1 /* SPDX-License-Identifier: GPL-2.0-only */
2 /*
3 *
4 * Copyright (C) 2011 Novell Inc.
5 */
6
7 #include <linux/kernel.h>
8 #include <linux/uuid.h>
9 #include <linux/fs.h>
10 #include <linux/fsverity.h>
11 #include <linux/namei.h>
12 #include <linux/posix_acl.h>
13 #include <linux/posix_acl_xattr.h>
14 #include "ovl_entry.h"
15
16 #undef pr_fmt
17 #define pr_fmt(fmt) "overlayfs: " fmt
18
19 enum ovl_path_type {
20 __OVL_PATH_UPPER = (1 << 0),
21 __OVL_PATH_MERGE = (1 << 1),
22 __OVL_PATH_ORIGIN = (1 << 2),
23 };
24
25 #define OVL_TYPE_UPPER(type) ((type) & __OVL_PATH_UPPER)
26 #define OVL_TYPE_MERGE(type) ((type) & __OVL_PATH_MERGE)
27 #define OVL_TYPE_ORIGIN(type) ((type) & __OVL_PATH_ORIGIN)
28
29 #define OVL_XATTR_NAMESPACE "overlay."
30 #define OVL_XATTR_TRUSTED_PREFIX XATTR_TRUSTED_PREFIX OVL_XATTR_NAMESPACE
31 #define OVL_XATTR_TRUSTED_PREFIX_LEN (sizeof(OVL_XATTR_TRUSTED_PREFIX) - 1)
32 #define OVL_XATTR_USER_PREFIX XATTR_USER_PREFIX OVL_XATTR_NAMESPACE
33 #define OVL_XATTR_USER_PREFIX_LEN (sizeof(OVL_XATTR_USER_PREFIX) - 1)
34
35 #define OVL_XATTR_ESCAPE_PREFIX OVL_XATTR_NAMESPACE
36 #define OVL_XATTR_ESCAPE_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_PREFIX) - 1)
37 #define OVL_XATTR_ESCAPE_TRUSTED_PREFIX OVL_XATTR_TRUSTED_PREFIX OVL_XATTR_ESCAPE_PREFIX
38 #define OVL_XATTR_ESCAPE_TRUSTED_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_TRUSTED_PREFIX) - 1)
39 #define OVL_XATTR_ESCAPE_USER_PREFIX OVL_XATTR_USER_PREFIX OVL_XATTR_ESCAPE_PREFIX
40 #define OVL_XATTR_ESCAPE_USER_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_USER_PREFIX) - 1)
41
42 enum ovl_xattr {
43 OVL_XATTR_OPAQUE,
44 OVL_XATTR_REDIRECT,
45 OVL_XATTR_ORIGIN,
46 OVL_XATTR_IMPURE,
47 OVL_XATTR_NLINK,
48 OVL_XATTR_UPPER,
49 OVL_XATTR_UUID,
50 OVL_XATTR_METACOPY,
51 OVL_XATTR_PROTATTR,
52 OVL_XATTR_XWHITEOUT,
53 };
54
55 enum ovl_inode_flag {
56 /* Pure upper dir that may contain non pure upper entries */
57 OVL_IMPURE,
58 /* Non-merge dir that may contain whiteout entries */
59 OVL_WHITEOUTS,
60 OVL_INDEX,
61 OVL_UPPERDATA,
62 /* Inode number will remain constant over copy up. */
63 OVL_CONST_INO,
64 OVL_HAS_DIGEST,
65 OVL_VERIFIED_DIGEST,
66 };
67
68 enum ovl_entry_flag {
69 OVL_E_UPPER_ALIAS,
70 OVL_E_OPAQUE,
71 OVL_E_CONNECTED,
72 /* Lower stack may contain xwhiteout entries */
73 OVL_E_XWHITEOUTS,
74 };
75
76 enum {
77 OVL_REDIRECT_OFF, /* "off" mode is never used. In effect */
78 OVL_REDIRECT_FOLLOW, /* ...it translates to either "follow" */
79 OVL_REDIRECT_NOFOLLOW, /* ...or "nofollow". */
80 OVL_REDIRECT_ON,
81 };
82
83 enum {
84 OVL_UUID_OFF,
85 OVL_UUID_NULL,
86 OVL_UUID_AUTO,
87 OVL_UUID_ON,
88 };
89
90 enum {
91 OVL_XINO_OFF,
92 OVL_XINO_AUTO,
93 OVL_XINO_ON,
94 };
95
96 enum {
97 OVL_VERITY_OFF,
98 OVL_VERITY_ON,
99 OVL_VERITY_REQUIRE,
100 };
101
102 enum {
103 OVL_FSYNC_VOLATILE,
104 OVL_FSYNC_AUTO,
105 OVL_FSYNC_STRICT,
106 };
107
108 /*
109 * The tuple (fh,uuid) is a universal unique identifier for a copy up origin,
110 * where:
111 * origin.fh - exported file handle of the lower file
112 * origin.uuid - uuid of the lower filesystem
113 */
114 #define OVL_FH_VERSION 0
115 #define OVL_FH_MAGIC 0xfb
116
117 /* CPU byte order required for fid decoding: */
118 #define OVL_FH_FLAG_BIG_ENDIAN (1 << 0)
119 #define OVL_FH_FLAG_ANY_ENDIAN (1 << 1)
120 /* Is the real inode encoded in fid an upper inode? */
121 #define OVL_FH_FLAG_PATH_UPPER (1 << 2)
122
123 #define OVL_FH_FLAG_ALL (OVL_FH_FLAG_BIG_ENDIAN | OVL_FH_FLAG_ANY_ENDIAN | \
124 OVL_FH_FLAG_PATH_UPPER)
125
126 #if defined(__LITTLE_ENDIAN)
127 #define OVL_FH_FLAG_CPU_ENDIAN 0
128 #elif defined(__BIG_ENDIAN)
129 #define OVL_FH_FLAG_CPU_ENDIAN OVL_FH_FLAG_BIG_ENDIAN
130 #else
131 #error Endianness not defined
132 #endif
133
134 /* The type used to be returned by overlay exportfs for misaligned fid */
135 #define OVL_FILEID_V0 0xfb
136 /* The type returned by overlay exportfs for 32bit aligned fid */
137 #define OVL_FILEID_V1 0xf8
138
139 /* On-disk format for "origin" file handle */
140 struct ovl_fb {
141 u8 version; /* 0 */
142 u8 magic; /* 0xfb */
143 u8 len; /* size of this header + size of fid */
144 u8 flags; /* OVL_FH_FLAG_* */
145 u8 type; /* fid_type of fid */
146 uuid_t uuid; /* uuid of filesystem */
147 u32 fid[]; /* file identifier should be 32bit aligned in-memory */
148 } __packed;
149
150 /* In-memory and on-wire format for overlay file handle */
151 struct ovl_fh {
152 u8 padding[3]; /* make sure fb.fid is 32bit aligned */
153 union {
154 struct ovl_fb fb;
155 DECLARE_FLEX_ARRAY(u8, buf);
156 };
157 } __packed;
158
159 #define OVL_FH_WIRE_OFFSET offsetof(struct ovl_fh, fb)
160 #define OVL_FH_LEN(fh) (OVL_FH_WIRE_OFFSET + (fh)->fb.len)
161 #define OVL_FH_FID_OFFSET (OVL_FH_WIRE_OFFSET + \
162 offsetof(struct ovl_fb, fid))
163
164 /* On-disk format for "metacopy" xattr (if non-zero size) */
165 struct ovl_metacopy {
166 u8 version; /* 0 */
167 u8 len; /* size of this header + used digest bytes */
168 u8 flags;
