xref: /linux/fs/ntfs3/ntfs.h (revision dc83d18cdd90482c70fa4320160bba70ec5c9ef8)
1 /* SPDX-License-Identifier: GPL-2.0 */
2 /*
3  *
4  * Copyright (C) 2019-2021 Paragon Software GmbH, All rights reserved.
5  *
6  * on-disk ntfs structs
7  */
8 
9 // clang-format off
10 #ifndef _LINUX_NTFS3_NTFS_H
11 #define _LINUX_NTFS3_NTFS_H
12 
13 #include <linux/blkdev.h>
14 #include <linux/build_bug.h>
15 #include <linux/kernel.h>
16 #include <linux/stddef.h>
17 #include <linux/string.h>
18 #include <linux/types.h>
19 
20 #include "debug.h"
21 
22 /* TODO: Check 4K MFT record and 512 bytes cluster. */
23 
24 /* Check each run for marked clusters. */
25 #define NTFS3_CHECK_FREE_CLST
26 
27 #define NTFS_NAME_LEN 255
28 
29 /*
30  * ntfs.sys used 500 maximum links on-disk struct allows up to 0xffff.
31  * xfstest generic/041 creates 3003 hardlinks.
32  */
33 #define NTFS_LINK_MAX 4000
34 
35 /*
36  * Activate to use 64 bit clusters instead of 32 bits in ntfs.sys.
37  * Logical and virtual cluster number if needed, may be
38  * redefined to use 64 bit value.
39  */
40 //#define CONFIG_NTFS3_64BIT_CLUSTER
41 
42 #define NTFS_LZNT_MAX_CLUSTER	4096
43 #define NTFS_LZNT_CUNIT		4
44 #define NTFS_LZNT_CLUSTERS	(1u<<NTFS_LZNT_CUNIT)
45 
46 struct GUID {
47 	__le32 Data1;
48 	__le16 Data2;
49 	__le16 Data3;
50 	u8 Data4[8];
51 };
52 
53 /*
54  * This struct repeats layout of ATTR_FILE_NAME
55  * at offset 0x40.
56  * It used to store global constants NAME_MFT/NAME_MIRROR...
57  * most constant names are shorter than 10.
58  */
59 struct cpu_str {
60 	u8 len;
61 	u8 ads_len;
62 	u16 name[];
63 };
64 
65 struct le_str {
66 	u8 len;
67 	u8 unused;
68 	__le16 name[];
69 };
70 
71 static_assert(SECTOR_SHIFT == 9);
72 
73 #ifdef CONFIG_NTFS3_64BIT_CLUSTER
74 typedef u64 CLST;
75 static_assert(sizeof(size_t) == 8);
76 #else
77 typedef u32 CLST;
78 #endif
79 
80 /* On-disk sparsed cluster is marked as -1. */
81 #define SPARSE_LCN64   ((u64)-1)
82 #define SPARSE_LCN     ((CLST)-1)
83 /* Below is virtual (not on-disk) values. */
84 #define RESIDENT_LCN   ((CLST)-2)
85 #define COMPRESSED_LCN ((CLST)-3)
86 #define EOF_LCN       ((CLST)-4)
87 #define DELALLOC_LCN   ((CLST)-5)
88 
89 enum RECORD_NUM {
90 	MFT_REC_MFT		= 0,
91 	MFT_REC_MIRR		= 1,
92 	MFT_REC_LOG		= 2,
93 	MFT_REC_VOL		= 3,
94 	MFT_REC_ATTR		= 4,
95 	MFT_REC_ROOT		= 5,
96 	MFT_REC_BITMAP		= 6,
97 	MFT_REC_BOOT		= 7,
98 	MFT_REC_BADCLUST	= 8,
99 	MFT_REC_SECURE		= 9,
100 	MFT_REC_UPCASE		= 10,
101 	MFT_REC_EXTEND		= 11,
102 	MFT_REC_RESERVED	= 12,
103 	MFT_REC_FREE		= 16,
104 	MFT_REC_USER		= 24,
105 };
106 
107 enum ATTR_TYPE {
108 	ATTR_ZERO		= cpu_to_le32(0x00),
109 	ATTR_STD		= cpu_to_le32(0x10),
110 	ATTR_LIST		= cpu_to_le32(0x20),
111 	ATTR_NAME		= cpu_to_le32(0x30),
112 	ATTR_ID			= cpu_to_le32(0x40),
113 	ATTR_SECURE		= cpu_to_le32(0x50),
114 	ATTR_LABEL		= cpu_to_le32(0x60),
115 	ATTR_VOL_INFO		= cpu_to_le32(0x70),
116 	ATTR_DATA		= cpu_to_le32(0x80),
117 	ATTR_ROOT		= cpu_to_le32(0x90),
118 	ATTR_ALLOC		= cpu_to_le32(0xA0),
119 	ATTR_BITMAP		= cpu_to_le32(0xB0),
120 	ATTR_REPARSE		= cpu_to_le32(0xC0),
121 	ATTR_EA_INFO		= cpu_to_le32(0xD0),
122 	ATTR_EA			= cpu_to_le32(0xE0),
123 	ATTR_PROPERTYSET	= cpu_to_le32(0xF0),
124 	ATTR_LOGGED_UTILITY_STREAM = cpu_to_le32(0x100),
125 	ATTR_END		= cpu_to_le32(0xFFFFFFFF)
126 };
127 
128 static_assert(sizeof(enum ATTR_TYPE) == 4);
129 
130 enum FILE_ATTRIBUTE {
131 	FILE_ATTRIBUTE_READONLY		= cpu_to_le32(0x00000001),
132 	FILE_ATTRIBUTE_HIDDEN		= cpu_to_le32(0x00000002),
133 	FILE_ATTRIBUTE_SYSTEM		= cpu_to_le32(0x00000004),
134 	FILE_ATTRIBUTE_ARCHIVE		= cpu_to_le32(0x00000020),
135 	FILE_ATTRIBUTE_DEVICE		= cpu_to_le32(0x00000040),
136 	FILE_ATTRIBUTE_TEMPORARY	= cpu_to_le32(0x00000100),
137 	FILE_ATTRIBUTE_SPARSE_FILE	= cpu_to_le32(0x00000200),
138 	FILE_ATTRIBUTE_REPARSE_POINT	= cpu_to_le32(0x00000400),
139 	FILE_ATTRIBUTE_COMPRESSED	= cpu_to_le32(0x00000800),
140 	FILE_ATTRIBUTE_OFFLINE		= cpu_to_le32(0x00001000),
141 	FILE_ATTRIBUTE_NOT_CONTENT_INDEXED = cpu_to_le32(0x00002000),
142 	FILE_ATTRIBUTE_ENCRYPTED	= cpu_to_le32(0x00004000),
143 	FILE_ATTRIBUTE_VALID_FLAGS	= cpu_to_le32(0x00007fb7),
144 	FILE_ATTRIBUTE_DIRECTORY	= cpu_to_le32(0x10000000),
145 	FILE_ATTRIBUTE_INDEX		= cpu_to_le32(0x20000000)
146 };
147 
148 static_assert(sizeof(enum FILE_ATTRIBUTE) == 4);
149 
150 extern const struct cpu_str NAME_MFT;
151 extern const struct cpu_str NAME_MIRROR;
152 extern const struct cpu_str NAME_LOGFILE;
153 extern const struct cpu_str NAME_VOLUME;
154 extern const struct cpu_str NAME_ATTRDEF;
155 extern const struct cpu_str NAME_ROOT;
156 extern const struct cpu_str NAME_BITMAP;
157 extern const struct cpu_str NAME_BOOT;
158 extern const struct cpu_str NAME_BADCLUS;
159 extern const struct cpu_str NAME_QUOTA;
160 extern const struct cpu_str NAME_SECURE;
161 extern const struct cpu_str NAME_UPCASE;
162 extern const struct cpu_str NAME_EXTEND;
163 extern const struct cpu_str NAME_OBJID;
164 extern const struct cpu_str NAME_REPARSE;
165 extern const struct cpu_str NAME_USNJRNL;
166 
167 extern const __le16 I30_NAME[4];
168 extern const __le16 SII_NAME[4];
169 extern const __le16 SDH_NAME[4];
170 extern const __le16 SO_NAME[2];
171 extern const __le16 SQ_NAME[2];
172 extern const __le16 SR_NAME[2];
173 extern const __le16 QUERY_STREAMS[13];
174 
175 extern const __le16 BAD_NAME[4];
176 extern const __le16 SDS_NAME[4];
177 extern const __le16 WOF_NAME[17];	/* WofCompressedData */
178 
179 /* MFT record number structure. */
180 struct MFT_REF {
181 	__le32 low;	// The low part of the number.
