_ioctl(file, command, (struct dm_ioctl __user *)u); 2244 } 2245 2246 #ifdef CONFIG_COMPAT 2247 static long dm_compat_ctl_ioctl(struct file *file, uint command, ulong u) 2248 { 2249 return (long)dm_ctl_ioctl(file, command, (ulong) compat_ptr(u)); 2250 } 2251 #else 2252 #define dm_compat_ctl_ioctl NULL 2253 #endif 2254 2255 static int dm_open(struct inode *inode, struct file *filp) 2256 { 2257 struct dm_file *priv; 2258 2259 nonseekable_open(inode, filp); 2260 2261 priv = filp->private_data = kmalloc_obj(struct dm_file); 2262 if (!priv) 2263 return -ENOMEM; 2264 2265 priv->global_event_nr = atomic_read(&dm_global_event_nr); 2266 2267 return 0; 2268 } 2269 2270 static int dm_release(struct inode *inode, struct file *filp) 2271 { 2272 kfree(filp->private_data); 2273 return 0; 2274 } 2275 2276 static __poll_t dm_poll(struct file *filp, poll_table *wait) 2277 { 2278 struct dm_file *priv = filp->private_data; 2279 __poll_t mask = 0; 2280 2281 poll_wait(filp, &dm_global_eventq, wait); 2282 2283 if ((int)(atomic_read(&dm_global_event_nr) - priv->global_event_nr) > 0) 2284 mask |= EPOLLIN; 2285 2286 return mask; 2287 } 2288 2289 static const struct file_operations _ctl_fops = { 2290 .open = dm_open, 2291 .release = dm_release, 2292 .poll = dm_poll, 2293 .unlocked_ioctl = dm_ctl_ioctl, 2294 .compat_ioctl = dm_compat_ctl_ioctl, 2295 .owner = THIS_MODULE, 2296 .llseek = noop_llseek, 2297 }; 2298 2299 static struct miscdevice _dm_misc = { 2300 .minor = MAPPER_CTRL_MINOR, 2301 .name = DM_NAME, 2302 .nodename = DM_DIR "/" DM_CONTROL_NODE, 2303 .fops = &_ctl_fops 2304 }; 2305 2306 MODULE_ALIAS_MISCDEV(MAPPER_CTRL_MINOR); 2307 MODULE_ALIAS("devname:" DM_DIR "/" DM_CONTROL_NODE); 2308 2309 /* 2310 * Create misc character device and link to DM_DIR/control. 2311 */ 2312 int __init dm_interface_init(void) 2313 { 2314 int r; 2315 2316 r = misc_register(&_dm_misc); 2317 if (r) { 2318 DMERR("misc_register failed for control device"); 2319 return r; 2320 } 2321 2322 DMINFO("%d.%d.%d%s initialised: %s", DM_VERSION_MAJOR, 2323 DM_VERSION_MINOR, DM_VERSION_PATCHLEVEL, DM_VERSION_EXTRA, 2324 DM_DRIVER_EMAIL); 2325 return 0; 2326 } 2327 2328 void dm_interface_exit(void) 2329 { 2330 misc_deregister(&_dm_misc); 2331 dm_hash_exit(); 2332 } 2333 2334 /** 2335 * dm_copy_name_and_uuid - Copy mapped device name & uuid into supplied buffers 2336 * @md: Pointer to mapped_device 2337 * @name: Buffer (size DM_NAME_LEN) for name 2338 * @uuid: Buffer (size DM_UUID_LEN) for uuid or empty string if uuid not defined 2339 */ 2340 int dm_copy_name_and_uuid(struct mapped_device *md, char *name, char *uuid) 2341 { 2342 int r = 0; 2343 struct hash_cell *hc; 2344 2345 if (!md) 2346 return -ENXIO; 2347 2348 mutex_lock(&dm_hash_cells_mutex); 2349 hc = dm_get_mdptr(md); 2350 if (!hc) { 2351 r = -ENXIO; 2352 goto out; 2353 } 2354 2355 if (name) 2356 strcpy(name, hc->name); 2357 if (uuid) 2358 strcpy(uuid, hc->uuid ? : ""); 2359 2360 out: 2361 mutex_unlock(&dm_hash_cells_mutex); 2362 2363 return r; 2364 } 2365 EXPORT_SYMBOL_GPL(dm_copy_name_and_uuid); 2366 2367 /** 2368 * dm_early_create - create a mapped device in early boot. 2369 * 2370 * @dmi: Contains main information of the device mapping to be created. 