169 u8 digest_algo; /* FS_VERITY_HASH_ALG_* constant, 0 for no digest */
170 u8 digest[FS_VERITY_MAX_DIGEST_SIZE]; /* Only the used part on disk */
171 } __packed;
172
173 #define OVL_METACOPY_MAX_SIZE (sizeof(struct ovl_metacopy))
174 #define OVL_METACOPY_MIN_SIZE (OVL_METACOPY_MAX_SIZE - FS_VERITY_MAX_DIGEST_SIZE)
175 #define OVL_METACOPY_INIT { 0, OVL_METACOPY_MIN_SIZE }
176
ovl_metadata_digest_size(const struct ovl_metacopy * metacopy)177 static inline int ovl_metadata_digest_size(const struct ovl_metacopy *metacopy)
178 {
179 if (metacopy->len < OVL_METACOPY_MIN_SIZE)
180 return 0;
181 return (int)metacopy->len - OVL_METACOPY_MIN_SIZE;
182 }
183
184 /* No atime modification on underlying */
185 #define OVL_OPEN_FLAGS (O_NOATIME)
186
187 extern const char *const ovl_xattr_table[][2];
ovl_xattr(struct ovl_fs * ofs,enum ovl_xattr ox)188 static inline const char *ovl_xattr(struct ovl_fs *ofs, enum ovl_xattr ox)
189 {
190 return ovl_xattr_table[ox][ofs->config.userxattr];
191 }
192
193 /*
194 * When changing ownership of an upper object map the intended ownership
195 * according to the upper layer's idmapping. When an upper mount idmaps files
196 * that are stored on-disk as owned by id 1001 to id 1000 this means stat on
197 * this object will report it as being owned by id 1000 when calling stat via
198 * the upper mount.
199 * In order to change ownership of an object so stat reports id 1000 when
200 * called on an idmapped upper mount the value written to disk - i.e., the
201 * value stored in ia_*id - must 1001. The mount mapping helper will thus take
202 * care to map 1000 to 1001.
203 * The mnt idmapping helpers are nops if the upper layer isn't idmapped.
204 */
ovl_do_notify_change(struct ovl_fs * ofs,struct dentry * upperdentry,struct iattr * attr)205 static inline int ovl_do_notify_change(struct ovl_fs *ofs,
206 struct dentry *upperdentry,
207 struct iattr *attr)
208 {
209 return notify_change(ovl_upper_mnt_idmap(ofs), upperdentry, attr, NULL);
210 }
211
ovl_do_rmdir(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry)212 static inline int ovl_do_rmdir(struct ovl_fs *ofs,
213 struct inode *dir, struct dentry *dentry)
214 {
215 int err = vfs_rmdir(ovl_upper_mnt_idmap(ofs), dir, dentry, NULL);
216
217 pr_debug("rmdir(%pd2) = %i\n", dentry, err);
218 return err;
219 }
220
ovl_do_unlink(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry)221 static inline int ovl_do_unlink(struct ovl_fs *ofs, struct inode *dir,
222 struct dentry *dentry)
223 {
224 int err = vfs_unlink(ovl_upper_mnt_idmap(ofs), dir, dentry, NULL);
225
226 pr_debug("unlink(%pd2) = %i\n", dentry, err);
227 return err;
228 }
229
ovl_do_link(struct ovl_fs * ofs,struct dentry * old_dentry,struct inode * dir,struct dentry * new_dentry)230 static inline int ovl_do_link(struct ovl_fs *ofs, struct dentry *old_dentry,
231 struct inode *dir, struct dentry *new_dentry)
232 {
233 int err = vfs_link(old_dentry, ovl_upper_mnt_idmap(ofs), dir,
234 new_dentry, NULL);
235
236 pr_debug("link(%pd2, %pd2) = %i\n", old_dentry, new_dentry, err);
237 return err;
238 }
239
ovl_do_create(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry,umode_t mode)240 static inline int ovl_do_create(struct ovl_fs *ofs,
241 struct inode *dir, struct dentry *dentry,
242 umode_t mode)
243 {
244 int err = vfs_create(ovl_upper_mnt_idmap(ofs), dentry, mode, NULL);
245
246 pr_debug("create(%pd2, 0%o) = %i\n", dentry, mode, err);
247 return err;
248 }
249
ovl_do_mkdir(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry,umode_t mode)250 static inline struct dentry *ovl_do_mkdir(struct ovl_fs *ofs,
251 struct inode *dir,
252 struct dentry *dentry,
253 umode_t mode)
254 {
255 struct dentry *ret;
256
257 /* vfs_mkdir() drops @dentry on failure and may replace it on success */
258 pr_debug("mkdir(%pd2, 0%o)\n", dentry, mode);
259 ret = vfs_mkdir(ovl_upper_mnt_idmap(ofs), dir, dentry, mode, NULL);
260 pr_debug("...mkdir = %i\n", PTR_ERR_OR_ZERO(ret));
261 return ret;
262 }
263
ovl_do_mknod(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry,umode_t mode,dev_t dev)264 static inline int ovl_do_mknod(struct ovl_fs *ofs,
265 struct inode *dir, struct dentry *dentry,
266 umode_t mode, dev_t dev)
267 {
268 int err = vfs_mknod(ovl_upper_mnt_idmap(ofs), dir, dentry, mode, dev, NULL);
269
270 pr_debug("mknod(%pd2, 0%o, 0%o) = %i\n", dentry, mode, dev, err);
271 return err;
272 }
273
ovl_do_symlink(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry,const char * oldname)274 static inline int ovl_do_symlink(struct ovl_fs *ofs,
275 struct inode *dir, struct dentry *dentry,
276 const char *oldname)
277 {
278 int err = vfs_symlink(ovl_upper_mnt_idmap(ofs), dir, dentry, oldname, NULL);
279
280 pr_debug("symlink(\"%s\", %pd2) = %i\n", oldname, dentry, err);
281 return err;
282 }
283
ovl_do_getxattr(const struct path * path,const char * name,void * value,size_t size)284 static inline ssize_t ovl_do_getxattr(const struct path *path, const char *name,