182 	__le16 high;	// The high part of the number.
183 	__le16 seq;	// The sequence number of MFT record.
184 };
185 
186 static_assert(sizeof(__le64) == sizeof(struct MFT_REF));
187 
ino_get(const struct MFT_REF * ref)188 static inline CLST ino_get(const struct MFT_REF *ref)
189 {
190 #ifdef CONFIG_NTFS3_64BIT_CLUSTER
191 	return le32_to_cpu(ref->low) | ((u64)le16_to_cpu(ref->high) << 32);
192 #else
193 	return le32_to_cpu(ref->low);
194 #endif
195 }
196 
197 struct NTFS_BOOT {
198 	u8 jump_code[3];	// 0x00: Jump to boot code.
199 	u8 system_id[8];	// 0x03: System ID, equals "NTFS    "
200 
201 	// NOTE: This member is not aligned(!)
202 	// bytes_per_sector[0] must be 0.
203 	// bytes_per_sector[1] must be multiplied by 256.
204 	u8 bytes_per_sector[2];	// 0x0B: Bytes per sector.
205 
206 	u8 sectors_per_clusters;// 0x0D: Sectors per cluster.
207 	u8 unused1[7];
208 	u8 media_type;		// 0x15: Media type (0xF8 - harddisk)
209 	u8 unused2[2];
210 	__le16 sct_per_track;	// 0x18: number of sectors per track.
211 	__le16 heads;		// 0x1A: number of heads per cylinder.
212 	__le32 hidden_sectors;	// 0x1C: number of 'hidden' sectors.
213 	u8 unused3[4];
214 	u8 bios_drive_num;	// 0x24: BIOS drive number =0x80.
215 	u8 unused4;
216 	u8 signature_ex;	// 0x26: Extended BOOT signature =0x80.
217 	u8 unused5;
218 	__le64 sectors_per_volume;// 0x28: Size of volume in sectors.
219 	__le64 mft_clst;	// 0x30: First cluster of $MFT
220 	__le64 mft2_clst;	// 0x38: First cluster of $MFTMirr
221 	s8 record_size;		// 0x40: Size of MFT record in clusters(sectors).
222 	u8 unused6[3];
223 	s8 index_size;		// 0x44: Size of INDX record in clusters(sectors).
224 	u8 unused7[3];
225 	__le64 serial_num;	// 0x48: Volume serial number
226 	__le32 check_sum;	// 0x50: Simple additive checksum of all
227 				// of the u32's which precede the 'check_sum'.
228 
229 	u8 boot_code[0x200 - 0x50 - 2 - 4]; // 0x54:
230 	u8 boot_magic[2];	// 0x1FE: Boot signature =0x55 + 0xAA
231 };
232 
233 static_assert(sizeof(struct NTFS_BOOT) == 0x200);
234 
235 enum NTFS_SIGNATURE {
236 	NTFS_FILE_SIGNATURE = cpu_to_le32(0x454C4946), // 'FILE'
237 	NTFS_INDX_SIGNATURE = cpu_to_le32(0x58444E49), // 'INDX'
238 	NTFS_CHKD_SIGNATURE = cpu_to_le32(0x444B4843), // 'CHKD'
239 	NTFS_RSTR_SIGNATURE = cpu_to_le32(0x52545352), // 'RSTR'
240 	NTFS_RCRD_SIGNATURE = cpu_to_le32(0x44524352), // 'RCRD'
241 	NTFS_BAAD_SIGNATURE = cpu_to_le32(0x44414142), // 'BAAD'
242 	NTFS_HOLE_SIGNATURE = cpu_to_le32(0x454C4F48), // 'HOLE'
243 	NTFS_FFFF_SIGNATURE = cpu_to_le32(0xffffffff),
244 };
245 
246 static_assert(sizeof(enum NTFS_SIGNATURE) == 4);
247 
248 /* MFT Record header structure. */
249 struct NTFS_RECORD_HEADER {
250 	/* Record magic number, equals 'FILE'/'INDX'/'RSTR'/'RCRD'. */
251 	enum NTFS_SIGNATURE sign; // 0x00:
252 	__le16 fix_off;		// 0x04:
253 	__le16 fix_num;		// 0x06:
254 	__le64 lsn;		// 0x08: Log file sequence number,
255 };
256 
257 static_assert(sizeof(struct NTFS_RECORD_HEADER) == 0x10);
258 
is_baad(const struct NTFS_RECORD_HEADER * hdr)259 static inline int is_baad(const struct NTFS_RECORD_HEADER *hdr)
260 {
261 	return hdr->sign == NTFS_BAAD_SIGNATURE;
262 }
263 
264 /* Possible bits in struct MFT_REC.flags. */
265 enum RECORD_FLAG {
266 	RECORD_FLAG_IN_USE	= cpu_to_le16(0x0001),
267 	RECORD_FLAG_DIR		= cpu_to_le16(0x0002),
268 	RECORD_FLAG_SYSTEM	= cpu_to_le16(0x0004),
269 	RECORD_FLAG_INDEX	= cpu_to_le16(0x0008),
270 };
271 
272 /* MFT Record structure. */
273 struct MFT_REC {
274 	struct NTFS_RECORD_HEADER rhdr; // 'FILE'
275 
276 	__le16 seq;		// 0x10: Sequence number for this record.
277 	__le16 hard_links;	// 0x12: The number of hard links to record.
278 	__le16 attr_off;	// 0x14: Offset to attributes.
279 	__le16 flags;		// 0x16: See RECORD_FLAG.
280 	__le32 used;		// 0x18: The size of used part.
281 	__le32 total;		// 0x1C: Total record size.
282 
283 	struct MFT_REF parent_ref; // 0x20: Parent MFT record.
284 	__le16 next_attr_id;	// 0x28: The next attribute Id.
285 
286 	__le16 res;		// 0x2A: High part of MFT record?
287 	__le32 mft_record;	// 0x2C: Current MFT record number.
288 	__le16 fixups[];	// 0x30:
289 };
290 
291 #define MFTRECORD_FIXUP_OFFSET_1 offsetof(struct MFT_REC, res)
292 #define MFTRECORD_FIXUP_OFFSET_3 offsetof(struct MFT_REC, fixups)
293 /*
294  * define MFTRECORD_FIXUP_OFFSET as MFTRECORD_FIXUP_OFFSET_3 (0x30)
295  * to format new mft records with bigger header (as current ntfs.sys does)
296  *
297  * define MFTRECORD_FIXUP_OFFSET as MFTRECORD_FIXUP_OFFSET_1 (0x2A)
298  * to format new mft records with smaller header (as old ntfs.sys did)
299  * Both variants are valid.