2371 * @spec_array: array of pointers to struct dm_target_spec. Describes the 2372 * mapping table of the device. 2373 * @target_params_array: array of strings with the parameters to a specific 2374 * target. 2375 * 2376 * Instead of having the struct dm_target_spec and the parameters for every 2377 * target embedded at the end of struct dm_ioctl (as performed in a normal 2378 * ioctl), pass them as arguments, so the caller doesn't need to serialize them. 2379 * The size of the spec_array and target_params_array is given by 2380 * @dmi->target_count. 2381 * This function is supposed to be called in early boot, so locking mechanisms 2382 * to protect against concurrent loads are not required. 2383 */ 2384 int __init dm_early_create(struct dm_ioctl *dmi, 2385 struct dm_target_spec **spec_array, 2386 char **target_params_array) 2387 { 2388 int r, m = DM_ANY_MINOR; 2389 struct dm_table *t, *old_map; 2390 struct mapped_device *md; 2391 unsigned int i; 2392 2393 if (!dmi->target_count) 2394 return -EINVAL; 2395 2396 r = check_name(dmi->name); 2397 if (r) 2398 return r; 2399 2400 if (dmi->flags & DM_PERSISTENT_DEV_FLAG) 2401 m = MINOR(huge_decode_dev(dmi->dev)); 2402 2403 /* alloc dm device */ 2404 r = dm_create(m, &md); 2405 if (r) 2406 return r; 2407 2408 /* hash insert */ 2409 r = dm_hash_insert(dmi->name, *dmi->uuid ? dmi->uuid : NULL, md); 2410 if (r) 2411 goto err_destroy_dm; 2412 2413 /* alloc table */ 2414 r = dm_table_create(&t, get_mode(dmi), dmi->target_count, md); 2415 if (r) 2416 goto err_hash_remove; 2417 2418 /* add targets */ 2419 for (i = 0; i < dmi->target_count; i++) { 2420 r = dm_table_add_target(t, spec_array[i]->target_type, 2421 (sector_t) spec_array[i]->sector_start, 2422 (sector_t) spec_array[i]->length, 2423 target_params_array[i]); 2424 if (r) { 2425 DMERR("error adding target to table"); 2426 goto err_destroy_table; 2427 } 2428 } 2429 2430 /* finish table */ 2431 r = dm_table_complete(t); 2432 if (r) 2433 goto err_destroy_table; 2434 2435 /* setup md->queue to reflect md's type (may block) */ 2436 r = dm_setup_md_queue(md, t); 2437 if (r) { 2438 DMERR("unable to set up device queue for new table."); 2439 goto err_destroy_table; 2440 } 2441 2442 /* Set new map */ 2443 dm_suspend(md, 0); 2444 old_map = dm_swap_table(md, t); 2445 if (IS_ERR(old_map)) { 2446 r = PTR_ERR(old_map); 2447 goto err_destroy_table; 2448 } 2449 set_disk_ro(dm_disk(md), !!(dmi->flags & DM_READONLY_FLAG)); 2450 2451 /* resume device */ 2452 r = dm_resume(md); 2453 if (r) 2454 goto err_hash_remove; 2455 2456 DMINFO("%s (%s) is ready", md->disk->disk_name, dmi->name); 2457 dm_put(md); 2458 return 0; 2459 2460 err_destroy_table: 2461 dm_table_destroy(t); 2462 err_hash_remove: 2463 down_write(&_hash_lock); 2464 (void) __hash_remove(__get_name_cell(dmi->name)); 2465 up_write(&_hash_lock); 2466 /* release reference from __get_name_cell */ 2467 dm_put(md); 2468 err_destroy_dm: 2469 dm_put(md); 2470 dm_destroy(md); 2471 return r; 2472 } 2473