285 void *value, size_t size)
286 {
287 int err, len;
288
289 WARN_ON(path->dentry->d_sb != path->mnt->mnt_sb);
290
291 err = vfs_getxattr(mnt_idmap(path->mnt), path->dentry,
292 name, value, size);
293 len = (value && err > 0) ? err : 0;
294
295 pr_debug("getxattr(%pd2, \"%s\", \"%*pE\", %zu, 0) = %i\n",
296 path->dentry, name, min(len, 48), value, size, err);
297 return err;
298 }
299
ovl_getxattr_upper(struct ovl_fs * ofs,struct dentry * upperdentry,enum ovl_xattr ox,void * value,size_t size)300 static inline ssize_t ovl_getxattr_upper(struct ovl_fs *ofs,
301 struct dentry *upperdentry,
302 enum ovl_xattr ox, void *value,
303 size_t size)
304 {
305 struct path upperpath = {
306 .dentry = upperdentry,
307 .mnt = ovl_upper_mnt(ofs),
308 };
309
310 return ovl_do_getxattr(&upperpath, ovl_xattr(ofs, ox), value, size);
311 }
312
ovl_path_getxattr(struct ovl_fs * ofs,const struct path * path,enum ovl_xattr ox,void * value,size_t size)313 static inline ssize_t ovl_path_getxattr(struct ovl_fs *ofs,
314 const struct path *path,
315 enum ovl_xattr ox, void *value,
316 size_t size)
317 {
318 return ovl_do_getxattr(path, ovl_xattr(ofs, ox), value, size);
319 }
320
ovl_do_setxattr(struct ovl_fs * ofs,struct dentry * dentry,const char * name,const void * value,size_t size,int flags)321 static inline int ovl_do_setxattr(struct ovl_fs *ofs, struct dentry *dentry,
322 const char *name, const void *value,
323 size_t size, int flags)
324 {
325 /* Use vfs_setxattr(), not __vfs_setxattr(): it idmaps the security.capability rootid. */
326 int err = vfs_setxattr(ovl_upper_mnt_idmap(ofs), dentry, name,
327 value, size, flags);
328
329 pr_debug("setxattr(%pd2, \"%s\", \"%*pE\", %zu, %d) = %i\n",
330 dentry, name, min((int)size, 48), value, size, flags, err);
331 return err;
332 }
333
ovl_setxattr(struct ovl_fs * ofs,struct dentry * dentry,enum ovl_xattr ox,const void * value,size_t size)334 static inline int ovl_setxattr(struct ovl_fs *ofs, struct dentry *dentry,
335 enum ovl_xattr ox, const void *value,
336 size_t size)
337 {
338 return ovl_do_setxattr(ofs, dentry, ovl_xattr(ofs, ox), value, size, 0);
339 }
340
ovl_do_removexattr(struct ovl_fs * ofs,struct dentry * dentry,const char * name)341 static inline int ovl_do_removexattr(struct ovl_fs *ofs, struct dentry *dentry,
342 const char *name)
343 {
344 int err = vfs_removexattr(ovl_upper_mnt_idmap(ofs), dentry, name);
345 pr_debug("removexattr(%pd2, \"%s\") = %i\n", dentry, name, err);
346 return err;
347 }
348
ovl_removexattr(struct ovl_fs * ofs,struct dentry * dentry,enum ovl_xattr ox)349 static inline int ovl_removexattr(struct ovl_fs *ofs, struct dentry *dentry,
350 enum ovl_xattr ox)
351 {
352 return ovl_do_removexattr(ofs, dentry, ovl_xattr(ofs, ox));
353 }
354
ovl_do_set_acl(struct ovl_fs * ofs,struct dentry * dentry,const char * acl_name,struct posix_acl * acl)355 static inline int ovl_do_set_acl(struct ovl_fs *ofs, struct dentry *dentry,
356 const char *acl_name, struct posix_acl *acl)
357 {
358 return vfs_set_acl(ovl_upper_mnt_idmap(ofs), dentry, acl_name, acl);
359 }
360
ovl_do_remove_acl(struct ovl_fs * ofs,struct dentry * dentry,const char * acl_name)361 static inline int ovl_do_remove_acl(struct ovl_fs *ofs, struct dentry *dentry,
362 const char *acl_name)
363 {
364 return vfs_remove_acl(ovl_upper_mnt_idmap(ofs), dentry, acl_name);
365 }
366
ovl_do_rename_rd(struct renamedata * rd)367 static inline int ovl_do_rename_rd(struct renamedata *rd)
368 {
369 int err;
370
371 pr_debug("rename(%pd2, %pd2, 0x%x)\n", rd->old_dentry, rd->new_dentry,
372 rd->flags);
373 err = vfs_rename(rd);
374 if (err) {
375 pr_debug("...rename(%pd2, %pd2, ...) = %i\n",
376 rd->old_dentry, rd->new_dentry, err);
377 }
378 return err;
379 }
380
ovl_do_rename(struct ovl_fs * ofs,struct dentry * olddir,struct dentry * olddentry,struct dentry * newdir,struct dentry * newdentry,unsigned int flags)381 static inline int ovl_do_rename(struct ovl_fs *ofs, struct dentry *olddir,
382 struct dentry *olddentry, struct dentry *newdir,
383 struct dentry *newdentry, unsigned int flags)
384 {
385 struct renamedata rd = {
386 .mnt_idmap = ovl_upper_mnt_idmap(ofs),
387 .old_parent = olddir,
388 .old_dentry = olddentry,
389 .new_parent = newdir,
390 .new_dentry = newdentry,
391 .flags = flags,
392 };
393
394 return ovl_do_rename_rd(&rd);
395 }
396
ovl_do_whiteout(struct ovl_fs * ofs,struct inode * dir,struct dentry * dentry)397 static inline int ovl_do_whiteout(struct ovl_fs *ofs,
398 struct inode *dir, struct dentry *dentry)
399 {
400 int err = vfs_whiteout(ovl_upper_mnt_idmap(ofs), dir, dentry);
401 pr_debug("whiteout(%pd2) = %i\n", dentry, err);
402 return err;
403 }
404
ovl_do_tmpfile(struct ovl_fs * ofs,struct dentry * dentry,umode_t mode)405 static inline struct file *ovl_do_tmpfile(struct ovl_fs *ofs,
406 struct dentry *dentry, umode_t mode)
407 {
408 struct path path = { .mnt = ovl_upper_mnt(ofs), .dentry = dentry };
409 struct file *file = kernel_tmpfile_open(ovl_upper_mnt_idmap(ofs), &path,