300  */
301 #define MFTRECORD_FIXUP_OFFSET  MFTRECORD_FIXUP_OFFSET_1
302 
303 static_assert(MFTRECORD_FIXUP_OFFSET_1 == 0x2A);
304 static_assert(MFTRECORD_FIXUP_OFFSET_3 == 0x30);
305 
is_rec_base(const struct MFT_REC * rec)306 static inline bool is_rec_base(const struct MFT_REC *rec)
307 {
308 	const struct MFT_REF *r = &rec->parent_ref;
309 
310 	return !r->low && !r->high && !r->seq;
311 }
312 
is_mft_rec5(const struct MFT_REC * rec)313 static inline bool is_mft_rec5(const struct MFT_REC *rec)
314 {
315 	return le16_to_cpu(rec->rhdr.fix_off) >=
316 	       offsetof(struct MFT_REC, fixups);
317 }
318 
is_rec_inuse(const struct MFT_REC * rec)319 static inline bool is_rec_inuse(const struct MFT_REC *rec)
320 {
321 	return rec->flags & RECORD_FLAG_IN_USE;
322 }
323 
clear_rec_inuse(struct MFT_REC * rec)324 static inline bool clear_rec_inuse(struct MFT_REC *rec)
325 {
326 	return rec->flags &= ~RECORD_FLAG_IN_USE;
327 }
328 
329 /* Possible values of ATTR_RESIDENT.flags */
330 #define RESIDENT_FLAG_INDEXED 0x01
331 
332 struct ATTR_RESIDENT {
333 	__le32 data_size;	// 0x10: The size of data.
334 	__le16 data_off;	// 0x14: Offset to data.
335 	u8 flags;		// 0x16: Resident flags ( 1 - indexed ).
336 	u8 res;			// 0x17:
337 }; // sizeof() = 0x18
338 
339 struct ATTR_NONRESIDENT {
340 	__le64 svcn;		// 0x10: Starting VCN of this segment.
341 	__le64 evcn;		// 0x18: End VCN of this segment.
342 	__le16 run_off;		// 0x20: Offset to packed runs.
343 	// Unit of Compression size for this stream, expressed
344 	// as a log of the cluster size.
345 	//
346 	// 0 means file is not compressed
347 	// 1, 2, 3, and 4 are potentially legal values if the
348 	// stream is compressed, however the implementation
349 	// may only choose to use 4, or possibly 3.
350         // Note that 4 means cluster size time 16.
351         // If convenient the implementation may wish to accept a
352 	// reasonable range of legal values here (1-5?),
353 	// even if the implementation only generates
354 	// a smaller set of values itself.
355 	u8 c_unit;		// 0x22:
356 	u8 res1[5];		// 0x23:
357 	__le64 alloc_size;	// 0x28: The allocated size of attribute in bytes.
358 				// (multiple of cluster size)
359 	__le64 data_size;	// 0x30: The size of attribute  in bytes <= alloc_size.
360 	__le64 valid_size;	// 0x38: The size of valid part in bytes <= data_size.
361 	__le64 total_size;	// 0x40: The sum of the allocated clusters for a file.
362 				// (present only for the first segment (0 == vcn)
363 				// of compressed attribute)
364 
365 }; // sizeof()=0x40 or 0x48 (if compressed)
366 
367 /* Possible values of ATTRIB.flags: */
368 #define ATTR_FLAG_COMPRESSED	  cpu_to_le16(0x0001)
369 #define ATTR_FLAG_COMPRESSED_MASK cpu_to_le16(0x00FF)
370 #define ATTR_FLAG_ENCRYPTED	  cpu_to_le16(0x4000)
371 #define ATTR_FLAG_SPARSED	  cpu_to_le16(0x8000)
372 
373 struct ATTRIB {
374 	enum ATTR_TYPE type;	// 0x00: The type of this attribute.
375 	__le32 size;		// 0x04: The size of this attribute.
376 	u8 non_res;		// 0x08: Is this attribute non-resident?
377 	u8 name_len;		// 0x09: This attribute name length.
378 	__le16 name_off;	// 0x0A: Offset to the attribute name.
379 	__le16 flags;		// 0x0C: See ATTR_FLAG_XXX.
380 	__le16 id;		// 0x0E: Unique id (per record).
381 
382 	union {
383 		struct ATTR_RESIDENT res;     // 0x10
384 		struct ATTR_NONRESIDENT nres; // 0x10
385 	};
386 };
387 
388 /* Define attribute sizes. */
389 #define SIZEOF_RESIDENT			0x18
390 #define SIZEOF_NONRESIDENT_EX		0x48
391 #define SIZEOF_NONRESIDENT		0x40
392 
393 #define SIZEOF_RESIDENT_LE		cpu_to_le16(0x18)
394 #define SIZEOF_NONRESIDENT_EX_LE	cpu_to_le16(0x48)
395 #define SIZEOF_NONRESIDENT_LE		cpu_to_le16(0x40)
396 
attr_ondisk_size(const struct ATTRIB * attr)397 static inline u64 attr_ondisk_size(const struct ATTRIB *attr)
398 {
399 	return attr->non_res ? ((attr->flags &
400 				 (ATTR_FLAG_COMPRESSED | ATTR_FLAG_SPARSED)) ?
401 					le64_to_cpu(attr->nres.total_size) :
402 					le64_to_cpu(attr->nres.alloc_size))
403 			     : ALIGN(le32_to_cpu(attr->res.data_size), 8);
404 }
405 
attr_size(const struct ATTRIB * attr)406 static inline u64 attr_size(const struct ATTRIB *attr)
407 {
408 	return attr->non_res ? le64_to_cpu(attr->nres.data_size) :
409 			       le32_to_cpu(attr->res.data_size);
410 }
411 
is_attr_encrypted(const struct ATTRIB * attr)412 static inline bool is_attr_encrypted(const struct ATTRIB *attr)
413 {
414 	return attr->flags & ATTR_FLAG_ENCRYPTED;
415 }
416 
is_attr_sparsed(const struct ATTRIB * attr)417 static inline bool is_attr_sparsed(const struct ATTRIB *attr)
418 {
419 	return attr->flags & ATTR_FLAG_SPARSED;
420 }
421 
is_attr_compressed(const struct ATTRIB * attr)422 static inline bool is_attr_compressed(const struct ATTRIB *attr)
423 {
424 	return attr->flags & ATTR_FLAG_COMPRESSED;
425 }
426 
is_attr_ext(const struct ATTRIB * attr)427 static inline bool is_attr_ext(const struct ATTRIB *attr)
428 {
429 	return attr->flags & (ATTR_FLAG_SPARSED | ATTR_FLAG_COMPRESSED);
430 }
431 
is_attr_indexed(const struct ATTRIB * attr)432 static inline bool is_attr_indexed(const struct ATTRIB *attr)
433 {
434 	return !attr->non_res && (attr->res.flags & RESIDENT_FLAG_INDEXED);
435 }
436 
attr_name(const struct ATTRIB * attr)437 static inline __le16 const *attr_name(const struct ATTRIB *attr)
438 {
439 	return Add2Ptr(attr, le16_to_cpu(attr->name_off));
440 }
441 
attr_svcn(const struct ATTRIB * attr)442 static inline u64 attr_svcn(const struct ATTRIB *attr)
443 {
444 	return attr->non_res ? le64_to_cpu(attr->nres.svcn) : 0;
445 }
446 
447 static_assert(sizeof(struct ATTRIB) == 0x48);
448 static_assert(sizeof(((struct ATTRIB *)NULL)->res) == 0x08);
449 static_assert(sizeof(((struct ATTRIB *)NULL)->nres) == 0x38);
450 
resident_data_ex(const struct ATTRIB * attr,u32 datasize)451 static inline void *resident_data_ex(const struct ATTRIB *attr, u32 datasize)
452 {
453 	u32 asize, rsize;
454 	u16 off;
455 
456 	if (attr->non_res)
457 		return NULL;
458 
459 	asize = le32_to_cpu(attr->size);
460 	off = le16_to_cpu(attr->res.data_off);
461 
462 	if (asize < datasize + off)
463 		return NULL;
464 
465 	rsize = le32_to_cpu(attr->res.data_size);
466 	if (rsize < datasize)
467 		return NULL;
468 
469 	return Add2Ptr(attr, off);
470 }
471 
resident_data(const struct ATTRIB * attr)472 static inline void *resident_data(const struct ATTRIB *attr)
473 {
474 	return Add2Ptr(attr, le16_to_cpu(attr->res.data_off));
475 }
476 
attr_run(const struct ATTRIB * attr)477 static inline void *attr_run(const struct ATTRIB *attr)
478 {
479 	return Add2Ptr(attr, le16_to_cpu(attr->nres.run_off));
480 }
481 
482 /* Standard information attribute (0x10). */
483 struct ATTR_STD_INFO {
484 	__le64 cr_time;		// 0x00: File creation file.