410 mode, O_LARGEFILE | O_WRONLY,
411 current_cred());
412 int err = PTR_ERR_OR_ZERO(file);
413
414 pr_debug("tmpfile(%pd2, 0%o) = %i\n", dentry, mode, err);
415 return file;
416 }
417
ovl_lookup_upper_unlocked(struct ovl_fs * ofs,const char * name,struct dentry * base,int len)418 static inline struct dentry *ovl_lookup_upper_unlocked(struct ovl_fs *ofs,
419 const char *name,
420 struct dentry *base,
421 int len)
422 {
423 return lookup_one_unlocked(ovl_upper_mnt_idmap(ofs),
424 &QSTR_LEN(name, len), base);
425 }
426
ovl_start_creating_upper(struct ovl_fs * ofs,struct dentry * parent,struct qstr * name)427 static inline struct dentry *ovl_start_creating_upper(struct ovl_fs *ofs,
428 struct dentry *parent,
429 struct qstr *name)
430 {
431 return start_creating(ovl_upper_mnt_idmap(ofs),
432 parent, name);
433 }
434
ovl_start_removing_upper(struct ovl_fs * ofs,struct dentry * parent,struct qstr * name)435 static inline struct dentry *ovl_start_removing_upper(struct ovl_fs *ofs,
436 struct dentry *parent,
437 struct qstr *name)
438 {
439 return start_removing(ovl_upper_mnt_idmap(ofs),
440 parent, name);
441 }
442
ovl_open_flags_need_copy_up(int flags)443 static inline bool ovl_open_flags_need_copy_up(int flags)
444 {
445 if (!flags)
446 return false;
447
448 return ((OPEN_FMODE(flags) & FMODE_WRITE) || (flags & O_TRUNC));
449 }
450
451 /* util.c */
452 int ovl_get_write_access(struct dentry *dentry);
453 void ovl_put_write_access(struct dentry *dentry);
454 void ovl_start_write(struct dentry *dentry);
455 void ovl_end_write(struct dentry *dentry);
456 int ovl_want_write(struct dentry *dentry);
457 void ovl_drop_write(struct dentry *dentry);
458 struct dentry *ovl_workdir(struct dentry *dentry);
459 const struct cred *ovl_override_creds(struct super_block *sb);
460
EXTEND_CLASS(override_creds,_ovl,ovl_override_creds (sb),struct super_block * sb)461 EXTEND_CLASS(override_creds, _ovl, ovl_override_creds(sb), struct super_block *sb)
462
463 #define with_ovl_creds(sb) \
464 scoped_class(override_creds_ovl, __UNIQUE_ID(label), sb)
465
466 static inline const struct cred *ovl_creds(struct super_block *sb)
467 {
468 return OVL_FS(sb)->creator_cred;
469 }
470
471 int ovl_can_decode_fh(struct super_block *sb);
472 struct dentry *ovl_indexdir(struct super_block *sb);
473 bool ovl_index_all(struct super_block *sb);
474 bool ovl_verify_lower(struct super_block *sb);
475 struct ovl_path *ovl_stack_alloc(unsigned int n);
476 void ovl_stack_cpy(struct ovl_path *dst, struct ovl_path *src, unsigned int n);
477 void ovl_stack_put(struct ovl_path *stack, unsigned int n);
478 void ovl_stack_free(struct ovl_path *stack, unsigned int n);
479 struct ovl_entry *ovl_alloc_entry(unsigned int numlower);
480 void ovl_free_entry(struct ovl_entry *oe);
481 bool ovl_dentry_remote(struct dentry *dentry);
482 void ovl_dentry_update_reval(struct dentry *dentry, struct dentry *realdentry);
483 void ovl_dentry_init_reval(struct dentry *dentry, struct dentry *upperdentry,
484 struct ovl_entry *oe);
485 void ovl_dentry_init_flags(struct dentry *dentry, struct dentry *upperdentry,
486 struct ovl_entry *oe, unsigned int mask);
487 bool ovl_dentry_weird(struct dentry *dentry);
488
ovl_dentry_casefolded(struct dentry * dentry)489 static inline bool ovl_dentry_casefolded(struct dentry *dentry)
490 {
491 return sb_has_encoding(dentry->d_sb) && IS_CASEFOLDED(d_inode(dentry));
492 }
493
494 enum ovl_path_type ovl_path_type(struct dentry *dentry);
495 void ovl_path_upper(struct dentry *dentry, struct path *path);
496 void ovl_path_lower(struct dentry *dentry, struct path *path);
497 void ovl_path_lowerdata(struct dentry *dentry, struct path *path);
498 struct inode *ovl_i_path_real(struct inode *inode, struct path *path);
499 enum ovl_path_type ovl_path_real(struct dentry *dentry, struct path *path);
500 enum ovl_path_type ovl_path_realdata(struct dentry *dentry, struct path *path);
501 struct dentry *ovl_dentry_upper(struct dentry *dentry);
502 struct dentry *ovl_dentry_lower(struct dentry *dentry);
503 struct dentry *ovl_dentry_lowerdata(struct dentry *dentry);
504 int ovl_dentry_set_lowerdata(struct dentry *dentry, struct ovl_path *datapath);
505 const struct ovl_layer *ovl_i_layer_lower(struct inode *inode);
506 const struct ovl_layer *ovl_layer_lower(struct dentry *dentry);
507 struct dentry *ovl_dentry_real(struct dentry *dentry);
508 struct dentry *ovl_i_dentry_upper(struct inode *inode);
509 struct inode *ovl_inode_upper(struct inode *inode);
510 struct inode *ovl_inode_lower(struct inode *inode);
511 struct inode *ovl_inode_lowerdata(struct inode *inode);
512 struct inode *ovl_inode_real(struct inode *inode);
513 struct inode *ovl_inode_realdata(struct inode *inode);
514 const char *ovl_lowerdata_redirect(struct inode *inode);
515 struct ovl_dir_cache *ovl_dir_cache(struct inode *inode);
516 void ovl_set_dir_cache(struct inode *inode, struct ovl_dir_cache *cache);
517 void ovl_dentry_set_flag(unsigned long flag, struct dentry *dentry);
518 void ovl_dentry_clear_flag(unsigned long flag, struct dentry *dentry);
519 bool ovl_dentry_test_flag(unsigned long flag, struct dentry *dentry);
520 bool ovl_dentry_is_opaque(struct dentry *dentry);
521 bool ovl_dentry_is_whiteout(struct dentry *dentry);
522 void ovl_dentry_set_opaque(struct dentry *dentry);
523 bool ovl_dentry_has_xwhiteouts(struct dentry *dentry);
524 void ovl_dentry_set_xwhiteouts(struct dentry *dentry);
525 void ovl_layer_set_xwhiteouts(struct ovl_fs *ofs,
526 const struct ovl_layer *layer);
527 bool ovl_dentry_has_upper_alias(struct dentry *dentry);
528 void ovl_dentry_set_upper_alias(struct dentry *dentry);
529 bool ovl_dentry_needs_data_copy_up(struct dentry *dentry, int flags);
530 bool ovl_dentry_needs_data_copy_up_locked(struct dentry *dentry, int flags);
531 bool ovl_has_upperdata(struct inode *inode);
532 void ovl_set_upperdata(struct inode *inode);
533 const char *ovl_dentry_get_redirect(struct dentry *dentry);
534 void ovl_dentry_set_redirect(struct dentry *dentry, const char *redirect);
535 void ovl_inode_update(struct inode *inode, struct dentry *upperdentry);
536 void ovl_dir_modified(struct dentry *dentry, bool impurity);
537 u64 ovl_inode_version_get(struct inode *inode);
538 bool ovl_is_whiteout(struct dentry *dentry);
539 bool ovl_path_is_whiteout(struct ovl_fs *ofs, const struct path *path);
540 struct file *ovl_path_open(const struct path *path, int flags);
541 int ovl_copy_up_start(struct dentry *dentry, int flags);
542 void ovl_copy_up_end(struct dentry *dentry);
543 bool ovl_already_copied_up(struct dentry *dentry, int flags);
544 char ovl_get_dir_xattr_val(struct ovl_fs *ofs, const struct path *path,
545 enum ovl_xattr ox);
546 bool ovl_path_check_origin_xattr(struct ovl_fs *ofs, const struct path *path);
547 bool ovl_path_check_xwhiteout_xattr(struct ovl_fs *ofs, const struct path *path);
548 bool ovl_init_uuid_xattr(struct super_block *sb, struct ovl_fs *ofs,
549 const struct path *upperpath);
550
ovl_upper_is_whiteout(struct ovl_fs * ofs,struct dentry * upperdentry)551 static inline bool ovl_upper_is_whiteout(struct ovl_fs *ofs,
552 struct dentry *upperdentry)
553 {
554 struct path upperpath = {
555 .dentry = upperdentry,
556 .mnt = ovl_upper_mnt(ofs),
557 };
558 return ovl_path_is_whiteout(ofs, &upperpath);
559 }
560
ovl_check_origin_xattr(struct ovl_fs * ofs,struct dentry * upperdentry)561 static inline bool ovl_check_origin_xattr(struct ovl_fs *ofs,
562 struct dentry *upperdentry)
563 {
564 struct path upperpath = {
565 .dentry = upperdentry,
566 .mnt = ovl_upper_mnt(ofs),
567 };
568 return ovl_path_check_origin_xattr(ofs, &upperpath);
569 }
570
571 int ovl_check_setxattr(struct ovl_fs *ofs, struct dentry *upperdentry,
572 enum ovl_xattr ox, const void *value, size_t size,
573 int xerr);
574 int ovl_set_impure(struct dentry *dentry, struct dentry *upperdentry);
575 bool ovl_inuse_trylock(struct dentry *dentry);
576 void ovl_inuse_unlock(struct dentry *dentry);
577 bool ovl_is_inuse(struct dentry *dentry);
578 bool ovl_need_index(struct dentry *dentry);
579 int ovl_nlink_start(struct dentry *dentry);
580 void ovl_nlink_end(struct dentry *dentry);
581 int ovl_check_metacopy_xattr(struct ovl_fs *ofs, const struct path *path,
582 struct ovl_metacopy *data);
583 int ovl_set_metacopy_xattr(struct ovl_fs *ofs, struct dentry *d,
584 struct ovl_metacopy *metacopy);
585 bool ovl_is_metacopy_dentry(struct dentry *dentry);
586 char *ovl_get_redirect_xattr(struct ovl_fs *ofs, const struct path *path, int padding);
587 int ovl_ensure_verity_loaded(const struct path *path);
588 int ovl_validate_verity(struct ovl_fs *ofs,
589 const struct path *metapath,
590 const struct path *datapath);
591 int ovl_get_verity_digest(struct ovl_fs *ofs, const struct path *src,
592 struct ovl_metacopy *metacopy);
593 int ovl_sync_status(struct ovl_fs *ofs);
594
ovl_set_flag(unsigned long flag,struct inode * inode)595 static inline void ovl_set_flag(unsigned long flag, struct inode *inode)
596 {
597 set_bit(flag, &OVL_I(inode)->flags);
598 }
599
ovl_clear_flag(unsigned long flag,struct inode * inode)600 static inline void ovl_clear_flag(unsigned long flag, struct inode *inode)
601 {
602 clear_bit(flag, &OVL_I(inode)->flags);
603 }
604
ovl_test_flag(unsigned long flag,struct inode * inode)605 static inline bool ovl_test_flag(unsigned long flag, struct inode *inode)
606 {
607 return test_bit(flag, &OVL_I(inode)->flags);
608 }
609
ovl_is_impuredir(struct super_block * sb,struct dentry * upperdentry)610 static inline bool ovl_is_impuredir(struct super_block *sb,
611 struct dentry *upperdentry)
612 {
613 struct ovl_fs *ofs = OVL_FS(sb);
614 struct path upperpath = {
615 .dentry = upperdentry,
616 .mnt = ovl_upper_mnt(ofs),
617 };
618
619 return ovl_get_dir_xattr_val(ofs, &upperpath, OVL_XATTR_IMPURE) == 'y';
620 }
621
ovl_get_opaquedir_val(struct ovl_fs * ofs,const struct path * path)622 static inline char ovl_get_opaquedir_val(struct ovl_fs *ofs,
623 const struct path *path)