485 	__le64 m_time;		// 0x08: File modification time.
486 	__le64 c_time;		// 0x10: Last time any attribute was modified.
487 	__le64 a_time;		// 0x18: File last access time.
488 	enum FILE_ATTRIBUTE fa;	// 0x20: Standard DOS attributes & more.
489 	__le32 max_ver_num;	// 0x24: Maximum Number of Versions.
490 	__le32 ver_num;		// 0x28: Version Number.
491 	__le32 class_id;	// 0x2C: Class Id from bidirectional Class Id index.
492 };
493 
494 static_assert(sizeof(struct ATTR_STD_INFO) == 0x30);
495 
496 #define SECURITY_ID_INVALID 0x00000000
497 #define SECURITY_ID_FIRST 0x00000100
498 
499 struct ATTR_STD_INFO5 {
500 	__le64 cr_time;		// 0x00: File creation file.
501 	__le64 m_time;		// 0x08: File modification time.
502 	__le64 c_time;		// 0x10: Last time any attribute was modified.
503 	__le64 a_time;		// 0x18: File last access time.
504 	enum FILE_ATTRIBUTE fa;	// 0x20: Standard DOS attributes & more.
505 	__le32 max_ver_num;	// 0x24: Maximum Number of Versions.
506 	__le32 ver_num;		// 0x28: Version Number.
507 	__le32 class_id;	// 0x2C: Class Id from bidirectional Class Id index.
508 
509 	__le32 owner_id;	// 0x30: Owner Id of the user owning the file.
510 	__le32 security_id;	// 0x34: The Security Id is a key in the $SII Index and $SDS.
511 	__le64 quota_charge;	// 0x38:
512 	__le64 usn;		// 0x40: Last Update Sequence Number of the file. This is a direct
513 				// index into the file $UsnJrnl. If zero, the USN Journal is
514 				// disabled.
515 };
516 
517 static_assert(sizeof(struct ATTR_STD_INFO5) == 0x48);
518 
519 /* Attribute list entry structure (0x20) */
520 struct ATTR_LIST_ENTRY {
521 	enum ATTR_TYPE type;	// 0x00: The type of attribute.
522 	__le16 size;		// 0x04: The size of this record.
523 	u8 name_len;		// 0x06: The length of attribute name.
524 	u8 name_off;		// 0x07: The offset to attribute name.
525 	__le64 vcn;		// 0x08: Starting VCN of this attribute.
526 	struct MFT_REF ref;	// 0x10: MFT record number with attribute.
527 	__le16 id;		// 0x18: struct ATTRIB ID.
528 	__le16 name[];		// 0x1A: To get real name use name_off.
529 
530 }; // sizeof(0x20)
531 
le_size(u8 name_len)532 static inline u32 le_size(u8 name_len)
533 {
534 	return ALIGN(offsetof(struct ATTR_LIST_ENTRY, name) +
535 		     name_len * sizeof(short), 8);
536 }
537 
538 /* Returns 0 if 'attr' has the same type and name. */
le_cmp(const struct ATTR_LIST_ENTRY * le,const struct ATTRIB * attr)539 static inline int le_cmp(const struct ATTR_LIST_ENTRY *le,
540 			 const struct ATTRIB *attr)
541 {
542 	return le->type != attr->type || le->name_len != attr->name_len ||
543 	       (!le->name_len &&
544 		memcmp(Add2Ptr(le, le->name_off),
545 		       Add2Ptr(attr, le16_to_cpu(attr->name_off)),
546 		       le->name_len * sizeof(short)));
547 }
548 
le_name(const struct ATTR_LIST_ENTRY * le)549 static inline __le16 const *le_name(const struct ATTR_LIST_ENTRY *le)
550 {
551 	return Add2Ptr(le, le->name_off);
552 }
553 
554 /* File name types (the field type in struct ATTR_FILE_NAME). */
555 #define FILE_NAME_POSIX   0
556 #define FILE_NAME_UNICODE 1
557 #define FILE_NAME_DOS	  2
558 #define FILE_NAME_UNICODE_AND_DOS (FILE_NAME_DOS | FILE_NAME_UNICODE)
559 
560 /* Filename attribute structure (0x30). */
561 struct NTFS_DUP_INFO {
562 	__le64 cr_time;		// 0x00: File creation file.
563 	__le64 m_time;		// 0x08: File modification time.
564 	__le64 c_time;		// 0x10: Last time any attribute was modified.
565 	__le64 a_time;		// 0x18: File last access time.
566 	__le64 alloc_size;	// 0x20: Data attribute allocated size, multiple of cluster size.
567 	__le64 data_size;	// 0x28: Data attribute size <= Dataalloc_size.
568 	enum FILE_ATTRIBUTE fa;	// 0x30: Standard DOS attributes & more.
569 	__le32 extend_data;	// 0x34: Extended data.
570 
571 }; // 0x38
572 
573 struct ATTR_FILE_NAME {
574 	struct MFT_REF home;	// 0x00: MFT record for directory.
575 	struct NTFS_DUP_INFO dup;// 0x08:
576 	u8 name_len;		// 0x40: File name length in words.
577 	u8 type;		// 0x41: File name type.
578 	__le16 name[];		// 0x42: File name.
579 };
580 
581 static_assert(sizeof(((struct ATTR_FILE_NAME *)NULL)->dup) == 0x38);
582 static_assert(offsetof(struct ATTR_FILE_NAME, name) == 0x42);
583 #define SIZEOF_ATTRIBUTE_FILENAME     0x44
584 #define SIZEOF_ATTRIBUTE_FILENAME_MAX (0x42 + 255 * 2)
585 
attr_from_name(struct ATTR_FILE_NAME * fname)586 static inline struct ATTRIB *attr_from_name(struct ATTR_FILE_NAME *fname)
587 {
588 	return (struct ATTRIB *)((char *)fname - SIZEOF_RESIDENT);
589 }
590 
fname_full_size(const struct ATTR_FILE_NAME * fname)591 static inline u16 fname_full_size(const struct ATTR_FILE_NAME *fname)
592 {
593 	/* Don't return struct_size(fname, name, fname->name_len); */
594 	return offsetof(struct ATTR_FILE_NAME, name) +
595 	       fname->name_len * sizeof(short);
596 }
597 
paired_name(u8 type)598 static inline u8 paired_name(u8 type)
599 {
600 	if (type == FILE_NAME_UNICODE)
601 		return FILE_NAME_DOS;
602 	if (type == FILE_NAME_DOS)
603 		return FILE_NAME_UNICODE;
604 	return FILE_NAME_POSIX;
605 }
606 
607 /* Index entry defines ( the field flags in NtfsDirEntry ). */
608 #define NTFS_IE_HAS_SUBNODES	cpu_to_le16(1)
609 #define NTFS_IE_LAST		cpu_to_le16(2)
610 
611 /* Directory entry structure. */
612 struct NTFS_DE {
613 	union {
614 		struct MFT_REF ref; // 0x00: MFT record number with this file.