624 {
625 return ovl_get_dir_xattr_val(ofs, path, OVL_XATTR_OPAQUE);
626 }
627
ovl_redirect_follow(struct ovl_fs * ofs)628 static inline bool ovl_redirect_follow(struct ovl_fs *ofs)
629 {
630 return ofs->config.redirect_mode != OVL_REDIRECT_NOFOLLOW;
631 }
632
ovl_redirect_dir(struct ovl_fs * ofs)633 static inline bool ovl_redirect_dir(struct ovl_fs *ofs)
634 {
635 return ofs->config.redirect_mode == OVL_REDIRECT_ON;
636 }
637
ovl_origin_uuid(struct ovl_fs * ofs)638 static inline bool ovl_origin_uuid(struct ovl_fs *ofs)
639 {
640 return ofs->config.uuid != OVL_UUID_OFF;
641 }
642
ovl_has_fsid(struct ovl_fs * ofs)643 static inline bool ovl_has_fsid(struct ovl_fs *ofs)
644 {
645 return ofs->config.uuid == OVL_UUID_ON ||
646 ofs->config.uuid == OVL_UUID_AUTO;
647 }
648
649 /*
650 * With xino=auto, we do best effort to keep all inodes on same st_dev and
651 * d_ino consistent with st_ino.
652 * With xino=on, we do the same effort but we warn if we failed.
653 */
ovl_xino_warn(struct ovl_fs * ofs)654 static inline bool ovl_xino_warn(struct ovl_fs *ofs)
655 {
656 return ofs->config.xino == OVL_XINO_ON;
657 }
658
ovl_should_sync(struct ovl_fs * ofs)659 static inline bool ovl_should_sync(struct ovl_fs *ofs)
660 {
661 return ofs->config.fsync_mode != OVL_FSYNC_VOLATILE;
662 }
663
ovl_should_sync_metadata(struct ovl_fs * ofs)664 static inline bool ovl_should_sync_metadata(struct ovl_fs *ofs)
665 {
666 return ofs->config.fsync_mode == OVL_FSYNC_STRICT;
667 }
668
ovl_is_volatile(struct ovl_config * config)669 static inline bool ovl_is_volatile(struct ovl_config *config)
670 {
671 return config->fsync_mode == OVL_FSYNC_VOLATILE;
672 }
673
674 /*
675 * To avoid regressions in existing setups with overlay lower offline changes,
676 * we allow lower changes only if none of the new features are used.
677 */
ovl_allow_offline_changes(struct ovl_fs * ofs)678 static inline bool ovl_allow_offline_changes(struct ovl_fs *ofs)
679 {
680 return (!ofs->config.index && !ofs->config.metacopy &&
681 !ovl_redirect_dir(ofs) && !ovl_xino_warn(ofs));
682 }
683
684 /* All layers on same fs? */
ovl_same_fs(struct ovl_fs * ofs)685 static inline bool ovl_same_fs(struct ovl_fs *ofs)
686 {
687 return ofs->xino_mode == 0;
688 }
689
690 /* All overlay inodes have same st_dev? */
ovl_same_dev(struct ovl_fs * ofs)691 static inline bool ovl_same_dev(struct ovl_fs *ofs)
692 {
693 return ofs->xino_mode >= 0;
694 }
695
ovl_xino_bits(struct ovl_fs * ofs)696 static inline unsigned int ovl_xino_bits(struct ovl_fs *ofs)
697 {
698 return ovl_same_dev(ofs) ? ofs->xino_mode : 0;
699 }
700
ovl_inode_lock(struct inode * inode)701 static inline void ovl_inode_lock(struct inode *inode)
702 {
703 mutex_lock(&OVL_I(inode)->lock);
704 }
705
ovl_inode_lock_interruptible(struct inode * inode)706 static inline int ovl_inode_lock_interruptible(struct inode *inode)
707 {
708 return mutex_lock_interruptible(&OVL_I(inode)->lock);
709 }
710
ovl_inode_unlock(struct inode * inode)711 static inline void ovl_inode_unlock(struct inode *inode)
712 {
713 mutex_unlock(&OVL_I(inode)->lock);
714 }
715
716
717 /* namei.c */
718 int ovl_check_fb_len(struct ovl_fb *fb, int fb_len);
719
ovl_check_fh_len(struct ovl_fh * fh,int fh_len)720 static inline int ovl_check_fh_len(struct ovl_fh *fh, int fh_len)
721 {
722 if (fh_len < sizeof(struct ovl_fh))
723 return -EINVAL;
724
725 return ovl_check_fb_len(&fh->fb, fh_len - OVL_FH_WIRE_OFFSET);
726 }
727
728 bool ovl_uuid_match(struct ovl_fs *ofs, const struct super_block *sb,
729 const uuid_t *uuid);
730 struct dentry *ovl_decode_real_fh(struct ovl_fs *ofs, struct ovl_fh *fh,
731 struct vfsmount *mnt, bool connected);
732 int ovl_check_origin_fh(struct ovl_fs *ofs, struct ovl_fh *fh, bool connected,
733 struct dentry *upperdentry, struct ovl_path **stackp);
734 int ovl_verify_set_fh(struct ovl_fs *ofs, struct dentry *dentry,
735 enum ovl_xattr ox, const struct ovl_fh *fh,
736 bool is_upper, bool set);
737 int ovl_verify_origin_xattr(struct ovl_fs *ofs, struct dentry *dentry,
738 enum ovl_xattr ox, struct dentry *real,
739 bool is_upper, bool set);
740 struct dentry *ovl_index_upper(struct ovl_fs *ofs, struct dentry *index,
741 bool connected);
742 int ovl_verify_index(struct ovl_fs *ofs, struct dentry *index);
743 int ovl_get_index_name_fh(const struct ovl_fh *fh, struct qstr *name);
744 int ovl_get_index_name(struct ovl_fs *ofs, struct dentry *origin,
745 struct qstr *name);
746 struct dentry *ovl_get_index_fh(struct ovl_fs *ofs, struct ovl_fh *fh);
747 struct dentry *ovl_lookup_index(struct ovl_fs *ofs, struct dentry *upper,
748 struct dentry *origin, bool verify);
749 int ovl_path_next(int idx, struct dentry *dentry, struct path *path,
750 const struct ovl_layer **layer);
751 int ovl_verify_lowerdata(struct dentry *dentry);
752 struct dentry *ovl_lookup(struct inode *dir, struct dentry *dentry,
753 unsigned int flags);
754 bool ovl_lower_positive(struct dentry *dentry);
755
ovl_verify_origin_fh(struct ovl_fs * ofs,struct dentry * upper,const struct ovl_fh * fh,bool set)756 static inline int ovl_verify_origin_fh(struct ovl_fs *ofs, struct dentry *upper,
757 const struct ovl_fh *fh, bool set)
758 {
759 return ovl_verify_set_fh(ofs, upper, OVL_XATTR_ORIGIN, fh, false, set);
760 }
761
ovl_verify_origin(struct ovl_fs * ofs,struct dentry * upper,struct dentry * origin,bool set)762 static inline int ovl_verify_origin(struct ovl_fs *ofs, struct dentry *upper,
763 struct dentry *origin, bool set)
764 {
765 return ovl_verify_origin_xattr(ofs, upper, OVL_XATTR_ORIGIN, origin,
766 false, set);
767 }
768
ovl_verify_upper(struct ovl_fs * ofs,struct dentry * index,struct dentry * upper,bool set)769 static inline int ovl_verify_upper(struct ovl_fs *ofs, struct dentry *index,
770 struct dentry *upper, bool set)
771 {
772 return ovl_verify_origin_xattr(ofs, index, OVL_XATTR_UPPER, upper,
773 true, set);
774 }
775
776 /* readdir.c */
777 extern const struct file_operations ovl_dir_operations;
778 struct file *ovl_dir_real_file(const struct file *file, bool want_upper);
779 int ovl_check_empty_dir(struct dentry *dentry, struct list_head *list);
780 void ovl_cleanup_whiteouts(struct ovl_fs *ofs, struct dentry *upper,
781 struct list_head *list);
782 void ovl_cache_free(struct list_head *list);
783 void ovl_dir_cache_free(struct inode *inode);
784 int ovl_check_d_type_supported(const struct path *realpath);
785 int ovl_workdir_cleanup(struct ovl_fs *ofs, struct dentry *parent,
786 struct vfsmount *mnt, struct dentry *dentry, int level);
787 int ovl_indexdir_cleanup(struct ovl_fs *ofs);
788
789 /*
790 * Can we iterate real dir directly?
791 *
792 * Non-merge dir may contain whiteouts from a time it was a merge upper, before
793 * lower dir was removed under it and possibly before it was rotated from upper
794 * to lower layer.
795 */
ovl_dir_is_real(struct inode * dir)796 static inline bool ovl_dir_is_real(struct inode *dir)
797 {
798 return !ovl_test_flag(OVL_WHITEOUTS, dir);
799 }
800
801 /* inode.c */
802 int ovl_set_nlink_upper(struct dentry *dentry);
803 int ovl_set_nlink_lower(struct dentry *dentry);
804 unsigned int ovl_get_nlink(struct ovl_fs *ofs, struct dentry *lowerdentry,
805 struct dentry *upperdentry,
806 unsigned int fallback);
807 int ovl_permission(struct mnt_idmap *idmap, struct inode *inode,
808 int mask);
809
810 #ifdef CONFIG_FS_POSIX_ACL
811 struct posix_acl *do_ovl_get_acl(struct mnt_idmap *idmap,
812 struct inode *inode, int type,
813 bool rcu, bool noperm);
ovl_get_inode_acl(struct inode * inode,int type,bool rcu)814 static inline struct posix_acl *ovl_get_inode_acl(struct inode *inode, int type,
815 bool rcu)
816 {
817 return do_ovl_get_acl(&nop_mnt_idmap, inode, type, rcu, true);
818 }
ovl_get_acl(struct mnt_idmap * idmap,struct dentry * dentry,int type)819 static inline struct posix_acl *ovl_get_acl(struct mnt_idmap *idmap,
820 struct dentry *dentry, int type)
821 {
822 return do_ovl_get_acl(idmap, d_inode(dentry), type, false, false);
823 }
824 int ovl_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
825 struct posix_acl *acl, int type);
826 struct posix_acl *ovl_get_acl_path(const struct path *path,
827 const char *acl_name, bool noperm);
828 #else
829 #define ovl_get_inode_acl NULL
830 #define ovl_get_acl NULL
831 #define ovl_set_acl NULL
ovl_get_acl_path(const struct path * path,const char * acl_name,bool noperm)832 static inline struct posix_acl *ovl_get_acl_path(const struct path *path,
833 const char *acl_name,
834 bool noperm)
835 {
836 return NULL;
837 }
838 #endif
839
840 int ovl_update_time(struct inode *inode, enum fs_update_time type,
841 unsigned int flags);
842 bool ovl_is_private_xattr(struct super_block *sb, const char *name);
843
844 struct ovl_inode_params {
845 struct inode *newinode;
846 struct dentry *upperdentry;
847 struct ovl_entry *oe;
848 bool index;
849 char *redirect;
850 char *lowerdata_redirect;
851 };
852 void ovl_inode_init(struct inode *inode, struct ovl_inode_params *oip,
853 unsigned long ino, int fsid);
854 struct inode *ovl_new_inode(struct super_block *sb, umode_t mode, dev_t rdev);
855 struct inode *ovl_lookup_inode(struct super_block *sb, struct dentry *real,
856 bool is_upper);
857 bool ovl_lookup_trap_inode(struct super_block *sb, struct dentry *dir);
858 struct inode *ovl_get_trap_inode(struct super_block *sb, struct dentry *dir);
859 struct inode *ovl_get_inode(struct super_block *sb,
860 struct ovl_inode_params *oip);
861 void ovl_copyattr(struct inode *to);
862
863 /* vfs fileattr flags read from overlay.protattr xattr to ovl inode */
864 #define OVL_PROT_I_FLAGS_MASK (S_APPEND | S_IMMUTABLE)
865 /* vfs fileattr flags copied from real to ovl inode */
866 #define OVL_FATTR_I_FLAGS_MASK (OVL_PROT_I_FLAGS_MASK | S_SYNC | S_NOATIME)
867 /* vfs inode flags copied from real to ovl inode */
868 #define OVL_COPY_I_FLAGS_MASK (OVL_FATTR_I_FLAGS_MASK | S_CASEFOLD)
869
870 /*
871 * fileattr flags copied from lower to upper inode on copy up.