615 		struct {
616 			__le16 data_off;  // 0x00:
617 			__le16 data_size; // 0x02:
618 			__le32 res;	  // 0x04: Must be 0.
619 		} view;
620 	};
621 	__le16 size;		// 0x08: The size of this entry.
622 	__le16 key_size;	// 0x0A: The size of File name length in bytes + 0x42.
623 	__le16 flags;		// 0x0C: Entry flags: NTFS_IE_XXX.
624 	__le16 res;		// 0x0E:
625 
626 	// Here any indexed attribute can be placed.
627 	// One of them is:
628 	// struct ATTR_FILE_NAME AttrFileName;
629 	//
630 
631 	// The last 8 bytes of this structure contains
632 	// the VBN of subnode.
633 	// !!! Note !!!
634 	// This field is presented only if (flags & NTFS_IE_HAS_SUBNODES)
635 	// __le64 vbn;
636 };
637 
638 static_assert(sizeof(struct NTFS_DE) == 0x10);
639 
de_set_vbn_le(struct NTFS_DE * e,__le64 vcn)640 static inline void de_set_vbn_le(struct NTFS_DE *e, __le64 vcn)
641 {
642 	__le64 *v = Add2Ptr(e, le16_to_cpu(e->size) - sizeof(__le64));
643 
644 	*v = vcn;
645 }
646 
de_set_vbn(struct NTFS_DE * e,CLST vcn)647 static inline void de_set_vbn(struct NTFS_DE *e, CLST vcn)
648 {
649 	__le64 *v = Add2Ptr(e, le16_to_cpu(e->size) - sizeof(__le64));
650 
651 	*v = cpu_to_le64(vcn);
652 }
653 
de_get_vbn_le(const struct NTFS_DE * e)654 static inline __le64 de_get_vbn_le(const struct NTFS_DE *e)
655 {
656 	return *(__le64 *)Add2Ptr(e, le16_to_cpu(e->size) - sizeof(__le64));
657 }
658 
de_get_vbn(const struct NTFS_DE * e)659 static inline CLST de_get_vbn(const struct NTFS_DE *e)
660 {
661 	__le64 *v = Add2Ptr(e, le16_to_cpu(e->size) - sizeof(__le64));
662 
663 	return le64_to_cpu(*v);
664 }
665 
de_get_next(const struct NTFS_DE * e)666 static inline struct NTFS_DE *de_get_next(const struct NTFS_DE *e)
667 {
668 	return Add2Ptr(e, le16_to_cpu(e->size));
669 }
670 
de_get_fname(const struct NTFS_DE * e)671 static inline struct ATTR_FILE_NAME *de_get_fname(const struct NTFS_DE *e)
672 {
673 	return le16_to_cpu(e->key_size) >= SIZEOF_ATTRIBUTE_FILENAME ?
674 		       Add2Ptr(e, sizeof(struct NTFS_DE)) :
675 		       NULL;
676 }
677 
de_is_last(const struct NTFS_DE * e)678 static inline bool de_is_last(const struct NTFS_DE *e)
679 {
680 	return e->flags & NTFS_IE_LAST;
681 }
682 
de_has_vcn(const struct NTFS_DE * e)683 static inline bool de_has_vcn(const struct NTFS_DE *e)
684 {
685 	return e->flags & NTFS_IE_HAS_SUBNODES;
686 }
687 
de_has_vcn_ex(const struct NTFS_DE * e)688 static inline bool de_has_vcn_ex(const struct NTFS_DE *e)
689 {
690 	return (e->flags & NTFS_IE_HAS_SUBNODES) &&
691 	       (u64)(-1) != *((u64 *)Add2Ptr(e, le16_to_cpu(e->size) -
692 							sizeof(__le64)));
693 }
694 
695 #define MAX_BYTES_PER_NAME_ENTRY \
696 	ALIGN(sizeof(struct NTFS_DE) + \
697 	      offsetof(struct ATTR_FILE_NAME, name) + \
698 	      NTFS_NAME_LEN * sizeof(short), 8)
699 
700 #define NTFS_INDEX_HDR_HAS_SUBNODES cpu_to_le32(1)
701 
702 struct INDEX_HDR {
703 	__le32 de_off;	// 0x00: The offset from the start of this structure
704 			// to the first NTFS_DE.
705 	__le32 used;	// 0x04: The size of this structure plus all
706 			// entries (quad-word aligned).
707 	__le32 total;	// 0x08: The allocated size of for this structure plus all entries.
708 	__le32 flags;	// 0x0C: 0x00 = Small directory, 0x01 = Large directory.
709 
710 	//
711 	// de_off + used <= total
712 	//
713 };
714 
715 static_assert(sizeof(struct INDEX_HDR) == 0x10);
716 
hdr_first_de(const struct INDEX_HDR * hdr)717 static inline struct NTFS_DE *hdr_first_de(const struct INDEX_HDR *hdr)
718 {
719 	u32 de_off = le32_to_cpu(hdr->de_off);
720 	u32 used = le32_to_cpu(hdr->used);
721 	struct NTFS_DE *e;
722 	u16 esize;
723 
724 	if (de_off >= used || size_add(de_off, sizeof(struct NTFS_DE)) > used)
725 		return NULL;
726 
727 	e = Add2Ptr(hdr, de_off);
728 	esize = le16_to_cpu(e->size);
729 	if (esize < sizeof(struct NTFS_DE) || de_off + esize > used)
730 		return NULL;
731 
732 	return e;
733 }
734 
hdr_next_de(const struct INDEX_HDR * hdr,const struct NTFS_DE * e)735 static inline struct NTFS_DE *hdr_next_de(const struct INDEX_HDR *hdr,
736 					  const struct NTFS_DE *e)
737 {
738 	size_t off = PtrOffset(hdr, e);
739 	u32 used = le32_to_cpu(hdr->used);
740 	u16 esize;
741 
742 	if (off >= used)
743 		return NULL;
744 
745 	esize = le16_to_cpu(e->size);
746 
747 	if (esize < sizeof(struct NTFS_DE) ||
748 	    off + esize + sizeof(struct NTFS_DE) > used)
749 		return NULL;
750 
751 	return Add2Ptr(e, esize);
752 }
753 
hdr_has_subnode(const struct INDEX_HDR * hdr)754 static inline bool hdr_has_subnode(const struct INDEX_HDR *hdr)
755 {
756 	return hdr->flags & NTFS_INDEX_HDR_HAS_SUBNODES;
757 }
758 
759 struct INDEX_BUFFER {
760 	struct NTFS_RECORD_HEADER rhdr; // 'INDX'
761 	__le64 vbn; // 0x10: vcn if index >= cluster or vsn id index < cluster
762 	struct INDEX_HDR ihdr; // 0x18:
763 };
764 
765 static_assert(sizeof(struct INDEX_BUFFER) == 0x28);
766 
ib_is_empty(const struct INDEX_BUFFER * ib)767 static inline bool ib_is_empty(const struct INDEX_BUFFER *ib)
768 {
769 	const struct NTFS_DE *first = hdr_first_de(&ib->ihdr);
770 
771 	return !first || de_is_last(first);
772 }
773 
ib_is_leaf(const struct INDEX_BUFFER * ib)774 static inline bool ib_is_leaf(const struct INDEX_BUFFER *ib)
775 {
776 	return !(ib->ihdr.flags & NTFS_INDEX_HDR_HAS_SUBNODES);
777 }
778 
779 /* Index root structure ( 0x90 ). */
780 enum COLLATION_RULE {
781 	NTFS_COLLATION_TYPE_BINARY	= cpu_to_le32(0),
782 	// $I30
783 	NTFS_COLLATION_TYPE_FILENAME	= cpu_to_le32(0x01),
784 	// $SII of $Secure and $Q of Quota
785 	NTFS_COLLATION_TYPE_UINT	= cpu_to_le32(0x10),
786 	// $O of Quota
787 	NTFS_COLLATION_TYPE_SID		= cpu_to_le32(0x11),
788 	// $SDH of $Secure
789 	NTFS_COLLATION_TYPE_SECURITY_HASH = cpu_to_le32(0x12),
790 	// $O of ObjId and "$R" for Reparse
791 	NTFS_COLLATION_TYPE_UINTS	= cpu_to_le32(0x13)
792 };
793 
794 static_assert(sizeof(enum COLLATION_RULE) == 4);
795 
796 //
797 struct INDEX_ROOT {
798 	enum ATTR_TYPE type;	// 0x00: The type of attribute to index on.
799 	enum COLLATION_RULE rule; // 0x04: The rule.
800 	__le32 index_block_size;// 0x08: The size of index record.
801 	u8 index_block_clst;	// 0x0C: The number of clusters or sectors per index.
802 	u8 res[3];
803 	struct INDEX_HDR ihdr;	// 0x10:
804 };
805 
806 static_assert(sizeof(struct INDEX_ROOT) == 0x20);
807 static_assert(offsetof(struct INDEX_ROOT, ihdr) == 0x10);
808 
809 #define VOLUME_FLAG_DIRTY	    cpu_to_le16(0x0001)
810 #define VOLUME_FLAG_RESIZE_LOG_FILE cpu_to_le16(0x0002)
811 
812 struct VOLUME_INFO {
813 	__le64 res1;	// 0x00
814 	u8 major_ver;	// 0x08: NTFS major version number (before .)
815 	u8 minor_ver;	// 0x09: NTFS minor version number (after .)
816 	__le16 flags;	// 0x0A: Volume flags, see VOLUME_FLAG_XXX
817 
818 }; // sizeof=0xC
819 
820 #define SIZEOF_ATTRIBUTE_VOLUME_INFO 0xc
821 
822 #define NTFS_LABEL_MAX_LENGTH		(0x100 / sizeof(short))
823 #define NTFS_ATTR_INDEXABLE		cpu_to_le32(0x00000002)
824 #define NTFS_ATTR_DUPALLOWED		cpu_to_le32(0x00000004)
825 #define NTFS_ATTR_MUST_BE_INDEXED	cpu_to_le32(0x00000010)
826 #define NTFS_ATTR_MUST_BE_NAMED		cpu_to_le32(0x00000020)
827 #define NTFS_ATTR_MUST_BE_RESIDENT	cpu_to_le32(0x00000040)
828 #define NTFS_ATTR_LOG_ALWAYS		cpu_to_le32(0x00000080)
829 
830 /* $AttrDef file entry. */
831 struct ATTR_DEF_ENTRY {
832 	__le16 name[0x40];	// 0x00: Attr name.
833 	enum ATTR_TYPE type;	// 0x80: struct ATTRIB type.
834 	__le32 res;		// 0x84:
835 	enum COLLATION_RULE rule; // 0x88:
836 	__le32 flags;		// 0x8C: NTFS_ATTR_XXX (see above).
837 	__le64 min_sz;		// 0x90: Minimum attribute data size.
838 	__le64 max_sz;		// 0x98: Maximum attribute data size.
839 };
840 
841 static_assert(sizeof(struct ATTR_DEF_ENTRY) == 0xa0);
842 
843 /* Object ID (0x40) */
844 struct OBJECT_ID {
845 	struct GUID ObjId;	// 0x00: Unique Id assigned to file.
846 
847 	// Birth Volume Id is the Object Id of the Volume on.
848 	// which the Object Id was allocated. It never changes.
849 	struct GUID BirthVolumeId; //0x10:
850 
851 	// Birth Object Id is the first Object Id that was
852 	// ever assigned to this MFT Record. I.e. If the Object Id
853 	// is changed for some reason, this field will reflect the
854 	// original value of the Object Id.
855 	struct GUID BirthObjectId; // 0x20:
856 
857 	// Domain Id is currently unused but it is intended to be
858 	// used in a network environment where the local machine is
859 	// part of a Windows 2000 Domain. This may be used in a Windows
860 	// 2000 Advanced Server managed domain.
861 	struct GUID DomainId;	// 0x30:
862 };
863 
864 static_assert(sizeof(struct OBJECT_ID) == 0x40);
865 
866 /* O Directory entry structure ( rule = 0x13 ) */
867 struct NTFS_DE_O {
868 	struct NTFS_DE de;
869 	struct GUID ObjId;	// 0x10: Unique Id assigned to file.
870 	struct MFT_REF ref;	// 0x20: MFT record number with this file.
871 
872 	// Birth Volume Id is the Object Id of the Volume on
873 	// which the Object Id was allocated. It never changes.
874 	struct GUID BirthVolumeId; // 0x28:
875 
876 	// Birth Object Id is the first Object Id that was
877 	// ever assigned to this MFT Record. I.e. If the Object Id
878 	// is changed for some reason, this field will reflect the
879 	// original value of the Object Id.
880 	// This field is valid if data_size == 0x48.
881 	struct GUID BirthObjectId; // 0x38:
882 
883 	// Domain Id is currently unused but it is intended
884 	// to be used in a network environment where the local
885 	// machine is part of a Windows 2000 Domain. This may be
886 	// used in a Windows 2000 Advanced Server managed domain.
887 	struct GUID BirthDomainId; // 0x48:
888 };
889 
890 static_assert(sizeof(struct NTFS_DE_O) == 0x58);
891 
892 /* Q Directory entry structure ( rule = 0x11 ) */
893 struct NTFS_DE_Q {
894 	struct NTFS_DE de;
895 	__le32 owner_id;	// 0x10: Unique Id assigned to file
896 
897 	/* here is 0x30 bytes of user quota. NOTE: 4 byte aligned! */
898 	__le32 Version;		// 0x14: 0x02
899 	__le32 Flags;		// 0x18: Quota flags, see above
900 	__le64 BytesUsed;	// 0x1C:
901 	__le64 ChangeTime;	// 0x24:
902 	__le64 WarningLimit;	// 0x28:
903 	__le64 HardLimit;	// 0x34:
904 	__le64 ExceededTime;	// 0x3C:
905 
906 	// SID is placed here
907 }__packed; // sizeof() = 0x44
908 
909 static_assert(sizeof(struct NTFS_DE_Q) == 0x44);
910 
911 #define SecurityDescriptorsBlockSize 0x40000 // 256K
912 #define SecurityDescriptorMaxSize    0x20000 // 128K
913 #define Log2OfSecurityDescriptorsBlockSize 18
914 
915 struct SECURITY_KEY {
916 	__le32 hash; //  Hash value for descriptor
917 	__le32 sec_id; //  Security Id (guaranteed unique)
918 };
919 
920 /* Security descriptors (the content of $Secure::SDS data stream) */
921 struct SECURITY_HDR {
922 	struct SECURITY_KEY key;	// 0x00: Security Key.
923 	__le64 off;			// 0x08: Offset of this entry in the file.
924 	__le32 size;			// 0x10: Size of this entry, 8 byte aligned.
925 	/*
926 	 * Security descriptor itself is placed here.
927 	 * Total size is 16 byte aligned.