872 * We cannot copy up immutable/append-only flags, because that would prevent
873 * linking temp inode to upper dir, so we store them in xattr instead.
874 */
875 #define OVL_COPY_FS_FLAGS_MASK (FS_SYNC_FL | FS_NOATIME_FL)
876 #define OVL_COPY_FSX_FLAGS_MASK (FS_XFLAG_SYNC | FS_XFLAG_NOATIME)
877 #define OVL_PROT_FS_FLAGS_MASK (FS_APPEND_FL | FS_IMMUTABLE_FL)
878 #define OVL_PROT_FSX_FLAGS_MASK (FS_XFLAG_APPEND | FS_XFLAG_IMMUTABLE)
879
880 void ovl_check_protattr(struct inode *inode, struct dentry *upper);
881 int ovl_set_protattr(struct inode *inode, struct dentry *upper,
882 struct file_kattr *fa);
883
ovl_copyflags(struct inode * from,struct inode * to)884 static inline void ovl_copyflags(struct inode *from, struct inode *to)
885 {
886 unsigned int mask = OVL_COPY_I_FLAGS_MASK;
887
888 inode_set_flags(to, from->i_flags & mask, mask);
889 }
890
891 /* dir.c */
892 extern const struct inode_operations ovl_dir_inode_operations;
893 int ovl_cleanup_and_whiteout(struct ovl_fs *ofs, struct dentry *dir,
894 struct dentry *dentry);
895 struct ovl_cattr {
896 dev_t rdev;
897 umode_t mode;
898 const char *link;
899 struct dentry *hardlink;
900 };
901
902 #define OVL_CATTR(m) (&(struct ovl_cattr) { .mode = (m) })
903
904 struct dentry *ovl_create_real(struct ovl_fs *ofs,
905 struct dentry *parent, struct dentry *newdentry,
906 struct qstr *qname,
907 struct ovl_cattr *attr);
908 int ovl_cleanup(struct ovl_fs *ofs, struct dentry *workdir, struct dentry *dentry);
909 #define OVL_TEMPNAME_SIZE 20
910 void ovl_tempname(char name[OVL_TEMPNAME_SIZE]);
911 struct dentry *ovl_create_temp(struct ovl_fs *ofs, struct dentry *workdir,
912 struct ovl_cattr *attr);
913
914 /* file.c */
915 extern const struct file_operations ovl_file_operations;
916 int ovl_real_fileattr_get(const struct path *realpath, struct file_kattr *fa);
917 int ovl_real_fileattr_set(const struct path *realpath, struct file_kattr *fa);
918 int ovl_fileattr_get(struct dentry *dentry, struct file_kattr *fa);
919 int ovl_fileattr_set(struct mnt_idmap *idmap,
920 struct dentry *dentry, struct file_kattr *fa);
921 struct ovl_file;
922 struct ovl_file *ovl_file_alloc(struct file *realfile);
923 void ovl_file_free(struct ovl_file *of);
924
925 /* copy_up.c */
926 int ovl_copy_up(struct dentry *dentry);
927 int ovl_copy_up_with_data(struct dentry *dentry);
928 int ovl_maybe_copy_up(struct dentry *dentry, int flags);
929 int ovl_copy_xattr(struct super_block *sb, const struct path *path, struct dentry *new);
930 int ovl_set_attr(struct ovl_fs *ofs, struct dentry *upper, struct kstat *stat);
931 struct ovl_fh *ovl_encode_real_fh(struct ovl_fs *ofs, struct inode *realinode,
932 bool is_upper);
933 struct ovl_fh *ovl_get_origin_fh(struct ovl_fs *ofs, struct dentry *origin);
934 int ovl_set_origin_fh(struct ovl_fs *ofs, const struct ovl_fh *fh,
935 struct dentry *upper);
936
937 /* export.c */
938 extern const struct export_operations ovl_export_operations;
939 extern const struct export_operations ovl_export_fid_operations;
940
941 /* super.c */
942 int ovl_fill_super(struct super_block *sb, struct fs_context *fc);
943
944 /* Will this overlay be forced to mount/remount ro? */
ovl_force_readonly(struct ovl_fs * ofs)945 static inline bool ovl_force_readonly(struct ovl_fs *ofs)
946 {
947 return (!ovl_upper_mnt(ofs) || !ofs->workdir);
948 }
949
950 /* xattr.c */
951
952 const struct xattr_handler * const *ovl_xattr_handlers(struct ovl_fs *ofs);
953 int ovl_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
954 struct iattr *attr);
955 int ovl_getattr(struct mnt_idmap *idmap, const struct path *path,
956 struct kstat *stat, u32 request_mask, unsigned int flags);
957 ssize_t ovl_listxattr(struct dentry *dentry, char *list, size_t size);
958