928 	 */
929 } __packed;
930 
931 static_assert(sizeof(struct SECURITY_HDR) == 0x14);
932 
933 /* SII Directory entry structure */
934 struct NTFS_DE_SII {
935 	struct NTFS_DE de;
936 	__le32 sec_id;			// 0x10: Key: sizeof(security_id) = wKeySize
937 	struct SECURITY_HDR sec_hdr;	// 0x14:
938 } __packed;
939 
940 static_assert(offsetof(struct NTFS_DE_SII, sec_hdr) == 0x14);
941 static_assert(sizeof(struct NTFS_DE_SII) == 0x28);
942 
943 /* SDH Directory entry structure */
944 struct NTFS_DE_SDH {
945 	struct NTFS_DE de;
946 	struct SECURITY_KEY key;	// 0x10: Key
947 	struct SECURITY_HDR sec_hdr;	// 0x18: Data
948 	__le16 magic[2];		// 0x2C: 0x00490049 "I I"
949 };
950 
951 #define SIZEOF_SDH_DIRENTRY 0x30
952 
953 struct REPARSE_KEY {
954 	__le32 ReparseTag;		// 0x00: Reparse Tag
955 	struct MFT_REF ref;		// 0x04: MFT record number with this file
956 }; // sizeof() = 0x0C
957 
958 static_assert(offsetof(struct REPARSE_KEY, ref) == 0x04);
959 #define SIZEOF_REPARSE_KEY 0x0C
960 
961 /* Reparse Directory entry structure */
962 struct NTFS_DE_R {
963 	struct NTFS_DE de;
964 	struct REPARSE_KEY key;		// 0x10: Reparse Key.
965 	u32 zero;			// 0x1c:
966 }; // sizeof() = 0x20
967 
968 static_assert(sizeof(struct NTFS_DE_R) == 0x20);
969 
970 /* CompressReparseBuffer.WofVersion */
971 #define WOF_CURRENT_VERSION		cpu_to_le32(1)
972 /* CompressReparseBuffer.WofProvider */
973 #define WOF_PROVIDER_WIM		cpu_to_le32(1)
974 /* CompressReparseBuffer.WofProvider */
975 #define WOF_PROVIDER_SYSTEM		cpu_to_le32(2)
976 /* CompressReparseBuffer.ProviderVer */
977 #define WOF_PROVIDER_CURRENT_VERSION	cpu_to_le32(1)
978 
979 #define WOF_COMPRESSION_XPRESS4K	cpu_to_le32(0) // 4k
980 #define WOF_COMPRESSION_LZX32K		cpu_to_le32(1) // 32k
981 #define WOF_COMPRESSION_XPRESS8K	cpu_to_le32(2) // 8k
982 #define WOF_COMPRESSION_XPRESS16K	cpu_to_le32(3) // 16k
983 
984 /*
985  * ATTR_REPARSE (0xC0)
986  *
987  * The reparse struct GUID structure is used by all 3rd party layered drivers to
988  * store data in a reparse point. For non-Microsoft tags, The struct GUID field
989  * cannot be GUID_NULL.
990  * The constraints on reparse tags are defined below.
991  * Microsoft tags can also be used with this format of the reparse point buffer.
992  */
993 struct REPARSE_POINT {
994 	__le32 ReparseTag;	// 0x00:
995 	__le16 ReparseDataLength;// 0x04:
996 	__le16 Reserved;
997 
998 	struct GUID Guid;	// 0x08:
999 
1000 	//
1001 	// Here GenericReparseBuffer is placed
1002 	//
1003 };
1004 
1005 static_assert(sizeof(struct REPARSE_POINT) == 0x18);
1006 
1007 /*
1008  * The value of the following constant needs to satisfy the following
1009  * conditions:
1010  *  (1) Be at least as large as the largest of the reserved tags.
1011  *  (2) Be strictly smaller than all the tags in use.
1012  */
1013 #define IO_REPARSE_TAG_RESERVED_RANGE		1
1014 
1015 /*
1016  * The reparse tags are a ULONG. The 32 bits are laid out as follows:
1017  *
1018  *   3 3 2 2 2 2 2 2 2 2 2 2 1 1 1 1 1 1 1 1 1 1
1019  *   1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0
1020  *  +-+-+-+-+-----------------------+-------------------------------+
1021  *  |M|R|N|R|	  Reserved bits     |	    Reparse Tag Value	    |
1022  *  +-+-+-+-+-----------------------+-------------------------------+
1023  *
1024  * M is the Microsoft bit. When set to 1, it denotes a tag owned by Microsoft.
1025  *   All ISVs must use a tag with a 0 in this position.
1026  *   Note: If a Microsoft tag is used by non-Microsoft software, the
1027  *   behavior is not defined.
1028  *
1029  * R is reserved.  Must be zero for non-Microsoft tags.
1030  *
1031  * N is name surrogate. When set to 1, the file represents another named
1032  *   entity in the system.
1033  *
1034  * The M and N bits are OR-able.
1035  * The following macros check for the M and N bit values:
1036  */
1037 
1038 /*
1039  * Macro to determine whether a reparse point tag corresponds to a tag
1040  * owned by Microsoft.
1041  */
1042 #define IsReparseTagMicrosoft(_tag)	(((_tag)&IO_REPARSE_TAG_MICROSOFT))
1043 
1044 /* Macro to determine whether a reparse point tag is a name surrogate. */
1045 #define IsReparseTagNameSurrogate(_tag)	(((_tag)&IO_REPARSE_TAG_NAME_SURROGATE))
1046 
1047 /*
1048  * The following constant represents the bits that are valid to use in
1049  * reparse tags.
1050  */
1051 #define IO_REPARSE_TAG_VALID_VALUES	0xF000FFFF
1052 
1053 /*
1054  * Macro to determine whether a reparse tag is a valid tag.
1055  */
1056 #define IsReparseTagValid(_tag)						       \
1057 	(!((_tag) & ~IO_REPARSE_TAG_VALID_VALUES) &&			       \
1058 	 ((_tag) > IO_REPARSE_TAG_RESERVED_RANGE))
1059 
1060 /* Microsoft tags for reparse points. */
1061 
1062 enum IO_REPARSE_TAG {
1063 	IO_REPARSE_TAG_SYMBOLIC_LINK	= cpu_to_le32(0),
1064 	IO_REPARSE_TAG_NAME_SURROGATE	= cpu_to_le32(0x20000000),
1065 	IO_REPARSE_TAG_MICROSOFT	= cpu_to_le32(0x80000000),
1066 	IO_REPARSE_TAG_MOUNT_POINT	= cpu_to_le32(0xA0000003),
1067 	IO_REPARSE_TAG_SYMLINK		= cpu_to_le32(0xA000000C),
1068 	IO_REPARSE_TAG_HSM		= cpu_to_le32(0xC0000004),
1069 	IO_REPARSE_TAG_SIS		= cpu_to_le32(0x80000007),
1070 	IO_REPARSE_TAG_DEDUP		= cpu_to_le32(0x80000013),
1071 	IO_REPARSE_TAG_COMPRESS		= cpu_to_le32(0x80000017),
1072 
1073 	/*
1074 	 * The reparse tag 0x80000008 is reserved for Microsoft internal use.
1075 	 * May be published in the future.
1076 	 */
1077 
1078 	/* Microsoft reparse tag reserved for DFS */
1079 	IO_REPARSE_TAG_DFS	= cpu_to_le32(0x8000000A),
1080 
1081 	/* Microsoft reparse tag reserved for the file system filter manager. */
1082 	IO_REPARSE_TAG_FILTER_MANAGER	= cpu_to_le32(0x8000000B),
1083 
1084 	/* Non-Microsoft tags for reparse points */
1085 
1086 	/* Tag allocated to CONGRUENT, May 2000. Used by IFSTEST. */
1087 	IO_REPARSE_TAG_IFSTEST_CONGRUENT = cpu_to_le32(0x00000009),
1088 
1089 	/* Tag allocated to ARKIVIO. */
1090 	IO_REPARSE_TAG_ARKIVIO	= cpu_to_le32(0x0000000C),
1091 
1092 	/* Tag allocated to SOLUTIONSOFT. */
1093 	IO_REPARSE_TAG_SOLUTIONSOFT	= cpu_to_le32(0x2000000D),
1094 
1095 	/* Tag allocated to COMMVAULT. */
1096 	IO_REPARSE_TAG_COMMVAULT	= cpu_to_le32(0x0000000E),
1097 
1098 	/* OneDrive?? */
1099 	IO_REPARSE_TAG_CLOUD	= cpu_to_le32(0x9000001A),
1100 	IO_REPARSE_TAG_CLOUD_1	= cpu_to_le32(0x9000101A),
1101 	IO_REPARSE_TAG_CLOUD_2	= cpu_to_le32(0x9000201A),
1102 	IO_REPARSE_TAG_CLOUD_3	= cpu_to_le32(0x9000301A),
1103 	IO_REPARSE_TAG_CLOUD_4	= cpu_to_le32(0x9000401A),
1104 	IO_REPARSE_TAG_CLOUD_5	= cpu_to_le32(0x9000501A),
1105 	IO_REPARSE_TAG_CLOUD_6	= cpu_to_le32(0x9000601A),
1106 	IO_REPARSE_TAG_CLOUD_7	= cpu_to_le32(0x9000701A),
1107 	IO_REPARSE_TAG_CLOUD_8	= cpu_to_le32(0x9000801A),
1108 	IO_REPARSE_TAG_CLOUD_9	= cpu_to_le32(0x9000901A),
1109 	IO_REPARSE_TAG_CLOUD_A	= cpu_to_le32(0x9000A01A),
1110 	IO_REPARSE_TAG_CLOUD_B	= cpu_to_le32(0x9000B01A),
1111 	IO_REPARSE_TAG_CLOUD_C	= cpu_to_le32(0x9000C01A),
1112 	IO_REPARSE_TAG_CLOUD_D	= cpu_to_le32(0x9000D01A),
1113 	IO_REPARSE_TAG_CLOUD_E	= cpu_to_le32(0x9000E01A),
1114 	IO_REPARSE_TAG_CLOUD_F	= cpu_to_le32(0x9000F01A),
1115 
1116 };
1117 
1118 #define SYMLINK_FLAG_RELATIVE		1
1119 
1120 /* Microsoft reparse buffer. (see DDK for details) */
1121 struct REPARSE_DATA_BUFFER {
1122 	__le32 ReparseTag;		// 0x00:
1123 	__le16 ReparseDataLength;	// 0x04:
1124 	__le16 Reserved;
1125 
1126 	union {
1127 		/* If ReparseTag == 0xA0000003 (IO_REPARSE_TAG_MOUNT_POINT) */
1128 		struct {
1129 			__le16 SubstituteNameOffset; // 0x08
1130 			__le16 SubstituteNameLength; // 0x0A
1131 			__le16 PrintNameOffset;      // 0x0C
1132 			__le16 PrintNameLength;      // 0x0E
1133 			__le16 PathBuffer[];	     // 0x10
1134 		} MountPointReparseBuffer;
1135 
1136 		/*
1137 		 * If ReparseTag == 0xA000000C (IO_REPARSE_TAG_SYMLINK)
1138 		 * https://msdn.microsoft.com/en-us/library/cc232006.aspx
1139 		 */
1140 		struct {
1141 			__le16 SubstituteNameOffset; // 0x08
1142 			__le16 SubstituteNameLength; // 0x0A
1143 			__le16 PrintNameOffset;      // 0x0C
1144 			__le16 PrintNameLength;      // 0x0E
1145 			// 0-absolute path 1- relative path, SYMLINK_FLAG_RELATIVE
1146 			__le32 Flags;		     // 0x10
1147 			__le16 PathBuffer[];	     // 0x14
1148 		} SymbolicLinkReparseBuffer;
1149 
1150 		/* If ReparseTag == 0x80000017U */
1151 		struct {
1152 			__le32 WofVersion;  // 0x08 == 1
1153 			/*
1154 			 * 1 - WIM backing provider ("WIMBoot"),
1155 			 * 2 - System compressed file provider
1156 			 */
1157 			__le32 WofProvider; // 0x0C:
1158 			__le32 ProviderVer; // 0x10: == 1 WOF_FILE_PROVIDER_CURRENT_VERSION == 1
1159 			__le32 CompressionFormat; // 0x14: 0, 1, 2, 3. See WOF_COMPRESSION_XXX
1160 		} CompressReparseBuffer;
1161 
1162 		struct {
1163 			u8 DataBuffer[1];   // 0x08:
1164 		} GenericReparseBuffer;
1165 	};
1166 };
1167 
1168 /* ATTR_EA_INFO (0xD0) */
1169 
1170 #define FILE_NEED_EA 0x80 // See ntifs.h
1171 /*
1172  * FILE_NEED_EA, indicates that the file to which the EA belongs cannot be
1173  * interpreted without understanding the associated extended attributes.
1174  */
1175 struct EA_INFO {
1176 	__le16 size_pack;	// 0x00: Size of buffer to hold in packed form.
1177 	__le16 count;		// 0x02: Count of EA's with FILE_NEED_EA bit set.
1178 	__le32 size;		// 0x04: Size of buffer to hold in unpacked form.
1179 };
1180 
1181 static_assert(sizeof(struct EA_INFO) == 8);
1182 
1183 /* ATTR_EA (0xE0) */
1184 struct EA_FULL {
1185 	__le32 size;		// 0x00: (not in packed)
1186 	u8 flags;		// 0x04:
1187 	u8 name_len;		// 0x05:
1188 	__le16 elength;		// 0x06:
1189 	u8 name[];		// 0x08:
1190 };
1191 
1192 static_assert(offsetof(struct EA_FULL, name) == 8);
1193 
1194 #define ACL_REVISION	2
1195 #define ACL_REVISION_DS 4
1196 
1197 #define SE_SELF_RELATIVE cpu_to_le16(0x8000)
1198 
1199 struct SECURITY_DESCRIPTOR_RELATIVE {
1200 	u8 Revision;
1201 	u8 Sbz1;
1202 	__le16 Control;
1203 	__le32 Owner;
1204 	__le32 Group;
1205 	__le32 Sacl;
1206 	__le32 Dacl;
1207 };
1208 static_assert(sizeof(struct SECURITY_DESCRIPTOR_RELATIVE) == 0x14);
1209 
1210 struct ACE_HEADER {
1211 	u8 AceType;
1212 	u8 AceFlags;
1213 	__le16 AceSize;
1214 };
1215 static_assert(sizeof(struct ACE_HEADER) == 4);
1216 
1217 struct ACL {
1218 	u8 AclRevision;
1219 	u8 Sbz1;
1220 	__le16 AclSize;
1221 	__le16 AceCount;
1222 	__le16 Sbz2;
1223 };
1224 static_assert(sizeof(struct ACL) == 8);
1225 
1226 struct SID {
1227 	u8 Revision;
1228 	u8 SubAuthorityCount;
1229 	u8 IdentifierAuthority[6];
1230 	__le32 SubAuthority[];
1231 };
1232 static_assert(offsetof(struct SID, SubAuthority) == 8);
1233 
1234 #endif /* _LINUX_NTFS3_NTFS_H */
1235 // clang-format on
1236